Data Retention Policy

Effective date: April 6, 2026 Last updated: April 28, 2026


1. Purpose

This policy defines how long Read the Room Intelligence LLC retains data collected through Read the Room, and when and how data is deleted. It applies to all data categories described in our Privacy Policy.

We follow the principle of data minimization: we keep data only as long as it serves a defined purpose, and we delete it when that purpose has been fulfilled.


2. Retention Schedule

The table below sets out the retention period for each data category, the trigger that starts the retention clock, and the deletion method.

Data categorySpecific fieldsRetention periodRetention triggerDeletion method
Active simulation dataMessages, deliverables, cross-team requests, injects, participant records, team recordsRetained while the simulation existsSimulation creationDeleted when facilitator deletes the simulation
Completed simulation dataMessages (content, senderName, channelType, roundNumber), deliverables (content, roundNumber), cross-team requests, injects12 months after simulation completionSimulation status changed to completedAutomated deletion of all associated records
Direct messagesDirectMessage records (content, sender, recipient)Deleted when simulation endsSimulation end eventImmediate automated deletion (by design, DMs do not persist beyond the active simulation)
Participant recordsNickname, teamId, sessionToken, isActive, lastActiveAt, createdAtDeleted with the simulation, or on individual requestSimulation deletion or data subject requestCascade deletion with simulation, or individual record deletion on request
Participant session recordsParticipantSession (startedAt, endedAt, durationSecs, endReason)12 months after simulation completionSimulation status changed to completedAutomated deletion with other simulation data
Facilitator accountsEmail, password hash, nickname, role, inviteCode, isActive, createdAtRetained while active, plus 6 months after account deletionAccount deletion request or admin deactivationHard deletion of all facilitator records after the 6-month retention window
Audit logsAuditLog records (facilitatorId, action, details, ipAddress, createdAt)24 months from creationLog entry creation dateAutomated deletion of records older than 24 months
Consent records (proof-of-consent fields)Participant and facilitator consent records (version, timestamp, accepted checkboxes, userAgent)Retained indefinitely (legal requirement)Consent givenNot deleted: legal requirement for proving that valid consent was obtained (GDPR Art. 7(1), Recital 42)
IP address on consent recordParticipantConsent.ipAddress (one IP per consent record, captured at join time)12 months from consent creationConsent givenScheduled job nulls out the ipAddress column after 12 months. The rest of the consent record is preserved. Rationale: forensic value of an IP drops sharply after 12 months (DHCP recycling, VPN changes), and indefinite retention would be disproportionate to the security/audit purpose.

3. Rationale for Retention Periods

Active simulation data (lifetime of simulation). Simulations are time-bounded training exercises. Data must remain available while the facilitator may need it for debriefing, assessment, or export. The facilitator controls when a simulation is deleted.

Completed simulation data (12 months). Facilitators and their institutions may need to review simulation results after the exercise ends, for grading, reporting, or training program evaluation. Twelve months provides adequate time for institutional review cycles (academic semesters, annual training reviews) without retaining data indefinitely.

Direct messages (deleted at simulation end). DMs are designed for real-time coordination during the exercise. They have no post-simulation assessment value. Immediate deletion reduces data exposure.

Participant records (deleted with simulation). Under the V2 pseudonymized model, participant records consist of a nickname and session metadata. These have no independent value once the simulation is removed.

Participant session records (12 months). Session data (duration, activity patterns) supports post-simulation analysis on the same timeline as other simulation content.

Facilitator accounts (active + 6 months). The 6-month buffer after account deletion allows us to investigate any security incidents or disputes that surface after a facilitator leaves. After 6 months, all facilitator data is permanently deleted.

Audit logs (24 months). Audit logs track facilitator actions for security and accountability. Twenty-four months aligns with standard practice for security logs and provides sufficient lookback for incident investigation. Logs older than 24 months are deleted.

