Data Retention
What Graider keeps, for how long, and what deletes it.
Last reviewed: July 2026
Deleted automatically
Some data is deleted on a schedule with no action required from you:
| Data | Retention |
|---|---|
| Student work images, original upload, after a teacher approves or rejects it | 30 days |
| Student work images that were uploaded but never reviewed | 60 days |
| Cached AI grades and feedback, reused to avoid re-grading identical work | 90 days |
Abandoned uploads get the longer window because a pending image may still receive legitimate teacher action. When the original is purged the masked copy is kept, so approving and grading continue to work. Seeing an image in the product after 30 days is expected and is not a retention failure.
The grade cache holds a second copy of grades and feedback the AI has already produced, kept so identical work is not sent for grading twice. Purging it removes that copy only. The grades a teacher has saved are listed below and are not on this schedule.
Retained until you delete it
Everything listed below is kept until a teacher or your school removes it. Graider does not expire this data on a timer:
- student records
- student submissions, and join-code submissions
- submission receipts
- class rosters, and class roster metadata
- classes you create
- published assignments, and published assessments
- grades and AI feedback
- grade history
- behavior notes, and behavior tracking sessions
- IEP and 504 accommodations
- English-learner designations
- guardian contact information, and queued guardian messages
- saved assistant context
- teacher grading corrections
- LTI student identities
- student login sessions
- student work images (the review record; the original image itself is purged on the schedule above)
Our FERPA audit log is retained indefinitely by design. An audit trail that expired would defeat its own purpose, so it is deliberately exempt from deletion.
Requesting deletion
A teacher can remove an individual student, or all of their student data, from inside Graider. That runs immediately and is scoped to that teacher's own account: it never reaches another teacher's data.
Anything broader, including closing an account entirely, is handled by contacting us. That request is carried out by a person, not by an automated job.
The limits of deletion
Deletion is scoped per teacher account and runs through documented deletion paths. We do not claim provably complete erasure of every historical copy. A copy that persists is never used to serve anyone else.
The grade cache is purged by age only. Entries are keyed by a one-way hash that includes the teacher account, so a cached grade is only ever returned to the teacher it belongs to, but the cache cannot be swept for a single account on request.
We maintain a detailed list of known limitations and provide it to districts on request under a data protection agreement.
Planned, not yet in place
The following are intended and are not implemented today. They are listed so you can hold us to them, and no date is promised:
- A scheduled purge for expired student login sessions.
- A per-account retention window that districts can configure.