RETROVIA

Privacy, intentionally minimal.

Last updated: August 18, 2026.

The short version

Retrovia uses organization workspaces, not personal student accounts. We do not ask students for a name, personal email, password, birth date, home address, grades, transcript, or school record. Student answers are stored under an anonymous return code, and an individual report is not shown to an inviting organization unless the student chooses to share it.

Organization workspaces and private links

Retrovia stores the school, co-op, or program name, a one-way hash of its private administrator code, private-link records, and aggregate assessment activity. Administrators create and revoke private student links. The complete link is displayed once; Retrovia stores a one-way hash and its final four characters. Administrators must distribute links only to the intended cohort and revoke them when finished.

What Retrovia stores

Retrovia stores assessment answers, report results, timestamps, an anonymous return-code hash, and the school workspace identifier when a private school link is used. For an independent paid report, Retrovia also stores the Stripe Checkout session identifier, payment status, amount, currency, and payment timestamp under the anonymous assessment identifier. It does not store card or bank details. A browser may also hold an unfinished draft or the anonymous report session needed to return from Checkout. Retrovia does not sell student information, use it for advertising, or build personal student profiles.

Payments through Stripe

Stripe processes independent-report payments on its hosted Checkout page and applies its own privacy practices. Stripe may collect payment credentials, billing information, device information, and other details needed to process the transaction and prevent fraud. Retrovia receives only the limited transaction record needed to confirm that the $1 report unlock was paid. See Stripe’s privacy policy ↗.

Free text is scrubbed before storage and AI use

Student-written answers pass through a server-side data-minimization filter before Retrovia stores them or sends them to an AI provider. The filter removes recognizable email addresses, phone numbers, government and student identifiers, precise street addresses, birth dates stated as such, social handles, precise coordinates, and names introduced with phrases such as “my name is.” This materially reduces exposure, but automated filtering cannot guarantee that every sensitive detail will be detected. Students are still told not to include sensitive information, and schools should reinforce that instruction.

OpenAI processing and retention

Retrovia sends the minimized assessment content to the OpenAI Responses API for clarification, compatibility analysis, career research, and evidence verification. Requests set store: false. OpenAI states that API data is not used to train its models by default, but default abuse-monitoring logs may retain customer content for up to 30 days. OpenAI Zero Data Retention is a separate control requiring approval and configuration. Retrovia does not claim that a pilot uses Zero Data Retention unless that exact API project has been approved, enabled, and verified. See OpenAI’s current API data-control documentation ↗.

School contract and subprocessor review

Before a live school pilot begins, the written school agreement must identify OpenAI as a subprocessor, document the applicable API retention setting, and incorporate or otherwise address the applicable OpenAI Data Processing Addendum (DPA) or equivalent school-approved data-processing terms. Retrovia will not describe those protections as active merely because the code uses store: false. The school must complete its own vendor, privacy, and legal review before sending real students through the service.

Retrovia retention

Retrovia applies a 90-day inactivity limit to student assessment answers and reports. Expired records are purged when service activity runs the retention cleanup and then disappear from the student return-code flow and school dashboard, including any report the student had chosen to share. Students may delete earlier from the Support page using the anonymous return code. Schools may request cohort or workspace deletion through the contact route in their pilot agreement.

Age and school authorization

Independent use is intended for people age 13 and older. Retrovia is not intended for a child under 13 unless a participating school has first confirmed and documented the consent or authorization required by applicable law and its own policies. A school serving younger grades is responsible for determining whether COPPA or another child-privacy rule applies and for obtaining any required parental consent before use.

Limits of anonymity

Not asking for identity is a data-minimization choice; it is not a promise that every use is legally anonymous or outside student-privacy law. A private link, technical logs, school context, or a student’s own free text may still create privacy considerations. Schools must review the final implementation and written agreement for FERPA, COPPA, state student-privacy laws, and their own policies before a pilot.