Permanently erase one visitor from the caller's account: identity, submissions scrub, interactions, worksheets, uploaded documents (rows + Storage objects). Requires `confirm: true` — pass true only after the human operator has agreed, not as a default. This is a GDPR erasure and cannot be undone. Unknown or cross-account visitors collapse to E_NOT_FOUND.
| Name | Type | Required | Description |
|---|---|---|---|
| request_id | string | Yes | — |
| visitor_id | uuid | Yes | — |
| confirm | boolean | Yes | Set to true only after the human operator has agreed to permanently erase this visitor's identity, activity, submissions, worksheets, and uploaded documents. Passing false (or omitting) raises E_CONFIRM_REQUIRED, the intended machine-readable signal to stop and ask the human. |
| Name | Type | Description |
|---|---|---|
| erased | true | — |
| visitor_id | uuid | — |
| documents_deleted | integer | — |
| storage_removed | integer | — |
| storage_failed_count | integer | — |
| idempotency_replay | false | — |
erase_visitor is called by an AI assistant connected to Sentway over MCP, not by hand. Point the assistant at the Sentway MCP endpoint and complete the OAuth flow, and the tool becomes available in the same session as the other 38 Sentway tools. See connecting over MCP.