Orlivas — Account & Data Deletion
Version 1.0.0 · Effective 2026-07-11 · Last updated 2026-07-11
This page explains how to delete your Orlivas account and data, exactly what is deleted,
what happens to your family and to any managed profiles, and what we may keep and why.
It is reachable without logging in at https://orlivas.com/legal/account-deletion.
1. Delete your account
In the app (recommended): open Settings → Account → Delete account, then confirm
with your password. This calls our authenticated deletion endpoint.
By web request (no login needed to ask): if you cannot use the app, email
privacy@orlivas.com from the address on your account (or use the form at
https://orlivas.com/legal/account-deletion) and ask us to close your account. We will
verify you control the account before acting.
Deletion is permanent and requires password confirmation for in-app requests.
2. Export first (optional)
Before deleting, you can download a machine-readable copy of your account data
(Settings → Privacy → Download my data, or GET /api/users/me/export).
3. What happens when you close your account
Closure runs as a single, all-or-nothing operation; physical files are removed only after
the database changes are safely committed.
3.1 Your identity
- Your email is replaced with an unusable value (
deleted+<id>@orlivas.invalid), your
name becomes "Deleted User", your phone and avatar are cleared, and your account is
marked deleted.
- All sessions/refresh tokens are revoked; push device tokens and notification
preferences are deleted.
3.2 Your personal (non-family) data — always hard-deleted
- Private medication reminders not linked to a family member (and their photos),
- privately uploaded files,
- your notification inbox,
- your usage-analytics trail,
- OCR text extracted from those private images.
3.3 Your families and managed profiles — depends on whether other caregivers remain
Orlivas health data belongs to the family group, not to a single login, so what
happens to a family depends on who else controls it:
- **You are the last remaining account holder of a family → the entire family is
permanently erased. Every member profile (including managed profiles** for
children, elders and dependents), every health record (medications, vitals, hydration,
mood/sleep/wellness, symptoms, appointments, documents, journals, wellness photos),
all files (records and physical blobs), OCR jobs, AI insights and AI execution
logs, alerts, family notifications and the family's audit trail are hard-deleted.
Rationale: with no account holder left, no data controller remains, and keeping
special-category health data would be unlawful.
- **Another active caregiver remains → the family and its managed profiles are kept for
them.** Only your membership is removed; you lose access. The records you contributed
stay with the family. To have specific member data removed, ask a remaining Owner or
Admin, or contact us.
4. What we may retain, and why
- A minimal security audit record that an account was closed (no health data) — kept
up to 12 months for security and abuse prevention.
- Billing ledger entries (plan grants/revocations, no health data) — kept as
required by tax/commercial law.
- Encrypted database backups roll off automatically within 14 days; deleted data
disappears from all backups within that window. Backups are used only for
whole-database disaster recovery.
5. Processors
- RevenueCat (if you had a subscription): we forward a customer-deletion request so
your purchase record is removed on their side.
- Push (FCM/APNs): your device tokens are deleted with the account.
6. Timing
In-app closure takes effect immediately. Web/email requests are actioned promptly after
we verify your control of the account, within the period your law requires (generally 30
days). Removal from backups completes within 14 days.
7. Contact
Deletion help and privacy requests: privacy@orlivas.com
General support: support@orlivas.com