Data protection
The people you message have rights over what you hold about them - in Nigeria under the Nigeria Data Protection Act, and similar laws elsewhere. Engage gives you the three tools those rights need: a copy of everything, erasure, and a limit on how long message text is kept.
This is not legal advice
These tools make the common requests easy to carry out. Whether and how you must act on a particular request is a question for your own adviser.
A copy of their data
On the customer's page, owners press Download their data. It is one JSON file: their details and numbers, consent records and opt-outs, the events your website reported, every conversation with every message, sales, and the workflows that ran for them.
GET /v1/customers/{id}/export (owners only)Erasing a customer
Erase personal data, also owners only, confirmed by typing ERASE. It cannot be undone.
POST /v1/customers/{id}/erase (owners only)| Field | Type | Notes |
|---|---|---|
Removed | gone for good | Name, phone number, email and your own id for them; their WhatsApp numbers and consent records; the text of every message; event details; workflow context. Any workflow waiting for them stops. |
Kept | anonymous | The customer record itself, their conversations and their sales - with nothing that says who they were - so your results do not change. |
Kept on purpose | their opt-out | If they replied STOP, the opt-out stays. It is what keeps them from being messaged again, and a person who asked not to be contacted still has that wish honoured after asking to be forgotten. |
If they write to your number again afterwards, they arrive as a new customer. The response says what was removed:
{
"erasedAt": "2026-09-18T10:42:00Z",
"messagesRedacted": 14,
"eventsRedacted": 3,
"workflowRunsStopped": 1,
"optOutKept": true
}How long message text is kept
By default, everything is kept. In Settings, Workspace, Message history, an owner can choose 3 months, 6 months, 1 or 2 years instead. Every night, message text and event details older than that are removed. Who wrote, when, and whether it was delivered are kept, so conversation counts and results do not change - only the words go.
PUT /v1/workspaces/current/retention (owners only)
{ "messageRetentionDays": 365 } 30 to 3650, or null to keep everythingAn event a workflow is still waiting on is kept until the run finishes, so a reminder never goes out with the order number missing.
When the AI assistant is on
Turning it on sends each customer message, with the recent conversation, your business facts and the matching catalog items, matching published knowledge and the current customer's latest three order references, recorded statuses, sources and timestamps, to Anthropic (Claude) to read. Anthropic processes it to answer and does not use it to train its models. What was sent and answered is kept with the conversation, blanked with it by the retention period and when a customer is erased. It is off until an owner turns it on in Settings → AI assistant.
A record of what was done
Exports, erasures and lifted opt-outs are written to the workspace's audit log with who did it and when - and never the personal details they were about, so the log itself cannot undo an erasure.
Next
Suppression and consent →
Opt-outs, and opting back in.