Account deletion

Delete your Aura account.

It takes about thirty seconds, it is permanent, and there is no cooling-off period or recovery window. Read the second half of this page first — two things deliberately survive deletion, and you should not find that out afterwards.

Applies to: the Aura Android app, the desktop apps, and the hosted web app · Last updated: 30 September 2026

Before you delete: take your data with you

Deletion is irreversible, and because Aura never held your keys there is nobody who can restore your account afterwards — not you, not us. If there is anything in your messages, notes, calls or Vault you might want later, export it first.

On Android: Settings → Export my data. That produces one JSON file containing everything on your device plus everything the server holds about your identity. Save it somewhere before you continue. Full detail is in the privacy policy.

In the Android app — the direct route

  1. Open Aura and go to Settings.
  2. Scroll to the security and privacy section and tap Delete my account.
  3. Read the confirmation screen, then type the confirmation phrase exactly as shown. This step exists so the action cannot be taken by a mis-tap.
  4. Re-enter your passphrase, and your second factor if you have one enabled.
  5. Confirm. The account is deleted server-side immediately, and the app wipes its local data from that device as part of the same action.

There is no undo and no grace period. The moment this completes, the identity is gone and cannot be recreated — a new signup is a new identity, with new keys, that nobody who knew the old one will recognise.

Other devices signed in to the same account lose access as soon as the identity is removed: their credentials stop authenticating. Any plaintext already downloaded and sitting on those devices is not remotely erasable; delete the app on each of them yourself.

On web and desktop

There is no delete control in the web or desktop interface today. We are not going to hide that behind a vague instruction to "check your settings" — it is not there.

If you have an Android device signed in to the same account, use the steps above; deletion is server-side and covers the whole identity, whichever device initiates it. If you do not, use the request route below.

Signing out of the hosted web app, or using its "forget this device" control, removes the local session only. It does not delete your account.

Requesting deletion without the app

If you no longer have Aura installed, or no longer have a device that can sign in, send a deletion request to:

[email protected] (subject: "Account deletion request")

Because Aura holds no email address or phone number for you, a request from outside the app is one we cannot straightforwardly tie to an account. Tell us your display name and the approximate date you created the account, and expect us to ask something only the account holder would know. We will not delete an account on an unverifiable request — that would itself be an attack. Where we cannot establish that a request is genuine, we will say so rather than act on it.

We aim to acknowledge requests within 7 days and to complete or refuse them within 30 days, which is the statutory period under the GDPR.

What deletion removes

  • Your identity record and display name.
  • Every device registered to the account, and their authorisations.
  • Every Reach Contract you granted or were granted, and their usage records.
  • Your relationships and pending connection requests, in both directions.
  • Your key packages.
  • Your mailbox and every message waiting in it.
  • Your membership of every conversation. A conversation left with no members at all is removed entirely.
  • Any moderation appeals you had filed.
  • Your public directory listing (display name and handle), if you had opted into public discovery — it stops being findable immediately.
  • Any business you owned's public cover/gallery images and public service-catalog listings.
  • On the device you delete from: the local app data, including cached messages, is wiped.

What survives deletion

Two things, both deliberate:

1. Audit log entries, not anonymised

The server keeps its hash-linked record of security-relevant actions on the account — device authorisations and revocations, recovery attempts, moderation decisions, and the deletion itself. These entries are retained after deletion and are not stripped of the identifiers in them. They record that an action happened, by which device, and when. They contain no message content.

The reason is that this log is the only thing that can later answer "was this account actually deleted?" or "who revoked that device?". A record that erases itself on request is not an audit record. If you think an entry about you should nonetheless be removed, raise it through the support page — we will weigh it rather than refuse by default.

2. Encrypted messages you sent to other people

Messages you sent were sealed separately to each recipient and placed in their mailboxes. Deleting your account does not reach into other people's mailboxes to remove them. To us they are opaque ciphertext; to the recipient they are their own correspondence. They age out under the ordinary retention rules once collected — 30 days after the recipient's device acknowledges them.

The same is true of anything already delivered to and stored on someone else's device. No messaging system can recall that, and we will not imply otherwise.

How long it takes

Deletion initiated in the app is applied immediately and synchronously — there is no queue and no delayed job. By the time the confirmation returns, the identity and everything listed above is gone from the server's live state.

Encrypted backups of the server database, taken for disaster recovery, may still contain a copy for as long as that backup is retained. Backups are not queryable and are not used to restore individual accounts; they age out on their own rotation.

A deletion requested through the channel above, rather than performed in the app, follows the acknowledgement and completion targets given in that section.