Account & Data Deletion Policy
Last updated: 2026-10-07 · Effective: 2026-10-07
This page explains how to delete your Refairly account or remove your data, including a child's record and a young person's own account. Full details are in our Privacy Policy and Terms of Service.
1. Data Removal Options
Refairly provides the following ways to manage your data:
- Deactivate your account — temporarily hides your profile while preserving account data. You can reactivate by logging back in. (Settings → Account → Deactivate.)
- End your relationship — flips the relationship to
Endedstatus. This does not by itself delete most per-relationship content. Your partner receives arelationship_endednotification; each of you keeps any subscription your own account holds. Daily check-ins, Partner Pulse history, Growth Plan content, Trip Plan content, Experience taste profile + reflections, Conflict descriptions / private session messages / agreements / signatures, Quick Repair threads, Joint Onboarding answers and BuzzCall history all remain stored, and either former partner can still retrieve them from their own account — ending the relationship removes them from the app's screens but does not lock them — until either partner closes their account. Without children, nothing else changes. With children both of you parent, one of you carries the family on: taking the family needs the other's acceptance, leaving it to the other does not. The one who leaves stops being the children's parent in the app and loses access to their records; what they wrote stays with the family, and their own entries stay in their data export. - Withdraw a consent — in Settings or by email. Withdrawing Reflection Insights deletes your digest; a young person withdrawing their teen-wellbeing consent deletes the themes made from their check-ins (Privacy Policy §2.3).
- Delete a child record — either parent can, as long as the child has no teen account. It removes the record with its card and health list, the parents' observations, the child's goals with their notes, photos and stored files, the child's Day and its medicine records, the expenses that were only for the child (one shared with a sibling stays, without their name), pocket money and the household expenses that mirror a parent's top-ups, what the parents answered about what the child enjoys, themes, safety-check records, claim codes, the alarms on the child's items and goals, every caregiver's link to the child (past ones too), the child's papers and the stored files behind them, and the child's chats — for both parents. Refairly's cards about the child are emptied: each stays under its reply only as a "no longer available" placeholder holding nothing it quoted, and goes when that reply goes. While a teen account exists the record cannot be deleted; a parent can pause the account, and once the young person deletes their own account the record returns to a plain record and can then be deleted.
- Delete a goal, a note, a photo or a file — anyone who keeps that list (both partners for the household's goals; the child's parents and the young person herself for a child's goals) can delete one at any time; the stored file goes with it.
- Remove an alarm, or step back from one — whoever set an alarm, and the child's parents (on the household's goals, either partner), can remove it. Anyone an alarm rings can turn it off for themselves, and decline it if they were asked. A one-time alarm is deleted 30 days after its date, and an alarm goes with the item, goal or child's record it is on.
- Clear your Refairly chat — "Clear my messages" deletes every message at once and dismisses its open cards. Cards that were dismissed or expired are deleted after 30 days.
- A young person deletes their own account — from the teen settings. See §5.
- Take a child back from a caregiver — either parent, at any moment, from the child's page. The caregiver stops seeing the child immediately, and a chat the young person had with that caregiver closes; when the last child of your family is taken back, the caregiver's chat with you closes too. Nothing about your child's record changes. The link itself is kept as history, marked as removed: it shows the caregiver nothing, and it lets your family's list offer her again as "looked after before" (a caregiver who left the family herself is not offered). It is deleted with the child's record or with the caregiver's account; when a parent's account is deleted, their id is removed from it.
- Delete your account — the only mechanism that hard-deletes the per-relationship multi-party data above. Your display name is removed and the account is deactivated immediately (your email is kept through the grace period solely so the account can be restored); the account row + related data is hard-deleted approximately 30 days after request via a daily background job.
⚠ Important. Deleting your Refairly account does not automatically cancel your Apple App Store / Google Play subscription. You should cancel your subscription through your device's app-store settings before deleting your account.
2. Deleting Your Account
You can request account deletion through:
- In-app — Settings → Account → Delete Account
- Web — refairly.app/delete-account (no login required; uses email verification with a 6-digit code, 15-minute expiry, 5 attempts max, with a 2-minute cooldown between code requests)
- Email — aoci@refairly.app
When you request account deletion:
- Your display name is removed; your account is deactivated; every signed-in device is signed out and its sign-in token revoked; your password-reset codes are cleared. Your email address is kept during the 30-day grace period solely so the account can be restored; it is hard-deleted with the account row at the end of the grace period. Nothing is "anonymized": the data stays as it was, unreachable, until it is deleted.
- If you were in a relationship, the relationship is ended (
Status=Ended); your partner receives arelationship_endednotification and keeps any subscription their own account holds. - Certain rows are soft-deleted immediately: your subscription row, your token-usage log rows, your device tokens, your notification preferences and history, the buzzes you sent, and the records of every Buzz Call you were on ("deleted person leaves no artifacts").
- Child records you are a parent of stay with the other parent. If you were the only parent, they are deleted with your account at the end of the grace period. A parent's deletion does not delete a young person's own account.
- Your underlying account data is retained in a restricted state for approximately 30 days. To restore it within that window: sign in with Google or Apple, or register again with the same email address — either restores the account as it was. A password login is refused during the window; write to aoci@refairly.app from your registered email instead.
- After the grace period, the
AccountCleanupServicebackground job runs daily and hard-deletes your account row, yourRelationshipsrow (which cascade-deletes Conflict / Quick Repair / Growth Plan and the household's goals with their stored files / Daily / Trip Planner / Experience / Joint Onboarding / Partner Pulses / Buzz / Buzz Calls / relationship facts), yourUserSubscriptions,AppAccountTokenMap,TokenUsageLogs,NotificationHistory,NotificationPreferences,DeviceTokens, sign-in sessions, consent records, your Refairly chat and its cards, your observations about children, the messages you wrote in every chat, your buzzes and calls, every caregiver link your account held as a caregiver (as a parent, your id is removed from the caregiver links that stay with the other parent), your profile pictures and receipt photos in storage, your place on every alarm and the alarm requests you sent that nobody answered, and allAspNetUser*tables. Goals and notes you wrote on a child's list stay with that list, without your name, and so do alarms you set, for the people on them.
2.1 Important honesty disclosures
Per-feature gap during the 30-day grace window. Daily check-ins, Partner Pulses, messages you authored in the couple's chat and the Trip Plan and Quick Repair chats, Growth Plan answers, goals and their notes, Trip Plan answers/content, Experience taste profile + reflections, Conflict descriptions/private sessions/summaries/agreements/signatures, family chat messages and Joint Onboarding answers are not explicitly soft-deleted during the grace window. They become invisible to your partner because the relationship is
Endedand you can't log in, but the underlying rows physically remain in the database until the 30-day cascade hard-delete runs. The buzzes you sent and your Buzz Call records are an exception — they are soft-deleted immediately.Alarms during the grace window. The request itself does not delete or change the alarms you set or are on; that happens at the hard-delete. Every device is signed out at the request, but an alarm already scheduled on a phone can still ring there until the app is next opened on it; logging out of the app before you delete removes them from that phone.
Subscription audit retention.
WebhookEventandSubscriptionAuditLogrows are not pruned by the cleanup job — including after account hard-delete. The rows are keyed on store transaction IDs, not user IDs; the user-id strings in those tables become orphan references retained indefinitely for billing / fraud-investigation audit purposes, consistent with retention required for tax and legal-compliance obligations on financial records.Trip Planner cached photos. Photos sourced from Google Places that the Trip Planner fetched and cached in our AWS S3 bucket under
trip-photos/are content-addressed (one object per unique Google photo reference) and are not pruned even on hard-delete. They are public-read business photos from Google, not user-uploaded content.Safety reports. A report you filed keeps its record of what was reviewed; your IP address and device are dropped from it after 90 days and your comment after 365 days.
Safety-check records about a young person are blanked after 90 days and deleted after 365 days regardless of any account action, and deleted immediately when the young person deletes their account.
Backup deletion. Database backups follow the same retention schedule as the primary data. When data is deleted from the primary database, it is removed from backups within the next backup rotation cycle.
In limited circumstances, certain data may be retained beyond the normal deletion schedule where required by applicable law, needed for fraud prevention or safety, or subject to a legal hold or investigation.
3. Exporting Your Data
You can export your personal data before deletion through in-app controls (Settings → Account → Export My Data, which calls GET /api/User/data-export). The export covers the full set of user-authored content across all feature layers, your consent records, and — for parents and young people — the family data described in Privacy Policy §9.1. Once your account is permanently deleted, your data may not be recoverable.
4. What Stays After Deletion
Per Privacy Policy §8.1 and the disclosures in §2.1 above:
- Your individually-authored content (your perspectives, your messages, your private journal, your check-ins, your profile, your trip and growth answers, your observations about children, your family chat messages) is removed when the relationship row and your account row are hard-deleted at the end of the 30-day grace window.
- AI-generated joint analyses that referenced your content are removed at the same time via the relationship cascade.
- Agreement / signature records (the fact that you signed a Conflict resolution agreement, when, and with whom) are removed at the same time.
- Child records with another parent stay with them, with the goals and notes you wrote on the child's list; your name disappears from them as their author reference is removed.
- Alarms you set stay for the people on them, without your name; an alarm left ringing nobody is deleted.
- Subscription audit metadata (
WebhookEvent,SubscriptionAuditLog) is retained indefinitely with orphan user-id strings for billing / fraud audit. - Trip Planner cached place photos in
trip-photos/are retained indefinitely (public-read business photos from Google). - Safety reports you filed stay as records of what was reviewed, without your IP, device or comment after their retention periods.
- Minimal operational metadata (request logs, IP addresses, server error events for up to 90 days) may be retained as required for security or legal compliance.
5. Children and Young People
- A child without an account exists only as a record kept by its parents. Either parent can delete it (§1); a child's data is otherwise removed when the last parent's account is deleted.
- A young person with a teen account can delete it themselves at any time from their settings. This removes their check-in entries, the themes made from them, the safety-check records about them and their claim link, and signs out their devices; at the end of the grace period her notes and files on goals, her Refairly chat and her place on alarms are deleted too. The child record, with her goals, returns to a plain record kept by the parents, without her check-in words. Their account then follows the same 30-day grace and hard-delete path as any other, and the young person can restore it within the window the same way.
- A parent cannot delete a young person's account and cannot delete the child record while that account exists. A parent can pause the account: the young person can read her goals and pocket money and cannot change anything, her phone is given no alarms to ring, and pausing, revoking or deleting does not show a parent more of her entries.
- A child's goals and their notes, photos and files can be deleted by the child's parents and by the young person herself, one at a time; they all go with the child's record.
- A child's papers (health reports, school letters, photos) are removed by either parent, one at a time from the child's page or all at once with the record; removing one deletes the stored file too. A young person can read the papers meant for her but cannot delete what her parents keep; a caregiver can do neither.
- A caregiver's account is their own. They can delete it at any time from their settings, or leave one family and keep another; either way the children's records are untouched — a caregiver holds no copy of them. A parent cannot delete a caregiver's account, only take their children back (§1).
- Rights requests about a young person's data are handled with the young person (Privacy Policy §9 and §10.8). We may ask a parent to confirm identity, but we will not disclose the young person's entries to the parent in doing so.
6. Related Policies
7. Contact
Ali Onur Can İrey Email: aoci@refairly.app Website: https://refairly.app
© 2026 Refairly — Ali Onur Can İrey