What deletion covers
Deleting your OnBetterTerms account is not a hidden flag or a disabled login. This page says what happens to each kind of thing, including the parts a sentence about databases usually skips.
Before anything happens
Nothing is touched for 30 days, and you can cancel for the whole of that time. After that it is carried out and it cannot be undone — not by you, and not by us.
Every kind of thing, and what happens to it
88 places in this system identify a person. The list below is the one the software uses — a test asks the database which of them exist and fails the build if any is missing a decision, so a new one cannot be added without somebody saying what forgetting you means for it.
These sentences were written for whoever maintains this, and they are shown here unedited. A reworded version would be a second thing to keep true.
Destroyed — 36 of 88
The rows go. Not flagged, not hidden from the interface — deleted, along with the key that made them readable.
- A block keeps one person from another; with the account gone there is nobody left to protect.
- A copy of everything, which must not outlive the account.
- A credential. (5 places)
- A log of what they shared, whose subjects are being destroyed with it.
- A private answer, and nobody else's to keep.
- A route to a device they no longer have.
- A sign-in method.
- A wording for an arrangement that was never proposed. Nobody else could read it and nobody else knew it was there.
- Addressed to them.
- Private to its author — the function that reads them says so.
- Something they started and never said. Nobody else could read it and nobody else knew it was there, so there is nobody it could be kept for.
- That they had finished, about lists that are being destroyed with it.
- The most sensitive rows in the product.
- The same, from the other side.
- Their behaviour, tied to them.
- Their membership of a space.
- Their own act. Only whether a tag is mutual is ever shown, so an erased account must not go on voting.
- Their own record of how things were.
- Their personal threads; room threads belong to the room.
- Their rating of an answer.
- Their record of asking the guide something — what it cost and how long it took, never a word of what was said.
- Their reflection on an argument.
- Their seat in a thread.
- Their settings.
- Their voice.
- Their writing.
- Unencrypted, and holds a file name they chose.
- What the guide was told about them, and nobody else's.
- What they said out loud.
- What they would and would not accept, written where nobody else could read it.
- What was noticed about them.
- Where they signed in from.
Left, without your name on it — 23 of 88
Things that are half somebody else’s. A message in a shared session is one side of a conversation the other person was also in, and taking it would edit their record of what happened. The authorship goes; the words stay, sealed under the space’s key. You can ask for these to be destroyed too when you delete — the choice is on the deletion screen.
- A change asked for, or a clarification written, about an arrangement the other person is still in. The words stay under the room key for them; the name comes off.
- A facilitator who leaves is not kept named in somebody else's space.
- A file they put in a space. Private and never-shared ones are destroyed with them, bytes and row together; a shared one is sealed under the room key and stays, unsigned, for the person it was put in front of — half of what a co-parent has is the rota the other one uploaded.
- A goal can be owned by one of them and worked on by both; ownership loses the name, not the goal.
- Parked by both of them; it stays parked.
- Private ones go; a shared one is sealed under the room key and stays, unsigned, for the person it was shared with.
- Private ones go; a shared one stays under the room key without its author.
- That it ended is the record; whose hand it was is between the two of them.
- That it was finished is the space's record; whose claim it was is not.
- That something was opened, and when, stays. Who opened it goes with them.
- That the ask was answered is part of the arrangement’s account of itself. Who answered it is not.
- The account goes and the line stays, unsigned: a record of an arrangement that loses half its events when one person leaves is not a record. The label written at the time carries who it was, which is what a reader a year later needs and what the other member is entitled to keep.
- The argument belongs to the space and stays for whoever is still in it.
- The correction is the other half, and answers the summary above it.
- The goal is the other person's too.
- The grant is the space's record; who proposed it is not.
- The option belongs to the table it was put on.
- The other half of the same fact.
- The question belongs to the space; who typed it does not.
- The summary is half of an exchange the other person keeps.
- The version stays; who replaced it does not.
