Legal
Data Retention & Deletion
Last updated: July 2026 · Effective: July 2026
1. What Data the Platform Holds
TCS Platform is a clinical education system. It holds no real patient information: every patient in the platform is fabricated for teaching. The data that does need a retention policy falls into these groups:
- Student education records: assessment scores, rubric item results, virtual patient attempts and the actions taken during them, clinical hour logs, and compliance documents the student uploaded.
- Account and directory data: names, institutional email addresses, roles, and cohort or programme membership.
- Operational logs: the audit trail of who accessed or changed what, and in-app messages.
- Content: scenarios, rubrics, fabricated patient charts, and uploaded scenario media authored by your institution or licensed from us.
- Commercial records: subscriptions, usage metering, invoices.
2. Retention Periods
These are the platform defaults. They are configuration, not code, and an institution may set a longer or shorter term for its own data where its records requirements differ.
| Data | Kept for | Then |
|---|---|---|
| Student education records (scores, attempts) | Until your institution deletes them | Never aged out by us |
| Anything you delete in the app | 12 months | Permanently erased |
| Audit and access logs | 24 months | Permanently erased |
| In-app messages | 36 months | Permanently erased |
| Raw usage metering events | 36 months | Permanently erased; monthly totals kept |
| Invoices and financial records | Statutory period | Retained as required by law |
| Scenarios and authored content | For the life of the account | Deleted on request or account closure |
Why student records are not aged out automatically: how long an education record must be kept is your institution's legal decision, driven by accreditation and state records requirements that commonly run five to seven years and sometimes longer. FERPA sets no maximum. We therefore never delete assessment data on our own initiative. An institution that wants a defined term sets one, and the platform then applies it.
3. What "Deleted" Means
Deletion happens in two stages, deliberately.
- Immediately: when a user deletes something, it disappears from the application for everyone. It is marked deleted rather than erased, so an administrator can recover it from a mistake and so an audit trail of the change survives.
- After 12 months: the record is permanently erased from the database by a scheduled process. At that point it is not recoverable, including by us.
Backups are a separate matter. A record erased from the live database may persist in encrypted backups until those backups age out on their own schedule. We do not restore individual records from backups on request.
4. Requesting Deletion
Because the platform is used by institutions, deletion requests are handled through the institution rather than individually, in the same way as any other education record.
- Students: contact your programme administrator. They can delete your records directly, and they are the party responsible for your education record under FERPA.
- Institutions: email privacy@osceapp.com from an administrator account. We confirm scope in writing before acting, then erase within 30 days and confirm when it is done.
- On account closure: your data is retained for 30 days so it can be exported, then erased apart from records we are legally required to keep, such as invoices.
Export before you delete: administrators can export scores, gradebooks and reports from the platform at any time. We cannot reverse an erasure.
5. How This Is Enforced and Evidenced
Retention is applied by a scheduled job, not by hand. Every run is recorded with the class of data, the cutoff date, and how many records were removed, and those records are available to your administrators and to auditors on request. A retention claim that nobody can audit is not a control, so the log exists whether or not anything was deleted.
6. Related Documents
- Privacy Policy, what we collect and why
- FERPA Compliance, how education records are protected
- Data Processing Agreement, the contractual terms for institutional customers
- Terms of Service
7. Changes
If we shorten a retention period in a way that would erase data you currently hold, we will give institutional administrators at least 60 days' notice so the data can be exported first. Lengthening a period, or adding a new category, takes effect on publication.