中文English日本語

Bullion Note

Delete Account

How to delete your account

Sign-in in Bullion Note is optional. Core holding records and valuation work without an account. A server-side account is created only if you choose Google or Apple sign-in.

In the app (recommended)
Open the app → bottom tab Profile → account card menu → Delete account → confirm. The current account is deactivated and signed-in devices are signed out.

Web / email request
If you cannot use the app, request deletion by email:
To: hi@incosmos.art
Suggested subject: Bullion Note Account Deletion Request
Please include the email used to sign in, the provider (Google or Apple), and any details that help us identify the account. We will process deletion requests within a reasonable time.

Data that is deleted

Account deletion removes server-side data associated with that account, including:
  • Account identifiers (email, display name, provider user ID)
  • Session records and the session cookie (bullionnote_session)
  • Device push tokens
  • Reminder / alert rules and alert events
  • Alert preferences (for example digest settings and quiet hours)
  • Provider credentials stored for the account, if any
Related security audit records are de-identified (user ID, network hashes, and metadata are cleared). An anonymous deletion event and an account deletion tombstone may be retained for security, abuse prevention, and data integrity.

Data that is kept or not auto-deleted

  • Local metal-ledger, life-ledger, and valuation data on your device are not deleted automatically when you delete the account. They stay in the app sandbox by default. To remove them, uninstall the app or clear app data in system settings.
  • Backup files you exported yourself (for example bullion-note-backup.json) remain under your control; account deletion does not recall exported files.
  • Information retained independently by Google or Apple is handled under those providers’ policies.

What optional sign-in stores

Only after you choose to sign in does the Cloudflare-hosted Worker / D1 store account-operation data: email, display name, provider user ID, sessions, and—if you enable reminders—device tokens, alert rules, and preferences. Without sign-in, core metal- and life-ledger features stay on-device; reminders can also run at device scope without a forced account binding. Optional sign-in is not cloud ledger sync.