privacysafe.xyz, privacysafe.me, or privacysafe.gg with an Ivy Cyber storefront, billing, or payment account. We can associate those separate account contexts only when a user or customer voluntarily provides information that links them, such as by identifying both accounts in a support, billing, purchase, or deletion request. Deleting one account context does not automatically delete the other.PrivacySafe account deletion
This is the deletion process for a PrivacySafe identity or account used with the PrivacySafe applications.
If you can access PrivacySafe:
- Open Settings.
- Select Account.
- Select Delete Account.
- Follow the instructions to confirm your request.
If you cannot access your PrivacySafe account, email privacy@ivycyber.com and identify the PrivacySafe account or hosted identity you want deleted. A PrivacySafe identity does not necessarily have an Ivy Cyber storefront email address or payment account associated with it, so do not assume that a billing email identifies the PrivacySafe account.
You do not need to reinstall PrivacySafe or regain access to the app just to submit a deletion request. We may take reasonable steps to verify that the request comes from the account holder before acting on it.
What is deleted with a PrivacySafe account
When PrivacySafe account deletion is completed, Ivy Cyber deletes or de-identifies PrivacySafe account information under its control that is no longer needed for a legitimate operational or legal purpose. PrivacySafe identities are not routinely linked to Ivy Cyber storefront or payment records. Depending on the service, this may include:
- the PrivacySafe account or hosted identity;
- PrivacySafe account settings and preferences;
- active PrivacySafe sessions;
- server-side PrivacySafe account records no longer needed to operate or secure the service; and
- hosted encrypted synchronization data associated with the deleted PrivacySafe account, subject to normal deletion and backup cycles.
For encrypted content protected by user-controlled keys, deletion or loss of keys may make the content permanently inaccessible. PrivacySafe account deletion may be irreversible.
PrivacySafe Social account export, migration, and deletion
PrivacySafe Social is a federated Mastodon service operated by PrivacySafe Foundation, Inc. It is a separate account context from a PrivacySafe encrypted identity at privacysafe.xyz, privacysafe.me, or privacysafe.gg, and it is also separate from an Ivy Cyber storefront/customer account. PrivacySafe Social is not a zero-knowledge encrypted PrivacySafe account. Public and federated Social content is distributed through Mastodon and ActivityPub and may already have been delivered to independently operated servers.
Download or back up your PrivacySafe Social data
Before moving or deleting a PrivacySafe Social account, you may want to export the information Mastodon makes available to you.
- Sign in at privacysafe.social.
- Open Settings.
- Select Import and export, then Export.
- Download the available CSV exports for followed accounts, lists, blocked accounts, muted accounts, and blocked domains that you want to keep.
- Use the archive option on that page if you also want a downloadable archive of your posts, media, profile information, and other supported account content.
Mastodon can import supported CSV lists into another Mastodon account. A posts-and-media archive is a personal backup; Mastodon does not currently import old posts or media into a new account.
Move to another Mastodon server
If you want to migrate rather than delete your account, export your data first and create the destination account before moving your PrivacySafe Social profile.
- Create and set up your new account on the destination Mastodon server.
- On PrivacySafe Social, go to Settings > Import and export > Export and download the lists you want to carry with you.
- On the new Mastodon account, go to Settings > Import and export > Import and import the supported lists you want to restore.
- On the new account, go to Settings > Account, find Moving from a different account, choose create an account alias, and enter your old PrivacySafe Social account handle.
- Back on your PrivacySafe Social account, go to Settings > Account, find Moving to a different account, choose the configuration option, enter the new account handle and your PrivacySafe Social password, and confirm the move.
A Mastodon account move redirects the old profile and attempts to move followers to the new account where supported. It does not move old posts or media, and after completing the move you should expect the old account to become inaccessible for normal use. Export anything you need before confirming the move.
Delete your PrivacySafe Social account
If you want to permanently delete the PrivacySafe Social account instead of moving it:
- Sign in at privacysafe.social.
- Open Settings.
- Select Account.
- Scroll to the account-deletion section at the bottom of the page and choose the option to Delete account.
- Review the warning and confirm the deletion.
PrivacySafe Social account deletion is irreversible. Mastodon also makes the deleted username unavailable for reuse on that server. Because PrivacySafe Social is federated, the Foundation can send deletion activities to servers that received your content, but it cannot guarantee deletion of copies already retained by independent servers, recipients, screenshots, archives, scrapers, caches, or other third parties.
