Control
Data erasure does not reach embeddings, vector stores or AI chat history
When a person's data must be erased, the deletion path also removes their embeddings, vector-store entries, chat history, agent memory and provider-side stored objects.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
Law in force in European Union (EU).
The guard to add
Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.
Extend the erasure path (DELETE /account, delete_user, the data-subject-request worker) so that after the primary records it deletes everything keyed to the person in AI stores: vector-store entries by id, metadata filter or per-user namespace, conversation and chat-history tables, agent memory and checkpoints, and files, vector-store files, threads or conversations held with the model provider. This requires writing the user id as metadata on every vector and recording every provider object id at creation, so the deletion can find them. Where a legal hold or retention exception applies, skip only the covered items and record the reason; log which stores were erased.
Where it goes: 1 application source code, 2 data models, 6 API calls and integrations.
What reviewers look for: in the same deletion handler or job, calls such as collection.delete(where={'user_id': ...}), index.delete(ids=...) or a namespace delete, vector_store.delete(ids), chat-history and memory deletes, and client.files.delete / client.conversations.delete for stored provider objects; user_id metadata written on every embedding; any retained item tied to a recorded legal hold or retention reason.
Example (FastAPI + Chroma + OpenAI SDK), before:
@app.delete('/account')
def delete_account(user=Depends(current_user)):
db.users.delete(user.id)
return {'status': 'deleted'}After:
@app.delete('/account')
def delete_account(user=Depends(current_user)):
db.users.delete(user.id)
collection.delete(where={'user_id': user.id}) # Chroma embeddings
db.chat_messages.delete_for_user(user.id) # conversation history
for f in db.provider_files.for_user(user.id):
client.files.delete(f.file_id) # files stored with OpenAI
for c in db.provider_conversations.for_user(user.id):
client.conversations.delete(c.conversation_id)
erasure_log.record(user.id, stores=['chroma', 'chat', 'openai_files', 'openai_conversations'])
return {'status': 'deleted'}Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Binding law — in force (1)
- European Union (EU)
- Erasure must also delete a person's embeddings, vector entries and AI chat history (GDPR Art. 17(1)) GDPR Article 17(1) · AI-adjacent law