Draft — pending legal review. This document is a working draft and is not yet legal advice or a final policy. It will be reviewed by licensed counsel before launch.
Data Retention
Last updated · Draft 2026-06-19
We keep personal information only as long as it serves the purpose we collected it for, then delete or de-identify it.
1. Principle
Data tied only to your own account is deleted or de-identified when you delete your account, or sooner on request. A narrow set of categories — the legal record of your consent, and shared classroom or session content that other participants rely on — are retained on their own trigger (described below) rather than a fixed calendar period. We do not keep data merely because we could; every retained category exists for a stated reason.
2. What we keep, and what happens when you delete your account
- While your account is active — we keep your profile, learning progress, AI chat conversations, usage data, and classroom activity so you can pick up where you left off.
- When you delete your account (self-serve, from Settings → Security) — your sign-in access is removed immediately through our authentication provider (Clerk), any subscription on a team only you own is canceled immediately, and we start an automatic purge of your personal data: conversations and messages, learning progress, usage counters, classroom responses/reactions/participation, session registrations, your personal activity-log entries, invitations to or from you, and any team you solely own. The purge runs in scheduled batches starting immediately when deletion begins, and continues until every category is cleared.
- What's retained after deletion — a minimal record proving you accepted our terms (kept as our legal record of consent); a pseudonymous reference in shared classroom or session history so records other participants rely on stay intact, with your display name cleared from it; and a minimal account marker that only prevents the same identity from being silently recreated after deletion.
- Payment records — held by Stripe, our payment processor, as required for financial-record purposes. We do not store full card numbers, and Stripe (not ThinkFirst) sets that retention period as the processor's own system of record.
- Provider backups — our providers (Clerk, Stripe, Convex) may retain data briefly in routine backups after a deletion request, on their own backup and rotation schedules rather than one we set.
- Shared team ownership or active instructor assignments — if you own a team with other members, or are assigned to an active or upcoming classroom session, account deletion is blocked until ownership is transferred or the assignment is reassigned. We'll show you what's blocking it in the product, or you can email us for help.
3. Deletion and export are self-serve
Signed-in users can export a portable JSON copy of their data and delete their account at any time from Settings → Privacy and Settings → Security respectively — no email round-trip required. If you'd rather we handle a request directly, need help with an edge case (for example, a jointly owned team), or want the complete history for a data category our self-serve export flags as partial, email privacy@thinkfirst.ai. We aim to respond to formal requests submitted this way within 30 days.
4. Security during retention
While retained, data is protected under our written information-security program with reasonable technical and organizational safeguards.
More from ThinkFirst Legal