Data lifecycle
Retention and Deletion Notice
Effective and last updated: August 6, 2026
Operational schedule
- Self-practice sight-singing audio: processed in memory for immediate grading and not intentionally stored by MIDI Mind.
- School-authorized raw practice audio: deleted after processing. A failed immediate cleanup is retried by the daily lifecycle job and must expire within 60 minutes.
- Hybrid-exam recordings and answer-page media: deleted after 30 days.
- Derived scores and educational records: retained while needed for the account or school relationship, then deleted on a verified request or contract-end schedule, subject to a documented legal exception.
- Verified export requests: targeted for completion within five business days.
- Verified deletion requests: completed within 30 calendar days, with identity and relationship verification before destructive action.
Automation and evidence
A production scheduler invokes the privacy lifecycle every day. Each run records its start, completion, status, deletion counts, and error summary. Failed or stale runs are visible to administrators and must be investigated. Deletion covers private object storage and the associated database records.
Backups and legal holds
Provider backups are access-restricted and are not restored to circumvent a deletion. Deleted data may persist only in encrypted disaster-recovery backups until the provider's configured backup cycle expires. A documented legal hold may pause deletion only for the records and period legally required; the requester is told when law permits.
Requests
Use the Privacy Requests page for access, correction, export, deletion, or authorization revocation.