How erasure treats content a person authored
Data-subject erasure deletes personal data across every store; documents and templates the person authored for the organization are anonymized, not destroyed.
Prerequisites
- Admin access to run a data-subject deletion
What is deleted
- An erasure run removes the subject's personal data from every content-bearing service: conversations, messages, files, usage rows, feedback the person wrote, and derived copies of that feedback (mined pattern samples and locally curated test copies).
- A deletion certificate is issued only when every service reports complete — a partial run never mints a certificate.
What is anonymized instead
- Prompt templates the person AUTHORED for the organization are anonymized: authorship and identifying fields are severed, the organizational content remains. Billing/cost-ledger rows and governance evidence keep their row with the subject identifiers severed.
- This is a deliberate, documented posture: erasure targets personal data, not the organization's work product. Destroying shared documents would exceed what data-protection law requires and damage the tenant.
Validate
- Erasure scope understood: personal data deleted, org work-product anonymized
- Deletion certificate reviewed after a run
Next steps
- Run a test erasure in a non-production tenant to observe the certificate