Skip to main content

Data Retention Policy

Version 2026-09-20Interim, under legal reviewContact theCoderSchool

We keep student data only as long as a student is learning with us, plus a fixed window so that a returning student finds their work. The numbers below are the site's defaults and are read from the same file the software uses.

Student accounts

StageWhenWhat happens
ActiveWhile the student is enrolledEverything on the Privacy Policy list is kept
ArchivedNo sign-in for 365 daysSign-in is disabled; name, progress and rewards record are kept so the account can be restored
Purged365 days after archivingThe account and its progress are deleted; an anonymised receipt with no name in it is kept

A parent can ask for deletion at any point instead of waiting; see Data & deletion.

Records the centre keeps

RecordKept forNotes
Audit log (who changed what, when)400 daysContains usernames and handles, never a student's legal name
Audit rows for credential reveals and deletions2 yearsLonger because they record staff access to sensitive actions
Reward records (rewards earned, asked for and paid)While the account existsDeleted with the account; the audit rows recording each payout stay for the audit log's period
Order records (online purchases)7 yearsAccounting; the payer's email is removed when the student's account is deleted
Consent recordWhile the account existsDeleted with the account
Friends and presence30 daysRefreshed while the student is active, then expire
Deletion receiptsIndefinitelyCounts and hashed identifiers only; no names

Residual copies we cannot edit

  • The database keeps a point-in-time recovery window of 7 days. Deleted data drops out of it on its own after that.
  • Server function logs are kept by Google Cloud for 30 days and then cleared.
  • Signed paper enrollment forms stay on paper at the centre under the centre's own records policy.

Review

This policy is reviewed when the numbers above change. The version date at the top of the page records the last change.