Skip to content
Privacy & Security

Retention that respects students

What we store, how long we keep it, and why short retention is a feature rather than a limitation.

LELena Fischer5 min readUpdated 5 August 2026

Default to less

The safest data is the data you never stored. Our defaults:

  • Message bodies: retained while the mailbox is active
  • Temporary inboxes: purged at expiry, no grace period
  • Attachment scans: verdict kept, payload discarded
  • Access logs: 30 days

Deletion means deletion

When a mailbox expires we delete rows, not flags. Storage objects are removed in the same transaction window as the database rows.

Exporting before you leave

Every account can export its own data as JSON and CSV from settings. No support ticket, no waiting period.

Campus compliance

For FERPA and GDPR reviews we publish a data map covering every table, its purpose, its retention window and its lawful basis. Ask us for the current version and we will send it the same day.

Share

About the author

Lena Fischer

Head of Trust & Privacy

Lena leads privacy engineering and campus compliance reviews, covering FERPA, GDPR and data-retention design.

All posts by Lena Fischer

Comments are coming soon

We're wiring up a moderated discussion thread for each post. Until then, reply by email and we'll add good questions to the article.

Send us a note