1. Delete your account
- Sign in and open Account → Privacy & data (
https://postriff-phase2-private.vercel.app/app/account/privacy). - Optionally export first: “Export drafts” gives you a zip with a receipt.
- Choose Delete account…, type
DELETEto confirm, and confirm again. - Only the workspace owner can do this after a recent sign-in. Cancel a renewing subscription and transfer any other owned workspaces first. Publications already handed to a platform must be resolved first; they cannot be recalled by cancelling. The app shows any unresolved publications. Waiting posts are removed unpublished when the workspace is deleted.
2. Disconnect one platform
- Open Channels and choose Disconnect on the account.
- The stored access token is wiped immediately and revoked with the platform where the platform supports it.
- Metrics and comments for that account stop being collected. Approved jobs for it are held, not published.
- You can also revoke Rafii from the platform’s own settings (for example LinkedIn → Settings → Permitted services, or Meta → Apps and websites); the next Rafii request will then fail and the connection will be shown as needing re-authorisation.
3. Remove a single source
In Ideas or Account → Privacy & data you can retract a source. Retraction removes its text and facts and blocks drafts that depend on it until drafted again. Waiting posts for those drafts are held until approved again. Retraction from Privacy & data also records a data request with a receipt.
4. What is deleted and what is kept
| On account deletion | Outcome |
|---|---|
| Account, memberships, sessions | Removed in separate stages. An identity-service failure leaves a pending receipt for recovery. |
| Workspace state: sources, drafts, approvals, schedules | Deleted. |
| Uploaded and generated media | Deleted from private storage. |
| Provider tokens | Wiped and revoked where supported. |
| Platform data (post ids, metrics, comments) | Deleted with the workspace. |
| Publication receipts and audit events | Limited deletion, trial and audit records remain; workspace publication records are removed. Retained records must not contain post text, media or tokens. |
| Billing records | Kept for as long as tax and accounting law requires; Stripe keeps its own records under its policy. |
| Backups | 30-day rotation is a candidate policy; release backup retention is not yet verified. |
5. Timing
Deletion first freezes workspace mutations and future dispatch, then removes stored media, workspace data and the sign-in identity. If storage fails, retry the pending deletion. If identity removal fails, the workspace has already been removed and its receipt stays pending. Backup expiry and recovery deletion replay must be verified for the release environment; a 30-day rotation is not yet an operational guarantee.
6. Requesting by email
If you cannot sign in, email privacy@postriff.app from the address on the account with the subject “Delete my data”. The privacy mailbox and handling deadline are pending review. Identity verification and a completion receipt are required; the draft does not promise an unverified response time. Platform users who never had a Rafii account but whose comment on a Rafii-published post was collected can use the same address; we remove the comment record and keep only a tombstone.
See also the Privacy Policy.