Account & Data Deletion — Re:Fill
Last updated: 2026-09-24
This page explains how to delete your Re:Fill account and the data linked to it.
Re:Fill is operated by Jansevt Labs.
Note: Most of your data stays on your device and never reaches an account. You have a cloud account when you connect your Apple or Google account in Re:Fill. The steps below delete that account and its cloud data.
Option 1 — Delete inside the app (fastest)
- Open Re:Fill.
- Go to Settings → Account.
- Tap Delete Account and confirm.
This starts the live account-deletion sequence and signs you out after it succeeds. A failed step may require a retry; it does not undo records already deleted. It does not make every provider recovery copy or log disappear instantly; the limits and fixed expiry windows are explained below.
On iOS, a temporary account-linked protection record can let your deletion request continue if an Apple connection-revocation notification arrives first and restrict other requests from recreating account records during deletion. It holds identifiers and limited authentication/protection times, not medication or backup contents. The limited permission to continue deletion lasts 2 hours from the setting or renewal of that deletion-request protection; an Apple account-change notification does not itself extend it. Record retention is separate: a protection-only record becomes eligible for asynchronous TTL deletion at that two-hour boundary, while an Apple access restriction or unresolved permanent-deletion safeguard follows the account-security criteria below. Waiting for record deletion does not keep expired permission valid. Firestore recovery copies follow the separate periods below. This protection does not introduce an extra consent screen.
Option 2 — Request by email
If you cannot use the app, email support@jansevtlabs.com from (or naming) the address you signed in with, using the subject “Delete my account.” We verify the request and then delete your account and cloud data.
Withdrawing Sign in with Apple and deleting the Apple Account
We verify the source and contents of Apple's account-change notifications before handling them as follows.
- Withdrawal of Sign in with Apple for Re:Fill: we restrict access using Apple sign-ins at or before that withdrawal. This alone does not delete your Re:Fill account, cloud backups or purchase entitlement. A later, newly authenticated Apple sign-in and a sign-in through another provider are treated separately. To erase cloud data, use account deletion or an email request.
- Request for permanent deletion of the Apple Account itself: we check the notification and associated Re:Fill account. Where there is no other linked sign-in provider and the account state can be safely confirmed, we restrict access and remove cloud backups, legacy account-linked entitlement/purchase-link records and the Re:Fill cloud account. A newer sign-in or account, another provider, an ongoing deletion or other uncertain state requires review rather than automatic deletion. Failure to find an account mapping is not proof that all earlier data has been erased.
- Change to Hide My Email forwarding only: we do not delete the account or backups. This route does not send automated email to you or create a new email-preference list.
Notification delivery and processing may be delayed. Do not rely on Apple Account deletion alone for immediate Re:Fill erasure; use in-app deletion or the email-request route when you need to request deletion directly. This server processing does not delete on-device data or cancel the store purchase itself. Purchase recovery after permanent deletion of the Apple Account depends on Apple's rules and is not guaranteed by Re:Fill.
Use methods 1 or 2 above to request deletion directly.
Purchasing and restoring “Remove Ads” do not require a Re:Fill account. Account deletion removes legacy cloud purchase records linked to that account; it does not erase the device's current verified store entitlement. Restore on the same store using the store account that owns the purchase (or eligible Apple Family Sharing). Re:Fill accounts and medication backups do not share purchases between Apple and Google. Older app versions may still create account-linked purchase records, which follow the retention rules below.
What gets deleted
- Your sign‑in record — the email and display name held by Firebase Authentication.
- Your cloud backups, including earlier versions. We request deletion of every generation. Google Cloud Storage keeps each deleted object recoverable by us for 7 days under Soft Delete; after that window, we can no longer recover it through Cloud Storage. Google then completes deletion from its systems under the provider timeline described below.
- Your legacy account-linked “Remove Ads” entitlement record — the cloud record of the purchase.
- The legacy link between your account and our purchase records. Records for purchases that were not refunded are deleted outright; see below for the one exception.
After Firebase Authentication reports an individual account deletion, the server re‑checks that account's backup folder and requests deletion of all remaining generations, including earlier versions, only after confirming the account is absent. If a backup or its metadata file finishes uploading later, a separate check requests deletion of only that exact file version if the account is absent. An existing account found by either check is preserved, including a disabled or recreated one; a failed check does not permit deletion. These cleanup routes do not read the file contents or bypass unresolved Apple account-deletion safeguards. Event delivery or processing can fail or be delayed. Retry windows are up to 7 days for account-deletion events and 24 hours for upload-completion events; unresolved cases require operational follow-up. These are retry limits, not waiting periods before deletion or guaranteed deletion deadlines. They do not replay all old account deletions or uploads, or change the recovery-copy periods below.
What this does not affect
- Data on your device. Information stored only on your phone is not part of your account. Remove it by deleting entries in the app or by uninstalling the app — we cannot delete on‑device data remotely.
- Your purchase. The “Remove Ads” purchase is held by Apple or Google, not by us. Deleting your account does not cancel or refund it, and you can restore it later. For purchase or refund help, contact the App Store or Google Play.
