Erase a visitor's data

Updated May 22, 2026

A visitor has asked you to delete everything you hold about them, which GDPR Article 17 entitles them to. Yaplet does this in one action from the inbox. It is immediate and irreversible — there is no undo and no way to restore the data from a backup afterwards, so be sure you have the right person before you start.

Only the organisation owner can erase a visitor. Nobody else sees the button. Every erasure is permanently recorded in the audit log.

How to erase a visitor's data

  1. Open any of that visitor's conversations in the inbox.
  2. In the sidebar on the right, open the visitor's details and scroll to the actions at the bottom.
  3. Click Delete visitor data.
  4. Confirm twice. The first dialog tells you the visitor and all their chats will be deleted; the second asks you to confirm that this cannot be undone.

What gets deleted

  • The visitor's profile — name, email, country, custom data fields and the external ID your own system passed in.
  • Everything Yaplet worked out about them — sessions, devices, IP addresses, risk signals, trust score and ban history.
  • Every conversation and message — across every channel and every brand in your organisation, from both the visitor and your team.
  • Uploaded files and images sent in those conversations, removed from storage rather than just unlinked.
  • Their session replays, along with the page-by-page event history behind them.

What is not deleted

  • The audit log entry. The record that the erasure happened — which visitor ID, how many chats, how many messages — is kept permanently. GDPR accountability requires it, and it is what you show as proof.
  • Tickets the visitor filed. A ticket on one of your boards is your team's working record, so it stays where it is; the link back to the visitor is removed, so the ticket no longer points at anybody. Any screenshot attached to it is deleted from storage. If a ticket's own text contains the person's details, you have to edit or delete that ticket yourself.

Check it worked

Search for their email address in Yaplet afterwards — you should find nothing. Then open the audit log and look for the visitor.erased entry, which records the visitor ID and how many chats and messages were removed.

Erasure versus correction

If the visitor only wants something corrected rather than deleted, do not run an erasure. Edit their profile fields directly instead — correcting a name or an email address does not require destroying their history.

Some of it may already be gone

Yaplet deletes old data on its own schedule, so part of what the requester is asking about may have expired before they asked. Conversations go after three years of inactivity on a paid plan, or 120 days on the free plan, and an anonymous visitor with no conversations left goes after 125 days of inactivity. Manual erasure is still the only way to guarantee removal on demand, and it is the only one that produces an audit-log entry naming you and the moment you did it. See What Yaplet deletes automatically.

GDPR timelines

You have 30 days to respond to a right-to-erasure request. The audit log entry gives you a verifiable timestamp you can share with the requester as proof that you acted.

Did this article answer your question?