Skip to contentSaltar al contenidoAle nan kontni anПерейти к содержимомуדלג לתוכן
EstateDraftFL

For Florida law firms

Deletion requests: a firm's client asks the firm to delete their records, and the firm answers on the record

firm lane · Deterministic — no model call

Current availability

ShippedConfigured and enabled: a person whose matter sits at a firm (the direct consumer account deletes its own records itself).

Where it lives
Security & data (/dashboard/security) for the person · Firm settings → Records (/firms/manage/records) for the firm · /api/account/deletion-requests · /api/admin/deletion-requests
What unlocks it
a person with records at a firm asks and withdraws; the firm's staff read the requests; an attorney or administrator of the firm, able to open the matter, takes one up and answers it

Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.

Capabilities

  • ShippedA person whose records sit at a firm asks it to delete one matter or everything of theirs at the firm, with a note in their own words — recorded, and the firm's attorneys and administrators hear of it in the app.
  • ShippedThe firm takes a request up and answers it: done — refused unless it is true (the firm's own deletion receipt for the matter exists; for everything, nothing of the person's remains at the firm) — or declined with the reason the person reads; the firm may keep a confidential note the person never sees.
  • ShippedThe person reads each request's status — received, under review, a legal hold applies (with the hold's public reason, while it stands), deleted, declined with the firm's reason, withdrawn — and withdraws an open one.
  • ShippedThe request is the firm's record: each step is set once, the record never changes otherwise, and a deleted account or matter leaves it with its plain ids and the names written at the time.

Limits

  • Asking deletes nothing: the firm deletes a matter from its Records under its retention policy (a matter inside its period, or under a legal hold, is kept) — the request records the ask and the answer.
  • The firm's own staff do not ask their firm this way; the direct consumer account deletes its own records from Security & data.
  • The person hears of an answer in the app; no e-mail is sent for it.

What EstateDraftFL refuses

Reason codeHTTPWhat it means
invalid400A request names one matter or everything at a firm; a decline needs the reason the person reads.
not-a-client403The firm's own staff do not ask the firm to delete its records this way.
not-authorized403An attorney or an administrator of the firm, able to open the matter, answers a deletion request.
unknown-matter404The matter was not found among the person's own at that firm.
unknown-firm404No records of the person's were found at that firm.
unknown-request404The request was not found.
self-service409The records are the person's own to delete, from their account.
withdrawn409The person withdrew the request.
decided409The request was already answered.
not-deleted409Not yet true: the records still stand — delete them first, or decline with the reason.
unavailable503The request or the answer could not be read or recorded just now — nothing was changed.

Evidence

  • supabase/migrations/20260928060000_phase10c_deletion_requests.sql
  • src/app/api/account/deletion-requests/route.ts
  • src/app/api/admin/deletion-requests/route.ts
  • src/lib/deletion-requests/policy.ts
  • src/components/DeletionRequestsPanel.tsx
  • src/components/deletion-requests/FirmDeletionRequests.tsx
  • docs/security/MASTER-PLAN-PHASE10C-PART4A-2026-09-28.md

Last reviewed 2026-09-28

← All surfaces