For Florida law firms
Deletion requests: a firm's client asks the firm to delete their records, and the firm answers on the record
firm lane · Deterministic — no model call
Current availability
ShippedConfigured and enabled: a person whose matter sits at a firm (the direct consumer account deletes its own records itself).
- Where it lives
- Security & data (/dashboard/security) for the person · Firm settings → Records (/firms/manage/records) for the firm · /api/account/deletion-requests · /api/admin/deletion-requests
- What unlocks it
- a person with records at a firm asks and withdraws; the firm's staff read the requests; an attorney or administrator of the firm, able to open the matter, takes one up and answers it
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedA person whose records sit at a firm asks it to delete one matter or everything of theirs at the firm, with a note in their own words — recorded, and the firm's attorneys and administrators hear of it in the app.
- ShippedThe firm takes a request up and answers it: done — refused unless it is true (the firm's own deletion receipt for the matter exists; for everything, nothing of the person's remains at the firm) — or declined with the reason the person reads; the firm may keep a confidential note the person never sees.
- ShippedThe person reads each request's status — received, under review, a legal hold applies (with the hold's public reason, while it stands), deleted, declined with the firm's reason, withdrawn — and withdraws an open one.
- ShippedThe request is the firm's record: each step is set once, the record never changes otherwise, and a deleted account or matter leaves it with its plain ids and the names written at the time.
Limits
- Asking deletes nothing: the firm deletes a matter from its Records under its retention policy (a matter inside its period, or under a legal hold, is kept) — the request records the ask and the answer.
- The firm's own staff do not ask their firm this way; the direct consumer account deletes its own records from Security & data.
- The person hears of an answer in the app; no e-mail is sent for it.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| invalid | 400 | A request names one matter or everything at a firm; a decline needs the reason the person reads. |
| not-a-client | 403 | The firm's own staff do not ask the firm to delete its records this way. |
| not-authorized | 403 | An attorney or an administrator of the firm, able to open the matter, answers a deletion request. |
| unknown-matter | 404 | The matter was not found among the person's own at that firm. |
| unknown-firm | 404 | No records of the person's were found at that firm. |
| unknown-request | 404 | The request was not found. |
| self-service | 409 | The records are the person's own to delete, from their account. |
| withdrawn | 409 | The person withdrew the request. |
| decided | 409 | The request was already answered. |
| not-deleted | 409 | Not yet true: the records still stand — delete them first, or decline with the reason. |
| unavailable | 503 | The request or the answer could not be read or recorded just now — nothing was changed. |
Evidence
- supabase/migrations/20260928060000_phase10c_deletion_requests.sql
- src/app/api/account/deletion-requests/route.ts
- src/app/api/admin/deletion-requests/route.ts
- src/lib/deletion-requests/policy.ts
- src/components/DeletionRequestsPanel.tsx
- src/components/deletion-requests/FirmDeletionRequests.tsx
- docs/security/MASTER-PLAN-PHASE10C-PART4A-2026-09-28.md
Last reviewed 2026-09-28