Retention is a promise about deletion, not about storage. The DPDP Act calls this storage limitation: data is kept only as long as the purpose needs it.
By category
| What | Kept for | Then |
|---|---|---|
| Account details — name, email, mobile, study stage | While the account is open | Deleted on request, or after the dormancy path below |
| Password hash | While the account is open | Deleted with the account |
| Teaching ID document | until 60 days after the verification decision | Kept for 60 days after the decision, so that a refusal can be explained and appealed, then destroyed automatically. It is used for verification and appeal only — never for marketing. |
| Consent records — what you agreed to, and when | Life of the account, plus 3 years | Deleted. Kept this long only to evidence a lawful basis |
| Sign-in and security logs | 12 months | Deleted |
| Error reports you send | 3 years | Deleted or anonymised |
| Rejected registrations | 6 months, to allow the one appeal | Deleted |
Dormancy
An account with no activity for 18 months is marked dormant. You are told before anything happens. If it stays dormant, it moves to deletion.
Deleting your account
Ask, and it is deleted. What survives is only what the law requires us to keep, and nothing that identifies you beyond that.
Deletion is real deletion, not a hidden flag. Backups roll off within 35 days, after which no copy exists.
What we cannot delete
If you have reported an error and it led to a correction, the correction stays — it is a change to the notes, not information about you, and it carries nothing identifying you.