Data Deletion
Last updated: May 15, 2026
You can delete your FlyBrand account and all associated data — both internal data and the data we received from connected providers (Meta / Facebook / Instagram, Google, Shopify, Mailchimp, Resend, and others).
Self-service deletion
- Sign in at dashboard.flybrand.app.
- Go to Settings → Account → Delete account.
- Confirm. We immediately revoke all provider OAuth tokens, mark your data for hard-deletion, and send a confirmation email.
Hard-deletion completes within 30 days. Backup copies are purged on rotation (max 90 days).
Disconnecting a single provider
If you only want to remove one connection (e.g. only Facebook): Dashboard → Brand → Connections → click the trash icon next to the provider. Token is revoked and provider-mirrored data is deleted within 30 days. Account stays open.
Email request
Don't have access to the dashboard? Email privacy@flybrand.app from the address tied to your account. Include "Data deletion request" in the subject. We confirm within 72 hours and complete deletion within 30 days.
Facebook / Meta data deletion callback
If you remove the FlyBrand app from your Facebook account, Facebook notifies us via the data deletion callback URL https://api-dev.flybrand.app/v1/meta/data-deletion-info. We delete your Meta-sourced data within 30 days and return a confirmation code Facebook can use to verify the deletion.
To remove the app directly from Facebook:
Facebook → Settings & Privacy → Settings → Apps and Websites → FlyBrand Pages → Remove.
What gets deleted
- Account profile, email, password, billing history.
- All connections, OAuth tokens, encrypted credentials, provider metadata (pages, accounts, properties).
- Mirrored provider data (posts, orders, customers, analytics snapshots).
- All drafts, briefs, generated content, scheduled jobs, audit logs (after legal retention).
What we keep (legal hold)
Tax invoices and minimal billing records are retained for the statutory period required by tax law (typically 7 years). Security audit logs are retained for 90 days. These contain no provider data and are not used for any purpose other than legal compliance.