> Lettrove docs 1.x · https://docs.lettrove.com/docs/data/erasure

# Erasure and privacy

When someone asks you to delete their data, one call erases everything they made in Lettrove.

```ts
await lettrove.users.erase('u_123'); // your own id for them
```

```http
DELETE https://api.lettrove.com/embed/v1/users/u_123
Authorization: Bearer lt_sk_live_…

→ 202 { "status": "erasing" }     erasure has started
→ 204                             Lettrove never saw this id: nothing to erase
```

## What happens

1. **At once**, no new token is issued for them: a token request answers `409 user_erased`, and an
   editor they have open stops at its next request.
2. **Within moments**, everything they made is erased: their designs and restore points, their
   uploaded and generated images, their brands, and the files of their exports. There is no grace
   period: they asked.
3. A `user.erased` [webhook](/docs/server/webhooks) tells your server when it is done.

Calling it again is the same request. After it is done, the same id is a new, empty person.

## What is kept

| Kept | Why |
|---|---|
| The **file** of an image an email went out with — not its record, its name or who uploaded it | Emails already sent load it from its address; deleting it would break them ([why](/docs/data/what-we-store#images-an-email-went-out-with-are-never-deleted)) |
| Export records and AI usage counts, **with the person's id removed** | Your usage and billing figures stay correct |
| The audit entry that the erasure happened (counts only, never what was erased) | Proof you did what was asked |

## Your obligations, and ours

- **You are the controller; Lettrove is the processor.** You decide whose data goes in and when it
  comes out; Lettrove processes it only to run the editor for you.
- **No personal data comes to Lettrove by design**: your users are opaque ids, and form submissions
  go to you.
- For data processing terms, subprocessors and regions, write to support@lettrove.com.