- A record of a refunded purchase. Account deletion removes your account identifier, raw store purchase identifier and ownership type from a refunded/revoked purchase claim. The remaining hash key, store/product, refund status and limited timestamps are pseudonymous, not guaranteed anonymous, and become eligible for automatic deletion 180 days after the account link is removed during deletion. Later notifications do not restore raw identifiers or extend that expiry. A minimal notification record without an account-linked claim retains its valid expiry; if none exists, we set one no later than 180 days from its authenticated event time, using an earlier recorded time where available. TTL deletion is asynchronous, typically within 24 hours after eligibility. Older app versions can link a valid purchase again through purchase restoration; a notification alone does not recreate your account. See Privacy Policy, Section 10.
- Account-security/deletion-processing records. Unresolved Apple account-change work keeps limited necessary identifiers, state, times and review information until resolved, subject to review of continued necessity. After resolution, direct account-linking fields are removed and a minimal duplicate-prevention receipt becomes eligible for automatic deletion 31 days after completion; it is not guaranteed anonymous. An ordinary Apple access restriction remains while the Re:Fill account exists and becomes eligible two hours after its absence is confirmed. Unresolved permanent-deletion protection remains even if the account is gone, and becomes eligible two hours after cleanup completion is confirmed. The limited permission to continue an in-app deletion request instead follows the two-hour rule under Option 1; it is not extended by these retention periods. A scan position can contain an account identifier until the full pass finishes and resets it; an interruption can prolong retention and requires review. TTL deletion is asynchronous, typically within 24 hours after eligibility, and does not erase recovery copies or logs immediately. See Privacy Policy Section 10.
- Firestore recovery copies. Point-in-time recovery may retain earlier account, purchase, feedback and temporary processing records for up to 7 days; daily managed backups retain snapshots for up to 28 days from creation. These periods are separate from live-record retention, so copies can remain after a live record is deleted. Individual records cannot be selectively edited in these copies, which expire automatically. Before restored data is used, subsequent deletions, expiries and revocations must be applied and checked. Affected records are not returned to service if that cannot be verified.
- Operational and security logs. Technical server logs may include your account identifier and are not designed to contain your medication database. Our ordinary operational/security log retention is 180 days for security, fraud prevention and refund, billing or deletion disputes. Google-required administrative audit logs have a separate, provider-fixed 400-day retention period. The logs expire on their respective schedules, not as a selective part of live-account deletion. Any legal exception to an erasure request must be assessed for that request; the log schedule is not a blanket exception.
- Feedback you sent. Feedback carries no dedicated account, email or user‑identifier field, so deleting the cloud account cannot automatically find it. That does not make it anonymous — what you wrote, or the diagnostic details sent with it, could still identify you. The Firestore record and its body-free email notification have a 365-day retention period after receipt, or less if their purpose ends earlier; automatic deletion is asynchronous as described in the Privacy Policy. To have a particular submission removed sooner, email us with its approximate time and text; we will locate and delete matching Firestore records, associated notifications and any existing content-bearing email copies on a best‑effort basis.
- Support correspondence. Your emails to us and our replies are not erased with the cloud account. Routine correspondence has a 365-day retention period after the final response and is then permanently deleted by the next scheduled application of the Workspace rule; the scheduled deletion might not occur at the exact moment the period ends. A documented record of an actual consumer complaint or dispute may be kept for 3 years, and an applicable electronic-commerce contract, withdrawal, payment or supply record for 5 years. Separately, an important business document covered by the Korean Commercial Act is kept for 10 years from its creation, and a voucher or similar document for 5 years from its creation. Another specific legal duty or claim receives its own recorded end date. These exceptions apply only when the correspondence actually falls within that record category.
How long it takes
For Apple permanent-account deletion, we remove existing cloud data and the account after safety checks, then check for late uploads against an eight-day boundary measured from confirmed revocation of sign-in credentials. Completion requires a new check started at or after that boundary confirming no residual data. Existing backups are not kept for eight days before deletion. Delays, failures or uncertain account states can postpone confirmation. Necessary processing records remain during that work, not a separate copy of medication contents. This eight-day check is not applied universally to ordinary in-app account deletion.
We act on deletion requests without undue delay, verify identity only as necessary, and notify you of the result or the reason for any lawful limitation within the period required by applicable law. We promptly remove or request deletion of live records in the account-deletion sequence. The separate retention and provider-deletion periods below are not waiting periods for handling your request. The provider‑held copies described above — the 7‑day Soft Delete window, the 7‑ and 28‑day Firestore recovery copies, and the 180-day ordinary logs and released-refund records, and the 400-day provider-required administrative audit logs — then become unavailable on their own schedules. When Google‑hosted Customer Data can no longer be recovered by us, the current Google Cloud Data Processing Addendum requires Google to delete it from its systems as soon as reasonably practicable and within a maximum of 180 days, unless applicable law requires storage. A product recovery deadline is therefore not a promise that every physical provider copy is erased on that same day.
Contact
Email: support@jansevtlabs.com