Delete your account & data
This page explains how to delete your PinPapers account (developer: Mindslake) and what happens to your data. You do not need to sign in, and you do not need to have the app installed, to make a request.
How to request deletion
During the Phase-1 private beta, account deletion is handled by email. Follow these steps:
- Email us. Write to info@mindslake.com from the email address registered to your PinPapers account so we can identify you.
- Use the subject line “Delete my account”. This routes your request straight to our deletion queue.
- We verify ownership. We confirm the request came from your registered address (we may reply to check a detail before we proceed).
- We schedule the deletion and confirm it to you. A 30-day reversible grace window begins — tell us within that window if you change your mind.
- Your data is crypto-shredded. When the 30-day window closes, the keys that unlock your files are destroyed. From then on nothing in PinPapers can open them and we will not restore them on request; once our encrypted backups roll over, no one can.
Email info@mindslake.com to delete my account
This cannot be undone
When the 30-day grace window closes we destroy the encryption keys that wrap your files (a “crypto-shred”). From that moment nothing on our side can open your documents — no server, no support process — and we will not restore them if you ask. For a short period afterwards those keys still exist inside our encrypted database backups, which we keep only for disaster recovery and which roll over on their own; once they have, your documents cannot be opened by anyone, including us. Please make sure you have your own copy of anything you want to keep before you ask us to delete your account.
At general availability an in-app Delete account flow will let you start deletion directly from the app’s settings. During this closed beta that in-app option is intentionally turned off, so the email process above is the way to delete your account.
What is deleted
When your deletion completes, we delete:
- Your document, photo and voice-note encryption-key wraps (including per-device restore re-wraps and any share recipient copies). Destroying these is the erasure event: without the key, the stored file is unreadable scrambled data (a “crypto-shred”).
- Your identity data — the salted email hash and your phone number.
- Your optional profile display name.
- Your pins and pin coordinates (precise location), your pin titles and labels, and document / upload records (the rows you own).
- Your sign-in account (AWS Cognito), your device identifier (the random Keychain/Keystore UUID), and your trusted-device records.
- Associated database records, and — as a best-effort janitorial follow-on, gated by storage Object-Lock — the encrypted storage objects themselves.
Deletion also reaches beyond your own account. If you created any companion accounts (additional devices that share your storage), those are deleted too — the companion devices lose all access, and the copies saved on them are removed the next time they connect. Anything you had shared also stops working: the people you shared with lose access and the item disappears from their “Shared with me” — they are not separately notified, and any copy a recipient already downloaded to their own device is outside our reach. Companion accounts are not available in the current private beta.
What is kept, and for how long
A small amount of data is retained after deletion, either because it is a legally-required record or because it is already inert. None of it can be used to read your documents once your keys are destroyed — apart from the encrypted database backups listed below, until those roll over.
| Data | Why it is kept | Retention |
|---|---|---|
| Immutable audit records (security & disclosure logs), kept intact and attributed to your account ID | Legal record under DPDP §8(7) / GDPR Art. 17(3)(b) | 7 years |
| Routine authentication audit events | Security | 90 days |
| Encrypted document ciphertext under S3 Object-Lock — inert once the keys are shredded, and unreadable by anyone once our encrypted backups have also rolled over | Write-once storage retention | Until each object’s lock expires |
| Encrypted database backups | Disaster recovery | Rolling 1-day window, encrypted at rest. This window will be longer once PinPapers leaves beta; we will update this table before it changes. |
| Diagnostics logs you explicitly shared with support | Support troubleshooting | Deleted within 30 days after your support case closes |
Related
For the full picture of how we handle your data, see the Privacy Policy (retention is detailed in §7). For any other help, visit Support or email info@mindslake.com.