Retention
How long we keep each thing
Per tier and per category, with the lifecycle events that end retention early. We copy every figure from the Privacy Policy or the linked support and security pages.
| Data | Retention | Who sees it / why |
|---|---|---|
| Your own practice record (which question, which answer, when) | Permanent | The member only, on every plan; export, reset, or delete it from your account page. |
| Free-tier aggregates | 90-day rolling window | Nobody. No admin view of them exists; they tune question difficulty. |
| Free-tier participation link (Slack user ID, per-question correctness) | Workspace link removed after 90 days | Never shown to admins; we use it to dedupe answers and compute the anonymous aggregates inside the window. The member keeps the answer in their own record. |
| Team workspace attribution (which member answered, for streaks and participation) | 365-day rolling window | The member only, plus nickname or anonymous leaderboards. When the window rolls, the workspace link is removed and the member keeps the answer. |
| Per-member progress summary (streaks, lifetime counts, per-skill scores) | While you remain a member | The member only; deleted on account erasure, admin removal, or when the subscription ends. The member's own record is unaffected. |
| Aggregated, anonymized statistics (no personal identifiers) | Indefinitely | Question quality and service improvement; cannot be traced back to any person. |
| Email suppression list (kept after unsubscribe) | Until account deletion | Kept only to honor the opt-out; never used for marketing email again. |
| Webhook event logs (payment, auth, email and Slack events we receive) | 30-day rolling window | Security, and debugging a delivery that failed. A sweep deletes anything older. |
| IP addresses | Transient, hours not days | Rate limiting and abuse prevention only. No IP is stored on your account or workspace record, and none is recorded in the audit log below. The one counter keyed on an installer's IP is deleted within two hours of the attempt. Otherwise IPs appear only in short-lived operational logs at our hosting and backend providers. |
| Workspace audit log (who changed what, and when) | 365-day rolling window | Workspace administrators. Entries record administrative actions, not practice answers, and carry no IP address or browser. We keep them for security and accountability (GDPR Art 6(1)(f)). Unlike everything above, they survive an individual erasure request: an audit trail an administrator could erase themselves is not an audit trail. What survives is the acting administrator's user ID and, where the action concerned another person, that person's user ID, Slack user ID, or the email an invitation was sent to. Deleting the workspace deletes them. |
| Billing and tax records | 7 years | Required by Swedish Bokföringslagen (1999:1078) and equivalent law. |
When a subscription ends
Cancellation takes effect at the end of the paid billing period; the workspace's attributed layer remains available and exportable until then. When the subscription ends, that layer is removed immediately and cannot be restored, even if you resubscribe: we delete the practice targeting set up for each member, and we permanently unlink every member's answers from the workspace. Each member keeps their own practice record. Anonymous team aggregates continue under the 90-day rolling window, and the workspace continues on the free tier until an administrator deletes it. Deleting the workspace, unlike a downgrade, also deletes the answers members gave inside it (see "Deletion and export" below).
Uninstall and reconnect
If you uninstall the Slack app, we permanently delete all attributed Slack-specific data within 15 days: a 14-day retention window plus a daily deletion sweep. Anonymous aggregates that contain no identifiers continue under the 90-day window.
We keep your configuration (channel, schedule, topics) if you reconnect to the same workspace within 14 days. After 14 days, disconnected workspace data is deleted as described in the Privacy Policy.
Anonymous statistics
We keep statistics that contain no personal identifiers indefinitely, to improve question quality and the service. Per-question accuracy rates across all users are one example. Before we delete an attributed record under the windows above, we fold it into these statistics. Deleting the record does not reverse that contribution, and no statistic can be traced back to a person.
Email suppression list
When you unsubscribe from marketing or product email, we keep your address on a suppression list so that we do not contact you again. The entry exists only to honor your opt-out, and we remove it entirely when your account is deleted.
Deletion and export
Your own data is self-serve: from your account page you can download your practice record as one machine-readable file (every answer, course progress, certificates, streaks and the apprentice, across every workspace you belong to), reset parts of it, or delete the account. We build the file and email a link that works for 24 hours, one export a day. For personal data the file does not carry, ask us and we will assemble it.
Workspace admins can delete a workspace, including all per-member responses and rollups, from billing settings. A full export of the workspace's history, or an erasure request made on someone else's behalf, is a manual request to the address on the support page. We complete workspace exports within five business days and act on verified erasure requests within 30 days. If you also want a refund, request the workspace export first, and request it early: the 14-day refund window runs from the charge and does not pause while we prepare the export. Account and profile data held by our authentication provider is removed when your account is deleted.
The authoritative versions live in the Privacy Policy under "Data storage & retention" and in the Data Processing Agreement. We also publish the export timeline on the support and security pages, and the reconnect timeline on the support page. Where anything here differs from the Privacy Policy or DPA, they govern.
