{
  "id": 11880745,
  "title": "Our delete all my data button leaves one table alone, and the dialog says so",
  "url": "https://urgent.news/2026/10/04/our-delete-all-my-data-button-leaves-one-table-alone-and-the-dialog",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-04T08:15:12.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/daniel_pertu/our-delete-all-my-data-button-leaves-one-table-alone-and-the-dialog-says-so-2n65"
  },
  "original_language": "en",
  "account": "The app contains two controls promised in the privacy policy: export everything and delete everything. Both are straightforward decisions, but the exclusion in the delete function is more complex. During export, seven tables are assembled into a single JSON document and returned as a download. Personal data, such as onboarding answers, is included to ensure the export is truly complete. The onboarding answers also include a deletion date, acknowledging the retention promise that the user accepts.\n\nThe delete function first performs a bulk delete operation and then issues four separate statements for other tables. This pipelining approach reduces network round trips and simplifies reasoning about concurrency, despite being initially perceived as a concurrency bug. The exclusion is that exercise attempts are not deleted by this control, as they are counted towards the AI scoring budget and must be retained. This decision prioritizes metering over deletion, ensuring that customers cannot easily reset paid features.\n\nThe deletion control also has an interesting trade-off. While it deletes certain data, it retains a marker indicating whether a review was requested, resetting the account to a state where the review prompt can appear again. This is considered a design choice, as suppressing repeat asks is the responsibility of the component rendering the prompt, not the deletion endpoint.\n\nThe policy explicitly states that assessment centre exercise attempts, including written answers and AI feedback, are retained until the account is deleted to enforce usage limits. They are removed immediately upon account deletion, as keeping this data would violate the principle of not retaining data unnecessarily. The deletion endpoint does not make product decisions, and its existence helps maintain the exclusion list in the privacy policy.",
  "summary": "Two of the controls a privacy policy promises, export everything and delete everything, live in the same route file in our app. Neither is complicated. The decisions inside them are, and the one I want to write down is an exclusion. Export: seven tables, one round trip, one header The export mode fires every read at once and assembles a single JSON document: const [ userRows , sessions ,…",
  "key_points": [
    "Delete function excludes exercise attempts for AI scoring budget",
    "Retains marker for review requests to reset account state",
    "Policy retains assessment centre data until account deletion"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}