Skip to main content
Request a deletion, review a preview of what will be removed, then confirm with a time-limited token. Scopes cover individual messages, full inboxes, or entire organizations. Every request is audit-logged.

How it works

  1. Create a deletion request — specify scope (organization, inbox, or messages) and get a preview
  2. Review the preview — see exactly what will be deleted before committing
  3. Confirm with token — use the time-limited confirmation token to execute
  4. Deletion executes — data is permanently removed and counts are returned

Create a deletion request

Parameters

Response

The confirmation_token is only returned once. Store it securely — you need it to confirm the deletion. The token expires at the confirm_by time (typically 1 hour).

Confirm deletion

Execute the deletion by providing the confirmation token:

Response

Check deletion status

Deletion statuses

Scopes

organization

Permanently deletes all data for your organization:
  • All messages, threads, attachments
  • All delivery events and suppressions
  • All inboxes and domains
  • All API keys and users
  • The organization itself

inbox

Deletes all data for a specific inbox:
  • All messages in the inbox
  • All attachments
  • All delivery events
  • Thread metadata

messages

Deletes messages matching the criteria:
  • Messages before the before date
  • Their associated attachments
  • Corresponding delivery events

Permissions

Data deletion requires either:
  • The admin permission on your API key, or
  • The data:delete permission
JWT-authenticated dashboard users can also create deletion requests.

Security

  • Confirmation tokens are hashed — only the hash is stored; the raw token is returned once
  • Time-limited — tokens expire after 1 hour
  • Audit logged — all deletion requests are recorded with the requester identity
  • Idempotent — confirming an already-completed request returns the completion status
  • Conflict detection — only one active deletion request per scope is allowed

What’s next?

Security Overview

Full picture of Commune’s security, compliance, and encryption.

Encryption

How email content is encrypted at rest with AES-256-GCM.

Authentication

API key permissions including the data:delete scope.

Delivery Monitoring

Track and audit email delivery history before deleting.
Last modified on March 19, 2026