Retention that respects students
What we store, how long we keep it, and why short retention is a feature rather than a limitation.
Default to less
The safest data is the data you never stored. Our defaults:
- Message bodies: retained while the mailbox is active
- Temporary inboxes: purged at expiry, no grace period
- Attachment scans: verdict kept, payload discarded
- Access logs: 30 days
Deletion means deletion
When a mailbox expires we delete rows, not flags. Storage objects are removed in the same transaction window as the database rows.
Exporting before you leave
Every account can export its own data as JSON and CSV from settings. No support ticket, no waiting period.
Campus compliance
For FERPA and GDPR reviews we publish a data map covering every table, its purpose, its retention window and its lawful basis. Ask us for the current version and we will send it the same day.
About the author
Lena Fischer
Head of Trust & Privacy
Lena leads privacy engineering and campus compliance reviews, covering FERPA, GDPR and data-retention design.
All posts by Lena FischerComments are coming soon
We're wiring up a moderated discussion thread for each post. Until then, reply by email and we'll add good questions to the article.
Send us a note