Delete your OpaqueShare account
Last updated: 7 July 2026
You control your OpaqueShare account, and you can delete it entirely at any time. This page explains how, and what happens to your data when you do.
Self-serve deletion (from inside the app)
- Open the OpaqueShare app on your device.
- Tap the account menu → Settings → Delete my account.
-
Type the confirmation phrase (
ERASE MY ACCOUNT) and enter your password. - Tap Delete.
Deletion is processed immediately. You'll be signed out on every device, and your account will no longer be discoverable by other users.
If you can't access the app
If you've lost access (forgot your password, lost your device, etc.), email contact@zihne.com from the email address registered to your account and ask for account deletion. We'll verify the request and process it within 30 days, as required by UK and EU GDPR.
What gets deleted immediately
- Your email address
- Your handle (username)
- Your password hash
- Your two-factor authentication secret and recovery codes
- All active session and refresh tokens (sign-out on every device)
- Your registered push-notification tokens
- Any pending file transfers you sent that haven't been downloaded yet — the ciphertext is queued for immediate deletion from object storage
What's retained (pseudonymised)
A small amount of data remains after deletion but no longer identifies you personally:
- Your user ID (a UUID) — required because past transfers, moderation records, and admin audit-log entries reference it. On its own, this identifier reveals nothing about you.
- Your public cryptographic keys — required so recipients of files you sent in the past can still verify the signatures on those files. Public keys are inherently non-secret and don't identify you outside the OpaqueShare system.
- Moderation and admin audit-log entries — where we're required to retain them for legal, compliance, or legitimate investigative purposes. This retention is required by UK Data Protection Act 2018 Schedule 2 Part 1 (crime, taxation, etc.) and is proportionate.
- Billing records (subscription and purchase history without direct personal identifiers) — retained for 7 years to meet UK tax record-keeping requirements.
What we never had (and therefore never delete)
Because OpaqueShare is zero-knowledge by design, several categories of data never existed in a form we could delete:
- The plaintext content of your files — we stored ciphertext only, without the decryption keys.
- Your plaintext filenames and metadata — same: encrypted with per-transfer keys we don't have.
- Your payment details — Google Play handles payment; we only ever saw purchase tokens for verification.
Where your data is hosted
OpaqueShare account data and encrypted file objects are stored in European Union regions by default. Ciphertext may be cached by our storage provider (Cloudflare R2) across regions to accelerate downloads; since caches contain only ciphertext with no access to keys, this does not constitute a transfer of readable personal data.
Questions
Contact contact@zihne.com for anything related to account deletion or data access requests.
For a fuller picture of how we handle your data, see our Privacy Policy.
Developer: Zihne — OpaqueShare application.