Answering a data-subject request
Your workspace decides what happens to the personal data your members put into it, and Yekar.AI carries out those decisions. So when a person asks for a copy of their data, or asks for it to be erased, an Owner or Admin of your workspace carries out the request from Settings → Users. Yekar.AI deletes the account itself once every workspace has erased its member.
A copy of a person's data
Anyone can export their own data from Settings → My data → Export my data. An Owner or Admin can prepare the same export for any member from the member's row in Settings → Users → Export data, for example to answer a request that reached you rather than the person.
The export is a ZIP file of JSON files. manifest.json lists what the export holds, how many items of each kind, and anything deliberately left out and why. The export holds:
- the person's profile and domain memberships;
- the conversations they started or wrote in. In a conversation other people also used, only the person's own messages are included;
- the original files they uploaded;
- their memories, ratings, and the runs they triggered;
- the names and last-used dates of their API keys, never the keys themselves.
The export is built in the background. Its status appears under Settings → My data, and an email tells the requester when it is ready. The file can be downloaded for 7 days. After that it is deleted, and a new export has to be requested. Only the person who requested an export can download it. Support sessions cannot download exports. Each export request and each download is recorded in the audit trail.
Erasing a member
An Owner or Admin erases a member from the member's row in Settings → Users → Erase member, and confirms by typing the member's name. The person loses access immediately, and an erased member can never be re-enabled. Erasure then does the following:
| What | Erasure |
|---|---|
| Conversations only this person used | Deleted, with their attachments and recorded actions |
| Their messages in conversations other people also used | Replaced with "[removed by erasure]". Other people's messages and the agent's replies stay |
| Their uploads in those shared conversations | Deleted |
| What the agent did for them in those conversations | The input and output of each action taken on their request are cleared. The record that the action happened stays |
| Agent turns in those conversations waiting on someone else | Their words in the turn's saved copy of the conversation are replaced the same way |
| Their memories, ratings, API keys, personal sign-ins and exports | Deleted |
| What they typed into runs they started, and their approval comments | Cleared. The runs and decisions themselves stay |
| Agent turns waiting on their approval or confirmation | Ended immediately, with a note in the conversation saying why |
| Triggers they created | Disabled, not deleted, because their run history belongs to the workspace |
| Agents, flows, published versions and knowledge they authored | Kept. They are the workspace's and keep working |
| Eval cases they saved and memories an agent kept | Kept, as the workspace's agent-quality assets. Delete them separately if they must go too |
| The audit trail | Kept. It names people by internal id only, and an erased member's id resolves to "Erased member" |
The member stays in the list as Erased member, with no name and no address. The audit trail records the erasure with the number of items removed and the number of kept copies (eval cases and agent memories), but never the person's name or address.
A member provisioned by a partner platform is erased through that platform's API, not from Settings → Users.
Deleting the account
A person's sign-in account can belong to several workspaces. Yekar.AI deletes the account itself, meaning the sign-in address, name and password, once every workspace the person belongs to has erased its member. Send that request to Yekar.AI support. After deletion, the address can sign up again. One free trial per address still applies, checked against a one-way digest of the address that deletion keeps for that purpose.
Deleting the workspace
An Owner can delete the whole workspace from Settings → Data → Delete workspace, confirming by typing the workspace name. Yekar.AI can also schedule the deletion when a contract ends. Either way:
- The workspace is suspended immediately. Nobody can use it and nothing runs. Owners can still export it, and anyone can still download their own exports.
- 30 days later, it is permanently deleted: every conversation, agent, flow, knowledge article, connection, member and stored file.
- Until that date, an Owner (or Yekar.AI) can cancel. The workspace then returns to the state it was in before the deletion was scheduled.
- A plan payment that goes through during those 30 days also cancels the deletion, and the workspace becomes active again.
- Once the date has passed, the deletion is under way and can no longer be cancelled, by a payment or otherwise.
- Every Owner is emailed when the deletion is scheduled, and again when it completes. The second email is the record of the deletion, with a reference number.
Before deleting, an Owner can take a full copy with Export workspace on the same page. The copy is a ZIP of JSON files covering members, domains, every conversation, the agents and flows with their published configuration, knowledge, the audit trail and the issued invoices, plus uploaded files. It is listed under Settings → My data. Stored credentials are never exported.
Three things are kept after the deletion, as the law requires:
- The audit trail, which names people by internal id only.
- Issued invoices, which are tax documents.
- The deletion record itself.
A person's sign-in account is not deleted with a workspace, because it may belong to others. See Deleting the account.