User Data Deletion Instructions
Last updated: September 2, 2026
SocialCannon (a service of Tiny Red Pixel Ltd) lets you delete your account and associated application data from the dashboard when self-service deletion is available. During a safety rollout the control may be visibly disabled; in that case, email support@socialcannon.app and we will handle the request. Limited records may remain with service providers for the periods described below.
How to Delete Your Account
- Sign in to SocialCannon at socialcannon.app/sign-in.
- Open Settings → Billing from the dashboard.
- Scroll to the Danger Zone section at the bottom of the page and click Delete My Account.
- Confirm the two-step warning prompt. Your API client and publishing access are disabled when the protected request starts. Completion can pause while an in-flight provider operation, billing cancellation, or storage cleanup is confirmed. Cleanup continues automatically; while your sign-in remains available, you can also resume from the deletion-pending page.
What Gets Deleted
Before the application identity is removed, active and noncurrent media generations in your tenant namespace are removed and every outstanding direct-upload path is sealed against a late write. Once that cleanup and the other deletion checks complete, the following are removed from our active systems:
- Your Firebase Authentication record (Google / GitHub sign-in identity).
- Your user profile and dashboard settings.
- Your API client and client secret — any agent, MCP server, or script using your API key will stop working immediately.
- All scheduled, published, and draft posts you created.
- All connected social accounts (Twitter / X, Facebook, Instagram, LinkedIn, TikTok, YouTube) including their encrypted OAuth tokens — we can no longer access any of those platforms on your behalf.
- All post analytics snapshots, tracked links with UTM data, engagement records (comments, replies, mentions), and A/B tests.
- Your Stripe customer record. Any active subscription is cancelled.
Removing SocialCannon from Facebook Alone
Removing SocialCannon from your Facebook Business Integrations settings (or your Twitter / Instagram / LinkedIn / TikTok / YouTube authorised-apps settings) will revoke our access to that single platform, but it does not delete your SocialCannon account or the rest of your data. To fully erase your data from SocialCannon, use the in-app deletion flow above.
What May Be Retained
A small amount of information may be retained after account deletion for legal, tax, fraud-prevention, security, operational, or provider-retention reasons:
- Billing records: Invoices and payment records held by our payment processor (Stripe) are retained as required by UK accounting and tax law.
- Cloud Storage soft-delete retention: Active media generations are removed before application identity deletion. If the storage provider's soft-delete policy is enabled, provider-retained deleted generations cannot be hard-deleted early and remain until their recorded hard-delete time. Permanent zero-byte, temporary-held blocker objects and their pseudonymous path-safety ledger may remain at random upload paths; they contain no uploaded media or original filenames and prevent an already accepted upload from recreating deleted data.
- Publishing safety journals: Terminal records used to prevent duplicate or orphaned provider actions can retain internal tenant, platform-account, and provider-result identifiers. They become eligible for Firestore's asynchronous TTL deletion 90 days after settlement. An unresolved provider action pauses deletion instead of being inferred as complete.
- Shared Meta grant safety registry: A complete Facebook/Instagram permission and asset inventory may remain under keyed pseudonyms so the same app-scoped Meta grant can be compared safely across connections and tenants. It contains no raw provider IDs or OAuth tokens. Each complete observation refreshes a 90-day Firestore TTL eligibility timestamp; a record shared by another active tenant may therefore remain until 90 days after its most recent complete observation.
- Stripe delivery safety journal: A global anti-replay record can retain a provider event pseudonym, event type, timestamps, and a finite failure code, but never the event payload or a raw failure message. It becomes eligible for Firestore's asynchronous TTL deletion 45 days after the latest delivery outcome. This is separate from billing records retained by Stripe.
- Deleted-identity safety barrier: A permanent one-way digest of the deleted Firebase user ID, plus the deletion request timestamp and state, prevents an old sign-in request from recreating the account. It contains no raw user ID, email address, profile data, or authentication token and is used only for deletion safety.
- Anonymised analytics: Aggregate, non-identifying usage metrics may remain in our analytics systems.
- Service diagnostics and email-delivery records: Limited Sentry diagnostic events and Hostinger delivery records may remain for the providers' configured retention periods or for applicable security, contractual, or legal requirements. We will use available provider controls if applicable law requires processor-held personal data to be deleted or anonymised following a verified request.
We restrict retained records to the purposes above and do not use them for marketing or profiling.
Questions
If you cannot access your account to use the in-app deletion flow, contact us:
Tiny Red Pixel LtdCompany Number: 17224220
Unit A, 82 James Carter Road
Mildenhall, Bury St. Edmunds, IP28 7DE
England