Your users can ask you what you hold about them and ask you to delete it. Because you're the controller, those requests land with you rather than with Gleap — and both are a couple of clicks.
Open the contact. Their page holds everything Gleap has about them — details, custom data, conversations, files, activity — and an export action that produces a file you can hand over.
That's the practical answer to an access request: export it, read it, send it.
The same page has a delete action, and it removes the contact together with their tickets.
If someone wants to stop hearing from you rather than disappear, unsubscribe them instead — it's reversible and keeps the history.
Your project's data export settings, available to administrators, cover two things:
Feedback items — choose the board, the fields, and filters including status, then export.
Contacts with an email address — by audience (all, users, guests, unsubscribed, or a custom list) and optionally a date range.
Both produce CSV.
A project's settings have a Danger zone with Delete this project, confirmed by name. It removes the project and what it contained — tickets, contacts, help center, workflows, settings.
Export anything you want to keep before you do it. There's no staging state and no recycle bin.
Deleting your organisation ends the relationship entirely. Gleap's privacy policy sets out what happens to personal data afterwards and the legal retention obligations that can outlast the account; for anything specific, [email protected].
Verify who's asking before you export or delete anything. “Delete my data” from an unverified email address is a request you should check, not act on — the person it affects may not be the person asking.
And delete the export file when you're done with it. It's personal data on a laptop, outside everything protecting it inside Gleap.