Deletion

Say exactly what can disappear.

Public protocol history, content storage, private service data, and local browser data have different deletion mechanics. One button cannot honestly promise all four.

Deletion disabled

Deletion ledger

Four scopes, four receipts.

Local browser
Drafts and preferences can be cleared through browser controls.
Service data
Requires authenticated operator deletion and a retention receipt.
Public storage
Availability depends on provider policy; permanent media cannot be promised erased.
Protocol state
Tombstones and rotations supersede state without rewriting finalized history.

No-op boundary

No deletion request can be submitted.

Identity authentication, exact-scope review, export-first confirmation, provider receipts, transaction finality, and post-action verification are not connected.

Pressing this disabled control changes no browser, service, storage, or protocol data.

Preview

Exact targets first

Every account, object, provider, and device scope must be listed before confirmation.

Recovery

Export before irreversible action

A verified archive and cooling-off period protect against accidental loss.

Proof

Receipts, then re-check

Success requires provider receipts and independent verification that each scope changed.