Help for personal data
Applies to /account/privacy
The page gives you two actions on your own data: export and erasure.
The export downloads a JSON file with the platform data the server holds about you: account, membership, preferences, archive metadata, shares, proof metadata and the audit events you triggered. It holds no images, descriptions, prices or keys, because those are encrypted on your device; the readable archive report is made from your archive on your own device. Erasing removes your sign-in, marks your memberships removed, revokes shares and removes your key envelopes.
When no active member is left in an account, the recovery envelope goes too, so the content cannot be opened by anyone. Proof, sharing and membership events are append-only and are kept without naming you, because they document what happened. If you are the last active owner in a family with other members, the ownership has to be handed on first. The action requires the confirmation word and cannot be undone.