Data Export and Deletion
Effective: v1.4 general availability. Last updated: 2026-07-18.
Export or delete one run
In desktop Settings, open Account and use the controls beside an evidence run. Export downloads the complete tenant-owned JSON ledger. Delete removes the run, its tool calls, witnesses and ledger events, and any derived artifact no longer referenced by another retained run.
The API equivalents are:
GET /api/evidence/runsGET /api/evidence/runs/{run_id}DELETE /api/evidence/runs/{run_id}
All operations require authentication and are tenant-scoped. A run owned by a different tenant is indistinguishable from a missing run.
Purge Aletheia account data
In Settings > Account, select Purge account data, type PURGE, and confirm. The signed desktop stops its active local worker, removes encrypted vault artifacts and crash-leftover plaintext, and deletes its native vault and device keys before requesting cloud deletion. Other ordinary analysis sessions must also be disconnected. A browser can request cloud deletion and device revocation, but cannot erase an encrypted vault on an offline desktop.
The service then:
- cancels an active Stripe subscription and persists the cancelled state;
- deletes enrollment tokens, challenges, enrolled device public keys and device display names, and disconnects every live local-node tunnel;
- deletes all tenant evidence, proof artifacts and API keys;
- installs a database purge fence so stale sessions cannot recreate evidence;
- replaces the Clerk service identifier with a non-reversible internal tombstone and clears organization, quota and usage state; and
- signs the desktop session out.
Payment records required for tax, accounting, fraud prevention, refunds or disputes remain a restricted exception. The Stripe customer link is retained only for payment reconciliation and webhook processing. The Aletheia purge does not itself delete the upstream Clerk identity; request that separately through Clerk account controls or [email protected].
Timing and backups
Deletion applies to the active service immediately after a successful response. Encrypted backup copies expire within 30 days and are not used for ordinary processing. A disaster-recovery restore must replay deletion tombstones before the restored service can accept traffic.
If an active session blocks purge, the desktop waits briefly for teardown and retries the cloud request. If a worker cannot stop safely or Stripe cannot confirm cancellation, account purge fails closed and does not report complete success. A local filesystem or keychain failure is surfaced explicitly; retry before removing the application. Contact [email protected] if the control remains unavailable.