security privacy

How to delete your account

GDPR Art. 17 — soft-delete with 30-day grace.

How deletion works

When you click Delete my account in Settings → Privacy & data:

  1. Your account is marked pending_deletion. Login is disabled immediately.
  2. We email you a confirmation with a restore link valid for 30 days.
  3. After 30 days, an automated job runs the hard delete:
    • All articles, keywords, brand profiles, and connector credentials are removed.
    • Your account record is removed.
    • Audit logs are anonymised (we keep timestamps for 6 years for legal compliance, with personal data stripped out).
  4. Your record with our payment provider is deleted. Your past invoices stay there per their retention policy.

What you keep

If you've published articles, those articles stay live on your CMS (we don't have permission to delete them — and we shouldn't). Your CMS is yours to manage.

What if I change my mind?

Click the restore link in the confirmation email any time before the 30 days are up. Account is back, login enabled, all data intact.

After 30 days the data is gone. We can't recover it.

Team deletion

If you're an admin or editor, deleting yourself only removes you. The organization stays. Only an owner can delete the whole organization.

What we keep

Six-year retention for anonymised audit logs is required by EU AML guidance and GDPR Art. 30 records of processing. The retained fields are timestamps, action types, and a salted hash of the user ID — they can't be reverse-engineered back to your identity.