Purge a single inbox conversation from Zernio's stored data (GDPR erasure)
We receive Instagram DMs through the Inbox API and process each message from the
message.receivedwebhook. Zernio keeps its own copy of each conversation (message text, sender IDs, metadata) for as long as the account stays connected, and the only way to remove it today is to disconnect the whole account.When one of our users deletes their account, GDPR requires us to erase their data from our processors too, but there's no way to remove just their conversation. The
DELETEmessage endpoint doesn't help: it's a platform unsend, it returns 400 on Instagram, and it can't remove the other participant's messages.Request: an endpoint such as
DELETE /v1/inbox/conversations/{conversationId}?accountId=...that hard-deletes the conversation and all its messages from Zernio's database. Instagram itself would be untouched. It would return 404 once the conversation is already gone, and log excerpts and backups would age out on their normal 90- and 30-day clocks.Related: a per-account retention window (for example, auto-delete stored messages after 30 days) would help anyone who only needs the webhook and not Zernio's stored copy.
Log in to comment and vote
No comments yet
Be the first to share your thoughts.