Data Retention
How long Safe For The Office™ retains different categories of data, and our approach to data minimization.
- Participant data: zero retention — cleared when the session ends
- Admin audit log: 1-year retention
- Operational events: 90-day retention
- Password reset tokens: expire after 1 hour, single-use
- Facilitator accounts: retained while the account is active
Retention Philosophy
Safe For The Office™ applies a data minimization approach: we retain only what is necessary to operate the platform, and we do not retain participant data at all. The goal is to collect the minimum information required to deliver the service, and to hold it for the minimum time necessary.
Participant Data — Zero Retention
Participant names and responses exist only in the server's active memory during a live session. They are never written to a database, log file, or any persistent storage. When a session ends — whether the facilitator closes it, it expires due to inactivity, or the server restarts — all participant data is immediately and permanently gone.
There is no retention period for participant data because there is nothing to retain. This is an architectural guarantee, not a configurable policy.
Retention Schedule
| Data Category | Retention Period | Basis |
|---|---|---|
| Participant names | Zero — cleared on session end | Privacy-first architecture |
| Participant answers | Zero — cleared on session end | Privacy-first architecture |
| Facilitator accounts | While account is active | Required to operate the service |
| Room records | Indefinite (no automated cleanup yet) | Session history for facilitators |
| Admin audit log | 1 year | Administrative accountability |
| Operational events | 90 days | Platform health monitoring |
| Password reset tokens | 1 hour (expire unused); cleaned up after 7 days | Security — single-use, time-limited |
Facilitator Accounts
Facilitator account records — email address, display name, and password hash — are retained while the account is active. Accounts that are suspended or deactivated are retained in the database to preserve audit trail integrity. Account deletion requests can be submitted via the contact form.
Room Records
When a facilitator runs a session, a room record is created. This record contains the room code, activity type, content pack selection, and timestamps. It does not contain any participant information. Room records are currently retained indefinitely to support facilitator session history. An automated cleanup policy for completed rooms is planned for a future platform update.
Admin Audit Log
All administrative actions — logins, logouts, room management operations, and account changes — are recorded in an append-only audit log. This log is retained for one year. The audit log does not contain participant data. It records only the actions of platform administrators.
Operational Events
The platform records anonymized room lifecycle events — when rooms are created, opened, started, and completed — for operational monitoring purposes. These events contain no participant names, answers, or identifiers. They are retained for 90 days.
Password Reset Tokens
When a password reset is requested, a single-use token is generated. The token expires after one hour. Only a cryptographic hash of the token is stored — the original token value is never persisted. Used and expired tokens are cleaned up periodically.
Data Minimization Principles
Safe For The Office™ applies the following data minimization principles:
- - Collect only what is necessary to deliver the service
- - Do not collect participant email addresses, phone numbers, or identifiers
- - Do not log participant IP addresses
- - Do not retain participant responses after a session ends
- - Store only cryptographic hashes of sensitive tokens — never the raw values
- - Apply defined retention periods to operational records
Last reviewed: October 2026