DRAFT — this document has not yet been reviewed by counsel and contains unresolved placeholders. Do not publish it in this state.
Account and Data Deletion
Last updated: September 1, 2026 · rev 4
This page tells you how to delete everything each of our apps holds. It is the page App Store Connect points to for account deletion, and it is referenced by our Privacy Policy.
The one-paragraph answer
Each app has an anonymous device account — no email address, no password, no profile — and the delete in the app's own settings deletes it and everything it owns. It removes what the app keeps on your phone and the rows and files your account owns on our server, in one action, from a screen you can reach in seconds. It is not a request we process by hand and it is not a queue: the app is signed in as your account when it asks, so it is the deletion itself.
The order is server first, then phone. If the server refuses, nothing on the phone is touched and the app tells you so — an app that reported a deletion it had not performed is the failure this whole path exists to prevent.
One thing survives, and it holds nothing about you: the anonymous identity row itself — an empty account record with no email address, no name and no profile in it. Everything it owned is gone. We leave the row because removing it is a separate operation on the authentication system and there is no personal information in it to remove.
It cannot be undone, and we cannot recover anything afterwards. If you want to keep something, export it first.
What each app deletes, and where the button is
Parcel Rush
| Where | Settings → Delete everything (also shown as Delete account) |
| What goes | On our server: everything your anonymous account owns — progress, board results, coins and stars, streaks, daily-run results, fleet unlocks, album entries and the purchase record. On the phone: your save and progress, the yard, your coins and stars, your streak, your settings, and the app's local analytics bookkeeping. Also the queued cloud writes, so nothing can be pushed back up after the delete |
| Export first? | Nothing to export |
| What survives, and why | Your App Store purchase of Remove ads. It belongs to your Apple ID, not to us — tap Restore purchases to bring it back on any device signed in to that Apple ID. Also the empty anonymous identity row described above |
| Server-side data | Yes — your game progress, under an anonymous account created at first launch. The delete above removes it, server first: if the server refuses, nothing is deleted anywhere and the app says so |
Pack Perfect
| Where | Settings → Delete everything |
| What goes | On our server: everything your anonymous account owns — progress, board results, trips, album postcards, streaks, cosmetics and the purchase record. On the phone: your save, your album and its snapshot, your coins, your settings, your analytics choice, and the growth module's own local store. The outbox is cleared in between, so a queued write cannot re-create the rows the delete just removed |
| Export first? | Nothing to export |
| What survives, and why | Your App Store purchase of Pack Perfect Complete — Restore purchases brings it back. Also the empty anonymous identity row described above |
| Server-side data | Yes — your game progress, under an anonymous account created at first launch. The delete above removes it, server first; if the server refuses, the sheet says "Nothing was changed" and means it |
Before I Unpack
There are two deletes in this app and they are deliberately not the same one. Backup is off until you switch it on, so most people only ever need the first.
