AgenTeach

Public · Last updated July 27, 2026

Data Retention & Deletion Schedule

How long AgenTeach keeps each class of data, how deletion works, and the erasure, export, and legal-hold processes available to schools and districts. Referenced by our Privacy Policy.

Applies to: the AgenTeach service (portal.agentea.ch / api.agentea.ch)  ·  Questions: privacy@agentea.ch

This schedule applies to the student content itself — AgenTeach's U.S. Azure environment is the system of record.

Our deletion commitment, in plain terms

District-directed deletion from active systems, and backup expiration under documented lifecycle rules, subject to legal retention, audit, and legal-hold obligations.

We never promise unconditional, instant deletion from every backup medium — no honest vendor can. Deletion means: the record is hard-deleted from the active database immediately (on an erasure request) or at its scheduled window (routine purging), and any database backups containing it age out and are overwritten under our hosting provider's documented backup lifecycle rather than being editable on demand.

Routine retention windows

These windows are enforced by an automated daily purge (it runs on a scheduled trigger every day — it does not depend on anyone remembering). Windows are configurable per deployment at an LEA's direction.

Data classDefault retention
Unsent draft parent emails (never sent, no longer edited)365 days
Resolved alerts180 days
Completed sync-job records90 days
Archived evidence items365 days
Failed/abandoned communication inputs90 days
Raw uploaded audio (voice memos, pre-processing)24 hours
Temporary processing artifacts30 days

Records belonging to a student under an active legal hold are always skipped by the purge and reported separately. Audit-trail and correction-history records are never auto-purged — they are retained per district and security policy, and are removed only through student erasure (below).

Student erasure (rights-based deletion)

On an authorized request from a school or district administrator, AgenTeach hard-deletes, in a single transaction, every record linked to that student: enrollments, submissions, tasks, alerts, email drafts and records, evidence items, communication inputs, observation notes, guardian contacts, attendance events, communication logs, outreach records, uploaded files (including the stored file content itself), the student's correction history, and the student record. The action is recorded in our append-only audit trail using opaque identifiers and per-category counts only — never names or content.

Erasure requests are honored within 60 days (typically immediately), consistent with our LEA agreements. If the student is covered by an active legal hold, erasure is refused until the hold is released, and the refusal itself is auditable.

One honest caveat: if the district's own Google Workspace roster still lists the student, a later roster sync may re-create the basic directory entry (name/email) from the district's own system of record. Erasure covers AgenTeach-authored and derived records; it cannot remove a student from the district's own roster.

Student export

Administrators can export a complete, usable package of everything AgenTeach holds about a student — the full content of every linked record plus correction history and related audit metadata. Export is never blocked by a legal hold, so districts and counsel can always obtain a full copy of a student's records even while deletion is suspended. Every export is recorded in the audit trail (identifiers and counts only).

Legal holds

Districts can direct AgenTeach to place a hold at three scopes — a single student, a whole school, or the whole district. An active hold blocks erasure (never export) for its scope until released, and a hold's full lifecycle — creation and release, by whom, when — remains permanently in the audit record.

Backups

Production database backups are retained and expire under Microsoft Azure's documented backup lifecycle, independent of this schedule. A deleted record disappears from the live database immediately and from backups as they expire and are overwritten on rotation.

Changes to this schedule are treated as compliance-reviewed changes and are posted here with an updated date. See our Privacy Policy for how we notify LEAs of material changes.