account deletion

Last updated: 13 September 2026.

How to delete your account

In the app: YOU → Settings → Account → Delete account. Confirm, and — if your account has a password — type it, because a stolen phone must not be able to erase somebody's whole history in one tap. An account that only ever signed in with Google or Apple has no password to ask for and is not asked for one. That is the entire flow.

On the web: oomfyapp.com/delete-account, if you cannot get into the app. This one is not the same thing, and we would rather say so than let it look like the same button. It files a support request that a person fulfils, and we confirm by email that the request really came from you before anything is destroyed — because a stranger who knows your email address must not be able to erase your account from a public form. So it is slower, it involves talking to someone, and the address you type stays on that support ticket afterwards, where the scrub below cannot reach it (§5). Use the app if you can get into the app.

There is no retention screen, no "here's what you'll lose" guilt page, and no offer of a discount to stay. You do not have to give a reason and nobody will email you to ask for one. Mail is sent, though, and we would rather name it: from the app, a notice to the address on the account saying deletion is scheduled, that the app cannot undo it, and that nothing is erased until the 30 days are up, so writing to us inside them is the one thing that can still help — it is the one warning that reaches you if it was not you who pressed the button. From the web form, an automatic acknowledgement carrying the ticket's reference, and then the human note confirming it really is you. Deactivating sends its own mail, saying how to come back.

If you just want to disappear for a while

Deactivation hides your account for 30 days. Logging back in silently reactivates it and nothing is destroyed. If you do not come back within 30 days, it is treated as a deletion.

This exists because "I need a break from this" and "I want this erased" are different requests, and a product that only offers the second one is quietly punishing you for the first.

What is destroyed

Everything that is about you. The rows are deleted, not flagged — with one deliberate exception, the account row itself, which is emptied and kept as a shell (§8 below):

  • your email, your handle, your display name, your avatar, your cover image and your bio, wiped off that shell,
  • every message you ever sent, and every reply you ever received, in one-to-one chats and in group rooms, with the summaries, open threads, bond notes and group asides written out of them,
  • every memory — every Fact any character formed about you, every pinned memory, every lorebook you wrote,
  • your personas,
  • your diary Moments, your daily questions and the answers you gave them, and your check-in streak,
  • your generated images and voice clips,
  • your story and game progress,
  • your notification tokens and device records, your notification inbox and settings, your browse channels and muted words,
  • your sign-in identities and every login session,
  • your likes, your reviews, your follows, the blocks you made,
  • your product events, the promotions you were shown, your per-day usage counts, your Sparks balance, coupon redemptions and the invites you sent,
  • any thread we started by writing to you, including what you wrote back.

If you signed in with Apple, we also revoke your Sign in with Apple tokens with Apple at the moment you delete, so the link between your Apple ID and oomfy ai is cut and not left dangling.

What survives, and exactly why

More than three things, and we are naming them rather than letting you discover them later — these are the ones we know of, and the list has grown every time we have gone looking. §8 of the Privacy Policy covers the same ground with the field-level detail, and is the fuller of the two.

1. Crisis-referral counts

A record, not a message. California SB 243 requires operators in this category to report the number of crisis referrals issued to the California Office of Suicide Prevention, annually, from July 2027.

The record holds when it happened, which classifier decided and how confident it was, what we did, which resources we showed you, whether you tapped through the card, your region and the reporting year. There is no message text in it, and when your account is scrubbed the references to you, your chat and your message are removed — so once your account is gone there is nothing in it that identifies you. We cannot report a count we deleted, and we are legally obliged to be able to report it.

2. Financial records

Purchases, subscriptions, creator earnings and payouts, and your Sparks ledger — kept for as long as tax law requires. A payout record also names the destination you gave us and the KYC state it was paid under, because that is what makes a payment auditable — and the anti-fraud assessment it was approved against, which scores the accounts that chatted with that creator, by account id. If you chatted with a creator, that is where your account id can outlive you: inside somebody else's payout record. There is no timer on any of them today; they are accounting records and nothing in the product deletes one.

Kept alongside them, and we would rather name it than bury it: the webhook receipts a payment provider sends us, stored verbatim and never redacted. For a web payment that copy carries the email address, phone number and UPI handle you gave the payment provider. It is not attached to your account, so the scrub above never sees it, and nothing deletes it.

3. Store-receipt claims

When an account verifies a Google orderId or an Apple transactionId, that receipt is claimed globally and permanently. That claim survives account deletion.

