# Export opted-out users

Returns members at the gym location who have opted out of health data and consumer-to-business (C2B) sharing. The response contains only externalAccountId and lastSeenAt; names and emails are omitted. Match this ID back to the externalAccountId you stored during your event exports to find and delete the member's previously exported data for GDPR and privacy compliance. The endpoint takes no query parameters and is not paginated; it returns all opted-out users for the gym location in a single response.

Endpoint: GET /api/v1/data/opted-out-users
Version: Pilot
Security: apiKeyAuth

## Security:

  - `apiKeyAuth` (unknown)
    apiKey in header x-api-key

## Response 200:

  - `200` (unknown)
    Opted-out users for the gym location.

## Response 200 fields (application/json):

  - `gym` (object)

  - `gym.name` (string)

  - `data` (array)

  - `data.externalAccountId` (string)
    Unique, stable identifier for the member's account. The opted-out users endpoint returns only externalAccountId and lastSeenAt; names and emails are omitted. Match this ID against the externalAccountId values saved from your exports to identify and delete all records for this member.

  - `data.lastSeenAt` (string)

## Response 401:

  - `401` (unknown)
    Missing, malformed, or invalid API key.

## Response 401 fields (application/json):

  - `message` (string)

## Response 403:

  - `403` (unknown)
    API key is not authorized to access this resource.

## Response 403 fields (application/json):

  - `message` (string)

## Response 500:

  - `500` (unknown)
    Unexpected server error.

## Response 500 fields (application/json):

  - `message` (string)

