Pre-launch counsel-review draft
Data deletion requests
How to record or cancel a reviewable account or organization deletion request. A request receipt is not immediate deletion, billing cancellation, or authorization for irreversible fulfillment.
Professional legal review required before publication
This draft is not effective, has not been approved by counsel, and is not legal advice. Bracketed decisions and review markers must be resolved before publication.
- Effective date
- To be set after professional legal approval
- Last revised
- To be set after professional legal approval
- Draft record
- M27 counsel-review draft 1, prepared August 27, 2026
Current request process
A signed-in user can open Settings → Data deletion to record or cancel a reviewable request. The current product creates a reversible request receipt with a pending or cancelled status. It does not perform an immediate destructive operation.
Account and organization requests are separate because an individual account and an organization's tenant-owned data have different ownership and authorization boundaries. Submit each applicable request through its own control.
Account deletion requests
- Sign in to the account whose deletion you want to request.
- Open Settings → Data deletion and locate the Signed-in account control.
- Enter the current account email exactly as shown and submit the request.
- The request applies to that signed-in account. It does not by itself request deletion of an organization or its tenant-owned data.
- You may cancel the request from the same control while it remains a request receipt.
If no email address is available on the account for confirmation, the in-product account request cannot be created. Use the email fallback below without sending credentials or other secrets.
Organization deletion requests
- Switch to the organization whose data is the subject of the request.
- A current organization owner must open Settings → Data deletion and locate the Organization data control.
- Enter the current organization name exactly as shown and submit the request.
- A member who is not a current owner cannot create or cancel an organization request.
- Each organization is handled separately; an account request does not substitute for an owner-authorized organization request.
What a request receipt does—and does not do
Submitting a request records reviewable intent. Until separately verified fulfillment is authorized and implemented, the account, sessions, organization, memberships, subscription state, usage records, audit evidence, customer content, and other retained records are not represented as deleted. Product access may continue while a request is pending.
A request can be cancelled through the signed-in control. Cancellation changes the request receipt; it is not restoration evidence for data that was already irreversibly deleted. The current workflow does not claim that irreversible deletion has occurred.
Billing cancellation is separate
A data-deletion request does not cancel a subscription, stop renewal, or create a refund.
Organization owners must manage renewal and period-end cancellation separately through Plan & billing and the Stripe-hosted Customer Portal when that path is configured and available. Verified Stripe state remains the source of subscription and entitlement changes.
A subscription scheduled for period-end cancellation remains on its current paid plan through the current billing period while it is otherwise entitled. A failed payment, paused collection, invalid plan mapping, or another non-entitling state can move it to Free earlier; otherwise, the scheduled cancellation becomes non-entitling after verified Stripe state reaches the terminal period-end state. A deletion request does not create a refund or override the separately reviewed refund policy.
Email fallback when you cannot use the signed-in path
If you cannot sign in, cannot access the relevant organization, or no email address is available on the account, email [email protected]. When possible, send from the account email and include the account email, organization name, whether the request concerns an account or organization, and a concise explanation of the access problem.
Email does not bypass account identity or organization-owner authorization and does not trigger immediate deletion. Any eventual irreversible action must first verify the requester's identity and authority through an approved process.
Do not email secrets. Do not send passwords, one-time sign-in links, API keys, OAuth or webhook secrets, connector authorization headers, payment-card details, or unnecessary private customer content. Support may request additional non-secret evidence through an approved verification channel once that process is finalized.
Irreversible fulfillment requires separate review
No deletion-completion timeline is stated in this draft. A timeline must not be promised until the operational process, legal requirements, and system capabilities have been verified and approved.