Delete your Private.Ki account
This page applies to the Private.Ki app for Android and the web app at app.privateki.net, both published by Private.Ki. It explains how to have your account deleted, what is removed, and what remains for a while afterwards.
How to request deletion
Account deletion is done on request. The app has no delete button in Settings yet; you ask us, we confirm the account is yours, and we delete it. You do not need to be able to sign in to make the request.
- Write to [email protected] with the subject “Delete my account” and your full Private.Ki address.
- Show that the account is yours. The simplest proof is to send the request from the Private.Ki address you want deleted, from a device that is signed in. If you cannot sign in, write from any address and, if you set a recovery email address on the account, send the request from that address.
- Confirm in the same message that you understand everything stored under the account will be deleted and cannot be recovered.
- We check and delete. Once we have confirmed the account belongs to you, we delete it and reply to tell you it is done. We process requests as soon as we have confirmed the account belongs to you, and answer within the one‑month period data‑protection law sets.
We cannot verify you by password or passphrase: we never see either, and we cannot reset a passphrase. If you have no way to prove the account is yours, we cannot delete it on your word alone — that protects every account from being deleted by someone else.
What happens when the account is deleted
- Deletion is immediate and cannot be undone. There is no grace period and no way to reactivate the account.
- Every device is signed out; existing sessions and refresh tokens stop working.
- Mail sent to the deleted address is no longer delivered. There is no forwarding, and the address is not reserved for you.
- Because your messages are encrypted with keys we do not have, we cannot give you an export of them first. Download anything you want to keep while you are still signed in.
What is deleted
Deleting the account removes the account record and everything stored under it from our active systems:
- The account itself: username, display name, sign‑in record (OPAQUE), two‑step verification settings and security keys, the hashes of your recovery email address and recovery key.
- Your encryption keys as stored with the account: the public key and the encrypted private key.
- All messages in every folder — received, sent, drafts and Trash — and all secure notes, together with their threads.
- All chats, including group chats you are in, your reactions, and the message tombstones and self‑destruct settings that belong to them.
- Encrypted attachments stored under your account. The files are removed from object storage by a background job right after the account is deleted; a daily check removes anything that job missed.
- Signatures, recipient history, imported public keys of your contacts, trusted image sources and chat invitations you issued.
- Device pairings and sessions, and the push‑notification tokens of your phones.
- Anti‑abuse records tied to the account, such as sending‑limit strikes.
What is kept, and for how long
- Copies held by other people. A message you sent is stored in the recipient's mailbox, encrypted to their key, and stays there until they delete it. The same applies to chat messages and to your address in another user's recipient history. Mail you sent to addresses at other providers has left our systems and cannot be recalled.
- Backups. Our database is backed up nightly into encrypted archives that no server can read. A deleted account can remain in these archives until they expire; the off‑site copies are removed automatically after 90 days at the latest. Backups are used to recover the service after a failure; they are not used to bring back individual accounts.
- Rate‑limiting counters. Some requests, such as sign‑up, are counted per keyed hash of the IP address for abuse prevention. The counter expires within an hour (one daily counter for the no‑sign‑up entry keeps it up to 24 hours) and is not linked to the account.
- Server logs. The mail server's delivery log records the addresses and times of messages exchanged with other providers. These logs are rotated as the server runs; they are not linked to the account and are not used to reconstruct it.
- A record that a deletion took place. Our staff console writes an audit entry for the deletion holding the date and the account's internal identifier — not your address or name. Audit entries are pruned after one year.
- Your own support message. The request you sent us stays in our support mailbox like any other correspondence.
Delete only some data
You do not have to delete the account to remove data. In the app you can delete individual emails and threads and then empty Trash, delete chats or single chat messages, unsend a chat message within the first hour, delete secure notes, remove your recovery email address, remove security keys, and sign out other devices. Each of these removes that data from our servers while the account stays. Delete your data has the step‑by‑step instructions for each kind of data. See also Delete and restore email and Delete a chat in the help center.
More
The Privacy Policy describes what we collect and store. The help center has more on inactive accounts and deletion and on your data‑protection rights.