Account & data deletion
How to delete your PotsTrack account and what happens to the data when you do.
Version 1.0.0 · Effective 2026-05-15
1. Delete your account from inside the app
This is the fastest path and removes everything immediately. No email exchange or waiting period needed.
- Open PotsTrack on your Android device.
- Tap the Settings tab in the bottom navigation bar.
- Scroll to the Danger zone section near the bottom.
- Tap Delete all data.
- In the confirmation dialog, tap Delete everything.
The action runs straight away: local data is wiped on your device, your account is signed out, and any encrypted cloud backup is removed from our storage.
2. Request deletion by email (if you've uninstalled)
If you've already uninstalled PotsTrack and can't reach the in-app control, email hello@potstrack.com from the address associated with your account (or include any account identifier you remember, such as the email you used to sign up). We respond within 30 days and aim for same-day in most cases.
3. What gets deleted
- All symptom logs, trigger logs, standing-test sessions, fluid/salt intake entries, medications and reminder schedules stored in the app's on-device encrypted database.
- Your encrypted backup ciphertext stored in our Supabase database — removed when the account row is dropped (row-level security cascade).
- Your Supabase authentication record (the anonymous user, or the email / Google identity if you linked one).
- Any cached Google Sign-In session on the device.
- The encryption key stored in your device's secure keystore — wiped when the app data is cleared.
4. What may be retained (and for how long)
A small set of records may persist after deletion. They are not used to profile you and are not linked back to your identity once the account is gone.
- Server access logs at our hosting providers (Vercel for the website, Supabase for the backup storage). Retained for up to 30 days for security and abuse-prevention purposes.
- Subscription and purchase records held by RevenueCat (our subscription processor) and Google Play. RevenueCat retains an anonymised customer record for audit, tax-compliance and fraud-prevention reasons; Google Play retains purchase history per its own policies (typically around 7 years for tax-record purposes). We don't control these retention windows.
- Email correspondence you've had with us. Kept for up to 24 months after the matter is resolved, unless we have a specific legal reason to keep it longer (e.g. an ongoing regulatory request).
- Aggregate, non-identifying analytics from the marketing website (potstrack.com). These are cookieless visitor counts and were never linked to your account in the first place, so they aren't affected by account deletion.
5. We cannot recover what you delete
Your on-device database is encrypted with a key only your phone holds, and your backup is encrypted with the same key before it ever leaves the device. When you delete your account, both the ciphertext and the key are wiped — there is no path by which either we or any third party can reconstruct your data. If you want a copy of your data before deletion, use Settings → Export data (JSON) first. That generates a complete machine-readable dump suitable for import elsewhere.
6. Related
- Our full Privacy Policy sets out what data we hold, why, the legal bases under UK / EU GDPR, and the wider data-subject rights you can exercise.
- Our Terms of Service cover the broader relationship between you and Kane Rigby.
Questions about this document? Read the FAQ or get in touch via the address listed above.