Overview
ReplayCore provides API support for the data subject rights you are most likely to action as a controller: erasure, subject access, and portability, keyed by player UUID. The endpoints are part of the v1 API and use ReplayCore request signing (see the Authentication article). Each request is accepted and queued, then actioned within our 72-hour SLA; the response identifies the operation so you can record it in your own compliance log.
Separately, your own panel account data can be exported as JSON (Settings, Export your data) and your account can be erased from the panel's danger zone; those flows run from the panel and need no API call.
Erasure (Article 17)
POST /v1/privacy/erase requests removal of a player's personal data from your stored replays. The request is accepted (HTTP 202) and actioned within our 72-hour SLA: the response identifies the operation, and GET /v1/privacy/erase/{id} reports its status.
Subject access and portability (Articles 15 and 20)
POST /v1/privacy/dsar raises a subject access request for a player UUID. The request is accepted (HTTP 202) and actioned within our 72-hour SLA; the response identifies the operation so you can track it. The data we compile is standard JSON rather than a proprietary binary format, so the same output supports the portability right under Article 20.
POST https://api.replaycore.com/v1/privacy/dsar
Authorization: ReplayCore tenant=<tenant-id>, ts=<unix-ms>, nonce=<nonce>, sig=<hex>, kid=<key-id>
Content-Type: application/json
{ "player_uuid": "550e8400-e29b-41d4-a716-446655440000" }Your responsibilities
Record each request and its operation reference in your own compliance log; requests are actioned within our 72-hour SLA. As the controller, you remain responsible for verifying the requester's identity and responding to the data subject within your own statutory deadlines.