Contact Chitipay
Feature feedback, bug reports, partnerships — email us; we usually reply within 1–2 business days.
Email: realdoan.dev@gmail.com
Request account and data deletion
You can request account or data deletion from outside the app by emailing our support address; you do not need to reinstall or open the app. Sending the request from the email linked to your account helps us verify it.
If you are still signed in with an email-linked account, you can start the self-service flow at Profile → Delete account. The server deletes that account first, then the app removes data from the device. Legacy anonymous sessions do not use this server-deletion path.
To request deletion from outside the app, email realdoan.dev@gmail.com and state that you want to delete your Chitipay account. This is an intake channel; we verify ownership before processing the request.
Data handled during deletion
- For an email-linked account, the sign-in account is deleted from the authentication system.
- A group you own is deleted from the cloud when it has no other active, linked, non-deleted member. If another active linked member remains, ownership is transferred; shared expense history and member labels may remain for the other members but are no longer linked to your account.
- Invites you created and your push notification registrations are removed. Bank BIN, account number, and account name fields are scrubbed from remaining payment instructions; transfer content and transaction history may remain.
- Device data is removed after the server confirms deletion. If you only use a local account and never linked it, use Delete data on this device in the app. A legacy anonymous session with cloud data follows a device-only path: signing out and wiping the device does not delete its cloud records, which become unreachable; this is not full cloud account deletion.
How long data is kept
- Deletion requests sent by email: we complete them within 30 days of verifying your identity.
- In-app account deletion: the server carries it out during that request, with no waiting period.
- Deleted photo attachments: the record is marked deleted right away, and the image file is kept for 90 days before it is removed from storage.
- Category-suggestion quality measurements: kept for 3 months, then deleted. These records carry no identity — no user id and no expense title, only the title's length and whether it had diacritics.
- Rate-limit windows for the category suggestion: kept for 1 day, then deleted.
- Expense titles sent for classification: not retained, either by the Vercel AI Gateway intermediary or by the TypeSafe provider.
- Routing logs at the Vercel AI Gateway: kept for 30 days, metadata about the call only, without request or response content.
- Crash reports: kept by Sentry under that provider's own retention policy.
- Database: there are currently no scheduled backups.