Deletion · public sample
Deletion needs a receipt, not a reassuring button.
The public sample workspace is fictional and browser-local. Clear this site’s local storage to remove its briefs, review choices, and preview calendar state from that browser.
Planned authenticated workflow
- An authorized workspace owner reauthenticates and confirms the request with a durable, expiring confirmation.
- The workspace freezes at a deletion epoch while exports, media, queued work, provider claims, and new mutations are fenced.
- Connector grants are revoked through the reviewed adapter path; D1 rows, R2 tenant prefixes, queue claims, receipts, analytics identities, and support records are removed or retained only where the final policy requires it.
- The service returns a non-sensitive completion receipt and retries cleanup failures without resurrecting tenant data.
Separate billing and deletion
Subscription cancellation and account deletion are different operations. Before public billing opens, the deployed product must show the correct owner action, preserve the required receipt, and reconcile any provider or retention obligation.
Evidence still required
Production proof requires a hosted, authenticated destructive canary with provider revocation, residual-object scanning, retry evidence, and a verified support/legal path. Until connected workspaces are offered, this remains a transparent design contract rather than a customer-account request form.