| Where — the phone | Settings → Delete everything on this phone |
| What goes | Every photograph, every voice note, every note, the address, the landlord's email, the meter readings, every record, the on-device diagnostics counters, and your settings |
| Where — the server | Settings → Backup → Delete the backup |
| What goes | Every photograph and voice note in our storage bucket, then every row your account owns — places, records, rooms, meters, key-set counts, inventory and compare pairs — then the account itself. The records on this phone are untouched, and the app says so before you confirm |
| If you never turned Backup on | There is nothing on our server to delete, because no account was ever created and the app never opened a connection |
| Export first? | Yes, if you want to keep the record. Export the PDF and save or send it before you delete |
| What survives, and why | Your App Store purchase — Restore purchases brings it back. Also the empty anonymous identity row described above |
| Never on our server in the first place | Your key codes, and the subject and body of the message you wrote to your landlord. They are excluded from the backup by the code that builds it, so there is nothing of theirs to delete |
| Analytics | Off unless you turned it on; if you did, see "Events already sent" below |
Milestone
| Where | Ajustes → Borrar mi cuenta |
| What goes | On our server, in this order: every photograph in the event's folders, then the event and everything hanging off it — the people and their names and phone numbers, the court and the padrinos, the sequence, decisions, rehearsals, day-of items, the thank-you list, and the money tables — then your membership row. On the phone: the whole plan, every photograph, the dates, the venue, your language and your analytics choice |
| How it is checked | The app reads the event back afterwards and refuses to call it deleted while a row is still there. A deletion reported from a response code is how an app tells somebody their data is gone while it is still there, and this one does not do that |
| Export first? | Yes. Ajustes → Exportar todo hands you the whole plan as a file on your device. Do this before deleting if the plan matters to you |
| What survives, and why | Your App Store purchase of the celebration pack — Restore purchases brings it back. Also the empty anonymous identity row described above |
| Server-side data | Yes — the owner's plan, under an anonymous account created at the first write to it. If nothing was ever mirrored, there is nothing on our server and the local wipe is the whole deletion |
Events already sent, if you turned analytics on
If analytics was on, our analytics provider holds a stream of counted events associated with a random identifier that app generated. It contains no name, no email address, no photograph, no note and no amount — but you can still have it deleted.
- Email support@get-creative.co with the subject "Privacy Rights Request" and say which app you used.
- We will tell you how to read that app's analytics identifier from its Settings screen, or ask you to send it if you already have it.
- With that identifier we will ask our analytics provider to delete the associated event stream, and confirm when it is done.
Without the identifier there is genuinely nothing for either of us to point at. We do not store a name, an email address or any account against which we could search — the anonymous account has no email address on it, so an email you send us cannot be matched to it, and we will not guess. We would rather say that plainly than describe a lookup we cannot perform. The route that does work is the one at the top of this page: the app is signed in as your account, so the delete in the app can do what a support ticket cannot.
The same route works for attribution data. See our Analytics and Advertising Partners page for each provider's own opt-out.
Refunds
We cannot refund an App Store purchase. Request a refund from Apple at https://reportaproblem.apple.com. If something in an app is broken, please email us first at support@get-creative.co — we would rather fix it.
Backups, and the one delay this page will not hide
We back our database up every night and keep the copies with two independent storage providers, so that a failure on our side does not lose your data. A backup taken before you deleted something still contains it until that backup ages out. That is true of every system that has backups at all, and it is why we say it here rather than leave it to be discovered: those copies are encrypted, used for disaster recovery and nothing else, and are never searched or read for any other purpose. [PLACEHOLDER — the backup retention window must be confirmed and stated here before publication.]
If our apps ever gain a sign-in
They do not have one today: the account is anonymous, it belongs to the phone, and there is no email address or password on it. If that ever changes — a sign-in, a shared plan, a membership — this page will change in the same release, and it will describe what that account holds and how to delete it.
Questions: support@get-creative.co
Change log
- September 1, 2026 · rev 4 — Hosting move only. This page is now published at https://legal.alc.fyi/legal/deletion.html — the address App Store Connect points at for account deletion — and every URL on it points at that host. Every deletion route, timing and caveat on this page is unchanged, and rights requests still go to support@get-creative.co.
- September 1, 2026 · rev 3 — Publisher rename only. Intentionally Creative (get-creative.co), rights requests to support@get-creative.co, page hosted under the studio's own domain (superseded at rev 4). Every deletion route, timing and caveat on this page is unchanged.
- September 1, 2026 · rev 2 — The backend now exists, so "there is no account to delete" is no longer true and has been replaced with what the in-app delete actually does: an anonymous device account per app, deleted server-first through a
delete_accountroutine, with the phone wiped only after the server confirms; Before I Unpack's two separate deletes (the phone, and Delete the backup) written out; Milestone's read-back check recorded; the surviving empty identity row stated plainly; and the honest delay that database backups introduce named rather than left to be discovered. - September 1, 2026 · rev 1 — First draft of the suite.