ForagePal

Your data

Delete your account

You can delete your ForagePal account at any time. The in-app control immediately removes the active account stores it covers, with no undo. If you have already uninstalled the app, email us to start a manual erasure request. The exact scope and current limits are below.

Request deletion by email

privacy@foragepal.com

No mail app? Copy this address: privacy@foragepal.com — subject “ForagePal account deletion request”.

In the app

If you still have ForagePal installed, use its own deletion control. After you confirm, the app pauses observation sync, deletes every private S3 photo-object version and delete marker for your account, then hard-deletes the active database account and its cascading rows, clears the covered subject-scoped device data, and deletes the Cognito sign-in. There is no 30-day undo period and the covered deletion cannot be reversed.

  1. Open ForagePal on your phone.
  2. Go to Settings.
  3. Choose "Delete account" and confirm.

If the server outcome cannot be confirmed, the app keeps sync paused and retries rather than risk restoring erased rows. If you cannot use the control, use the email route below.

If you have already uninstalled the app

You do not need to reinstall anything and you do not need to sign in. Email privacy@foragepal.com to start a manual erasure request. This route is deliberately available without an app session; it is not presented as an instant automated deletion.

So that we can match the request to the right account, please include:

  • The email address you used to sign up — this is what we match on, so send your request from that address where you can.
  • A line saying you want your ForagePal account and its data deleted.

Please do not send us passwords, payment-card details, or anything else we did not ask for. We will never ask you for a password. If you only want part of your data removed — for example every private photo-object version or one observation — you do not have to close your account: email the same address and tell us what you want deleted.

What the automatic route deletes

After a confirmed in-app deletion, the implemented automatic route removes:

  • Every current and older version and delete marker for each private S3 photo-object key, before the active database account and Cognito identity are deleted.
  • The active Postgres account row and its cascading observations, consent records and database entitlement rows.
  • The device SQLite observations, sync cursor, both raw legacy-import backups and local consent, agreement and privacy caches, together with the subject-scoped home county or region, onboarding state and other covered device caches.
  • Saved observation-photo bytes in the device photo store.
  • Find coordinates held in those active database and device observations, including any exact coordinates you consented to store.
  • The separate DynamoDB subscription/access mirror row for your account, and your identification and map-lookup counter rows, in the same request as the database account. Anything the request could not remove is named in the receipt it returns.
  • The Cognito authentication identity, after the server receipt is confirmed.

Pseudonymised usage totals, RevenueCat records and store-controlled purchase records remain outside the automatic transaction, as listed below.

Deleting your account does not cancel your subscription

Your ForagePal subscription is bought from, and billed by, the App Store or Google Play — not by us. Deleting your account does not cancel it and does not stop it renewing. You have to cancel it yourself, in the store account that pays for it.

  • On iPhone or iPad: open Settings, tap your name, tap Subscriptions, choose ForagePal, then Cancel Subscription — or go to apps.apple.com/account/subscriptions.
  • On Android: open the Play Store, tap your profile picture, then Payments and subscriptions, then Subscriptions, choose ForagePal and cancel — or go to play.google.com/store/account/subscriptions.

Because the store is the merchant, cancellations and refunds are handled there, not by us. Cancel before you delete your account if you can — it is the same store account either way.

What is outside automatic deletion

The following stores do not simply vanish when the in-app database transaction succeeds. We state each boundary so an active-account deletion is not mistaken for complete erasure from every system.

  • Daily usage totals used to monitor cost are stored under a pseudonym rather than against your account, and the automatic route does not delete them today. They carry no coordinates, photos or account details and expire on their own retention window. Email us if you want them removed and we will handle it manually.
  • Service-wide rate-limit and circuit-breaker counters are not held against any account and are not affected by deleting one. Your own identification and map-lookup counters are deleted with your account, as listed above.
  • RevenueCat records are not deleted by the current route. App Store and Google Play account, payment and purchase records are controlled by those stores under their own policies; we cannot erase an independent store record on their behalf.
  • Encrypted RDS backups age out on a seven-day rolling window and AWS CloudWatch operational logs on a 14-day retention setting. They are not an undo copy available to restore your account.

Email privacy@foragepal.com to request manual erasure of records Echofold controls. For store-account or purchase-history rights, use the privacy controls provided by the App Store or Google Play. Any backup restore must replay account erasures and coordinate re-coarsening before user traffic resumes.

How long it takes

A confirmed in-app deletion hard-deletes the covered active stores immediately. It has no undo period. If the request outcome is ambiguous, the app does not report completion; it keeps sync paused and retries the idempotent server route.

We respond to deletion requests within one month of receiving them. For a complex request we may extend that by up to two further months — three in total — and we will tell you if we need to, and why. This is the response time GDPR sets for rights requests.

The seven-day backup window, 14-day operational-log setting and usage-total time-to-live described above are age-out periods for copies outside the active database. They do not delay or reverse the immediate active-store deletion.