PrivacySafe Social privacy and deletion questions should be sent to privacy@privacysafe.net. The PrivacySafe Social Privacy Notice and Terms of Use provides additional details about federation, retention, moderation, export, and deletion.
Ivy Cyber storefront and customer-account deletion
An Ivy Cyber storefront or customer account at ivycyber.com may contain different information from a PrivacySafe account, including a store username or email address, billing or shipping details, order history, subscription records, support history, tax information, discounts, and payment or transaction metadata. It may also include affiliate information if you participate in the Ivy Cyber Affiliate Program.
To request deletion of an Ivy Cyber storefront/customer account or eligible storefront personal data, email privacy@ivycyber.com and clearly state that the request concerns your Ivy Cyber store/customer account. Include the email address or username associated with the storefront account and, where useful for verification, an order number. Do not send full payment-card or bank-account credentials.
Deleting an Ivy Cyber storefront/customer account does not by itself delete a PrivacySafe identity or hosted PrivacySafe account. Likewise, deleting a PrivacySafe account does not by itself erase Ivy Cyber order, billing, tax, subscription, chargeback, fraud-prevention, or other storefront records. If you want both account contexts deleted, say so in your request.
Storefront and transaction retention
Ivy Cyber removes, anonymizes, or obfuscates storefront account and order information when it is no longer needed for order fulfillment, customer support, subscription administration, accounting, tax, chargebacks, fraud prevention, disputes, security, or other legal and operational requirements. Consistent with the retention schedule published in our Privacy Policy, our storefront retention targets include:
- Inactive storefront accounts: retained for 12 months; accounts that have not logged in or placed an order during that period may be deleted and related orders may be anonymized as guest orders.
- Pending orders: retained for 1 week, then removed when abandoned.
- Failed orders: retained for 1 week, then removed.
- Cancelled orders: retained for 1 month, then removed where no longer required.
- Refunded orders: retained for 12 months, after which personally identifying information may be obfuscated when no longer required.
- Completed orders: retained for 12 months, after which personally identifying information may be obfuscated when no longer required.
- Ended subscriptions: retained for 12 months, after which personally identifying information may be obfuscated when no longer required.
- Payment-processor metadata: processor identifiers and similar transaction metadata may be retained for up to 12 months, subject to accounting, tax, chargeback, fraud-prevention, dispute, processor, and legal requirements.
Ivy Cyber does not intentionally store complete payment-card numbers, bank-account credentials, or card security codes in its ordinary storefront records. Payment providers process those credentials under their own terms and privacy notices.
Delete eligible data without deleting an account
You may request deletion of eligible personal data while keeping either a PrivacySafe account or an Ivy Cyber storefront/customer account active. Email privacy@ivycyber.com and identify which account context is involved and the data or category of data you want deleted.
We will delete, de-identify, or restrict eligible data when reasonably possible. Some information may be necessary to provide a feature you choose to continue using, maintain an active subscription, fulfill an order, preserve legally required transaction records, prevent fraud or abuse, or protect account security. If deleting requested data would disable or materially affect a feature or service, we will explain that where practical.
Other information that may be retained
Some limited information may be retained after an account or data-deletion request when reasonably necessary for security, fraud prevention, accounting, tax, subscription administration, chargebacks, disputes, legal obligations, or to document and complete the deletion request.
- Server logs containing IP addresses: no more than 90 days under our ordinary retention target.
- IP addresses associated with registered users: no more than 12 months under our ordinary retention target.
- Correspondence about a deletion request: when necessary to document or complete the request, resolve disputes, or meet legal obligations.
- Encrypted data in technical backups: until applicable backup cycles rotate or expire.
Retention of paid PrivacySafe synchronization data may also depend on account status, technical backup cycles, contractual commitments, legal obligations, and the selected service. Where a specific retention period is material to a paid service, it is stated in the applicable service description or agreement.
Ivy Cyber does not retain personal data merely because an account has been deleted when there is no continuing legitimate reason to keep it.
Contact
PrivacySafe application and Ivy Cyber storefront privacy/deletion requests: privacy@ivycyber.com
PrivacySafe Social privacy/deletion requests: privacy@privacysafe.net
General Ivy Cyber support: support@ivycyber.com
