Legal

Data Retention Policy

Last updated: August 4, 2026

This page states how long each category of data lives in Peerfold, in concrete terms. Where retention is bounded by the life of a workspace, deletion of the workspace removes the data (see “Deletion” below).

Short-lived security artifacts

Each lifetime above is when the artifact stops working. A daily sweep then deletes the expired rows themselves, so an expired code, session or grant does not sit in the database indefinitely.

Learning records

Operational records

Backups

The database runs on Neon with point-in-time recovery. Deleted data leaves the recovery window as it expires — deletion is complete within that window, and backups are never used to resurrect erased records.

Deletion

  • Workspace deletion removes the workspace’s learners, content, media, logs and queue rows — storage is keyed to the workspace, so deletion cascades structurally.
  • Learner erasure hard-deletes where the record can go, and anonymizes where the record must survive (certificates, audit logs, aggregate analytics — which are learner-blind already). A suppression marker prevents a connected CRM sync from re-creating the learner afterwards.
  • CRM copies written into the customer’s own HubSpot, Day.ai or Salesforce are under the customer’s control; the erasure report tells the customer exactly which records those systems hold so they can be handled there.

Requests

Retention or deletion requests: privacy@peerfold.com. See also the Privacy Policy and the Data Processing Addendum.

Questions? Write to hello@peerfold.com and a person will answer.

Contact us