Compliance

Retention schedule

Last reviewed: 28 June 2026

All compliance documents

Retention is enforced automatically. A scheduled job (`run_retention_purge()`) runs nightly at 03:00 UTC under `pg_cron` and removes records that have passed the schedule below. Soft deletes (account closure, prayer deletion) are honoured within 30 days.

CategoryRetentionTriggerMechanism
Active staff accountLife of the accountAccount closure or 24 months of inactivitySoft delete → 30-day purge
Active pupil accountLife of the classClass teacher removes the pupil, or end of academic yearSoft delete → 30-day purge
Prayer contentUntil deleted by author or schoolUser actionHard delete on next nightly purge
Safeguarding flagPer school's safeguarding policy, capped at 7 yearsTime since creationAutomated purge after the cap
Pastoral-context audit log90 daysTime since creationAutomated purge
Email send log12 monthsTime since sendAutomated purge
Authentication events (Supabase Auth)Managed by provider (≤ 90 days typical)Provider defaultProvider managed
Soft-deleted accounts30 daysAccount deletion requestAutomated purge
BackupsUp to 30 days (provider rolling window)Backup ageProvider managed

User-initiated deletion

Every authenticated user can click Delete my account on the Profile page. This signs them out immediately, blocks future sign-ins, and queues the account for permanent deletion at the next nightly purge. Class teachers can restore a pupil within the 30-day window; after that the deletion is irreversible.

Questions? Email info@classprayer.app.