Your data

Delete your account & data

App: PinPapers Developer: Mindslake Phase 1 private beta, India

This page explains how to delete your PinPapers account (developer: Mindslake) and what happens to your data. You do not need to sign in, and you do not need to have the app installed, to make a request.

How to request deletion

During the Phase-1 private beta, account deletion is handled by email. Follow these steps:

  1. Email us. Write to info@mindslake.com from the email address registered to your PinPapers account so we can identify you.
  2. Use the subject line “Delete my account”. This routes your request straight to our deletion queue.
  3. We verify ownership. We confirm the request came from your registered address (we may reply to check a detail before we proceed).
  4. We schedule the deletion and confirm it to you. A 30-day reversible grace window begins — tell us within that window if you change your mind.
  5. Your data is crypto-shredded. Within 30 days the keys that unlock your files are destroyed, and your documents become permanently unrecoverable.

Email info@mindslake.com to delete my account

This is irreversible

Once the 30-day window closes, your documents cannot be recovered

Deletion destroys the encryption keys that wrap your files (a “crypto-shred”). After that, the stored ciphertext is mathematically undecryptable — even by us. Please make sure you have your own copy of anything you want to keep before you ask us to delete your account.

At general availability an in-app Delete account flow will let you start deletion directly from the app’s settings. During this closed beta that in-app option is intentionally turned off, so the email process above is the way to delete your account.

What is deleted

When your deletion completes, we delete:

  • Your document, photo and voice-note encryption-key wraps (including per-device restore re-wraps and any share recipient copies). Destroying these is the erasure event: the stored ciphertext becomes mathematically undecryptable (crypto-shred).
  • Your identity data — the salted email hash and your phone number.
  • Your optional profile display name.
  • Your pins and pin coordinates (precise location), your pin note bodies, and document / upload records (the rows you own).
  • Your sign-in account (AWS Cognito), your device identifier (the random Keychain/Keystore UUID), and your trusted-device records.
  • Associated database records, and — as a best-effort janitorial follow-on, gated by storage Object-Lock — the encrypted storage objects themselves.

What is kept, and for how long

A small amount of data is retained after deletion, either because it is a legally-required record or because it is already inert. None of it can be used to read your documents once your keys are destroyed.

Retained after account deletion
DataWhy it is keptRetention
Immutable audit records (security & disclosure logs), kept intact and attributed to your account IDLegal record under DPDP §8(7) / GDPR Art. 17(3)(b)7 years
Routine authentication audit eventsSecurity90 days
Encrypted document ciphertext under S3 Object-Lock — inert and undecryptable once the keys are shreddedWrite-once storage retentionUntil each object’s lock expires
Encrypted database backupsDisaster recoveryRolling 30-day window
Crash reports at Sentry (only if you enabled optional C2 consent)Bug diagnostics90 days; withdrawal deletes within 30 days

Related

For the full picture of how we handle your data, see the Privacy Policy (retention is detailed in §7). For any other help, visit Support or email info@mindslake.com.