Published in openvibe-contracts v0.76.0 (docs/adr/ADR-033-account-export-and-deletion.md), rendered as is.

ADR-033: Exporting and deleting an account

Status: Accepted 2026-09-27 (roadmap WS-B task 7). Implementation follows in OpenVibe.Network and each service that keeps data about a person.

Context and current evidence

Decision

It then confirms with POST /internal/account-deletions/:deletion_id/confirmations, carrying network.account-deletion-confirmation@1 and the capability network.account.deletion.confirm, with counts of what it erased and retained.

Alternatives considered

Migration consequences

Network gains the account_exports, account_export_parts, account_deletions and account_deletion_confirmations tables, a users deleted_at, and an hourly due-deletion check. Contracts gain two events, four schemas and two capabilities. Every service that stores data about people consumes both events. Until a service does, its export part is missing (the export says so) and its deletion confirmation is outstanding (staff see it).

Rollback

Stop offering export and deletion (the account page hides both cards). Scheduled deletions can be cancelled by staff before their date. A deletion already carried out is not reversible, by design.

Acceptance tests