Trust Center

Data Retention

How long Safe For The Office™ retains different categories of data, and our approach to data minimization.

Retention At A Glance
  • Participant data: zero retention — cleared when the session ends
  • Admin audit log: 1-year retention
  • Operational events: 90-day retention
  • Password reset tokens: expire after 1 hour, single-use
  • Facilitator accounts: retained while the account is active

Retention Philosophy

Safe For The Office™ applies a data minimization approach: we retain only what is necessary to operate the platform, and we do not retain participant data at all. The goal is to collect the minimum information required to deliver the service, and to hold it for the minimum time necessary.

Participant Data — Zero Retention

Participant names and responses exist only in the server's active memory during a live session. They are never written to a database, log file, or any persistent storage. When a session ends — whether the facilitator closes it, it expires due to inactivity, or the server restarts — all participant data is immediately and permanently gone.

There is no retention period for participant data because there is nothing to retain. This is an architectural guarantee, not a configurable policy.

Retention Schedule

Data CategoryRetention PeriodBasis
Participant namesZero — cleared on session endPrivacy-first architecture
Participant answersZero — cleared on session endPrivacy-first architecture
Facilitator accountsWhile account is activeRequired to operate the service
Room recordsIndefinite (no automated cleanup yet)Session history for facilitators
Admin audit log1 yearAdministrative accountability
Operational events90 daysPlatform health monitoring
Password reset tokens1 hour (expire unused); cleaned up after 7 daysSecurity — single-use, time-limited

Facilitator Accounts

Facilitator account records — email address, display name, and password hash — are retained while the account is active. Accounts that are suspended or deactivated are retained in the database to preserve audit trail integrity. Account deletion requests can be submitted via the contact form.

Room Records

When a facilitator runs a session, a room record is created. This record contains the room code, activity type, content pack selection, and timestamps. It does not contain any participant information. Room records are currently retained indefinitely to support facilitator session history. An automated cleanup policy for completed rooms is planned for a future platform update.

Admin Audit Log

All administrative actions — logins, logouts, room management operations, and account changes — are recorded in an append-only audit log. This log is retained for one year. The audit log does not contain participant data. It records only the actions of platform administrators.

Operational Events

The platform records anonymized room lifecycle events — when rooms are created, opened, started, and completed — for operational monitoring purposes. These events contain no participant names, answers, or identifiers. They are retained for 90 days.

Password Reset Tokens

When a password reset is requested, a single-use token is generated. The token expires after one hour. Only a cryptographic hash of the token is stored — the original token value is never persisted. Used and expired tokens are cleaned up periodically.

Data Minimization Principles

Safe For The Office™ applies the following data minimization principles:

  • - Collect only what is necessary to deliver the service
  • - Do not collect participant email addresses, phone numbers, or identifiers
  • - Do not log participant IP addresses
  • - Do not retain participant responses after a session ends
  • - Store only cryptographic hashes of sensitive tokens — never the raw values
  • - Apply defined retention periods to operational records

Last reviewed: October 2026