- What somebody told the guide it had got wrong about them, which the other person read beside the reply it answers. The correction stays, unsigned: removing it would leave a characterisation standing that its subject rejected.
- Who stopped a conversation, and until when. The pause stays because the other person is still waiting on it; the name on it goes.
Kept, and why — 29 of 88
The short list. Everything on it is here because keeping it protects somebody, or because we are required to.
- A record of what an operator did, which is not the operator's personal data to erase. (9 places)
- A report about somebody is also the record of the person who made it, and theirs to keep.
- A staff action, not the subject's data.
- All but one are destroyed. The consent to this deletion stays, because it is the evidence that the erasure was asked for by the person it happened to.
- An abuse history that ends with the account is an invitation to make another one.
- An audit trail that can be edited by its subject is not one.
- Financial records are kept for as long as the law says, and no longer.
- Money that went back to somebody is a financial record with its own retention period.
- Outstanding ones are revoked so they cannot be redeemed; the row stays to say what became of it.
- Same, and a report is also the subject's record.
- The line items behind an invoice, which the invoice would be unexplainable without.
- The record of this erasure. Deleting it would erase the evidence that it happened.
- The record that somebody joined a space, which is the other member's history too.
- The space still exists for whoever is still in it.
- What staff did to an account is the account holder's protection, and outlives them.
- What the payment processor said and when, which reconciliation depends on.
- What was charged and why, kept for as long as the law requires it.
- Who asked the space to agree to a record. A proposal is cleared when the record starts or is withdrawn, so this is almost always null — and while it is set, the question of who is asking is the other members' to see.
- Who ended it, which the other member is entitled to know.
- Who proposed a resolution, which the other member is entitled to see.
- Who put the space on the record, which is part of what the record says about itself and is the other member's history too.
Backups
Backups are the question a list of tables cannot answer, because a copy taken last night is not reached by anything done today.
Your writing is not stored in a form a backup can hand back. It is encrypted under a key that belongs to your account alone, and deletion destroys that key — so a dump taken before you deleted holds the encrypted version, which nothing can open — including us. The backups are kept fourteen deep and a dump older than that is removed, so within a fortnight there is no copy holding even the unreadable version.
We are telling you what we do rather than what is impossible. A backup is a copy of a database, and the reason this one is safe is the key, not our intentions.
Caches, indexes and derived summaries
- There is no search index. Nothing about you is copied into a separate index for searching. What the product reads, it reads from the database rows above.
- Nothing you write is cached by a CDN or a proxy. Everything behind sign-in is marked not to be stored, and there is no third party in front of this site holding a copy of a page it rendered for you.
- A live session is held in memory only while it is live. A guided, joint or practice session ends when you end it, after thirty minutes of silence, or after eight hours whatever happens — and the conversation itself is not written to disk on the way out. What is recorded is that model calls were made, which is how your allowance is counted — the cost and the timing, never a word of what was said. Those records are destroyed with the account.
- Derived things go with what they were derived from. Patterns and insights are destroyed; a summary written into a shared record is treated like any other shared writing — it stays for the person you shared it with, without your name.
Things that go on a schedule instead
Some records age out whether or not anybody deletes anything, and deleting your account destroys them immediately rather than waiting.
- Analytics events: 365 days.
- Notifications: 90 days.
- Ended sessions: 30 days.
- Privileged-action audit entries: 730 days, and never fewer than 90 — a log that can be shortened to nothing is not a log. These record staff actions rather than anything you wrote.
What is kept when everything else has gone
An anonymous billing record — amounts and dates, with no name and no email — because we are required to keep one. And the record of the deletion itself, which is the evidence that it was asked for by the person it happened to.
Asking for it
It is in the product, not in an email to us: Privacy & security in your account, where you can also take an export of everything first. If something here does not match what you were shown, tell us at privacy@onbetterterms.com — a page about deletion that is wrong is worse than no page.
Related: Privacy policy · How the privacy model works