1. What this page is
This page tells you how to have your data deleted from STACKD, and exactly what happens when you ask. There are two routes: delete it yourself inside the app, or email us. Both are set out below, in full, with no form to buy and no support ticket to chase.
It applies to you if any of the following is true:
- you have, or used to have, a STACKD account;
- you were invited to a STACKD workspace, whether or not you accepted;
- you connected a Facebook Page, Instagram account, LinkedIn, X or TikTok account to STACKD, or authorised STACKD to use a Google or Microsoft mailbox;
- you joined the STACKD early-access waitlist;
- you are a journalist or other contact whose details are held in STACKD, and you want them removed.
If you connected a Facebook Page or Instagram account to STACKD and never had a STACKD login of your own, go straight to section 3 and email us. We will find the connection from the Page or account name and delete the data held against it.
STACKD is operated by STACKD, Dubai, United Arab Emirates. What we hold and why is described in our Privacy Policy.
2. Delete your data in the app
This is the fastest route and it takes effect immediately.
- Log in to STACKD.
- Open Settings.
- Choose Delete my data.
- Confirm with your password.
Your account is anonymised the moment you confirm. You are signed out, and the login you just used stops working. There is no grace period and no undo, so be sure before you confirm. Section 5 lists precisely what is removed.
Closing a whole workspace
If you are the owner of a workspace, you can also close the entire workspace rather than just your own account. In Workspace Settings, type the workspace name to confirm you mean it, then confirm with your password. This removes the workspace and its members, not only you. Do not use it if colleagues still rely on the workspace.
3. Request deletion by email
If you cannot log in, or you never had a login, email us instead.
- Send to: hello@stackd.bot
- Subject: Data deletion request
- Send from: the email address registered with STACKD, if you have one.
- Include: the name of the workspace your data belongs to.
If you email from a different address than the one registered with us, expect us to verify your identity before we act. That is a protection for you: it stops anyone else deleting your data by asking nicely.
If you came through Facebook or Instagram and never had a STACKD login
Tell us, in the email:
- which Facebook Page or Instagram account was connected to STACKD, by name or handle;
- which business or organisation connected it, if you know;
- the email address you want us to reply to.
We will locate the connection, delete the stored credentials and any data held against that connection, and confirm in writing when it is done. You do not need a STACKD account to make this request and we will not ask you to create one.
4. Disconnecting a social or mailbox account
Deleting data and revoking access are two different things, and it is worth doing both. You can cut STACKD access from the platform side at any time:
- Facebook and Instagram. In Facebook, go to Settings and privacy, then Settings, then Business integrations. Find STACKD and choose Remove.
- Google, including Gmail and Search Console. Go to your Google Account, then Security, then Third-party apps and services, or Data and privacy, then Third-party access. Select STACKD and choose Remove access.
- Microsoft and Outlook. Sign in to your Microsoft account, open the apps and services permissions page, find STACKD and revoke it.
- LinkedIn, X and TikTok. Each has a connected apps or permissions screen in account settings. Remove STACKD there.
Doing this stops STACKD from using the connection immediately. Separately, when a connection is removed inside STACKD, or when your account is deleted, we delete the stored credentials for that connection. Tokens are not kept "just in case".
Revoking access at the platform is not the same as deleting your STACKD data. If you want both, revoke access and then follow section 2 or section 3.
5. What actually happens when you ask
A deletion request is carried out by anonymising you: every identifier that links a record to you is destroyed or replaced, permanently. Specifically:
- your name is replaced with "Deleted user";
- your email address is replaced with an anonymised address that cannot receive mail and cannot be used to log in;
- your password is reset to an unusable value that no one can authenticate with;
- your two-factor secret and recovery codes are destroyed;
- your passkeys are deleted;
- all your login sessions are ended, on every device;
- any outstanding password-reset tokens are invalidated;
- your connected mailboxes and social connections are deleted, along with the stored credentials for each;
- the free-text profile of your workspace, including the business description, vision, mission and onboarding context, is cleared;
- any pending team invitations you sent or received are deleted;
- task attachments are deleted from storage.
Two consequences you should be clear about before you confirm:
- Your login stops working immediately. Not at the end of the month, not after a cooling-off period. Immediately.
- It cannot be undone. Anonymisation is irreversible. We cannot restore your name or your email address afterwards, because we no longer hold them. If you come back later, you start a new account from scratch.
6. What is kept, and why
Some business records survive anonymisation. They are kept because UK company and tax law requires seven years of records, and that obligation does not disappear because someone asks us to delete their account. What survives is:
- invoices and billing records;
- credit transactions;
- records that a pitch was sent, and to whom it was sent;
- content that was already published;
- approval and legal-review records for work that went out.
The important part: after anonymisation these records hold no personal identifiers for you. They are financial and operational facts, with the link back to the individual removed. Nobody can read an old invoice and learn your name or your email address.
Suppressed-email records are also kept, deliberately and indefinitely. They exist so that we never contact an address that has opted out. Deleting the suppression record would undo the opt-out, which is the opposite of what anyone asking for it wants.
7. How long it takes
- In-app deletion: immediate. The moment you confirm with your password, the anonymisation runs and your session ends.
- Email requests: within 30 days. That is the legal maximum and it is not our normal pace. In practice these are handled in days, and we confirm in writing when it is done. If identity verification slows things down, we will say so.
- Backups: within 35 days. Encrypted database backups roll forward on a 35-day cycle, so a deleted or anonymised record has aged out of every backup within that window. Backups are never used to repopulate deleted data.
If a deletion request for any reason cannot be completed, we will tell you why and what we can do instead, within the same 30 days.
8. Journalists and other third parties
If you are a journalist and you have received a pitch from STACKD, or you believe your contact details are held in STACKD, you can have them removed. You do not need an account and you do not have to give a reason.
Email hello@stackd.bot from the address that was contacted, and say you want your contact record removed. We will:
- remove your record from the global STACKD journalist database;
- suppress your email address so no workspace on the platform can pitch you again;
- confirm in writing when it is done.
Suppression applies across the whole platform, not just to the customer who contacted you. If you would rather only correct your details, say so instead and we will update your publication, beat or preferred address.
The same route is open to anyone else whose personal data sits inside a customer workspace. Where the customer is the data controller we will pass your request to them, help them act on it, and tell you who they are. Our role and theirs is explained in the Privacy Policy.
9. Contact and escalation
For anything on this page, including a request you have already made and have not heard back on:
- Email: hello@stackd.bot
- Post: STACKD, Dubai, United Arab Emirates
If you are not happy with how we handled your request, tell us first and we will look at it again. You also have the right to complain to a data protection regulator: in the UK that is the Information Commissioner's Office at ico.org.uk; in the EEA it is the authority where you live or work; in the United Arab Emirates it is the UAE Data Office. Complaining to a regulator does not affect any other remedy available to you.
This page is governed by the laws of England and Wales. For the wider picture, read our Privacy Policy, our Cookie Policy and our Terms of Service, or return to the STACKD home page.