# Data privacy, retention and learner data requests

> Set how long learner data is kept, download a full workspace export, and see how one learner's data is exported or deleted on request.

- Plans: All plans
- Canonical: https://docs.devlin.ai/workspace-and-team/data-privacy-and-retention

The **Data & privacy** page holds a workspace's settings for learner data: how long it is kept, who sees learner identity, whether AI scoring is allowed, and a download of the workspace's simulations, coaches and learner activity. Workspace owners and admins can open it on all plans. The retention window is the exception: only the workspace owner can set one, on the Team, Enterprise plans.

## Before you start
- Open **Settings → Data & privacy**. The page applies to the workspace you currently have active, whether that is your personal workspace or an organization.
- You need to be an owner or admin of the workspace. A member who opens the page sees "Data and privacy settings are managed by your workspace owner and admins." and nothing else.
- To set a retention window you need to be the workspace owner, and the workspace has to be on one of these plans: Team, Enterprise. An admin does not see the **Learner data retention** card. An owner on another plan sees the card with a **View plans** button in place of the controls.
- A retention window deletes data permanently. If you need a copy of older conversations, download a workspace export first (see below).

## What is on the page
- **Learner data retention**: the retention window, described on this page. Owner only.
- Learner identity: whether simulations ask learners who they are, which fields they fill in, and, in an organization, who sees those values (**Learner identity visibility**). See [Collecting learner identity](https://docs.devlin.ai/workspace-and-team/learner-identity).
- **AI scoring**: a workspace switch that makes every simulation give written feedback only, with no points, percentages or pass/fail.
- **Export workspace data**: a download of the workspace's simulations, coaches and learner activity.

Exporting or deleting a single learner's data is done on the Learners page, not here. See "Learner data requests" below.

## Steps
1. Open **Settings → Data & privacy** as the workspace owner.
2. In the **Learner data retention** card, open the **Retention window** list and choose **Keep indefinitely**, **30 days**, **90 days**, **180 days**, **1 year** or **Custom**.
3. If you chose **Custom**, enter a whole number of days from 7 to 3650. Both ends are allowed. A value outside that range is rejected and nothing is saved.
4. Select **Save retention window**.

## Result
The card confirms the save and the window applies from the next daily sweep. A new workspace has no retention window: learner data is kept until you delete it, and **Keep indefinitely** returns a workspace to that state.

The window is not limited to future data. Learner data that is already older than the window when you save is deleted by the next sweep, and that cannot be undone.

## What the retention sweep deletes and keeps
A scheduled job runs once a day and goes through every workspace that has a retention window. It covers conversations with simulations and with coaches, and what learners submit to evaluators.

It permanently removes:
- Messages: each message in a conversation, once that message is older than the window.
- Voice transcripts: the stored transcript of a voice conversation, once the conversation started longer ago than the window.
- Anonymous learner IDs: the ID that ties a conversation and its evaluation, or an evaluator session and its result, to a learner's browser is cleared at the same point. After that, those attempts can no longer be matched to a learner ID.
- Evaluation feedback: the written feedback and the per-criterion detail of an evaluation, once the evaluation is older than the window.
- Evaluator submissions: what a learner submitted to an evaluator, once that submission is older than the window.
- Evaluator results: the written feedback, the per-criterion detail and the stored copy of what was scored (the submitted fields and any linked simulation transcript), once the result is older than the window.
- Learner identity: the learner identifier (for example a name or employee ID, whether the learner typed it on the start screen or it was passed in the embed URL) and any extra identity field values are cleared from each attempt once that attempt started longer ago than the window, and from each evaluator submission once it is older than the window. A learner who also has recent attempts keeps their name on those.
- Session summaries generated for a conversation, and AI-written learner summaries. A learner summary is removed when the oldest attempt it was written from passes the window, so a summary never outlasts the attempts behind it.

It keeps:
- The record that each conversation happened, with its start and end time, so attempt counts keep working.
- Each evaluation's pass or fail result and score, so pass rates and average scores keep working. The score is kept as the percentage the attempt earned, for evaluations and for evaluator results. One exception: simulation evaluations that the sweep cleared before October 2026 keep the points score they had, which can read lower than the percentage the attempt earned. That cannot be corrected.
- The record that each evaluator session happened, and each evaluator result's pass or fail result and score. A combined score for an evaluator linked to a simulation is kept too.
- Human review records: a reviewer's adjusted result, reason and note on an evaluation or an evaluator result.
- Credit usage records.

Because an aged attempt no longer carries a name or a learner ID, three things change for it:
- It no longer appears under the learner's name in learner history or in the per-learner CSV exports. It still counts in the simulation's totals, pass rate and average score.
- A per-learner attempt limit stops counting it, so a learner whose earlier attempts have aged out can start again.
- A learner data request (below) can no longer reach it, because nothing identifying is left on it.

