Skip to content

Expanded owned privacy export ​

Migration 20261011002000_expanded_owned_privacy_exports.sql adds prepare_privacy_export_v2. The original six-collection preparation function and artifacts remain compatible. The new preparation route is POST /admin/privacy-export-artifacts/cases/:id/prepare-expanded with { "revision": <displayed case revision> }.

The version-two snapshot contains thirteen declared collections. It retains the original profile, private wallet, owned orders, authored marketplace messages, owned support tickets and authored support messages. It adds:

  • Owned saved addresses, including the subject's saved name, contact and address fields.
  • Cart product identifiers, quantities and selected variants, excluding embedded seller profiles and cached product details. Malformed cart fields fail the complete snapshot.
  • Owned favorites and search history.
  • Owned assistant-session identifiers, titles and creation/update times.
  • Only user-authored assistant messages in those owned sessions. Model/system messages, embedded reviews/orders/search results and attachments are excluded.
  • Device, location and activity times for owned login-session observations. Session identifiers, IP addresses and user agents are excluded.

All thirteen collections share one database query snapshot and the existing private artifact storage, quota lock, 10,000-record / 10 MiB bounds, SHA-256 checksum, 24-hour expiry and retained receipt policy. A missing source, malformed selected cart item, oversized inventory or failed audit prevents artifact creation. An active global privacy operator must remain the assigned staff member for the verified, in-progress case, at the exact revision and without a hold. Preparation, status and download enforce these case and current-authority gates.

Completeness covers only the declared minimized database scope. Subject-authored free text and saved address labels may mention other people and are not independently reviewed for those mentions. External provider data, stored files, incoming/shared content, internal investigation evidence, security credentials and other collections remain excluded. Staff download does not prove delivery to the subject and never completes the full privacy request.

Local representative verification: scripts/db-expanded-privacy-export-checks.mjs replays both artifact migrations against a disposable database and tests the legacy and expanded paths. Full historical migration replay and native concurrency verification remain separate release checks. No hosted migrations or real member exports are performed by these tests.

Released under Proprietary Enterprise License.