Skip to main content

Building Account-Scoped Data Exports in Rails

Follow how Inpages.me builds account-scoped data exports in Rails, collecting only owned records and attachments while keeping recovery material separate.

Exporting personal data is not a database dump. A safe export has to answer a narrower question: which records and files belong to this account, which references remain valid, and what recovery material must stay out of the archive?

Start from the account, not a convenient query

Inpages.me builds an export from one authenticated identity and follows only records owned by that identity. Journals, Memories, daily check-ins, North Stars, decisions, photo books, and their attachments are collected through account-scoped relations rather than a broad attachment query.

That distinction prevents an export from becoming an accidental cross-account archive when a reference is malformed or a feature adds a new association.

Declare the archive domains

The archive lists its included domains and serializes records as versioned JSON Lines. A manifest makes the format inspectable, while per-domain counts make partial work visible. An export is intentionally not described as a point-in-time snapshot: records can change while a long job is running.

The result is more honest than implying a transactional copy of every table and blob.

Scope attachments independently from records

Attachments need their own ownership checks. The builder derives attachment scopes from account-owned records, registers each selected blob once, and records references back to its domain. This is important for photo-book pages that can refer to the same blob as a source Memory.

For that reference lifecycle, continue to reusing Active Storage blobs safely.

Preserve the difference between plaintext and protected data

Encrypted fields and attachments stay encrypted in the archive. The data format labels that protection rather than decrypting data as an export side effect. Plaintext and ciphertext therefore remain distinguishable to the offline reader without asking a Rails worker to handle a usable Master Key.

The browser encryption architecture explains why that key boundary is maintained.

Do not package a recovery secret by default

The archive includes recovery metadata such as the supported format and verifier context, but not the Recovery Key itself. Losing a recovery key and exporting data are separate problems. Combining them would make a delivery artifact carry more authority than it should.

Read designing Recovery Keys without server key access for the recovery boundary.

Make availability follow verification

Before an archive is offered for download, Inpages.me verifies the ZIP structure and writes a manifest and SHA-256 digest. The next note, verifying ZIP data exports before download, covers why that check is part of export correctness rather than a cosmetic checksum.