Data Retention & Deletion

Districts own their data. StorylineIQ is the processor.

Last updated August 24, 2026

Customer ownership of data

Schools and districts retain ownership of all student records and educational data stored within StorylineIQ. StorylineIQ acts as a service provider and data processor under the district's direction.

Data export

District administrators can generate a complete record for any student from AdminIQ → Student Record Export. The export is delivered as a structured JSON document suitable for archiving or transfer to another system, alongside a printable copy for a family request.

A district can also export the whole tenant. StorylineIQ produces a structured archive covering every category of district data it holds, with a checksum for each file and a manifest that names the categories deliberately withheld and why. See end-of-contract offboarding below.

Retention practices

Districts configure per-record retention windows from AdminIQ → Data Retention. Records that exceed the configured window are soft-deleted automatically by a nightly job. Soft-deleted records are hidden from the application but can be restored by an administrator for 30 days, after which they are permanently removed.

Deletion on request

  • Controlled per-student deletion: District administrators can open a deletion request for a specific student from AdminIQ → Privacy & Security → Controlled deletion. The request shows an impact inventory before anything is removed, is approved separately from being requested, requires a current second factor to execute, and produces a record of what was deleted and what was anonymized.
  • Per-record amendment: Parent-requested amendments are recorded via AdminIQ → Parent Amendments; the original record is preserved alongside the amendment per FERPA.
  • Anonymization instead of deletion: Where a record must remain for audit or aggregate reporting, the student-identifying fields are removed rather than the row, so the remaining data cannot be traced back to a student.

End-of-contract offboarding

StorylineIQ supports district-directed offboarding as a staged workflow in the application, not as a manual back-office task:

  1. Review: the district can see, ahead of time, which categories of data are included in its export and which are withheld, with the reason for each.
  2. Export: StorylineIQ produces a structured archive of the district's records with a checksum for every file, retrieved through a short-lived authorized link. We record that access to the archive was authorized; we do not claim to observe delivery. A district that does not want an export can waive it explicitly, with a recorded reason.
  3. Read-only grace period: the district is held read-only before anything is removed. Reads and exports continue; new operational data cannot be written. The request can be cancelled for the whole window.
  4. Final review and confirmation: execution requires a current second factor and the district's own name, typed by the administrator. It cannot be brought forward before the grace period ends.
  5. Staged removal: data is removed in a fixed order, one stage at a time. Uploaded files are removed from storage, and credentials for roster and Ed-Fi integrations are destroyed.
  6. Verification and evidence: completion is refused while any category that must be removed still holds data. When the run closes, the district receives a record of what was removed, what was retained, and why.

What StorylineIQ retains after offboarding is limited to aggregate district-level counts with no student identifiers, plus the billing and audit records we are required to keep as the operator of the service.

We do not currently publish a figure for how long district data persists in our hosting provider's infrastructure backups after removal from the live service, or a recovery-time commitment. Those depend on our infrastructure provider and we will not state them until we hold written confirmation. Ask us and we will share the current status.

Legal holds

Retention obligations may be affected by legal, contractual, or regulatory requirements (e.g. active litigation hold). In those cases, deletion is suspended for the affected records and the district is notified.

Contact

privacy@storylineiq.com