TechnicalCollectible prompt
Data export and account deletion for privacy rights
Act as a senior backend engineer who builds privacy features. Add self-serve data export and account deletion to my {{tech_stack}} app, which stores {{data_to_store}}. Services that also hold user data: {{integrations}}. Before changing anything, map every table, storage bucket and third-party service that holds data about a person, and show me the map.
Export:
- A Download my data button in account settings, after the person enters their password again
- A ZIP of machine-readable JSON plus CSV for tables, uploaded files, and a readme explaining each file
- Built in a background job and delivered by an emailed, signed link that expires in 24 hours
- Rate limited to a few per day, and logged without the contents
Deletion:
- A Delete account flow: re-enter the password, see what will be deleted and what we must keep, and type to confirm
- A grace period of 14 to 30 days with a cancel link, then a scheduled job deletes
- Delete or anonymize rows in every table, delete stored files, cancel subscriptions, and remove the person from email lists, analytics and the payment provider where allowed
- Keep only what the law requires, such as invoices for tax, minimized and documented
- Shared content: decide with me whether it's deleted or shown as Deleted user
- Backups age out on their normal schedule; say so in the privacy policy
- A confirmation email when it's done
Also: an admin view of pending requests, a way to handle requests that arrive by email, and a deadline tracker, since requests generally need an answer within a month. This is a technical build, not legal advice; flag anything for my lawyer.
Write a test that creates a user with data everywhere, deletes them, and confirms nothing identifiable remains.
Finish with the data map, the files changed and anything you assumed.
Technicalnvoka.com/library/nvoka-gdpr-data-export-and-account-deletionScan to open
Technical
Data export and account deletion for privacy rights
Let people download all their data and delete their account for real, across every system.
Curated by Nvoka
Claude CodeCursorCodexLovable
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 3 filledYour prompt
Act as a senior backend engineer who builds privacy features. Add self-serve data export and account deletion to my {{tech_stack}} app, which stores {{data_to_store}}. Services that also hold user data: {{integrations}}. Before changing anything, map every table, storage bucket and third-party service that holds data about a person, and show me the map.
Export:
- A Download my data button in account settings, after the person enters their password again
- A ZIP of machine-readable JSON plus CSV for tables, uploaded files, and a readme explaining each file
- Built in a background job and delivered by an emailed, signed link that expires in 24 hours
- Rate limited to a few per day, and logged without the contents
Deletion:
- A Delete account flow: re-enter the password, see what will be deleted and what we must keep, and type to confirm
- A grace period of 14 to 30 days with a cancel link, then a scheduled job deletes
- Delete or anonymize rows in every table, delete stored files, cancel subscriptions, and remove the person from email lists, analytics and the payment provider where allowed
- Keep only what the law requires, such as invoices for tax, minimized and documented
- Shared content: decide with me whether it's deleted or shown as Deleted user
- Backups age out on their normal schedule; say so in the privacy policy
- A confirmation email when it's done
Also: an admin view of pending requests, a way to handle requests that arrive by email, and a deadline tracker, since requests generally need an answer within a month. This is a technical build, not legal advice; flag anything for my lawyer.
Write a test that creates a user with data everywhere, deletes them, and confirms nothing identifiable remains.
Finish with the data map, the files changed and anything you assumed.