Privacy requests
Export or erase the records of one of your end users when they exercise their right of access or erasure.
When one of your own users asks for a copy of their data, or asks you to delete it, use Privacy in the sidebar. The screen is titled Data subject requests. It covers the right of access and the right to erasure under the DPDP Act and the GDPR.
A request here is about one end user. To erase everything your organization holds, see organization settings.
Before you start
The screen finds a person by the user id your application sends with each request, in the user field of the request's metadata. Requests sent without it cannot be tied to a person, so they cannot be found here.
The id is never stored in the clear. Requests are matched by a hash of it, and the request list on this screen shows that hash, not the id.
Running an export or an erasure needs the owner or admin role. Other roles can see the list of past requests.
Export a user's data
- Enter the id in End-user id (metadata.user).
- Press Export data.
Your browser downloads a JSON file named after the user's hash. It lists the user's requests: the request id, the time, the model, the tokens and the cost. It holds request details only, never the prompts or responses themselves, and never another user's records.
The screen confirms how many records were exported, and the export appears in the list below.
Erase a user's data
- Enter the id in End-user id (metadata.user).
- Press Erase data.
- Type
eraseto confirm, and press Erase data.
Erasure does two things:
- It deletes the payload archive for the user's requests, so the archived prompts and responses can no longer be read.
- It unlinks the user from analytics. Your usage totals stay the same, but the requests no longer point to the user.
Erasure cannot be undone. The screen confirms how many records were erased.
See past requests
The table lists the export and erasure requests your organization has run, with:
- Kind: erasure or export.
- Subject: the hash of the user id.
- Records: how many records the request covered.
- When: the time it ran.
Each row is your receipt that the request was carried out.
Breach notification template
The Breach notification template link in the introduction opens a template for notifying a data breach. It carries the reporting deadlines that apply under Indian and EU rules.
Related
- Data policy: what is archived in the first place, and for how long.
- Privacy API reference: the same requests from your own code.