This page must be published at a public URL. Google Play requires a
dedicated, publicly reachable data-deletion page for any app that lets people
create an account, and it must be reachable _without_ signing in or installing
anything. A privacy policy that mentions deletion does not satisfy it — Play
asks for this link separately in the Play Console, and a missing or gated one is
a routine rejection.
In the app: Settings → Account → Delete account.
You will be asked to confirm. Deletion is immediate and cannot be undone.
If you cannot reach the app — you have lost the device, or can no longer sign
in — email support@brightfoundrygraphix.com from the address on the account and
ask us to delete it. We will confirm within 30 days.
Permanently, from our servers:
wishlist, sealed items, and play records
Abuse reports that you filed about someone else. These are kept, with your
account link removed so they are no longer tied to you.
A safety record that disappears when the reporter deletes their account is not a
safety record — it would mean anyone could erase the evidence against someone
they had reported by deleting their own account. The report and the copied
message stay; you do not.
Reports filed about you are likewise retained, for the same reason.
Nothing else is kept.
Deleting your account does not touch the copy on your device. That is
deliberate: your collection is yours, and closing a cloud account should not
destroy years of local records.
To remove the local data as well, uninstall the app. On desktop you can also
delete the database directly — Settings → Storage shows you where it lives.
Export first if you might want it. Settings → Backup writes a file you can
import later. Once local data is gone we cannot recover it, because we never had
a copy.
You do not have to delete your whole account to clear a conversation. Open the
conversation and delete it; that removes those messages from our servers for
both people.
If you want to stop syncing but keep the account, sign out and turn sync off.
To remove what has already been uploaded, delete the account — there is
currently no partial server-side wipe, and we would rather say so than imply a
control that does not exist.