Four separate controls in Tildi could each be called “delete my data”, and they do very different amounts. Only one of them is permanent, so this starts by working out which one you actually want.
01
First
Four things that all sound like deleting
These do very different amounts, and only the last one cannot be undone. Find yours here before you go any further.
Signing out: clears this browser. Your account and everything on it stays.
Making this browser forget: clears the local draft and preferences. Saved and your account are untouched.
Clearing Saved: deletes the versions you kept, on every device. The account remains.
Deleting your account: removes the active account and ordinary product data. Permanent.
02
Before the permanent one
Take a copy with you
Your account page can hand you a copy of your active Tildi data. If there is any chance you will want something back, do this before deleting: the deleted account and product data cannot be restored.
Export from your account page in the web room.
Saved entries are the part people miss most.
Deleting is not reversible, and support cannot restore an account.
03
Just the words
Removing what you kept, without leaving
If what you actually want is for a particular message to stop existing, that is a Saved deletion and not an account one. It takes effect on every device you are signed in on, immediately.
Delete one entry, or clear everything at once.
Both remove it from all your devices, not just this one.
There is no undo on either.
04
The permanent one
Deleting your account
This removes the active account and ordinary product data attached to it. Tildi asks you to type DELETE first, which is deliberate friction on the one action in the product that cannot be taken back.
Type DELETE to confirm. Nothing happens until you do.
Deleting is not the same as signing out: signing out leaves everything in place.
Saved entries, people, and your voice profile all go.
An indefinite, minimal security tombstone keeps only an opaque account identifier and limited cleanup metadata so old credentials cannot recreate the account.
Identity Platform, Stripe cleanup, and the two-pass PostHog provider-erasure workflow may continue asynchronously after local deletion. PostHog erasure is queued automatically, but it is not complete until the provider confirms it.
Backups remain until the applicable rolling backup expires or is deleted. Records required for billing, accounting, fraud prevention, disputes, or law may remain for their applicable retention period.
Anything held only on your own device goes when you clear it or uninstall.
05
The other route
If you cannot get into the account
Deletion normally happens from inside the room, which needs you to be signed in. When that is not possible, there is a route on the site that does not require it.
Use the delete-your-data page and follow what it asks for.
Or write to privacy@tildi.app from the address on the account.
Ask from the account’s own email address: it is how a request is confirmed as yours.