Clarvyn

Keeping and deleting data

v0.1-draft · last reviewed 15 September 2026

Working draft. This page says how Clarvyn intends to operate. It has not been reviewed by a Ghana-qualified lawyer, and the wording will change when it is. We publish it now because a school deciding whether to trust us with children’s records should be able to read what we claim to do. Tell us where it is wrong: support@clarvyn.ai.

While a school is using Clarvyn

We keep a school’s records for as long as the school wants them. That is the point of the product: a leaving certificate written in 2031 needs the marks from 2026. The school decides what to delete and when, and can do it in the console.

When a school leaves

The school’s entire schema is dropped. That removes every student, staff, attendance, fee and result record belonging to it. It is not a soft delete and it is not reversible, so we do it only on a clear instruction from the school, and the instruction is recorded in an audit table that outlives the school.

Take your export first. Ask before termination, not after.

What we have not automated

Stated plainly, because a policy that promises a schedule nobody runs is worse than no policy:

  • There is no automatic purge job today. Data is removed when a school asks, or when a school is terminated. Nothing expires on a timer.
  • We have not set a retention period for server logs. Logs are operational records, they can contain a phone number, and we will publish the period here once it is fixed.

Both are on the list to close before we take on a school at scale. Until each is done, this page will keep saying so.

Deleting one person rather than a whole school

See deleting your account.