Acquainto
← API reference

Subjects

POST/v1/subjects/{subjectRef}/erase

Erase a subject

Erases every response for one respondent, across all of your eflows, and returns a receipt you can hand to your own regulator.

It also scrubs the personalized links minted for them: subjectRef and prefill are cleared and the links are revoked, so nothing you asserted about that person survives the call. Anonymous campaign links (minted without a subjectRef) are left alone — their prefill belongs to everyone who redeems them.

The receipt covers our systems, and stops at yours. Data already delivered to a destination you connected — a row in your Google Sheet, a payload your webhook endpoint accepted, a completion email already in an inbox — sits in a system we do not control and is not reached by this call. Those are your own processors, and an erasure commitment you make to your respondent has to carve them out explicitly or cover them yourself.

subjectRef is the raw identifier you supplied when the session started — the same value subjectRef reports on a response. Erasing a subject we hold no data for is a success with zero counts, not a 404: “we hold nothing for this person” is a valid answer to a deletion request.

Requires the responses:write scope.

Example request

curl https://api.acquainto.com/v1/subjects/string/erase \
  -H "Authorization: Bearer acq_live_xxxxxxxx" \
  -X POST \
  -H "Content-Type: application/json"

Parameters

  • subjectRefpathstringrequired

    Your own respondent identifier, URL-encoded.

Responses

200Erase a subject
  • subjectRefstringrequired

    Echoed back so the receipt is self-describing.

  • erasedAtstringrequired
  • responsesDeletedintegerrequired
  • answersDeletedintegerrequired
  • transcriptTurnsDeletedintegerrequired
  • linksScrubbedintegerrequired

    Personalized links minted for this subject whose subjectRef and prefill were erased. Those links are revoked in the same transaction.

400The request was malformed or failed validation.
  • errorobjectrequired
    • type"invalid_request_error" | "authentication_error" | "permission_error" | "not_found_error" | "idempotency_error" | "rate_limit_error" | "api_error"required

      The bucket a client branches on to decide how to react.

    • codestringrequired

      Stable machine-readable code. Branch on this, not on `message`.

    • messagestringrequired

      Human-readable. May change without notice.

    • paramstring

      The offending request field, when the error names one.

    • requestIdstringrequired

      Echoes the `req_...` id; quote it in support requests.

401Missing, invalid, or revoked credential.
  • errorobjectrequired
    • type"invalid_request_error" | "authentication_error" | "permission_error" | "not_found_error" | "idempotency_error" | "rate_limit_error" | "api_error"required

      The bucket a client branches on to decide how to react.

    • codestringrequired

      Stable machine-readable code. Branch on this, not on `message`.

    • messagestringrequired

      Human-readable. May change without notice.

    • paramstring

      The offending request field, when the error names one.

    • requestIdstringrequired

      Echoes the `req_...` id; quote it in support requests.

403The credential lacks the scope this route requires.
  • errorobjectrequired
    • type"invalid_request_error" | "authentication_error" | "permission_error" | "not_found_error" | "idempotency_error" | "rate_limit_error" | "api_error"required

      The bucket a client branches on to decide how to react.

    • codestringrequired

      Stable machine-readable code. Branch on this, not on `message`.

    • messagestringrequired

      Human-readable. May change without notice.

    • paramstring

      The offending request field, when the error names one.

    • requestIdstringrequired

      Echoes the `req_...` id; quote it in support requests.

404No such resource, or it belongs to another tenant.
  • errorobjectrequired
    • type"invalid_request_error" | "authentication_error" | "permission_error" | "not_found_error" | "idempotency_error" | "rate_limit_error" | "api_error"required

      The bucket a client branches on to decide how to react.

    • codestringrequired

      Stable machine-readable code. Branch on this, not on `message`.

    • messagestringrequired

      Human-readable. May change without notice.

    • paramstring

      The offending request field, when the error names one.

    • requestIdstringrequired

      Echoes the `req_...` id; quote it in support requests.

429Rate limited. Retry after the interval in `Retry-After`.
  • errorobjectrequired
    • type"invalid_request_error" | "authentication_error" | "permission_error" | "not_found_error" | "idempotency_error" | "rate_limit_error" | "api_error"required

      The bucket a client branches on to decide how to react.

    • codestringrequired

      Stable machine-readable code. Branch on this, not on `message`.

    • messagestringrequired

      Human-readable. May change without notice.

    • paramstring

      The offending request field, when the error names one.

    • requestIdstringrequired

      Echoes the `req_...` id; quote it in support requests.

500Something failed on our side. Safe to retry.
  • errorobjectrequired
    • type"invalid_request_error" | "authentication_error" | "permission_error" | "not_found_error" | "idempotency_error" | "rate_limit_error" | "api_error"required

      The bucket a client branches on to decide how to react.

    • codestringrequired

      Stable machine-readable code. Branch on this, not on `message`.

    • messagestringrequired

      Human-readable. May change without notice.

    • paramstring

      The offending request field, when the error names one.

    • requestIdstringrequired

      Echoes the `req_...` id; quote it in support requests.

Browse every operation, with full request/response schemas, in the full API reference.