Skip to main content

Purge a single inbox conversation from Zernio's stored data (GDPR erasure)

We receive Instagram DMs through the Inbox API and process each message from the message.received webhook. Zernio keeps its own copy of each conversation (message text, sender IDs, metadata) for as long as the account stays connected, and the only way to remove it today is to disconnect the whole account.

When one of our users deletes their account, GDPR requires us to erase their data from our processors too, but there's no way to remove just their conversation. The DELETE message endpoint doesn't help: it's a platform unsend, it returns 400 on Instagram, and it can't remove the other participant's messages.

Request: an endpoint such as DELETE /v1/inbox/conversations/{conversationId}?accountId=... that hard-deletes the conversation and all its messages from Zernio's database. Instagram itself would be untouched. It would return 404 once the conversation is already gone, and log excerpts and backups would age out on their normal 90- and 30-day clocks.

Related: a per-account retention window (for example, auto-delete stored messages after 30 days) would help anyone who only needs the webhook and not Zernio's stored copy.

Log in to comment and vote

No comments yet

Be the first to share your thoughts.