> ## Documentation Index
> Fetch the complete documentation index at: https://aftercaredocs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Document Management: Retrieve and Delete Your Records

> GET /documents/{id}/original retrieves your decrypted file. DELETE /documents/{id} permanently removes the document, plan, and all associated data.

AfterCare stores your discharge documents securely. These two endpoints give you full control over your data: retrieve the original file you uploaded, or permanently delete every trace of a document from the system. Both operations are scoped to the authenticated user — you can only access documents you uploaded.

<Note>
  You can only retrieve or delete documents that belong to your account. Attempting to access another user's document returns a 404, not a 403, to avoid leaking whether a document exists.
</Note>

***

## Retrieve the original document

Download the decrypted original file exactly as it was uploaded. The response uses the document's original MIME type and filename so your browser or client can handle it correctly.

```http theme={null}
GET /documents/{documentId}/original
```

<ParamField path="documentId" type="string (UUID)" required>
  The UUID of the document to retrieve. Must be a document that belongs to the authenticated user.
</ParamField>

### Example

```bash cURL theme={null}
curl -X GET https://api.aftercare.app/documents/3fa85f64-5717-4562-b3fc-2c963f66afa6/original \
  -H "Authorization: Bearer <your_access_token>" \
  --output discharge-instructions.pdf
```

### Response — 200 OK

Returns the raw file bytes with the appropriate `Content-Type` header (for example, `application/pdf` or `image/jpeg`). The `Content-Disposition` header provides the original filename so the file saves with the correct name.

### Response — 404 Not Found

```json theme={null}
{ "error": "Document not found" }
```

Returned when the document does not exist or belongs to a different user.

***

## Delete a document

Permanently remove a document, its encrypted file, its generated recovery plan, and all associated data (medications, appointments, warning signs, and timeline entries). This operation cannot be undone.

```http theme={null}
DELETE /documents/{documentId}
```

<ParamField path="documentId" type="string (UUID)" required>
  The UUID of the document to delete. Must be a document that belongs to the authenticated user.
</ParamField>

<Warning>
  **This action is permanent and cannot be undone.** Deleting a document removes the original file, the AI-generated recovery plan, all extracted medications, appointments, and warning signs — everything. AfterCare has no mechanism to restore deleted data. Download the original file first if you need a copy.
</Warning>

### Example

```bash cURL theme={null}
curl -X DELETE https://api.aftercare.app/documents/3fa85f64-5717-4562-b3fc-2c963f66afa6 \
  -H "Authorization: Bearer <your_access_token>"
```

### Response — 204 No Content

An empty response with HTTP status 204 confirms that the document and all its data have been permanently deleted.

### Response — 404 Not Found

```json theme={null}
{ "error": "Document not found" }
```

Returned when the document does not exist or belongs to a different user. The response is intentionally the same shape as the retrieve 404 to avoid leaking information about document ownership.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.