Compliance
Retention schedule
Last reviewed: 28 June 2026
Retention is enforced automatically. A scheduled job (`run_retention_purge()`) runs nightly at 03:00 UTC under `pg_cron` and removes records that have passed the schedule below. Soft deletes (account closure, prayer deletion) are honoured within 30 days.
| Category | Retention | Trigger | Mechanism |
|---|---|---|---|
| Active staff account | Life of the account | Account closure or 24 months of inactivity | Soft delete → 30-day purge |
| Active pupil account | Life of the class | Class teacher removes the pupil, or end of academic year | Soft delete → 30-day purge |
| Prayer content | Until deleted by author or school | User action | Hard delete on next nightly purge |
| Safeguarding flag | Per school's safeguarding policy, capped at 7 years | Time since creation | Automated purge after the cap |
| Pastoral-context audit log | 90 days | Time since creation | Automated purge |
| Email send log | 12 months | Time since send | Automated purge |
| Authentication events (Supabase Auth) | Managed by provider (≤ 90 days typical) | Provider default | Provider managed |
| Soft-deleted accounts | 30 days | Account deletion request | Automated purge |
| Backups | Up to 30 days (provider rolling window) | Backup age | Provider managed |
User-initiated deletion
Every authenticated user can click Delete my account on the Profile page. This signs them out immediately, blocks future sign-ins, and queues the account for permanent deletion at the next nightly purge. Class teachers can restore a pupil within the 30-day window; after that the deletion is irreversible.
Questions? Email info@classprayer.app.