Account control

Account & Data Deletion

How to permanently delete a PlaysAll account, what is removed and what must be cancelled separately.

1. Delete in the app

Open PlaysAll Settings, select the account/device section and choose Delete Account. Review the warning and confirm the destructive action. After authentication, the request permanently deletes the registered PlaysAll account and turns the current installation into an anonymous installation. Platform wording may vary slightly.

For account protection, deletion requires a password or social sign-in verified by our server within the previous 15 minutes. If that verification has expired, the app asks you to verify again before it sends the deletion request; no account or RevenueCat deletion occurs until verification succeeds.

2. If you cannot access the app

Email from the address associated with the account and use the subject “Account deletion request”. We will verify control of the account before deletion. Do not send a password, parental PIN, source credentials or full playlist URL.

3. Account records deleted

  • Account email, display name, password hash/salt and account security fields.
  • Adult and child profiles, avatars, parental-PIN hash/salt and profile records.
  • Other registered devices, registered-device tokens, consent records and connected sessions. The current installation is handled as described below.
  • Encrypted synced-source envelopes and associated source identifiers.
  • PlaysAll entitlement records and other usage rows linked to the registered account, subject only to the limited records described below.
  • A customer-deletion request is sent to RevenueCat for the customer associated with the deleted PlaysAll account.

4. Current anonymous installation and local data

After confirmed deletion, the current client clears its account session and account-linked cloud state, then continues as an anonymous installation. We retain only pseudonymous device-authentication fields — its hashed installation identifier and authentication token — plus a neutral device label, platform and app/system versions, creation and last-seen timestamps, and the installation’s one-time Free playback allowance. These fields are no longer linked to the deleted account. We use this limited pseudonymous record to secure the service and prevent deletion/re-sign-up abuse; it remains only while the installation is active and for no more than 180 days after it was last seen.

Media sources, source vaults, favorites and player history stored only on a device are local player data, not registered-account records. They may remain on the current device or another offline device until you remove the source, clear app data or uninstall the app. Remove local sources and clear devices you no longer control before deletion where possible.

5. Limited retention exceptions

A purchase webhook event with its PlaysAll account reference removed may remain for no more than 180 days to prevent duplicate processing and investigate billing events. Stores, RevenueCat, Stripe, email providers or advisers may retain their own transaction, fraud, support or legal records under their policies and legal duties. We may retain the minimum direct-sale record required by tax, accounting, fraud, chargeback, security or claim law and will restrict it to that purpose.

Deleted account data may remain temporarily in access-restricted disaster-recovery history: Cloudflare D1 for the applicable provider window, no longer than 30 days, and a rolling maximum of 14 Hetzner daily database copies. Recovery copies are not used for normal operation. If a pre-deletion copy is restored, deletion controls must be reapplied before normal service resumes.

6. Subscriptions are separate

Deleting the PlaysAll account does not cancel an Apple, Google, Amazon or direct web subscription and does not itself create a refund. Cancel through the purchase channel before deletion where possible; a web subscription must be managed through the billing link or customer portal supplied with that purchase. Without the deleted account, restoring an account-linked entitlement may require a new account and purchase-channel verification.

7. Finality and help

Server-side account deletion is intended to be permanent and cannot normally be reversed. Export any account data you need before deleting. A later signup creates a new registered account and does not restore deleted profiles, encrypted sync data or entitlements, and it does not reset the current installation’s one-time Free playback allowance.