You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
🎯 A small, repeatable erasure script a dev runs when support fields a deletion request, plus a short runbook saved in the repo describing the process end to end.
📋 Background
Users are asking Giveth to delete their accounts (GDPR "right to erasure"). On the legacy platform, support fields the request and a dev runs the erasure. The approach is anonymization in place, not hard deletion: donation records must survive for stats, and the database blocks deleting a user with donations, projects, or boosts anyway. The v6 stack has its own self-serve erasure (Giveth/giveth-v6-core#501), which defines the do-not-resync marker contract this routine implements.
🔨 What to build
The erasure script — given a user, in one run: scrub all identity on the account in place (name, email, avatar reference, location, social handles, identity/trust scores and attestations, and the account's wallet address — the person-to-wallet link is what's being erased; wallet addresses on donation records remain). Deactivate every owned project and scrub the owner's identity from it, including verification-form (GIVbacks) personal info — never hard-delete a project, and leave free-text content untouched. Remove GIVpower boosts. Purge the contact from Ortto and the notification service. Set the erased marker per Giveth/giveth-v6-core#501 so the v6 sync never re-imports the profile.
The runbook — a short reference doc committed next to the script: when to run it (a legacy user's erasure request, and any v6 self-deletion where the person also has a legacy copy), how to run it, and how to confirm completion back to support.
✅ Acceptance criteria
AC1 — One-run erasure — Given a legacy user, When a dev runs the erasure routine for them, Then in a single run all identity fields on the account are permanently scrubbed in place (including the account's wallet address), owned projects are deactivated with the owner's identity and verification-form personal info scrubbed, GIVpower boosts are removed, the contact is purged from the marketing/email platform (Ortto) and the notification service, and the erased marker is set so the v6 legacy sync never re-creates the profile.
AC2 — Donations retained — Given the erased user had donations (including recurring/streaming), Then every donation record survives with its transaction hash, amount, USD value, chain, and project intact — platform stats and project totals unchanged — but no longer points to any identifiable person.
AC3 — Nothing else touched — Given any erasure run, Then no donation record, project, finalized QF round result, or platform statistic is altered, recomputed, or deleted; no project is ever hard-deleted; the person's authored free-text content (descriptions, updates) is left as-is.
AC4 — Runbook exists — Given the routine ships, Then a short process doc lives alongside it covering: when to run it, how to run it, and confirming completion back to support.
📎 Artifacts
Source of truth: this backend owns erasure of the legacy database and fans out to Ortto + the notification service; the marker contract is defined in Giveth/giveth-v6-core#501.
🚫 Out of scope
v6 self-serve erasure and the v6 side of the sync guard → Giveth/giveth-v6-core#501
The delete-account UI on v6 → Giveth/giveth-v6-fe#664
🔗 Related issues
⛔ Blocked by Giveth/giveth-v6-core#501 — defines the shared do-not-resync marker contract (the script itself can be built in parallel).
Legacy user erasure routine + runbook
📋 Background
Users are asking Giveth to delete their accounts (GDPR "right to erasure"). On the legacy platform, support fields the request and a dev runs the erasure. The approach is anonymization in place, not hard deletion: donation records must survive for stats, and the database blocks deleting a user with donations, projects, or boosts anyway. The v6 stack has its own self-serve erasure (Giveth/giveth-v6-core#501), which defines the do-not-resync marker contract this routine implements.
🔨 What to build
✅ Acceptance criteria
📎 Artifacts
🚫 Out of scope
🔗 Related issues