Delete your Bioflow account

This page explains how to delete your account for Bioflow (bioflow.io) and the Bioflow app for Android, what is removed when you do, and what we keep. Deleting your account here deletes it everywhere — the app and the website are the same account.

How to delete your account

  1. Sign in at bioflow.io, or open the Bioflow app and sign in.
  2. Go to Dashboard → Privacy.
  3. Under “Cancellation”, choose “Delete my account”.
  4. Type “delete my account” in the confirmation box, exactly as shown.
  5. Confirm. Your account is deleted immediately and you are signed out on every device.

There is no waiting period and no undo. If you have a paid subscription, it is cancelled as part of the same step — you do not need to cancel it first.

If you cannot sign in

You do not need access to your account to have it deleted. Write to [email protected] from the email address registered on the account, tell us the username you want removed, and we will delete it after confirming you own it. We answer deletion requests within 30 days.

What is deleted

The following are erased immediately, not archived, when the account is deleted:

  • Your account: email address, password, name, biography, profile photo and settings.
  • Your public profile and every link, section and text block on it — the page stops resolving right away.
  • Your short links, and the click records attached to them.
  • Your visitor analytics: visits, clicks, countries and device data for your profile.
  • Your loyalty programs and their membership records, stamps and wallet passes.
  • Your followers and the accounts you follow.
  • Sign-in sessions, refresh tokens, two-factor backup codes and push notification tokens for your devices — which is what signs you out everywhere and stops app notifications.
  • Your AI Insights history and any cached analysis.
  • Your support conversations with us, and any report another person filed about your profile.

What we keep, and why

A few records outlive the account. Each is either disconnected from you or kept for a stated reason:

  • A record that an account with your username was deleted, and when. It keeps the username because a handle can live on a printed QR code, a saved wallet pass or somebody else’s page, and we need to know a name was released before someone else takes it.
  • Your username and profile URL are reserved for 30 days after deletion, so that nobody can immediately claim a handle that still points at you elsewhere. After that they become available again.
  • Issue reports you sent us, and reports you filed about someone else, are kept without their link to your account — the account reference is removed, so they no longer identify you.
  • If you joined someone else’s loyalty program, the business keeps its own membership and stamp record, with the link to your account removed. That record belongs to them, not to us; loyalty programs you ran yourself are deleted with your account.
  • Server activity records (which endpoints were called, when, from which IP) are kept without their link to your account, for security and abuse investigation.
  • Anything the law requires us to keep, such as invoices and payment records needed for tax obligations. Payment details themselves are held by Stripe, not by us.
  • Backups are overwritten on their normal cycle; a deleted account may survive in a backup until that cycle completes, and is not restored to the live service.