Data Retention Policy
Last Updated: August 8, 2026 · Effective: August 8, 2026
1. Purpose
How long Pathion Inc. (operating as LILO Learning) keeps your data, and how to ask us to delete it sooner.
Two things we want to be direct about:
- We keep learning data longer than a typical consumer app, because measuring whether this platform actually improves outcomes requires it. We explain the reasoning in Section 3.
- Most of our deletion is currently manual, not automated. Section 5 says exactly what is and is not automated today.
2. Two Retention Clocks
We split retention by purpose rather than applying one window to everything.
Identity and outcome data (up to 5 years) — the minimum needed to answer "did this person get an engineering job, and did we help?"
Learning activity data (up to 24 months) — the detailed record of how you worked through problems. Used for progress tracking, instructor reporting, and efficacy measurement.
Operational data (30 to 90 days) — logs and security data with no analytical value beyond the short term.
3. Retention Schedule
3.1 Identity and outcome — up to 5 years
| Data | Retention | Location | Purpose |
|---|---|---|---|
| Name, email, profile picture | Up to 5 years from last activity | MongoDB, Supabase | Identity, outcome tracking |
| Graduation year, program, cohort | Up to 5 years | MongoDB | Cohort outcome analysis |
| Outcome data you share (offers, placement) | Up to 5 years | MongoDB | Efficacy measurement |
| Enrollment and completion status | Up to 5 years | MongoDB, Airtable | Program records |
| Completion certificates | Indefinite | MongoDB | Credential verification |
Why 5 years. Interview preparation pays off over years, not weeks. To show that students who used this platform got offers, we have to be able to connect a person to an outcome after they graduate. That requires keeping identifying information. We keep the minimum set that makes it possible: name, email, graduation year. We do not keep IP addresses, device fingerprints, or browsing history for this purpose.
Answering is voluntary. We may contact you after the program to ask how your job search went. You are never required to respond. If you would prefer we not retain your information for outcome tracking at all, email privacy@learnwleo.com and we will remove you from it while leaving your account intact.
Institutional students: outcome information you provide may be shared with your institution. See Section 6.4 and Privacy Policy Section 12.
3.2 Learning activity — up to 24 months
| Data | Retention | Location |
|---|---|---|
| Code submissions | Up to 24 months | MongoDB |
| Test results and execution logs | Up to 24 months | MongoDB |
| Decision traces (run/submit events) | Up to 24 months | MongoDB |
| Time on lessons and projects | Up to 24 months | MongoDB |
| Engagement scores | Up to 24 months | MongoDB |
| Learner profiles (AI-generated) | Up to 24 months | MongoDB |
| Session recordings | Up to 24 months | Mixpanel |
| Analytics events | Up to 24 months | Mixpanel |
| Custom test cases | Up to 24 months | MongoDB |
| Reflections (pre/post problem) | Up to 24 months | MongoDB |
| Study preferences, planner state | Active account + 30 days | MongoDB |
3.3 Operational — short
| Data | Retention | Location |
|---|---|---|
| Truncated IP address (/24) | 30 days | Server logs |
| Application logs | 30 days | Server logs |
| Login history | 90 days | Supabase |
| Browser family and major version | Up to 24 months | Mixpanel |
| Backups | 30 days after deletion from primary | Encrypted backups |
No longer collected: full IP addresses and complete user-agent strings. Previously logged; collection stopped as of August 8, 2026. Existing records purged.
3.4 User content
| Data | Retention | Location |
|---|---|---|
| Bug reports (text) | Until resolved, then 6 months | MongoDB, Airtable |
| Bug attachments (screenshots, video) | Until resolved, then 6 months | S3 |
| Feature requests | 1 year | MongoDB, Airtable |
| Course feedback and ratings | 2 years | MongoDB |
| Resumes (Academy) | Program duration + 1 year | S3, Airtable |
3.5 De-identified data
Aggregated or de-identified data that cannot reasonably be re-identified may be retained indefinitely for efficacy research, institutional reporting, and grant reporting.
4. Prospective Application
These periods apply to data collected on or after August 8, 2026.
Data collected before that date remains subject to the retention periods published at the time of collection. We are not retroactively extending retention on data collected under earlier commitments.
5. What Is Automated and What Is Not
Being precise here, because our previous policy described automation that did not exist.
Currently automated
None as of this version.
Not yet automated — manual review
- Learning activity aging past 24 months
- Identity and outcome data aging past 5 years
- Test-account cleanup
- Inactive-account deletion
We enforce these limits through periodic manual review. Automated enforcement is in development. This policy will be updated when it ships, and the date noted.
Handled by the vendor
- Mixpanel data is subject to Mixpanel's own retention configuration.
If you want your data deleted sooner than these periods, ask. We will do it.
6. Deletion Requests
6.1 How to request
Email privacy@learnwleo.com, subject "Account Deletion Request."
There is no self-service delete button. Requests go through identity verification and a legal-hold check, then our team processes them. We complete deletion within 30 days and confirm by email.
6.2 What happens
Deleted: account record (email, name, picture), study preferences, planner state, learner profile, outcome data.
Anonymized: code submissions, test results, decision traces, engagement scores. These are stripped of identifiers and retained for aggregate analysis.
Third parties: we request deletion from Supabase, Mixpanel, and Airtable, and delete S3 and R2 files. Their timelines are typically 30 to 90 days.
Backups: purged within 30 days.
6.3 Data export
Email privacy@learnwleo.com, subject "Data Export Request." JSON or CSV within 30 days.
6.4 Students enrolled through an institution
If you use this platform through a course, your institution controls your education records. FERPA gives you rights of access and amendment, not erasure. Deletion of institutional records is governed by our agreement with your school.
Send access or amendment requests to your institution, which will direct them to us.
7. Exceptions
We may retain data beyond these periods where:
- Legal hold: court order, subpoena, or tax obligation
- Integrity investigation: academic-integrity or fraud investigation, retained up to 3 years for defense
- Active dispute: until resolved
- De-identified: cannot identify you, retained indefinitely
- Institutional agreement: where a contract with your school specifies different periods, that agreement controls
8. Inactive Accounts
We may delete accounts inactive for 5 years. We will attempt to notify you by email before doing so.
This is not currently automated. Academy participants, institutional accounts, and accounts on legal hold are excluded.
9. Questions
privacy@learnwleo.com, subject "Data Retention Question." Response within 7 business days.