Summary
- Have an account? Delete it yourself on the account page — deletion is immediate.
- Can’t sign in, have no account (e.g. you are only on the waitlist), or want only some data deleted? Email privacy@rentyourtime.app.
- We reply without undue delay and within one month at the latest (Article 12(3) GDPR).
- Some data must be kept — mainly payment records required by tax law (section 6).
Delete your account yourself
- Sign inGo to rentyourtime.app/account and sign in as usual (email and password, or Google, Apple, Facebook or Discord).
- Optionally download your dataIn “Your data”, click “Download my data” to save a JSON file with your account data.
- Switch off subscription renewalIf you have a renewing Pro subscription paid through Stripe, first switch off renewal (“Subscription” tab → manage subscription). Cancel App Store or Google Play subscriptions in the store settings.
- Confirm deletionClick “Delete account”. Accounts created with an email confirm with their password. Accounts created with Google, Apple, Facebook or Discord confirm by typing the account email and must have signed in within the last 15 minutes (sign out and back in if needed).
Once confirmed, the account is disabled immediately, every session is signed out and data is deleted as described in section 5. If you use the mobile app, open the same page in a browser or email us.
Request deletion by email
Email privacy@rentyourtime.app, ideally from the address linked to your account or used for the waitlist. Use the subject “Data deletion request” (for Facebook data: “Facebook data deletion request”) and include:
- the account or sign-up email address (shown on the account page);
- how you sign in (email, Google, Apple, Facebook, Discord), if you have an account;
- what you want: deletion of the whole account, of specific data (e.g. a waitlist entry, Founder profile, shipping details) or only disconnecting Google, Apple, Facebook or Discord from the account.
We never ask for your RentYourTime, Facebook, Google, Apple or Discord password.
Verification and timelines
- Requests sent from the address linked to the account or sign-up are handled once we confirm the address matches.
- If a request comes from another address or we have reasonable doubts about your identity, we will ask for confirmation from the linked address or for other information needed to confirm your identity (Article 12(6) GDPR). We do not act on requests we cannot link to the person the data relates to.
- We reply without undue delay and within one month of receiving the request. For complex cases this may be extended by two months — we will tell you within the first month. Deletion is free of charge.
- Once done, we confirm by email and tell you what data was kept and why.
What we delete
Deleting an account (yourself or at your request) immediately:
- disables the account; the email address is replaced with a technical address that does not identify you, and the username, password, Google, Apple, Facebook and Discord account IDs, Apple subscription identifiers, the stored Google, Facebook and Discord profile picture addresses, last sign-in date and email verification status are removed;
- deletes all session tokens and email verification and password reset tokens; removes IP addresses and user agents from mobile app sessions; removes device names and push notification tokens;
- deletes account settings, usage data, virtual receipts, the Founder profile (name and consents), your profile photo (the stored file), and waitlist and beta entries with the same email address.
Your email address is released — you can later create a new account with the same address or the same Facebook account. Waitlist, Teams pilot or beta data of people without an account is deleted on email request.
What may be kept and why
| Data | Why | How long |
|---|---|---|
| Payment records: subscriptions, invoices, Founder purchases and support payments, and the Stripe customer ID — linked to the disabled account’s technical ID, not to your email address | Legal obligation (tax law) and establishing, exercising or defending legal claims — Article 17(3)(b) and (e) GDPR | Until the tax liability limitation period ends (as a rule 5 years from the end of the calendar year in which the tax payment deadline fell) or, if longer, until claims become time-barred |
| Founder Black kit shipping details | Shipping and complaints; part of the purchase records | Not deleted automatically on account deletion; on request we delete them once no longer needed for shipping, complaints or as purchase records |
| The disabled account record (technical ID, creation date) and technical device records | Consistency of payment records and security | As long as the payment records |
| Security event log entries | Security and accountability (Article 6(1)(f) GDPR); entries are not linked to your email address | No automatic deletion period at the moment |
| Database backups | Disaster recovery; not used for anything else | Overwritten on a rolling basis, according to the provider’s documentation for no more than 30 days; if the database is ever restored from a backup, the deletion is applied again |
| Administrator notifications in Discord about your sign-up (email address, source, date) | They remain in the messaging history | Until they are deleted from the message history |
| Correspondence with us, including about your request | Showing the request was handled properly, defending claims | Until any claims become time-barred |
| Data held by Stripe, Google, Apple, Meta and Discord | These providers process some data as separate controllers | Under their privacy policies — you can contact them directly |
| Google Analytics and DataFast statistics (if you consented) | We do not send them your account ID or email address, so we cannot link them to your account | Per the tools’ settings (Privacy Policy, section 10); delete the cookies in your browser or via “Cookie settings” |
| Newsletter (Mailchimp), if you were on the waitlist or subscribed | Deleting the account unsubscribes you; Mailchimp keeps your address marked as unsubscribed so that it is never emailed again by mistake | Until you ask us to delete it from Mailchimp as well |
| PostHog analytics (if you consented) | Deleting the account does not remove data already sent to PostHog; the data linked to your account ID is deleted on request | Per our PostHog project’s retention (Privacy Policy, section 10), or earlier when you ask us to delete it |
Effect on subscriptions and payments
- You cannot delete an account yourself while a Stripe subscription still renews — switch off renewal first. If you ask by email, we cancel the subscription and delete the account.
- Deleting your account does not cancel App Store or Google Play subscriptions — cancel them in the store settings to avoid further charges.
- Deleting the account ends Pro access and Founder Program benefits; the Founder number is not reassigned.
- Deleting the account is not a withdrawal from a contract and does not by itself trigger a refund. If you are entitled to withdraw or to a refund (Terms, §11–§12), raise it before deleting the account.
Data received through Facebook Login
With Facebook sign-in we ask only for the public_profile and email permissions. We store your Facebook user ID for our app, your email address (if you share it) and your name as the account name. We do not store your Facebook access token and we do not copy your profile picture; we keep only the web address of it that Facebook returns at sign-in, and delete it with the account. We do not fetch your friends list, posts or messages.
How to request deletion of Facebook data
- The whole account: delete it yourself (section 2) or email us (section 3) with the subject “Facebook data deletion request”. We delete your Facebook ID, name, email address and profile picture address as described in section 5.
- Only the Facebook link: click Disconnect next to Facebook under “Connected accounts” on the account page and confirm with your RentYourTime password, or email us; the Facebook ID and the stored Facebook profile picture address are removed from your account. An account without a password first sets one through “Forgot password”.
Removing RentYourTime in Facebook settings
In Facebook, go to Settings & privacy → Settings → Apps and websites, select RentYourTime and click Remove (option names may vary between Facebook versions). This stops RentYourTime from receiving new data from Facebook, but does not delete your RentYourTime account or the data stored with us — use the methods above for that. We handle deletion requests through the methods on this page; we do not process automated deletion notifications sent by Facebook.
Google, Apple and Discord sign-in
We store the ID that Google, Apple or Discord assigns to you for our app (to recognise you at sign-in), but not the tokens of these providers; for Discord we also revoke our access right after each sign-in. That ID, the email address and name received at sign-in are deleted with the account (section 5), and so is the web address of your Google profile picture or Discord avatar that we keep (not the image itself; Apple provides no profile picture). To remove only the connection with Google, Apple or Discord, click Disconnect next to it under “Connected accounts” on the account page and confirm with your RentYourTime password, or email us (see section 3): the ID and the stored picture address are removed from your account. An account without a password first sets one through “Forgot password”. You can also revoke RentYourTime’s access at the provider — in your Google Account connections or in your Apple ID settings (“Sign in with Apple”). Revoking access at the provider does not delete your RentYourTime account.
Contact and right to complain
If you believe we are breaching data protection law, you can lodge a complaint with a supervisory authority — in Poland: President of the Personal Data Protection Office (Prezes UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, uodo.gov.pl.
This page: https://rentyourtime.app/privacy/data-deletion