Data handling and retention
This article describes data storage locations and retention considerations for institution reviewers.
Where data is stored
| Data type | Location |
|---|---|
| User accounts and profiles | Supabase (PostgreSQL) |
| Courses, rubrics, evaluations | Supabase (PostgreSQL) |
| Speech media | Supabase Storage (instructional hosting) |
| Audit logs | Supabase (PostgreSQL) |
Hosted instructional storage
Evaluation materials for institutional courses are stored in the hosted database and object storage for instructional use by the instructor and authorized unit administrators. Affirmative student consent is required only for ValidBound LLM / R&D exports (deidentified), not for instructional storage.
Retention
Retention periods may be configured per institution agreement. Product defaults may target multi-year instructional retention; FERPA itself does not mandate a single vendor retention period. Contact ValidBound for institution-specific data processing terms. Pilot/contract wind-down archive-or-delete within ~30 days is an operational commitment — see the operator checklist in the repo: docs/PILOT_WIND_DOWN_RUNBOOK.md.
Subprocessors
See Subprocessors and data locations for the current list of third-party services, data categories, and typical storage locations.
Related: Trust overview