Skip to main content

User Management

Comprehensive guide to user account management, data deletion cascade, and GDPR compliance in Plugged.in.

Overview

Plugged.in is a trademark of VeriTeknik B.V. in the Netherlands and fully complies with GDPR regulations.
The platform provides:
  • Complete user account management
  • GDPR-compliant data deletion
  • Cascading deletion of all related data
  • Audit trail for compliance
  • User data export functionality

User Account Structure

Data Hierarchy

User Data Categories

Core Data

  • User profile (name, email, bio)
  • Authentication credentials
  • Projects and profiles
  • Sessions and tokens

Generated Content

  • MCP server configurations
  • Documents and RAG data
  • Collections and shares
  • Activity logs

Social Features

  • Follower relationships
  • Shared servers
  • Public profiles
  • User ratings

Preferences

  • Email settings
  • Notification preferences
  • UI customizations
  • API keys

GDPR Compliance

Right to be Forgotten

When a user account is deleted, ALL related data is permanently removed:
1

User Request

User initiates account deletion from settings
2

Confirmation

Email confirmation sent to verify identity
3

Data Deletion

Complete cascade deletion of all user data
4

Audit Log

Deletion logged for compliance records
5

Notification

Admin notified of GDPR deletion

Data Deletion Cascade

Complete list of data deleted with user account:

Core User Data

MCP Server Data

Document & RAG Data

Social Features

Email & Preferences

Registry Data

Account Deletion Process

User-Initiated Deletion

Account deletion is permanent and cannot be undone. All data will be lost.

Admin-Initiated Deletion

For GDPR requests or violations:

Data Export

User Data Export

Users can export their data before deletion:

Export Format

User Management API

Get User Profile

Update User Profile

Manage Email Preferences

Privacy Controls

Profile Visibility

Users can control their profile visibility:

Data Sharing Controls

Audit & Compliance

Audit Trail

All user management actions are logged:

Compliance Reports

Generate GDPR compliance reports:

Testing User Deletion

Deletion Checklist

Test Script

Security Considerations

Authentication Requirements

  • Password verification for deletion
  • Email confirmation for sensitive changes
  • Session invalidation after deletion
  • Rate limiting on deletion requests

Data Retention

Deleted data is permanently removed and cannot be recovered.
  • No soft deletes for user data
  • Immediate deletion from database
  • File system cleanup for avatars
  • Cache invalidation across all services

Best Practices

Periodically audit user data to ensure compliance
Inform users about data deletion consequences
Encourage users to export data before deletion
Keep detailed logs of all deletions for compliance
Regularly test that all related data is deleted

Support

For user management assistance: