Account deletion removes the live account and its content, subject to completion of the deletion steps. Retained proof records, recovery data and external-provider handling are explained below. A completed deletion cannot be undone.
From inside the app
Start in Settings → Trust centre → Delete my account. After confirmation, the app requests account deletion. A completed request returns a receipt; interrupted requests can remain pending and require retry or operator follow-up.
Account deletion attempts to revoke external provider grants, including applicable Apple access. A revocation can fail while account deletion completes; its outcome is recorded on the receipt for follow-up.
If you no longer have the app
If you no longer have the app, email support@maybesitter.com from the address you signed in with, requesting account deletion. Ownership must be verified before deletion. The operator monitors this mailbox and handles support, privacy and account/data deletion requests.
What is deleted
- Your sign-in account.
- Every commitment, reminder and capture.
- Everything MaybeSitter remembered about you: your routine answers and every memory fact, including the ones you edited.
- Your consents, your settings and your feedback history.
- Every calendar record imported into the account is included in account-data deletion. External grant revocation is attempted and its result is recorded.
- Your device's notification token.
This is a real delete, not a flag. Once it is done we cannot restore it, and neither can you — which is the point.
Retained records and pending retention decisions
- Production Firestore currently has a seven-day point-in-time recovery window. This is separate from deletion of the live account tree; it is not a promise that every external provider deletes its copies at the same time.
- The app does not explicitly attach an account ID to Crashlytics reports, but SDK installation identifiers and device metadata exist. Firebase states that crash data and associated identifiers are retained for 90 days before removal from live and backup systems begins. This is not a guarantee that removal is complete on day 90. Deleting your MaybeSitter account does not itself delete these reports.
- After account deletion, a pseudonymous deletion receipt is marked for expiry after 400 days and a deletion-job record after 30 days. These configured expiry periods are not a guarantee of the exact purge time. They retain a keyed hash rather than your raw account ID; the completed job no longer contains your UID. These records support proof of deletion and safe repeat requests.
- An incomplete or stuck deletion job can still contain the account UID so the deletion can be resumed. Completed jobs receive a 30-day expiry timestamp. Firestore TTL for that field was verified active in production on 25 September 2026; deletion after expiry is asynchronous, not a guarantee of removal exactly on day 30.
- Early-access website registrations are separate from an app account and are not automatically removed by account deletion. To request removal, use the contact route in the privacy policy.
- Production recording is currently disabled. In enabled builds, recording requires a separate opt-in for the current signed-in session; analytics consent does not enable it. Clarity receives masked screen layout, taps, navigation and SDK device/session metadata. Text and images are masked, and WebView recording is disabled. Revoking consent stops future capture. Deleting your MaybeSitter account does not delete recordings already uploaded to Clarity. Production replay must remain disabled until the owner approves and publishes its retention period and deletion-request process. These decisions are still pending; this page does not promise a retention period.
Questions
privacy@maybesitter.com, or read the privacy policy.