Skip to content
Customers and leads7 min read

Anonymize a customer

Permanently strip a person's identity from your workspace, including their chat text. Irreversible, and the right tool for an erasure request.

Browse topics

What it is

Anonymizing a customer permanently strips a person's identity out of your workspace while leaving the shape of their activity behind for your reporting. It is the tool for an erasure request.

It is irreversible. There is no undo, no recycle bin, and no version of the data that support can restore. The on-screen warning is accurate: "This permanently removes personal data (name, email, phone) while keeping aggregate activity. This cannot be undone."

This is different from deleting a customer, and the difference matters — see the comparison below.

When you would use it

When someone exercises a right to erasure and you have to be able to say the data is gone.

When a test identity, or a real person's details entered by mistake, should not be in your workspace.

When you are blocking an abusive visitor and want to be certain they cannot be silently re-matched to their old history if they come back.

Not as routine tidying. If the list is simply cluttered, delete the record instead. If you are cleaning up test data before a launch, delete — deletion is recoverable and anonymizing is not.

Where to find it

Dashboard → Customers → open the person → Anonymize.

For several people at once, select the rows on Dashboard → Customers and use the bulk action.

You need the manage-customers permission.

Steps

  1. If you might ever need the details again for a legitimate reason, export them first — see Export customers to CSV. After this action they are gone from Agentency.
  2. Open Dashboard → Customers and open the person. Verify you have the right one. Check the email, not just the name.
  3. Select Anonymize and read the confirmation.
  4. Confirm.
  5. Wait for the page to show the anonymized state. Their lead status becomes Blocked.
  6. Search for their email address. Nothing should come back.
  7. Open one of their old conversations. The message text is redacted.

For a batch: select the rows, run the bulk anonymize, and check the processed count in the result. Rows that belong to a different workspace are skipped silently rather than failing the whole batch, so a count lower than your selection usually means some rows were not yours to act on.

What is actually removed

Anonymizing reaches further than the profile page, which is the point — a name scattered across half a dozen places is not erased by clearing one field.

Removed or blanked:

  • Every contact field on the profile: name, email, phone, company, job title, website, and any custom fields your form collected.
  • The identifiers Agentency uses to recognise a returning visitor. This is what makes the erasure stick — the person cannot be silently re-attached to this record later.
  • The customer name and email stored alongside their conversations, and the conversation summaries.
  • The conversation text itself. Their questions are replaced with a redaction marker and the answers are cleared. This matters because personal details are often typed into the chat rather than into the form.
  • The inputs and summaries recorded for any Call action that ran on their behalf.

Kept, deliberately:

  • The record itself, as a blocked shell, so your historical counts do not silently change.
  • The activity timeline, including a permanent Customer anonymized entry.
  • Consent records, which are the evidence that consent was given and withdrawn.
  • The fact that conversations happened, and their timing, so analytics stay honest.

Anonymize versus delete

AnonymizeDelete
Personal dataPermanently removed, including chat textRetained, just hidden from the list
ReversibleNoYes — support can restore it
Record remainsYes, as a blocked shellHidden from the list
Right-to-erasure requestUse thisNot sufficient
Tidying up test rowsOverkillUse this

The delete confirmation says as much: "This soft-deletes the customer profile. This can be reverted by support." If you have been asked to erase someone's data, deleting them does not do it. Anonymize.

Erasing everyone, not just one person

Anonymizing works one record — or up to 200 records — at a time. If what you actually want is for the whole workspace and every contact in it to be gone, that is account deletion, and it behaves very differently.

Closing your workspace is scheduled, not immediate. Confirming it starts a 30-day recovery window: you are signed out, your public chatbots go offline straight away, and a deletion date is set 30 days ahead. Nothing is erased on the day you ask. Signing back in at any point inside that window cancels the request and puts everything back, customer records included.

Once the window closes, the workspace becomes eligible for permanent removal — chatbots, knowledge, conversations, and every customer record together — and you can no longer recover it yourself.

Three consequences worth planning around:

  • Export first if you need the contacts. After the window there is nothing left to export. See Export customers to CSV.
  • Your teammates keep their logins but lose your data. Membership of your workspace ends with the workspace.
  • A 30-day wait is not an erasure response. If someone has asked you to erase their data, anonymize that record now. Do not tell them to wait for a workspace deletion that you might cancel.

The full procedure, including how to cancel, is in Delete your account.

Limits and plan notes

Irreversible, with no exceptions. Support cannot recover an anonymized record. This is not a policy that can be waived; the data is genuinely gone.

Bulk actions take up to 200 rows at a time. For a larger batch, work through it in passes. The same cap applies to bulk delete.

Requires the manage-customers permission. View-only members cannot anonymize.

It only covers this record. Records are per chatbot, so the same person captured on two chatbots has two records and you must anonymize both. Search their email before you finish to confirm nothing is left.

It does nothing to copies you have already made. A CSV you exported last week, a contact you pushed into your own CRM, and a screenshot in a ticket are all outside Agentency. A complete erasure request means handling those too.

Anonymizing is not the same as stopping the chatbot. If a person should not be able to talk to it at all, that is a separate concern — see Activate or pause a chatbot or the access controls on the hosted page.

Common problems

I anonymized the wrong person.

Nothing can be recovered from Agentency. If you exported recently, that file is your only copy. If they contact you again and complete a form, they will become a new record with no history.

Bulk anonymize reported zero processed.

None of the selected rows belonged to the workspace you are currently in. Check the account switcher — see Switch accounts — and retry with rows you can actually see.

Their name still shows in an old conversation.

Refresh. If a name genuinely persists after the record shows as anonymized, note the conversation and the time and contact support — do not include the personal data itself in the message.

The record is still in my Customers list.

That is correct. The shell stays so your historical numbers do not change. It carries no personal data and its status is Blocked.

Someone asked me to delete their data entirely, shell and all.

Anonymize removes the personal data, which is what an erasure request is about. If your obligations require the row itself to be gone, contact support and describe the requirement.

Common questions

What is the difference between anonymize and delete?

Delete hides the record and can be reverted by support, so it does not satisfy an erasure request. Anonymize permanently removes the personal data — including the conversation text — and cannot be undone.

Does anonymizing redact the chat messages too?

Yes, and that is the point. People often type personal details into the conversation rather than the form, so their questions are redacted and the answers cleared.

Why is the record still in my list afterwards?

A blocked shell is left behind on purpose so your historical counts do not silently change. It carries no personal data.

How many can I anonymize at once?

Up to 200 selected rows per action. The same cap applies to bulk delete. Work through a larger batch in passes.

The bulk action reported zero processed.

None of the selected rows belonged to the workspace you are currently in. Check the account switcher and retry with rows you can actually see.

What happens to my customer records if I close the whole workspace?

Deleting the workspace starts a 30-day recovery window. Signing back in inside it cancels everything. After the window the workspace becomes eligible for permanent removal, contacts included, so export anything you need first.

Was this article helpful?

Ready to try it on your own content?

Create a free workspace, add a document, and ask the questions your team is tired of answering.