Data Retention Policy
Last updated: 25 August 2026
Purpose
This policy defines how long Teacher's Buddy retains different categories of data and how data is disposed of when no longer required.
Retention Periods
| Data Category | Retention Period |
|---|---|
| User accounts and organisation memberships | While the account or relevant service relationship remains active, then until deletion is completed or continued retention is required for legal, security or dispute-resolution purposes |
| Generated content, workspaces and AI conversation history | Until deleted through an available product control, an authorised account or organisation deletion process, or an agreed contractual offboarding process |
| Uploaded resources and generated files | Until deleted through an available product control or an authorised deletion/offboarding process; residual copies may remain temporarily in backups, caches or provider systems |
| Session data | 7 days (refreshed on daily activity) |
| Magic link tokens | 15 minutes |
| Email OTP codes | 10 minutes |
| Organisation invitations | 7 days |
| AI-provider request data | As required to provide the requested feature and under the selected provider's contractual terms and configured retention controls |
| Operational, diagnostic and security records | For the period reasonably required for reliability, support, fraud prevention, security investigation and legal obligations, subject to system-specific retention settings |
| Billing and transaction records | For the period required by applicable tax, accounting, contractual and legal obligations |
| Primary database point-in-time backups | Generally up to 7 days under the current operational configuration, then automatically aged out by the provider |
Your Rights
- Access and data copy: You can export supported teaching artifacts using available product controls. For a copy of personal information not covered by those controls, email privacy@teachersbuddy.com.
- Account deletion: Where self-service account deletion is available, it removes the account and the database records covered by that workflow. You may contact us for a broader privacy deletion request.
- Content deletion: You can delete supported outputs, workspaces and resources using the controls available for that content and your role.
Account Deletion
When self-service account deletion is completed:
- The account and supported associated records are deleted from the primary operational database, subject to ownership, shared-organisation and referential-integrity rules.
- Authentication sessions and connected-account records covered by the workflow are revoked or deleted.
- Deletion does not immediately remove residual copies from backups, security records, billing records, third-party systems or records controlled by a school. Those records are handled under their applicable retention periods and legal basis.
- Some uploaded or generated files may require separate deletion processing. Contact privacy@teachersbuddy.com if you require a broader erasure assessment or confirmation.
Organisation Agreement Termination
Organisation offboarding is handled under the applicable customer agreement and the authorised school's instructions. Ending an organisation agreement does not automatically delete independently owned user accounts or every record associated with those users. Before termination, authorised administrators should contact us to agree any required export, access transition, retention, deletion and written-confirmation steps.
Deletion Limitations and Exceptions
We may retain limited information where reasonably necessary to comply with law, protect the security and integrity of the Service, prevent fraud, resolve disputes, enforce agreements or maintain an appropriate audit record. Where a school controls the relevant information, we may refer or coordinate a request with its authorised administrator.
Contact
Questions about data retention? Contact privacy@teachersbuddy.com