Guide · erasure engineering

Soft-delete is not erasure

deleted_at = now() hides a row. Right-to-erasure asks whether personal data is still recoverable — in your DB, backups, and the SaaS tools around your product.

Tombstones

A tombstone (or soft-delete flag) is useful: it stops the app from treating the user as active, preserves referential integrity, and gives operators a chance to undo mistakes. It is not erasure.

Prefer: wipe or anonymise PII → write an immutable deletion record (who/what/when/method) → keep only what you truly need for integrity or legal retention.

Backups

Point-in-time recovery and nightly snapshots will still contain the pre-erasure state until those backups expire. Claiming “deleted everywhere” while a 30-day backup window holds the full row is inaccurate.

Third-party SaaS

Your product is rarely the only processor. Billing, email, analytics, support, and error tracking may hold the same subject. Soft-deleting your users table does not delete their Stripe customer or Intercom contact.

Operational checklist for mapping those systems: DSAR checklist for solo founders.

Certificate of deletion

A useful certificate is a signed, datestamped statement of what you did — not a guarantee about the entire internet. Honest contents usually include:

It should not claim independent storage-fabric audits, zero backup residue, or vendor wipes you did not perform. Overclaiming is worse than a narrow, accurate attestation.

CTA — Waymark Deletion

Waymark Deletion helps small SaaS teams run a scoped erasure job and export a signed PDF certificate for what that job covered. Free: 1 deletion per month. We do not invent uptime or customer logos on the product page.