ShootHarbor Account and Data Deletion
How to request deletion and understand what may remain for ShootHarbor.
This page gives cautious, version-independent instructions and repeats the retention boundaries from the current Privacy Policy.
Request deletion
- Use any account or data deletion control currently presented inside the app. Labels and placement can change between versions, so this page does not prescribe an exact navigation path.
- If you cannot use the app, email [email protected] with “ShootHarbor deletion request” in the subject. If an account exists, write from its associated email address where practical.
- Do not send passwords, authentication codes, identity documents, customer records or other unnecessary sensitive content. Blue Sparrow may ask for proportionate verification before acting on connected records.
- Removing connected records does not retrieve exports, delivered messages, recipient copies or files already shared outside the app. Device-only copies may need to be removed separately.
- Account deletion does not cancel a Google Play subscription. Manage cancellation separately through Google Play.
Retention and deletion boundaries
Studio records are generally kept while the account is active and until the operator edits, removes or deletes the related workspace data. No single implemented schedule currently covers every account, synchronization, analytics, crash, security, notification, support and public-link record.
Hosted invoice and shoot-report links use a configurable expiry, with a service default of 60 days. File cleanup has a configurable grace period, but the cleanup worker defaults to disabled and dry-run unless production configuration enables actual deletion. Delivery tokens do not have a separate expiry field in the audited schema. Provider analytics, crash, purchase, message and delivery records follow provider or operational settings.
Account deletion first asks for recent Google confirmation, unregisters notification access where reachable, requests deletion of the PostgreSQL workspace and related cascading records, then deletes the Firebase Auth user and clears the local database. A minimal deletion tombstone is retained to prevent later subscription delivery from recreating the account. Google Play subscription cancellation is separate.
The audited deletion path does not explicitly remove every imported file from the local media folder or every backend file object after its database row is removed. Backups, security logs, provider records, already delivered email and recipient-held exports or links may also remain for a limited period or outside Blue Sparrow's control. These are release and deletion-verification gaps rather than promises of complete immediate erasure.
Contact
For deletion or privacy help, email [email protected]. For general product help, email [email protected]. Website: https://bluesparrow.dev.