Erasure and privacy
When someone asks you to delete their data, one call erases everything they made in Lettrove.
await lettrove.users.erase('u_123'); // your own id for them
DELETE https://api.lettrove.com/embed/v1/users/u_123
Authorization: Bearer lt_sk_live_…
→ 202 { "status": "erasing" } erasure has started
→ 204 Lettrove never saw this id: nothing to erase
What happens
- At once, no new token is issued for them: a token request answers
409 user_erased, and an editor they have open stops at its next request. - Within moments, everything they made is erased: their designs and restore points, their uploaded and generated images, their brands, and the files of their exports. There is no grace period: they asked.
- A
user.erasedwebhook tells your server when it is done.
Calling it again is the same request. After it is done, the same id is a new, empty person.
What is kept
| Kept | Why |
|---|---|
| The file of an image an email went out with — not its record, its name or who uploaded it | Emails already sent load it from its address; deleting it would break them (why) |
| Export records and AI usage counts, with the person's id removed | Your usage and billing figures stay correct |
| The audit entry that the erasure happened (counts only, never what was erased) | Proof you did what was asked |
Your obligations, and ours
- You are the controller; Lettrove is the processor. You decide whose data goes in and when it comes out; Lettrove processes it only to run the editor for you.
- No personal data comes to Lettrove by design: your users are opaque ids, and form submissions go to you.
- For data processing terms, subprocessors and regions, write to support@lettrove.com.