Data Deletion Instructions
Last updated: July 20, 2026
Overview
This page explains how to request deletion of information associated with a Kanvify account. Plus Ultra Industries, LLC processes deletion requests through a combination of product controls, scheduled lifecycle jobs, and manual verification where needed. Deletion is not instantaneous, and some records must be retained for the reasons described below.
For a complete description of our data practices, see the Privacy Policy.
Delete Your Account in the Service
- Sign in to Kanvify.
- Open Settings, then Profile.
- Select Delete account.
- Use the verification code sent to your account email.
- Confirm the request.
If you are the sole owner of a shared account or workspace, transfer ownership before requesting deletion. After a verified request, account access and active sessions are disabled and the deletion request is queued. Completion can require automated and manual work across database, sandbox, storage, authentication, and integration systems.
Request Help by Email
If you cannot sign in or the in-product process does not complete, email privacy@plusultra.industries from the account email address. You may also contact support@plusultra.industries for product assistance. We will verify your identity and authority before acting and will respond within the period required by applicable law.
Do not email passwords, live API keys, provider keys, or other secrets.
Data Covered by a Deletion Request
Subject to shared-account ownership, technical completion, and the retention exceptions below, a deletion request covers:
- Your profile, authentication sessions, magic-link records, preferences, and notifications
- Accounts and workspaces you solely own, including associated sandbox records and configuration
- Sandbox filesystems processed through the sandbox destruction lifecycle
- Checkpoint records and corresponding backend snapshots
- Workspace-scoped LLM cache entries, aliases, provider credentials, and registry credentials
- User API keys, OAuth applications, grants, and tokens
- Service-process and network-policy configuration
- Activity records tied only to an account being deleted
Your membership in an account owned by someone else can be removed without deleting that account or its data. Records needed to preserve the other account’s security, billing, or activity history may instead be minimized or de-identified.
Information That May Remain
- Customer-provided LLM providers. If a request was sent using your Anthropic or OpenAI key, that provider may retain information under your provider agreement. Plus Ultra cannot delete data from your provider account.
- Third-party copies. Information you sent to another person or system may remain in that person’s or system’s possession.
- Shared workspaces. Content belonging to accounts or workspaces owned by other customers remains for those customers.
- Billing and tax records. We retain minimized, de-identified billing and transaction records for the period needed to satisfy tax, accounting, audit, and legal obligations.
- Security, dispute, and legal records. We may retain limited information needed to prevent fraud or abuse, establish or defend legal claims, comply with a legal hold, or meet other legal obligations.
- Backups. Deleted information may remain in restricted backups for no more than 30 days before aging out, unless a legal hold requires longer retention. Restored backups remain subject to the deletion process.
Feature Retention Before Account Deletion
- Checkpoint records and backend snapshots are pruned daily after the account-configured operational period, which defaults to 90 days.
- LLM response-cache entries expire at the workspace-configured time-to-live and are purged after expiry by a recurring sweep.
- Sessions are swept after 14 days idle or 30 days from creation, whichever occurs first.
- OAuth tokens are revoked on their scheduled lifecycle.
- Processed Stripe webhook payloads are swept after 30 days.
Timing and Confirmation
Verification disables access promptly, but end-to-end deletion may take longer and can require manual remediation. We do not promise completion within minutes. We process verified requests without undue delay and within applicable statutory deadlines. Backup copies age out within the 30-day maximum described above.
For status or confirmation, email privacy@plusultra.industries and include the account email and the approximate request date. Do not include secrets.
Contact
Privacy and deletion requests: privacy@plusultra.industries
Product assistance: support@plusultra.industries
Plus Ultra Industries, LLC accepts deletion requests by email only when the in-product process is unavailable or incomplete.