# Data and privacy (/docs/account/data-and-privacy)



Open **Settings > Data and privacy** for workspace export and browser analytics controls. Workspace deletion lives in Workspace. Personal account deletion lives in Profile.

## Product analytics [#product-analytics]

Optional product analytics starts off. Each browser stores its own choice. If you opt in, Invokeable records allowlisted product events without form capture, session replay, or customer content.

You can withdraw consent from the same control. Withdrawal stops future analytics from that browser and clears its local analytics state.

## Error monitoring [#error-monitoring]

Minimized browser error monitoring is separate from optional analytics. It records generic failures and approved operation labels. It excludes names, customer messages, form values, request bodies, cookies, secrets, and raw exceptions.

## Export workspace data [#export-workspace-data]

<Steps>
  <Step>
    ### Request an export [#request-an-export]

    Open Data and privacy and choose the workspace export action. Invokeable records the export scope, limitations, integrity information, and expiry.
  </Step>

  <Step>
    ### Wait for processing [#wait-for-processing]

    The export may move through requested, processing, ready, failed, expired, or revoked states.
  </Step>

  <Step>
    ### Download the ready export [#download-the-ready-export]

    A ready export uses a temporary, workspace-authorized download URL. Download it before the displayed expiry.
  </Step>
</Steps>

If an export fails, request a replacement after resolving the displayed cause. A revoked or expired export cannot be downloaded.

## Evidence access [#evidence-access]

Workspace roles set the maximum evidence access a member can receive. Active evidence restrictions can require an additional, purpose-bound grant. Deny decisions take precedence, and an existing export cannot bypass a later restriction.

## Privacy requests [#privacy-requests]

Use the published privacy contact for access, correction, portability, or personal-data deletion requests. Do not include credentials or unrelated customer records in the request.

## Deletion boundaries [#deletion-boundaries]

* Workspace deletion closes an organization's workspace after a grace period and blocker checks.
* Personal account deletion removes one user's identity after ownership checks.
* Governed deletion applies retention, legal hold, and audit rules to specific records.

See [Workspace and members](/docs/account/workspace-and-members) and [Safety and verification](/docs/concepts/safety-and-verification).