Consent records (indefinite, except IP address). GDPR Article 7(1) requires data controllers to be able to demonstrate that a data subject consented to processing. Deleting consent records would eliminate our ability to prove consent was validly obtained. The version, timestamp, accepted checkboxes, and userAgent fields are retained indefinitely. The IP address field is scrubbed after 12 months — its forensic value drops sharply within that window, and proportionality requires a shorter retention than the rest of the record.


4. Deletion Procedures

4.1 Automated Deletion

The following deletions occur automatically without manual intervention:

  • Direct messages: Purged when a simulation ends.
  • Completed simulation data: A scheduled process identifies simulations that have been in "completed" status for more than 12 months and deletes all associated records (messages, deliverables, cross-team requests, injects, participant records, session records).
  • Audit logs: A scheduled process deletes log entries older than 24 months.
  • Facilitator accounts past retention: A scheduled process deletes facilitator records that have been in "deleted" status for more than 6 months.
  • Consent record IP addresses: A scheduled process nulls out the ipAddress column on ParticipantConsent rows older than 12 months. The rest of the consent record is preserved.

4.2 Facilitator-Initiated Deletion

Facilitators can delete simulations at any time through the platform interface. Deleting a simulation permanently removes all associated data: messages, deliverables, participant records, session records, cross-team requests, and injects. This action is irreversible.

4.3 Data Subject Requests

Participants and facilitators can request deletion of their personal data by contacting us (see Section 7). Upon receiving a verified request:

  • Participants: We delete the participant record (nickname, session data) and can attribute their messages to an anonymized sender. If the participant requests deletion of message content, we delete the messages. We respond within 30 days (GDPR) or 45 days (CCPA).
  • Facilitators: We initiate the account deletion process. The account is deactivated immediately. All associated data is permanently deleted after the 6-month retention window, unless the facilitator requests immediate deletion and we have no legal obligation to retain it.

4.4 Deletion Verification

When data is deleted from our database, it is permanently removed from Neon PostgreSQL. Database backups maintained by Neon follow Neon's own retention schedule (see neon.com/dpa). We do not maintain independent backups outside of our database provider.


5. Data the Platform Does Not Store

Under the V2 pseudonymized model, the following data is explicitly not stored by Read the Room:

  • Participant email addresses
  • Participant passwords
  • Real names (participants choose their own nicknames)
  • Geolocation derived from IP (the IP itself is captured with the consent record for security/audit, but never resolved to a city, region, or coordinates)

The facilitating institution is responsible for maintaining any nickname-to-identity mapping outside of this platform.

Note on participant IP addresses. The platform records one IP address per participant on the consent record at join time. This is used solely for security, audit, and consent non-repudiation, and is scrubbed after 12 months (see Section 2). It is not stored on any other model, not used for tracking, and not shared with third parties beyond what our infrastructure providers see in the normal course of routing HTTPS requests.


6. Exceptions to Standard Retention

We may retain data beyond the periods listed above in the following circumstances:

  • Legal hold. If we receive a legal preservation request, litigation hold, or regulatory inquiry, affected data will be preserved until the hold is lifted, regardless of the standard retention period.
  • Active security investigation. If data is relevant to an ongoing security incident investigation, it will be retained until the investigation concludes.
  • Consent records. As noted above, consent records are exempt from deletion to satisfy legal proof-of-consent requirements.

7. Contact

To request data deletion, ask questions about this policy, or exercise any data protection right:

Data Controller: Read the Room Intelligence LLC

Email: info@readtheroom.tech

Postal address: 1950 Barrett Lakes Blvd NW, Apt 215, Kennesaw, GA 30144


8. Changes to This Policy

We may update this Data Retention Policy to reflect changes in our data practices, legal requirements, or platform features. Material changes will be communicated through the platform and, for facilitators, by email. The "Last updated" date at the top of this document will reflect the most recent revision.


This Data Retention Policy should be read alongside our Privacy Policy, Terms of Service, and Security Overview.