Skip to content

Legal

Data-Deletion Policy

Effective date: 16 August 2026

Last updated: 2 October 2026

Version: 3.1

Hudood provides an in-app account-deletion path and this public web route so a user can request deletion without reinstalling the app.

1. How to request deletion

In the app, open your profile, tap the gear to open Settings, choose Account lifecycle > Delete account and confirm the request. If you signed in with Apple, Hudood asks Apple to revoke its access to your Apple ID when you make the request.

If you cannot get into your account, use the email route instead - it is the whole reason this page exists, because somebody locked out is exactly the person who ends up reading it. Email a deletion request (legal@hudood.com, subject Account Deletion Request), from the account email where possible. Include the username and enough information for Hudood to verify control of the account.

Hudood may request proportionate identity verification to prevent unauthorized deletion. Never send a password.

2. What happens

  1. Immediately: the account is deactivated, login is blocked, and the public profile and content are hidden.
  2. For 30 days: the account remains in a recovery period. A verified recovery request may restore it unless a safety or legal restriction prevents restoration.
  3. After 30 days: Hudood scrubs the canonical user record, removes or de-identifies public attribution, deletes active session and service data that is no longer needed, and starts provider deletion jobs.
  4. Completion: Hudood records each deletion stage so failed provider deletions can be retried without restoring the public account.

Deleting an account is different from deleting the app from a device. Uninstalling does not submit a deletion request.

3. What is deleted or de-identified

Subject to the exceptions below, deletion covers account/profile data, active sessions, push-notification identifiers, Firebase identity, any encrypted Apple token held for Sign in with Apple, user media in active blob storage and derived copies, OneSignal device records, any RevenueCat customer record if one exists, and other processor records tied to the account.

Public content is removed or de-identified. Content another user lawfully copied or independently posted is not under Hudood's control. Aggregated statistics that no longer identify you may remain.

4. Limited retention after deletion

Hudood retains only what is needed for a stated legal or safety purpose:

  • registration information required by Rule 3(1)(h) of India's IT Rules is retained for 180 days after cancellation or withdrawal;
  • routine pseudonymous moderation/compliance events may remain for up to 90 days after the canonical account scrub;
  • high-risk hashed abuse, fraud, or security signals may remain for up to 180 days after the canonical account scrub;
  • security logs may be retained for the period required by applicable cyber-security rules;
  • reports, grievances, transactions, or legal-request evidence may remain while a legal duty, dispute, limitation period, or valid preservation order applies; and
  • bounded backups expire on their normal cycle, including Azure database backups configured for up to 35 days.

A legal hold must record its reason, authority, approver, start date, and expiry or review date. Retained data is access-restricted and is not restored to the public service.

5. Individual content and third-party records

You can delete individual content without deleting the account where the product provides that control. Reports or messages involving another user may retain a restricted record needed to protect that person, investigate abuse, or demonstrate a moderation decision.

6. Confirmation and questions

Where the request was made by email, Hudood will confirm receipt and may send completion status to the verified account address. For questions, email legal@hudood.com with the subject Privacy Request.

See the Privacy Policy for the full retention table and data rights.