Account lifecycle

Request intake is available; deletion remains inactive.

Signed-in users can record a non-destructive account-deletion request after recent-session verification and receive live safety, billing, and last-owner preflight results. This intake never deletes data, closes an account, cancels billing, or schedules deletion.

Intake only · no deletion scheduled Content revision September 1, 2026

Current status

Visiting this page does not submit a deletion request.

Use the signed-in privacy-request page to record intake deliberately. A recorded receipt is not completed app-store deletion compliance; destructive deletion remains disabled until policy, retention, provider cleanup, and production acceptance gates are approved.

Available now

Protect and retrieve your data.

01

Download a workspace export

Signed-in owners and members can download structured records visible to them. Export files can include precise locations and sensitive field, client, contact, equipment, and photo-reference data.

Open Privacy & data →
02

Clear offline field data

The Privacy & data page can remove cached pages, viewed tiles, and saved analysis context from that browser. This does not delete cloud records or close the account.

Open device controls →
03

Manage an active subscription

Workspace owners can use Billing for the portal actions currently configured for their subscription. Cancellation and account deletion are separate actions.

Open Billing →
04

Record a non-destructive request

Signed-in users can create an intake receipt and see current safety, billing, ownership, and recent-session preflight items. No deletion is performed or scheduled.

Open privacy request →

Deletion prerequisites

Some account relationships must be resolved safely first.

The private preflight is designed to identify these categories without exposing another person’s private content.
  • Active Field Check-in

    End or safely resolve an active safety session so account removal cannot strand a guardian or destroy current trip evidence.

  • Workspace ownership

    Transfer control when the account is the last owner of a shared workspace, or choose a separately approved organization-deletion path.

  • Billing action

    Resolve an active subscription and any required billing state before account execution.

Candidate workflow

What is built, and what still blocks activation.

  1. 1
    Authenticate and preview — built

    The API accepts same-origin web sessions and native bearer sessions, verifies the JWT session ID against the actual Auth session creation time, and returns live blockers without exposing another user’s records.

  2. 2
    Confirm and cancel — built, disabled

    The signed-in flow requires the exact typed phrase and three consequence acknowledgements. Request, status, and cancellation operations are exact-retry safe, but intake remains off.

  3. 3
    Inventory and execute — candidate only

    The database inventories solo workspaces, shared identity, private Storage prefixes, camera connections, billing, legal, financial, safety, profile, and Auth scopes. Durable leases, retries, dead letters, and receipts are installed; provider and approved policy adapters are not active.

  4. 4
    Verify and close — guarded

    Auth is ordered last and cannot be marked successful while the Auth user still exists or while required cleanup is unverified. Production acceptance and approved backup/retention behavior are still required.

Owner-adopted boundary

Deletion does not mean silently erasing shared history.

The owner-adopted Privacy Notice describes the current intake-only state and retention criteria without promising destructive completion. Exact rules for personal-record deletion, shared-record anonymization, legal, financial, and safety evidence, backup expiry, billing, private Storage, and provider copies remain execution and production-proof gates. The candidate treats each unresolved operation as an explicit activation blocker.