Legal
Data Deletion Instructions
You have the right to request deletion of all personal data Cloutbox holds about you.
1. Export Your Data First (Optional)
Before deleting your account, you have the right under GDPR Article 20 to receive a copy of your personal data in a structured, machine-readable format (JSON/CSV).
To request a data export: email privacy@cloutbox.ai with subject "Data Export Request". We will deliver your data within 30 days. You can then request deletion separately.
Your export includes: account profile data, organisation data, post history, and notification preferences. OAuth tokens are not exported as they are security credentials.
2. Delete Your Account In-App
Sign in to Cloutbox
Go to https://cloutbox.ai and log in.
Open Account Settings
Click your name or avatar in the bottom-left corner, then select Account Settings.
Navigate to Danger Zone
Scroll to the Danger Zone section at the bottom of the Account Settings page.
Confirm Deletion
Click Delete Account, type DELETE to confirm, and submit.
Irreversible: account deletion is permanent. If you are the sole admin of a workspace, all workspace data is also deleted. Export your data first if needed.
3. Request Deletion by Email
If you cannot access your account:
- 1
Email us
Send a message to privacy@cloutbox.ai with subject "Data Deletion Request".
- 2
Provide your details
Include the email address on your Cloutbox account and any other details to identify your data (workspace name, approximate sign-up date).
- 3
Identity verification
We may ask you to verify ownership of the email address before processing.
- 4
Acknowledgement
We will confirm receipt within 5 business days and complete deletion within 30 days.
4. What Gets Deleted and When
Deleted on request (within 24 hours of processing):
- User profile (display name, email link, avatar, preferences).
- All OAuth access and refresh tokens for connected social platforms.
- All scheduled posts and draft content.
- Workspace data (if you are the sole admin).
- Notification preferences and account settings.
Deleted within 30 days (sub-processor cascade):
- Supabase: database backups containing your data are purged on a rolling 30-day cycle.
- Sentry: error events linked to your user ID are anonymised within 30 days.
- Resend: email delivery logs containing your address are deleted within 30 days.
- Vercel: edge function logs containing your IP address are purged after 90 days per Vercel's log retention policy.
- Inngest: job history containing your identifiers is purged after 30 days.
Retained by legal obligation:
- Stripe billing records: retained for 7 years as required by tax law. Your email may persist in Stripe but is no longer linked to an active Cloutbox account.
- Security and fraud logs: retained for up to 12 months. After this period they are purged or fully anonymised.
- Legal hold data: if a legal proceeding or regulatory inquiry requires us to preserve data, we will retain only what is legally required for the duration of the hold.
5. Revoke Social Platform Access
Deleting your Cloutbox account revokes our token-based access to your platforms. For additional assurance, revoke directly from each platform:
Settings → Apps and Websites
Settings → Apps and Websites
X (Twitter)
Settings → Connected apps
Settings → Permitted services
TikTok
Settings → Apps and Permissions
Google / YouTube
Account permissions page
Facebook and Instagram are separate apps
Revoking Facebook access does not automatically revoke Instagram access, and vice versa. If you connected both, you must revoke each one individually via the links above.
6. Facebook / Meta Data Deletion Callback
In accordance with Meta's Platform Terms, if you remove Cloutbox from Facebook via Facebook's App Settings, Meta automatically sends a deletion request to our systems. Upon receiving this request:
- Within 1 hour: we acknowledge the deletion request and revoke your Facebook OAuth token.
- Within 48 hours: all Facebook-related connection data is deleted from our database.
- Within 30 days: data is purged from backups and sub-processor systems per the cascade described in Section 4.
Note: this process deletes only your Facebook connection data. To delete your full Cloutbox account and all data, use the in-app deletion in Section 2 or the email request in Section 3.
7. Contact
For deletion requests, data exports, or verification status:
privacy@cloutbox.aiWe acknowledge all privacy requests within 5 business days and complete deletion within 30 days, or within the timeframe required by applicable law (e.g., 45 days under CCPA).