Retention and deletion
A learning record needs an end condition.
Seneca keeps a record only for a stated account or program purpose. The table below is the current baseline; an executed school schedule must set shorter or more specific periods where required.
| Data class | Current baseline | Deletion event |
|---|---|---|
| Consumer account and learning record | While the account remains active. | Verified account-deletion request, subject to legal and school-record conflicts. |
| School-program learning record | Not accepted in production until the school schedule defines the program end and return/deletion instructions. | Verified school instruction or scheduled program expiry. |
| Gmail connection state | While the user keeps the optional connection active. | Disconnect immediately revokes access and removes stored mailbox identity and sync state. |
| OAuth codes and short-lived credentials | Short operational lifetime; expired records are swept. | Expiry, revocation, or disconnect. |
| Security and audit events | Feature-specific operational window. | Scheduled cleanup unless a security or legal hold applies. |
| Provider backups and logs | Provider-controlled recovery and security windows. | A deleted record may persist temporarily in protected backups until provider rotation; it is not restored to active use except for disaster recovery. |
How deletion works
- Vindica verifies the requester and whether the record is consumer-controlled or school-controlled.
- Active object storage and database records in the documented deletion manifest are removed.
- Authentication credentials are removed only after the data deletion succeeds.
- Failures remain open and are not reported as completed. The requester receives a result or a request identifier for follow-up.
Current limitation: the comprehensive cross-product deletion migration and rehearsal are still a production gate. Until that evidence exists, Vindica will not describe automated deletion as complete for an identifiable K–12 pilot.
Requesting deletion
Consumer users may use the in-product control or email kevinchoi@vindicaseneca.com. School-program requests should go to the school, which can send Vindica a verified instruction. Vindica’s target is to resolve verified requests within 30 days; if law or a school retention duty prevents deletion of specific records, Vindica will identify the category and reason instead of claiming full deletion.