Scene SizeUpSchedule a demo

Data, recordings, and retention

What the system stores, for how long, and who can see it: accounts, scenarios and their imagery, the record of every drill, radio audio and its transcripts, evaluations, and the audit trail. This is the page to read before a records request or a procurement review.

What is stored#

Data Where it lives
Accounts Your department's roster: display name, username, role, and a hashed password.
Scenarios Your department's scenarios, including uploaded and fetched imagery.
Drill records Every action in every drill, with its exercise time.
Radio audio An audio clip per transmission made after the clock starts.
Transcripts Automatic text of each transmission.
Evaluations Scores, notes, and debrief summaries, with a release state.
Audit records Administrative actions: sign-ins and failed sign-ins, account changes, scenario changes, drill creation and start, and department or plan changes, each with who did it, when, what changed, and the IP address and browser used.

Retention#

Drill records are permanent. Everything that happened in a drill, including radio transcripts and CAN reports, stays with the department's training record.

Radio audio is kept for 14 days, then deleted automatically. After that the review still shows every transmission, who made it, when, and its transcript; the play buttons are silent. If you need the audio of a particular drill beyond that window, debrief it inside the window.

Scenario photos are kept for as long as anything uses them. An image belongs to the scenario you put it in, and a drill keeps its own copy of the scenario it ran, so a past drill's review always has its photographs even if you later edit that scenario or delete it outright.

An image nothing uses any more is removed about a week after you last touched it. That covers a photo you uploaded and then replaced, or one left behind by a view you deleted. Two things follow from it worth knowing:

  • Building a scenario is safe. The week starts from when the file was last touched, so photos you upload while you are still putting a scenario together are never taken away underneath you.
  • A photo is only removed when NO scenario and NO past drill refers to it. Dropping a view from a scenario you have already drilled does not delete its photo, because that drill's review still needs it.

If you want an image kept regardless, keep it in a scenario.

If storage runs low, uploads are refused rather than half-saved. You will be told the image was not saved and that nothing else is affected, and the drill you are running is unaffected: radio audio keeps recording. Photos are the thing that gives way, because they can wait and a live drill cannot.

Audit records are retained for the life of the account, because a history with holes in it cannot answer the questions an audit trail exists for. They are readable only by the platform administrator, and nothing in the product edits or deletes them.

Lobby conversation is never stored. Open-mic talk before the clock starts is relayed live to the people in the session and kept nowhere.

Who can see what#

  • Members see drills they take part in, their own released evaluations, and the documentation.
  • Instructors see their department's scenarios, sessions, reviews, evaluations, roster, and settings.
  • Departments are separated. One department cannot see another's people, scenarios, sessions, or records.
  • Evaluations are private to the instructor who wrote them until released, and then visible only to the person evaluated.

Recording notice for your members#

People are recorded when they transmit during a drill. That is not hidden, but it is worth telling crews plainly the first time they use it:

Radio transmissions during a drill are recorded and transcribed. They are part of the training record, visible to anyone in the drill and to your instructors, and kept as audio for 14 days. Conversation in the lobby before the drill starts is not recorded.

Departments with their own records-retention rules should check that the 14-day audio window fits them, and debrief or extract anything they need to keep.

The full privacy notice is at getsizeup.com/privacy.

Deleting#

Instructors can delete a session, which takes its record and its audio out of the review list. A session with people still connected cannot be deleted.

Deleting is recoverable. An Undo bar appears straight after, and even if you miss it the record is held for 30 days before it is removed for good, so a drill deleted by mistake can be brought back. The same is true of a deleted scenario. Nothing about a deletion is instant except its disappearance from the list.

In the builder, deleting a view, an element, a situation level, a rig, or a response configuration works the same way: the Undo bar appears and puts it straight back. These live inside the thing you are editing rather than in the database, so they are recoverable until you leave, not for 30 days.

Deactivating a person blocks their sign-in but leaves their name in past drills, because removing it would put holes in the accountability record.