If it did not, then "buy, redeem, delete, re-register, replay" would be a working exploit — one purchase, redeemed forever, on an endless carousel of fresh accounts. The claim is on the receipt, not on you. It is an opaque store identifier with no personal data attached.

4. Characters you made, and scenes you published

Characters you made are hidden, not destroyed — every one of them, published or not: they go inactive and private, so they vanish from every rail, every search and every discovery surface and nobody can start a new chat with them. Scenes you published stay published and playable. Both keep the artwork; your name on them becomes "Deleted user".

The reason is the same one that stops a creator deleting a character out from under other people: strangers are mid-conversation and part-way through a scene, and a creator leaving must not vaporise thousands of other people's chats. This is a decision we made in favour of those readers, and it is the one place where leaving does not take everything with it.

5. A support ticket you filed

If you wrote to support, the whole thread survives — the subject, your first message, everything you wrote back on it afterwards, and any screenshot you sent us — because it may be the only record of something we were told. That includes the stored image itself, not just the record of it: the screenshot stays in our storage, and nothing sweeps it automatically — removing it would be a person's decision, not a timer's. Your account is detached from the ticket. A ticket you filed while signed in never carried an email address, by design; one filed from the logged-out web form — including a deletion request sent from oomfyapp.com/delete-account — keeps the address you typed, and nothing removes that.

A report you filed about somebody else's content survives the same way, detached from you, because it is a safety signal about a third party — but the text you wrote in the report stays with it.

6. Safety and enforcement records

Strikes and enforcement decisions taken on your account, with the reason recorded at the time, and the moderation records of actions we took. The quiet safety signals — a note that you seemed distressed on a date — are destroyed with the account.

If a moderator ever acted on your account, the admin audit trail keeps one more thing: the account as it read at that moment, including the email address, handle, display name and bio it had then — because a decision nobody can tie to an account is not an auditable decision. Those rows are not stripped the way the account row is, and nothing deletes them.

7. Three records that belong to other people

  • a per-month count of how many messages you exchanged with each character, which stays with that character's creator statistics, attached to your deleted account id and to nothing else about you,
  • an invite you accepted, which stays on the account of the person who invited you — it is their record of an invite that paid them — and by then names your deleted account and nothing else about you,
  • blocks other people made against you, because they are their decision and not yours.

8. A stripped account row

The shell the records above hang from. Your account row is not deleted: it is emptied, marked deleted and kept, because the records above have to hang from something and because a row that is gone cannot say "this account was deleted" to a login that arrives afterwards. It keeps your region, timezone and language, the dates you accepted these terms, the dates the account was created and deleted, and a store account token. No email, no handle, no name, no avatar, no bio, no referral code. Also kept: AI cost and token-count rows for accounting, with no account attached to them, and any prompt version you authored or promoted through our console, which stays on the platform with your name taken off it.

Timing

  • The account is unreachable immediately.
  • Data is destroyed within 30 days.
  • The files behind it — avatars, portraits, generated images, voice clips — are only unreferenced by that scrub. There is no automatic sweep and no window we can promise you: bytes are reclaimed by hand, from an admin console that lists unreferenced objects for a person to review before anything is deleted, so a file can outlive the row that pointed at it indefinitely. The free clips our own voice server produces are the exception — those are deleted from storage once the link to them has expired, by the same code that made them. A screenshot on a support ticket is different: the ticket still points at it, so the scrub never unpicks it — it is kept on purpose, as §5 says.
  • An export bundle, if you took your data with you before leaving, is on that same manual footing. The download link stops working after 72 hours; nothing deletes the file automatically, and it stays in our storage.
  • Backups roll off within 7 days after that.
  • A waitlist entry sits outside all of this. If you ever typed your address into the list form on our website, that entry was never attached to your account, nothing sweeps it and no window covers it — write to us and we will remove it by hand.

Take it with you first

You do not have to choose between leaving and keeping what you made.

Settings → Export your data. You get one JSON file: your account record, your one-to-one chats and every message in them decrypted for you — group rooms are not in the bundle today — the Facts a character formed about you, every character you made with its lorebook, your own lorebooks, your personas, your Sparks ledger and your subscriptions. A character leaves as its whole definition, field for field, so nothing you wrote about them is summarised away. A Character Card V2/V3 export exists as well, per character — but it is an API route today (GET /characters/:id/export) and no button in the app calls it.

We built the export before we built the paywall. A platform you cannot leave is a platform that has stopped having to earn you, and we would rather keep having to earn you.

Questions

[email protected] — we answer within 30 days, usually within one.