How to request deletion
You can request deletion of your personal data, account, or a workspace you are authorized to manage. Submit and track a request while signed in, or email privacy@keyguardrail.com. You do not need an active subscription, a new account, a legal citation, or a reason for your request. Other requests received by our team are routed for manual review too.
Tell us the email address you used and which data or workspace you mean, if known. You may ask us to help clarify the scope. We do not charge for this process. If you act for someone else, we may need proportionate evidence of their authorization.
Verification without collecting unnecessary data
We first use existing account authentication or confirmation through the contact address already on record. A signed-in request is evidence of account access, not by itself permission to erase other people’s workspace data. Where there are reasonable doubts or a risk to other people, we explain the concern and request the minimum additional information needed.
We do not routinely request government ID, a selfie, notarization, a home address, or full payment details. Never send passwords, secret keys, recovery codes, full card numbers, or identity documents through the request form. If additional evidence is genuinely necessary, we will explain why, offer reasonable alternatives, and arrange an appropriate channel. Verification information is used for verification and kept only as long as necessary; we prefer a record of the check over a copy of a document.
Personal data and shared workspaces
Every individual may ask us to review their personal data. Deleting an entire workspace requires confirmation of the requester’s authority and an assessment of other users’ rights. We may coordinate with your organization when it controls workspace data, while handling the account and service data for which we are responsible. We do not treat a member’s request as authorization to delete the whole organization.
Manual review and status updates
A person reviews every request. We aim to acknowledge it within seven calendar days and provide a substantive response within 28 calendar days of receipt, sooner where required. Verification questions do not silently reset that target. If an applicable law permits extra time, we explain the reason and revised date within the original legal response period. A target is not permission to delay unnecessarily.
Signed-in requesters can see the current status and update history. We send email notices when the status changes. Requests received outside the portal are acknowledged and updated through an appropriate verified contact channel. Contact privacy@keyguardrail.com if you cannot access your status page.
What deletion changes
Submitting a request does not itself delete information, cancel billing, or issue a refund. Before manual action we explain its scope, any loss of access, and whether a subscription needs to end. Export is available where supported, but downloading an export is not a condition of exercising privacy rights. We do not delete workspace data solely because a payment is overdue.
Exceptions, audit records and backups
Some information may need to be retained for a specific legal obligation, security purpose, or legal claim. Retention must be necessary and justified for the relevant data; calling a record an audit log is not a blanket exemption. Where we cannot erase everything, we explain the categories retained, the reason, and the applicable expiry or review date, and restrict further use as appropriate.
We normally keep closed privacy-request case records and their update history for 24 months after closure. A documented, necessary retention hold may extend that period and has a recorded review date. This case-record period is separate from the retention of the underlying account, workspace, financial records, and backups.
Encrypted backups may contain residual copies. Their write-protection period is not a deletion deadline. We review the actual backup lifecycle and any legal hold, explain residual retention in the outcome, and require deleted data to be addressed before a restored backup is returned to normal service. We do not describe a request as fully erased while unexplained residual copies remain. Relevant service providers are included in the review.
If you disagree with our response
Reply to the request or email privacy@keyguardrail.com to ask for reconsideration. We explain a refusal or partial response and available appeal routes. This process does not limit your right to contact a competent privacy regulator or seek a judicial remedy. For EU/EEA and UK rights, you may contact your applicable supervisory authority. Any shorter mandatory deadline or stronger applicable right takes precedence over this policy.
Scope of this policy
Our privacy practices are informed by recognized privacy frameworks and regulatory guidance. We publish our policies and document how we handle verification, deletion, retention, and exceptions. We offer this request process globally. Applicable rights depend on the circumstances and jurisdiction. This policy describes our deletion-request process; it is not a claim of certification or blanket compliance with every privacy law.