Legal · Document 04

Delete your H2H account

Updated 2026-09-05

This page explains how to permanently delete your H2H Protocol account and all associated data, both on your device and on our servers. Inside the app the control is called Delete profile & erase everything, because H2H has no sign-up accounts in the usual sense: what you delete is your device identity, your anonymous backend identity, and everything stored under them.

⚠ This action is permanent

Once you delete your account, your local chat history, attachments, identity, and all preferences are erased from your device. Your anonymous backend identity and any optional profile metadata are deleted from our servers. None of this can be recovered.

1. Delete from inside the app (recommended)

The fastest and most complete way to delete your account is from inside the H2H Protocol app:

Steps

  1. Open the H2H Protocol app on your device.
  2. Tap your profile icon (top-right of the radar screen).
  3. Scroll to the Danger Zone section at the bottom of the Profile page.
  4. Tap Delete profile & erase everything.
  5. Read the confirmation dialog carefully, then tap Delete.

The app will then:

  • Delete your optional profile metadata document and profile photo from our Firestore and Storage servers.
  • Purge any pending (offline-queue) messages addressed to or from you on the relay, and anonymise reports you filed so they can no longer be linked to you.
  • Delete your anonymous Firebase Authentication identity from our servers.
  • Erase your local chat history database and all message states.
  • Erase all chat attachments, voice recordings, and announcement-voice cache files from device storage.
  • Erase your device-bound cryptographic identity, Proximity preferences, and security material.
  • Sign you out of all backend services.
  • Run a postcondition audit and report whether anything remained. If anything fails to delete, the app surfaces an error so you can retry or contact us.

2. Request deletion by email (alternative)

If you cannot access the app — for example, you have already uninstalled it, lost the device, or the in-app deletion is failing — you can request deletion by email instead.

How to request

Send an email to privacy@h2hprotocol.com with:

  • Subject: "Account deletion request"
  • Body: a brief statement that you wish to delete your H2H account.
  • Optional: if you remember your six-character peer ID (visible in the app under Profile → Device & Identity), include it. This helps us locate any optional profile metadata associated with your account. Without it, we will still process the request based on identity-verification information you provide.

We aim to respond within 30 days of receiving a verifiable deletion request, in line with applicable data-protection law. If we cannot fulfil your request in that time, we will tell you why and provide an updated timeline.

3. What gets deleted

Whether you delete from inside the app or by email, the following data is removed:

  • Server-side: your anonymous backend identity (Firebase Auth account), your optional profile metadata document (Firestore users/{aid} — display name, photo, last-active timestamp) and profile photo, and any pending relay messages to or from you.
  • Device-side (in-app deletion only): chat history database, message states, blocked-peer records, attachments, voice recordings, announcement-voice cache, peer profile cache, selected keywords, Proximity on/off state, security keys, identity material, all app preferences.

4. What may persist briefly

For service operation, abuse prevention, and legal compliance, the following data may be retained for the periods documented in our Privacy Policy § 6.3:

  • SOS rooms you took part in, with the messages you posted in them, remain visible to the other members until the room's 90-day retention ends (Privacy Policy § 6.8). Write to privacy@h2hprotocol.com to ask for earlier removal.
  • City reach presence, Free Match codes, and match records until their normal expiry (presence within about an hour, matches within 24 hours); your notification registration within 60 days.
  • Pending relay messages addressed to you, if the server step could not run at the moment of deletion (up to 30 days); voice-clip report evidence (up to 90 days).
  • Push-notification delivery records (up to 30 days).
  • Crash reports and diagnostic logs (up to 90 days).
  • Server-side abuse-prevention records, if any (up to 6 months).
  • Operational backups of relay infrastructure (up to 30 days).
  • Audit and security records required by law (typically up to 7 years).

These records are not associated with your message content or your active identity after deletion — they exist as required by service operation and applicable law.

5. Data our servers never see in readable form

The following never reach our servers in readable form, so there is nothing of them to delete beyond what happens automatically:

  • Your private chat messages, voice notes, photos, and files. They are end-to-end encrypted between you and the other person; the relay holds only an encrypted copy for an offline recipient, for at most 30 days, and cannot read it.
  • Your Free Match words. They never leave your phone; after a mutual match they are sent end-to-end encrypted to that one person only.
  • Your Pulses content (encoded as a 1-byte index over BLE, not as plain text on the wire).
  • Your selected keywords and Free Match topics. They travel only as scrambled codes that change every day.

The exception is SOS. An SOS alert is a public call for help and an SOS room is a group conversation; their cloud copies, including photos, voice notes, and any exact location you chose to share, are stored in readable form so that members can catch up and reports can be acted on (Privacy Policy § 1.10), and are deleted on the schedule in § 6.8.

6. After deletion

You can reinstall H2H Protocol at any time. A new anonymous identity will be generated locally on first launch, and you will be treated as a new user. There is no link between your old and new identities — they are cryptographically distinct.

7. Questions

If anything on this page is unclear, or if you encounter problems with the deletion flow, please contact us at privacy@h2hprotocol.com. For general support, write to support@h2hprotocol.com.