Account deletion
Delete your WITHSTAND account
You can delete your account yourself, from inside the app, at any time. You do not need to ask anyone, explain why, or cancel anything first. Deletion cannot be undone.
Deleting in the app
- Open WITHSTAND and scroll to the bottom of the Home screen.
- Choose Delete account, below Blocked lights and Notifications.
- Sign in again when you are asked to. Deletion is irreversible, so it requires a recent sign-in rather than trusting a sign-in from hours ago.
- Read what is kept, then confirm.
What happens when you confirm
All of this happens together, or none of it does. There is no half-deleted account.
- a session in progress ends;
- you leave the Watch queue, and any open request or offer is cancelled;
- every device you registered is invalidated and its push token is destroyed, so no further notification can be sent to it;
- your account is disconnected from your sign-in identity, so the app cannot act as you from that moment — a session token already on a device stops resolving to anyone.
What is erased
- your Recovery Focus, its commitment phrase, and your vulnerability windows;
- your Recovery Plan;
- your check-ins and the events behind your day count;
- your private Journal entries, including their notes and trigger notes;
- your anonymous name, your light, and the country you answered for;
- Personal Circle invitations and memberships involving you, including the display names stored with them;
- Personal Circle mute records that name your account, in both directions — mutes you set and mutes set against you;
- the WITHSTAND backend’s current Plus and Supporter entitlement snapshot and its latest verification details;
- the push token of every device you registered. The device record itself is kept, invalidated and emptied of anything that could reach you, because the history of a device being invalidated is part of the abuse-prevention record below;
- your record of accepting the peer guide and the policies;
- the token your device used for its private channel, and the counters behind rate limits;
- the link between you and any product-measurement events: the pseudonymous key is replaced, so past events can no longer be traced back to you;
- the copy of your plan and everything else the app had cached on your device.
What is kept, and why
A small set of safety records outlives the account: reports you filed, reports filed about you, blocks and the matching exclusions that come from them, safety actions taken on the account, and the audit record of the deletion itself.
Some ordinary records outlive it too, and it would be dishonest to leave them out:
- the record of sessions you took part in — when they happened, how they ended, and which fixed signals were exchanged — with your light removed from your side of them, because a session is also the other member’s history;
- requests, queue entries and offers that the retention schedule has not swept yet, and a request that produced a session for as long as that session is kept. The privacy page gives the schedule;
- the count of how often you and another member were matched, which is what makes a peer familiar. It names neither of you, and removing it would take the other member’s side of it as well;
- the language you used and the date the account was created, on the record itself. They describe an account, not a person.
All of it stays attached to a record that no longer identifies anyone. It holds no sign-in identity, no email address, no anonymous name, no Circle display name, no light, no country, no Focus, no Journal, and no plan.
Separately, Apple and RevenueCat may retain App Store purchase and transaction records under their own legal and operational obligations. Those records are outside the WITHSTAND account database deletion.
There are two reasons, and both are about someone else’s safety:
- deleting an account must not be a way to erase evidence of harm and come back with a fresh one;
- a block another member placed for their own protection has to keep working after you leave.
Nothing in those records describes your recovery. A reviewer sees report and session metadata, never a Recovery Plan or a check-in — the safety page lists exactly what they see.
Timing
Your access ends as soon as the request completes: the account stops answering to your sign-in in the same instant everything above happens.
Removing the sign-in identity itself is the one step that finishes outside that moment. If it fails, your access stays revoked — nothing re-enables the account, and there is no step that could — and the remaining step is completed when the service is restored, within 30 days (usually the same day).
Subscriptions
Deleting your WITHSTAND account does not cancel a subscription. Plus and Supporter are App Store subscriptions, and only the App Store can cancel them — Apple gives no one else, including us, the ability to do it on your behalf. If you want both, cancel first and then delete; deletion is never conditional on cancelling, so the order is yours to choose.
You can reach the cancellation screen from inside the app at 設定 → メンバーシップ → Manage subscription, or from Settings on your device. Cancelling stops the renewal; the time you have already paid for runs to the end of its period.
Nothing you can cancel or fail to cancel affects safety. Asking for help, and being there for someone, are free and always will be.
If you cannot get into the app
Write to asterworks3322@gmail.com from the email address you sign in with, or from the Apple relay address if you hid your own. Say that you want your account deleted.
That address is the only way an account can be identified. Because members are anonymous, an account cannot be found from an anonymous name, and an account that cannot be connected to a sign-in identity cannot be deleted on request.
Starting again later
You can sign up again with a different email address straight away. With the same address, you can sign up again once the sign-in identity has finished being removed.
A new account starts empty and carries nothing from the deleted one. Nothing means nothing: not your day count, not your Plan, not the peers you had met before — and not the reports or blocks that concerned the old account either, because the record they stay attached to is not connected to any sign-in identity.
That is the honest cost of being anonymous here. Members are not identified across accounts, so protection works at the level of a session rather than a person: anyone can block or report the account they are actually with, at any point, and that decision takes effect immediately.