Timing details:
- "Older than the window" is measured to the moment of the sweep, so an item is removed in the first daily run after it passes the window. It can stay up to about a day longer than the window.
- Each run handles a bounded amount of data. A large backlog, such as the first run after you set a window on a busy workspace, can take more than one day to clear.
- The window follows the setting, not the plan. If a workspace with a window moves to a plan that is not in the list above, the sweep keeps applying the saved window. The owner then sees a **Saved retention window** card that states the window, and can select **Keep indefinitely** to remove it and stop the deletions. The controls to change the window to another length are not shown on that plan.

An AI tool connected through the [MCP server](https://docs.devlin.ai/integrations/mcp-server-and-ai-tool-connectors) cannot change the retention window. It is set only on this page.

## Export workspace data
Owners and admins can download the workspace's data from the **Export workspace data** card with **Download workspace export**.

- The download is one NDJSON file named `workspace-export-<date>.ndjson`. Each line is one record, with the name of the table it came from and the full record.
- It contains the workspace's simulations and coaches, every conversation with them, the messages in those conversations, evaluations, session summaries, human review records for evaluations, and AI-written learner summaries.
- It does not contain anything else in the workspace, such as members, billing records or uploaded knowledge documents.
- Records are exported as stored, including learner IDs and any identity values learners entered. Content that the retention sweep has already removed is not in the file.
- Each owner or admin can start up to 5 exports of a workspace in any one-hour period.

## Learner data requests
When a learner asks for a copy of their data, or asks for it to be deleted, an owner or admin of the workspace handles it on the Learners page. The learner is found by their learner identifier: the name or ID they entered on the start screen, or the one passed in the link.

### Export or delete one learner's data
1. Open **Results → Learners** and select the learner. See [learner history and AI summaries](https://docs.devlin.ai/results-and-analytics/learner-history).
2. Under the attempts, find **All data for this learner**. Only owners and admins see it.
3. Select **Download all data** for a copy, or **Delete all data** to remove it.

**Download all data** downloads one JSON file with everything recorded under that identifier in the workspace: each simulation conversation with its messages, transcript, evaluation and summary, each evaluator session with what the learner submitted and how it was scored, and the AI summaries written about the learner. Nothing in it is masked. Coach conversations are stored without a learner identifier, so they are not included here or removed by **Delete all data**. To handle a learner's coach conversations, contact devlin.ai with the learner ID, as described under "Learners with no identifier". The file name does not contain the identifier.

**Delete all data** asks you to type the learner's identifier to confirm, then permanently removes the same records. The deleted attempts no longer appear in results or count toward metrics. Credit usage records are kept, and credits already used are not returned. A per-learner attempt limit no longer counts the deleted attempts, so the learner can start again. A deletion cannot be undone.

Both actions match the identifier exactly, and only within the active workspace:
- A learner who entered their name in two different ways appears as two learners. Handle each one.
- Another person who used the same browser under a different identifier is not affected.
- Attempts older than the retention window no longer carry an identifier, so they are not included. Nothing identifying is left on them.

Each owner or admin can run up to 20 of these downloads and 10 deletions in any one-hour period. After that the page shows "Too many deletions in the last hour. Try again later." for a deletion.

### Learners with no identifier
A learner who never entered an identifier is not listed on the Learners page. devlin.ai can still find their data by learner ID. Each learner's browser is given a random learner ID the first time it opens a simulation, and the ID is stored with every conversation from that browser. It is in the `learner_id` column of a simulation's attempts CSV export, next to the `learner_identifier` column. To get a copy of that learner's data, or to have it deleted, contact devlin.ai from an owner or admin account of the workspace and include the learner ID. Two things follow from how the ID works:
- A learner who used more than one browser or device has more than one learner ID. Each one is handled separately.
- Once the retention sweep has cleared the learner ID from an attempt, that attempt can no longer be found by learner ID.

### Pseudonymized learner IDs in exports
A workspace setting, off by default and with no control in the app, replaces the learner ID in attempts CSV exports with a pseudonym that starts with `lrn_`. The same learner always gets the same pseudonym within a workspace, so rows still group by learner, and the pseudonym cannot be turned back into the learner ID. It does not change stored data, the copy devlin.ai prepares for a learner by learner ID, or the workspace export, which carry the real learner ID. The **Download all data** file on the Learners page is found by learner identifier and does not include a learner ID. Only the workspace owner can change the setting.

## Related
- [Collecting learner identity](https://docs.devlin.ai/workspace-and-team/learner-identity)
- [Account settings](https://docs.devlin.ai/workspace-and-team/account-settings)
- [Members, roles, invitations and the activity log](https://docs.devlin.ai/workspace-and-team/members-and-roles)
- [Personal and organization workspaces](https://docs.devlin.ai/workspace-and-team/workspaces)
- [Learner results and attempts](https://docs.devlin.ai/results-and-analytics/learner-results-and-attempts)
- [MCP server and AI tool connectors](https://docs.devlin.ai/integrations/mcp-server-and-ai-tool-connectors)
