Skip to content

docs: ADR-0017 data deletion and retention, TDD-0004 deletion and export - #25

Open
AlessioBrillo wants to merge 1 commit into
mainfrom
docs/tdd-0004-deletion-export
Open

AlessioBrillo wants to merge 1 commit into
mainfrom
docs/tdd-0004-deletion-export

Conversation

@AlessioBrillo

Copy link
Copy Markdown
Owner

What

  • ADR-0017 (proposed): hard delete, data-free tombstones, account deletion of Averyn data only, backups expire per operator policy.
  • TDD-0004: endpoints DELETE /v1/activities/{id}, DELETE /v1/me, GET /v1/me/export, order of operations, tests.
  • OpenAPI, data classification, threat model, roadmap, self-hosting guide and TDD-0002 Q3 updated.

Why

TDD-0002 Q3 and the data classification rules ("deletion is real", "every user can export") require this before any public instance.

Review focus

  • Account deletion marks the user row deleted_at first and answers 403 afterwards, except DELETE /v1/me (idempotent retry).
  • ADR stays proposed until the implementation PRs merge.

🤖 Generated with Claude Code

Resolves TDD-0002 Q3: hard delete with data-free tombstones (410 on re-upload), account deletion
of Averyn data only, operator-owned backup retention, synchronous ZIP export.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant