Skip to content
Products
Encrypted Email Messenger Group Chat
Security
How encryption works What our servers can and cannot see Account security Private.Ki over Tor Private.Ki and VPNs
Company
Pricing About Careers Statement Help center Contact
Language
EnglishEN DeutschDE · soon EspañolES · soon FrançaisFR · soon
Create a free account Sign in
Account

Delete your data in Private.Ki

This page applies to the Private.Ki app for Android and the web app at app.privateki.net, both published by Private.Ki. It explains how to delete some of your data while keeping your account, what each step removes from our servers, and what remains for a while afterwards. To delete the account itself, see Delete your account.

Delete data in the app

Everything below is done while you are signed in, in the Android app or the web app — the two offer the same controls under the same names. Each action removes your copy of that data from our servers straight away; nothing you delete is kept in a hidden folder for you. Because your content is encrypted with keys only you hold, we cannot pick out individual messages on your behalf, so these steps are the way to delete messages.

Emails and email threads

  1. Move to Trash. In a mail folder, long‑press (or right‑click) a conversation and choose Move to trash, or swipe the row to the right. Inside an open conversation, a single message's menu has Delete. A conversation in Trash can still be brought back with Restore.
  2. Delete permanently. Open the Trash folder. Long‑press a conversation and choose Delete permanently, or select several and choose Delete permanently from the selection bar. Inside an open conversation in Trash, a message's menu has Delete permanently as well.
  3. Empty Trash. In the Trash folder, tap Clear in the header and confirm with Empty in the “Empty Trash” dialog. Every message in Trash is deleted at once.

Trash is not emptied for you automatically: mail stays there, on our servers, until you delete it permanently or empty the folder. A mail you sent to yourself has two copies (Sent and Inbox); deleting one permanently deletes both.

Drafts and secure notes

  1. Drafts. In the Drafts folder, long‑press a draft and choose Discard draft. The draft is deleted from our servers at once, with any files it holds. (A draft inside a conversation can also be moved to Trash with Move to trash and deleted permanently from there.)
  2. Secure notes. Open the note in the Notes folder and choose Delete note, then confirm. A note is deleted at once, together with anything attached to it.

Chats

  1. Delete a single chat message. Long‑press a message bubble and choose Delete, then confirm in “Delete selected message?”. This removes your copy only.
  2. Unsend or destroy a message for both sides. Within one hour of sending, long‑press your own message and choose Unsend; within one hour of receiving, long‑press the other person's message and choose Destroy. The message is emptied on our servers for both of you and replaced by an “Unsent” or “Destroyed” marker. After the hour, only Delete (your copy) remains.
  3. Delete a whole conversation. In the chat list, swipe a conversation to the right (you get a few seconds to undo), or long‑press it and choose Delete chat. In an open conversation the header menu has Delete chat; confirm with Delete in “Delete selected chat?”. Every message of that conversation is deleted from your account at once. There is no Trash for chats.
  4. Let messages delete themselves. In a conversation, open the timer control in the header (Self‑destruct timer) and choose a duration. Messages sent after that are deleted on our servers when their time is up, on both sides. Turn off self‑destruct stops it for new messages.

Group chats

  1. Leave the group. Open the group's info screen and choose Leave group. You stop receiving its messages and the other members are told you left. If you were the admin, the group freezes for the others; when the last person leaves, the group is gone.
  2. Delete the group's messages from your account. Leaving does not delete the messages you already have. Delete the conversation as described under Chats (Delete chat).

Attachments

Attachments belong to the message that carries them: deleting the message permanently, unsending or destroying a chat message, or emptying Trash deletes the encrypted file from storage as well. A file cannot be deleted separately from its message.

A mail you have just sent

For a few seconds after you send an email, the app shows Undo. Undo stops delivery and turns the mail back into a draft, which you can then discard. How long the window lasts is set under Settings → General → Undo send (up to 60 seconds; 0 turns it off). Once the window has passed, the mail has been delivered and cannot be recalled.

Devices and sessions

  1. Sign out this device. Open the account menu and choose Log out. The app tells our servers to forget this phone's push‑notification registration before it signs out.
  2. Sign out other devices. Go to Settings → Security and privacy → Signed‑in devices. Tap Sign out beside a device, or Sign out other devices. Every session and token on those devices stops working immediately, and every browser push subscription on the account is removed. The device you are using stays signed in.

Contacts, keys, signatures and settings

  1. Suggested addresses (your recipient history): Settings → Suggested addresses, then Remove beside an address and confirm “Remove this address?”.
  2. Public keys of people you write to: Settings → Encryption keys, then delete a key and confirm “Delete this key?” with Delete.
  3. Signatures: Settings → Signatures, delete a signature and confirm “Delete this signature?” with Delete.
  4. Recovery email: Settings → Recovery email → Remove recovery email. We stored only a hash of the address; removing it clears that hash.
  5. Recovery key: Settings → Security and privacy → Recovery key → Remove recovery key. Only a hash of the phrase was stored; it is cleared.
  6. Two‑step verification: under Settings → Security and privacy → Two‑step verification, choose Remove the authenticator app, or Remove beside a security key or passkey. The secret or the key's public record is deleted.
  7. Display name and other settings can be changed at any time under Settings → General; the old value is overwritten, not kept.

Delete your whole account

To have the account and everything stored under it removed, follow the steps on Delete your account.

Request deletion by email

If something cannot be done from the app — for example a phone you no longer have, an account you can no longer sign in to, or a question about what we hold — write to [email protected].

  1. Say what should be deleted and give your full Private.Ki address. Name the data by type (for example “the push registration of my old phone”, “all sessions”, or “the account”); we cannot see message content, so we cannot find or delete individual messages for you.
  2. Show that the account is yours. The simplest proof is to send the request from the Private.Ki address itself, from a device that is signed in. If you cannot sign in, write from any address and, if you set a recovery email on the account, send the request from that address. We cannot verify you by password or passphrase — we never see either.
  3. We check, act and reply. Once we have confirmed the account belongs to you, we carry out what can be done on our side and tell you what was deleted. Where the request is about messages, we will point you to the steps above or to account deletion.

What is deleted

  • Messages. Permanent deletion, emptying Trash, discarding a draft, deleting a note and deleting a chat remove the message rows themselves from our database — the encrypted body, headers and subject — and the thread when nothing is left in it. Nothing is kept in a marked‑as‑deleted state.
  • Unsent and destroyed chat messages. The content, headers and sender name are emptied on both participants' copies; a content‑free marker row remains so the conversation keeps its shape.
  • Self‑destructing chat messages. Deleted from both sides by a server job that runs every minute, once their time is up.
  • Attachments. The encrypted file in object storage is deleted by a background job right after the message goes; a daily check removes anything that job missed. Reactions to a deleted message go with it.
  • Sessions. Signing out other devices ends every token on the account immediately; browser push subscriptions are removed at the same time. Signing out a phone removes that phone's push registration.
  • Suggested addresses, imported public keys, signatures are deleted rows. Recovery email, recovery key, authenticator secret, security keys are cleared or deleted from the account record.

What is kept, and for how long

  • Copies held by other people. Deleting a message or a conversation removes your copy only. An email or chat message you sent is stored in the recipient's mailbox, encrypted to their key, until they delete it — the only exceptions are Unsend/Destroy within the hour and self‑destruct timers, which act on both sides. Mail already delivered to an address at another provider has left our systems and cannot be recalled. Your address stays in other users' recipient history until they remove it.
  • Backups. Our database is dumped nightly into encrypted archives that no server can read. Deleted data can remain in these archives until they expire: the local dumps are kept for 14 days, the off‑site copies are removed automatically after 90 days at the latest and cannot be deleted earlier than 30 days after upload. Backups are used to recover the service after a failure, not to restore individual messages.
  • Delivery records for sent mail. The scheduling record of an emailed message, which names the addresses it went to, is removed by a daily job about a week after delivery.
  • Attachment bookkeeping. After the file itself is gone, a content‑free row (object name, size, dates) stays for the storage report for up to 400 days; it is detached from your account when the file is deleted.
  • Sending‑limit memory. To rate sending, we keep keyed fingerprints (HMAC) of the addresses you have written to — not the addresses themselves — for 90 days after the last mail to each. Sending‑limit counters expire within two days.
  • Rate‑limiting counters. Some requests, such as sign‑up, are counted per keyed hash of the IP address. Most of these counters expire within an hour; the counter for the no‑sign‑up start door expires within a day. They are not linked to your account.
  • Server logs. The mail server's delivery log records the addresses and times of messages exchanged with other providers. These logs are rotated as the server runs; they are not linked to your account and are not used to reconstruct messages. We keep no web‑server access logs with query strings.
  • Staff actions. If our staff act on your request through the operator console (for example revoke sessions or delete the account), an audit entry with the date and your account's internal identifier — not your address — is kept for one year.
  • Your own support message. A request you email us stays in our support mailbox like any other correspondence.

More

The Privacy Policy describes what we collect and store. The help center has step‑by‑step guides on deleting and restoring email, undo send, deleting a chat, unsend and destroy, self‑destructing messages and managing a group.