Account & Data Deletion Request

Statutory information and instructions on requesting permanent erasure of your personal data and RenewGuard account under GDPR Article 17 and Google Play policy.

Effective date: August 25, 2026

1. Regulatory Scope & Google Play Compliance

RenewGuard respects your privacy and fundamental data protection rights. In accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR" Article 17 – Right to Erasure) and Google Play's Account Deletion Policy, all users have the right to request permanent deletion of their account and all associated personal data.

This public page is provided so that any user who created an account with RenewGuard can initiate and understand account and data deletion without having the mobile app installed and without active authentication.

2. Scope of Erasure (What Data Is Removed)

When your account deletion is confirmed, our systems execute a cascading purge across all database tables. The following categories of personal data are permanently deleted:

Account & Identity Credentials

Your authentication record, registered email address, display name, password hashes (argon2/bcrypt), multi-factor TOTP secrets, and user profile data.

Subscriptions & Spend Tracking

All tracked subscriptions, service names, recurring costs, billing frequencies, renewal dates, payment histories, and payment method aliases.

Alerts & Notification Rules

Configured email reminder schedules, renewal alert notifications, monthly budget thresholds, and notification delivery logs.

Security Logs & Preferences

Session tokens, active sign-in sessions, security audit entries, MFA backup codes, and custom currency/theme preferences.

3. Data Retention Position & Timelines

RenewGuard adheres to a strict zero-residual-retention policy for deleted accounts:

  • Immediate Operational Purge: Deletion removes all records from active production databases immediately upon execution.
  • Disaster Recovery Backups: Encrypted system backup snapshots rotate on an automated cycle and are permanently overwritten within 30 days. Backup data is strictly isolated and never restored except for full-system disaster recovery.
  • No Third-Party Residuals: Subprocessors (Supabase, Cloudflare, Resend) hold no persistent copies of your personal data after account deletion.

4. How to Request Account Deletion

Option A: In-App Self-Service Erasure (Instant)

If you have access to your RenewGuard account, you can permanently delete your account and all associated data with instant effect:

  1. Sign in at renewguard.net/auth or in the RenewGuard app.
  2. Navigate to Account Settings > Danger Zone.
  3. Click Delete Account, type DELETE into the confirmation prompt, and confirm.

✓ Processing time: Instantaneous. All data is immediately purged.

Option B: Unauthenticated Deletion Request (Without App or Sign-in)

If you do not have the mobile application installed, have lost access to your account credentials, or prefer to request deletion directly from our data governance team, you can submit an unauthenticated request via email:

To: privacy@renewguard.net

Subject: Account Deletion Request - [Your Registered Email Address]

Body: Please delete my RenewGuard account and all associated data linked to [your email address].

Verification & Statutory SLA: For security and to prevent unauthorized erasure, our compliance team will verify sender ownership of the registered address before executing the deletion. Pursuant to GDPR Article 12(3), requests are processed without undue delay and at the latest within 30 days of verification.

5. Data Controller Contact & Governance

For inquiries regarding account deletion or statutory data subject rights under GDPR, contact:

Panagiotis Koletsos (RenewGuard Data Governance)

Email: privacy@renewguard.net

Supervisory Authority: Hellenic Data Protection Authority (HDPA) • www.dpa.gr