01

Delete inside Ottr

Open Settings → Profile → Delete account permanently. Review the consequences and confirm. After the server accepts the request, Ottr disables the account, ends the shared world, removes the public profile and username, clears notification tokens, revokes every registered device and cryptographic identity, queues deletion of the Firebase Authentication user, and erases this phone’s owner-bound keys.

02

Delete without the app

Email ottr.chat@gmail.com from the Google email used for Ottr and use the subject “Ottr account deletion request.” If you cannot send from that address, explain why and we will use proportionate account verification. Never send your password, sign-in code, private message, private key, or recovery secret.

We will confirm the request and complete it within the period required by applicable law after verification. A request may be delayed only where reasonably necessary to verify ownership, prevent fraud, protect another person’s rights, or comply with law.

Email a deletion request

03

What deletion cannot erase

Messages or keys already delivered to your partner’s trusted devices cannot be remotely removed from those devices. Ottr may retain a minimal disabled identity tombstone, opaque shared ciphertext, and limited security, transaction, or legal records where needed to stop silent account recreation, protect the other participant’s legitimate copy, prevent fraud, or meet legal obligations.

Deleted data may remain inaccessible in encrypted rolling backups until those backups expire. A restore must reapply deletion safeguards before restored records can become active. See the retention details and account-deletion disclosures in the Privacy Policy.

04

Choose the action you mean

  • Sign out: removes readable account data from that phone while preserving only a sealed, account-bound recovery vault.
  • Forget this device: destructively removes this phone’s local identity and recovery material.
  • Revoke a device: blocks that registered device from future access.
  • Disconnect: ends the pair and starts the documented mutual-recovery period.
  • Delete account permanently: closes the Ottr identity and is not reversible after acceptance.