SYSTEM ADMIN
/manage/data-requests

Data export & deletion requests

Anyone using tibbi can ask for a copy of everything held about them, or ask for their account to be erased. Both are legal entitlements with a deadline attached, so they are worked here as a queue with a clock rather than as favours.

Erasing an account is not a way out of a safety control

A seven-day break from the betting floor is the thing this product exists to protect. If asking for erasure ended a cooldown, erasure would quietly become the reset button, and whoever most wanted to keep betting would find it first.

So the identifying record is destroyed and the control marker stays: a one-way code holding an end date and nothing else — no name, no email, no history. It is checked at sign-up, so erasing an account and starting again does not return a fresh run or a shorter break. This is stated to the account holder before they confirm, not discovered afterwards.

Open requests
3
1 export · 2 erasures
Earliest deadline
31 Jul
4 days left · request #DR-0030
Past the deadline
0
none since the pilot opened
Time allowed
30 days
from the day the request arrives

Days left are counted from a server date. Nobody in the admin area can move a due date; extending one takes a written reason sent to the account holder before the deadline, not after it.

The queue

Request Account What was asked for Arrived Due Stage Action
#DR-0030 U-10188
In cooldown · 2 days left
A copy of my data
Asked from the account's own privacy screen
01/07/2026 31/07
4 days left
File built · awaiting release
#DR-0031 U-10412
Active · run #1, day 3
Erase my account
Confirmed twice, 24 hours apart
05/07/2026 04/08
8 days left
Open below Being worked now
#DR-0032 U-10466
Suspended
Erase my account
Arrived after the account was suspended
10/07/2026 09/08
13 days left
Waiting on identity

A suspension does not pause the clock. #DR-0032 is still due on 9 August, and the reason it is waiting is recorded against the request, not left as a gap.

Request #DR-0031 — erase account U-10412

Step 1 · Identity confirmed

Done 27/07 08:33

A challenge was sent to the address held on the account and answered from inside the account's own signed-in session. Two things follow from that, and both matter more than they look:

  • No identity document is asked for, collected or stored. Demanding a driver licence to leave would mean collecting more sensitive data at the exact moment someone asked us to hold less.
  • The one record opened to do this — account status and cooldown state — is written to the access log with the reason and with Dr Alice Brennan's confirmation, timed before the record was opened.

Nothing on this screen shows a name, an email address or a phone number. The identity check runs against the stored value and returns a yes or a no.

Step 2 · What erasure destroys, and what it does not

This is the part worth reading slowly. Anything in the left column is gone for good and cannot be restored by anyone, at any level of access. Anything in the right column stays, stripped of identity, because removing it would destroy the evidence that the safety controls were applied at all.

Destroyed within 30 days, unrecoverableKept, with identity removed
Email address, sign-in details and two-factor device Token ledger — how many tokens were earned and staked, attached to a one-way code rather than to a person. This is what proves tokens are never bought, and it holds nothing that points back to anyone.
Age declaration and postcode Safety control records — that a cooldown started on a date, that a warning was shown, that a support number was offered. Erasing these would erase the record of protecting the person, not the record of watching them.
Linked activity-session identifiers and any baseline/endline research records still attached to the revocable pilot code. The cooldown marker — an end date against a one-way code. U-10412 is not in cooldown today. Were it running, as it is for U-10188 with two days left, the countdown would carry on after erasure and a new sign-up would not reset it.
Learning progress, quiz history and the link between this account and any operational session Pilot figures already published — counts of 20 or more people that cannot be traced back to one person and cannot be recalculated to exclude them.

The right-hand column is written into the schema as append-only. There is no admin screen that can reach it, including this one — it is listed here so the boundary is visible, not so it can be edited. E-37 real-world survey answers are not in either account column: they are written without an account identifier and cannot be located for an individual deletion request.

Step 3 · Carry out the erasure

Erasure runs like every other irreversible action in this area: a written reason, a second person, and a permanent line in the log. There is no single-click path, and the person who raises it cannot be the person who approves it.

See this request in the access log

Once approved, the account holder is told what was destroyed and what was kept, in the same words used above.

The clock on this request

StageDate on record
Arrived05/07/2026
Acknowledged to the account holder06/07/2026 · within one working day
Identity confirmed27/07/2026
Must be finished by04/08/2026 · 8 days left

If a request cannot be met in 30 days, the account holder must be told why before the deadline passes, with a new date. Going quiet is a breach on its own, separate from the delay.

What an export contains

#DR-0030

The file is assembled by the system and released straight to the account holder. No staff account opens it — there is no screen anywhere in the admin area that displays its contents.

  • Account details and the date of registration
  • Token ledger: every token earned from completed lessons or fixed Showdown milestones, and every token staked
  • Betting session history, including the transparency figures shown at the time
  • Learning progress, quiz results and linked baseline/endline answers while the pilot code still exists
  • Cooldown history with start and end dates
  • No companion transcript: the current companion opens an external service and tibbi does not collect or store the conversation text

E-37 answers are also absent because they are anonymous at save; no individual record exists to export. The file is delivered from the account holder's own privacy screen after signing in again. The link lasts seven days. It is never sent as an email attachment.

Who can act on these

System admin raises, a second person approves, and both names stay on the record. The impact analyst and any sponsor account cannot reach this screen at all — an attempt is refused and recorded as a refusal in the access log.

Not available here: erasing an account without a second person · shortening or ending a cooldown as part of an erasure · deleting a row from the safety control records or the access log · reading a companion conversation in order to "check" an export · moving a due date to buy time.