Data export & deletion requests
Anyone using tibbi can ask for a copy of everything held about them, or ask for their account to be erased. Both are legal entitlements with a deadline attached, so they are worked here as a queue with a clock rather than as favours.
Erasing an account is not a way out of a safety control
A seven-day break from the betting floor is the thing this product exists to protect. If asking for erasure ended a cooldown, erasure would quietly become the reset button, and whoever most wanted to keep betting would find it first.
So the identifying record is destroyed and the control marker stays: a one-way code holding an end date and nothing else — no name, no email, no history. It is checked at sign-up, so erasing an account and starting again does not return a fresh run or a shorter break. This is stated to the account holder before they confirm, not discovered afterwards.
Days left are counted from a server date. Nobody in the admin area can move a due date; extending one takes a written reason sent to the account holder before the deadline, not after it.
The queue
| Request | Account | What was asked for | Arrived | Due | Stage | Action |
|---|---|---|---|---|---|---|
| #DR-0030 | U-10188 In cooldown · 2 days left |
A copy of my data Asked from the account's own privacy screen |
01/07/2026 | 31/07 4 days left |
File built · awaiting release | |
| #DR-0031 | U-10412 Active · run #1, day 3 |
Erase my account Confirmed twice, 24 hours apart |
05/07/2026 | 04/08 8 days left |
Open below | Being worked now |
| #DR-0032 | U-10466 Suspended |
Erase my account Arrived after the account was suspended |
10/07/2026 | 09/08 13 days left |
Waiting on identity |
A suspension does not pause the clock. #DR-0032 is still due on 9 August, and the reason it is waiting is recorded against the request, not left as a gap.
Request #DR-0031 — erase account U-10412
Step 1 · Identity confirmed
Done 27/07 08:33A challenge was sent to the address held on the account and answered from inside the account's own signed-in session. Two things follow from that, and both matter more than they look:
- No identity document is asked for, collected or stored. Demanding a driver licence to leave would mean collecting more sensitive data at the exact moment someone asked us to hold less.
- The one record opened to do this — account status and cooldown state — is written to the access log with the reason and with Dr Alice Brennan's confirmation, timed before the record was opened.
Nothing on this screen shows a name, an email address or a phone number. The identity check runs against the stored value and returns a yes or a no.
Step 2 · What erasure destroys, and what it does not
This is the part worth reading slowly. Anything in the left column is gone for good and cannot be restored by anyone, at any level of access. Anything in the right column stays, stripped of identity, because removing it would destroy the evidence that the safety controls were applied at all.
| Destroyed within 30 days, unrecoverable | Kept, with identity removed |
|---|---|
| Email address, sign-in details and two-factor device | Token ledger — how many tokens were earned and staked, attached to a one-way code rather than to a person. This is what proves tokens are never bought, and it holds nothing that points back to anyone. |
| Age declaration and postcode | Safety control records — that a cooldown started on a date, that a warning was shown, that a support number was offered. Erasing these would erase the record of protecting the person, not the record of watching them. |
| Linked activity-session identifiers and any baseline/endline research records still attached to the revocable pilot code. | The cooldown marker — an end date against a one-way code. U-10412 is not in cooldown today. Were it running, as it is for U-10188 with two days left, the countdown would carry on after erasure and a new sign-up would not reset it. |
| Learning progress, quiz history and the link between this account and any operational session | Pilot figures already published — counts of 20 or more people that cannot be traced back to one person and cannot be recalculated to exclude them. |
The right-hand column is written into the schema as append-only. There is no admin screen that can reach it, including this one — it is listed here so the boundary is visible, not so it can be edited. E-37 real-world survey answers are not in either account column: they are written without an account identifier and cannot be located for an individual deletion request.
Step 3 · Carry out the erasure
Erasure runs like every other irreversible action in this area: a written reason, a second person, and a permanent line in the log. There is no single-click path, and the person who raises it cannot be the person who approves it.
Once approved, the account holder is told what was destroyed and what was kept, in the same words used above.
The clock on this request
| Stage | Date on record |
|---|---|
| Arrived | 05/07/2026 |
| Acknowledged to the account holder | 06/07/2026 · within one working day |
| Identity confirmed | 27/07/2026 |
| Must be finished by | 04/08/2026 · 8 days left |
If a request cannot be met in 30 days, the account holder must be told why before the deadline passes, with a new date. Going quiet is a breach on its own, separate from the delay.
What an export contains
#DR-0030The file is assembled by the system and released straight to the account holder. No staff account opens it — there is no screen anywhere in the admin area that displays its contents.
- Account details and the date of registration
- Token ledger: every token earned from completed lessons or fixed Showdown milestones, and every token staked
- Betting session history, including the transparency figures shown at the time
- Learning progress, quiz results and linked baseline/endline answers while the pilot code still exists
- Cooldown history with start and end dates
- No companion transcript: the current companion opens an external service and tibbi does not collect or store the conversation text
E-37 answers are also absent because they are anonymous at save; no individual record exists to export. The file is delivered from the account holder's own privacy screen after signing in again. The link lasts seven days. It is never sent as an email attachment.
Who can act on these
System admin raises, a second person approves, and both names stay on the record. The impact analyst and any sponsor account cannot reach this screen at all — an attempt is refused and recorded as a refusal in the access log.
Not available here: erasing an account without a second person · shortening or ending a cooldown as part of an erasure · deleting a row from the safety control records or the access log · reading a companion conversation in order to "check" an export · moving a due date to buy time.