Delete your account & data
This page explains how to delete your PinPapers account (developer: Mindslake) and what happens to your data. You do not need to sign in, and you do not need to have the app installed, to make a request.
How to request deletion
During the Phase-1 private beta, account deletion is handled by email. Follow these steps:
- Email us. Write to info@mindslake.com from the email address registered to your PinPapers account so we can identify you.
- Use the subject line “Delete my account”. This routes your request straight to our deletion queue.
- We verify ownership. We confirm the request came from your registered address (we may reply to check a detail before we proceed).
- We schedule the deletion and confirm it to you. A 30-day reversible grace window begins — tell us within that window if you change your mind.
- Your data is crypto-shredded. Within 30 days the keys that unlock your files are destroyed, and your documents become permanently unrecoverable.
Email info@mindslake.com to delete my account
Once the 30-day window closes, your documents cannot be recovered
Deletion destroys the encryption keys that wrap your files (a “crypto-shred”). After that, the stored ciphertext is mathematically undecryptable — even by us. Please make sure you have your own copy of anything you want to keep before you ask us to delete your account.
At general availability an in-app Delete account flow will let you start deletion directly from the app’s settings. During this closed beta that in-app option is intentionally turned off, so the email process above is the way to delete your account.
What is deleted
When your deletion completes, we delete:
- Your document, photo and voice-note encryption-key wraps (including per-device restore re-wraps and any share recipient copies). Destroying these is the erasure event: the stored ciphertext becomes mathematically undecryptable (crypto-shred).
- Your identity data — the salted email hash and your phone number.
- Your optional profile display name.
- Your pins and pin coordinates (precise location), your pin note bodies, and document / upload records (the rows you own).
- Your sign-in account (AWS Cognito), your device identifier (the random Keychain/Keystore UUID), and your trusted-device records.
- Associated database records, and — as a best-effort janitorial follow-on, gated by storage Object-Lock — the encrypted storage objects themselves.
What is kept, and for how long
A small amount of data is retained after deletion, either because it is a legally-required record or because it is already inert. None of it can be used to read your documents once your keys are destroyed.
| Data | Why it is kept | Retention |
|---|---|---|
| Immutable audit records (security & disclosure logs), kept intact and attributed to your account ID | Legal record under DPDP §8(7) / GDPR Art. 17(3)(b) | 7 years |
| Routine authentication audit events | Security | 90 days |
| Encrypted document ciphertext under S3 Object-Lock — inert and undecryptable once the keys are shredded | Write-once storage retention | Until each object’s lock expires |
| Encrypted database backups | Disaster recovery | Rolling 30-day window |
| Crash reports at Sentry (only if you enabled optional C2 consent) | Bug diagnostics | 90 days; withdrawal deletes within 30 days |
Related
For the full picture of how we handle your data, see the Privacy Policy (retention is detailed in §7). For any other help, visit Support or email info@mindslake.com.