Retention and deletion

A learning record needs an end condition.

Seneca keeps a record only for a stated account or program purpose. The table below is the current baseline; an executed school schedule must set shorter or more specific periods where required.

Data classCurrent baselineDeletion event
Consumer account and learning recordWhile the account remains active.Verified account-deletion request, subject to legal and school-record conflicts.
School-program learning recordNot accepted in production until the school schedule defines the program end and return/deletion instructions.Verified school instruction or scheduled program expiry.
Gmail connection stateWhile the user keeps the optional connection active.Disconnect immediately revokes access and removes stored mailbox identity and sync state.
OAuth codes and short-lived credentialsShort operational lifetime; expired records are swept.Expiry, revocation, or disconnect.
Security and audit eventsFeature-specific operational window.Scheduled cleanup unless a security or legal hold applies.
Provider backups and logsProvider-controlled recovery and security windows.A deleted record may persist temporarily in protected backups until provider rotation; it is not restored to active use except for disaster recovery.

How deletion works

  1. Vindica verifies the requester and whether the record is consumer-controlled or school-controlled.
  2. Active object storage and database records in the documented deletion manifest are removed.
  3. Authentication credentials are removed only after the data deletion succeeds.
  4. Failures remain open and are not reported as completed. The requester receives a result or a request identifier for follow-up.
Current limitation: the comprehensive cross-product deletion migration and rehearsal are still a production gate. Until that evidence exists, Vindica will not describe automated deletion as complete for an identifiable K–12 pilot.

Requesting deletion

Consumer users may use the in-product control or email kevinchoi@vindicaseneca.com. School-program requests should go to the school, which can send Vindica a verified instruction. Vindica’s target is to resolve verified requests within 30 days; if law or a school retention duty prevents deletion of specific records, Vindica will identify the category and reason instead of claiming full deletion.

Last reviewed: September 27, 2026 (deletion gate re-checked)