# Data privacy and retention

## Data model

The release has no account, analytics, telemetry endpoint, advertising code, remote database or automatic upload. Data exists in two places only:

1. browser-local storage used for convenience and resume;
2. files deliberately exported by the user.

## Data that may be recorded

Depending on staff and learner choices, a project may contain:

- learner alias;
- commission and essential question;
- pathway and mission code;
- predictions, confidence, reasoning and calibration;
- design state, measurements and decision timeline;
- typed reflection or teacher verification;
- imported photographs or visual snapshots;
- source notes and moderation annotations.

## Recommended practice

- Use an alias or approved identifier rather than a full name.
- Avoid entering health, safeguarding, family or behaviour information.
- Review photographs before capture or export; crop or replace images containing faces, names, screens, timetables or other identifying context.
- Store exported files only in approved locations with appropriate access controls.
- Apply the setting’s existing retention schedule rather than keeping files indefinitely because they are easy to export.
- Delete browser-local projects after secure export where shared devices are used.

## Browser storage limitations

Local storage can be cleared by users, browser policy, privacy mode, profile reset or device management. Behaviour also varies when files are opened directly from disk. Local storage is therefore not a records-management system. Exported files are the transferable record.

## Moderation workflow

The Portfolio Moderation Hub supports blind aliases and evidence sampling. Blinding reduces unnecessary exposure during review but is not anonymisation if the evidence itself contains names, faces or uniquely identifying work. Review source files before wider sharing.

## Deletion

The apps include local reset or project replacement controls. Staff should also remove downloaded project files and photographs from device download folders, recycle bins and shared locations in accordance with local procedure.

## Security boundary

Portable project files are readable JSON and are not encrypted or password-protected. Their transparency supports audit but means access must be controlled by the storage system. Do not rely on the custom filename extension as a security measure.
