This page explains how to delete your account in the CarePilot application (developed by Utility Lab Studio) and what data is removed or retained when you do so. Deletion is complete, immediate and irreversible, in accordance with the right to erasure (GDPR Art. 17).
1. Delete from the app (recommended)
The fastest and most reliable way to delete your account is directly from the app:
- Open CarePilot on your device.
- Go to the Settings tab (gear icon).
- Scroll down to the Account section.
- Tap Delete my account.
- Confirm by entering your recovery PIN.
- Deletion runs immediately. You don’t need to do anything else.
The deletion is triggered from your device through a secure server-side function (Cloud Function deleteMyAccount) that cascades the removal of all resources associated with your account.
2. Delete if you have no access to the app
If you’ve lost access to the app (lost device, forgotten password or missing recovery PIN), you can request deletion by sending an email to:
Use «CarePilot account deletion request» as the subject and include in the body:
- The email address you used to sign up to CarePilot.
- An explicit confirmation that you request deletion of your account and associated data.
We will verify your identity and proceed with deletion within a maximum of 30 calendar days, per GDPR. We will confirm by email once it’s completed.
3. What data is deleted
When you delete your account, the following is wiped immediately and completely:
- Your user account and profile (name, photo, email, language, settings).
- The groups where you were administrator, including all sub-collections: medications, appointments, tasks, expenses, notes, documents, audit logs and photos in Storage.
- Your membership in other groups where you were not administrator (the group data persists for the remaining active members).
- The encryption keys from the recovery backup tied to your PIN.
- Your Firebase authentication account (email + password, Google Sign-In link if used).
- Your anonymized identity in RevenueCat (subscription state linked to your UID).
4. What data may be retained
Some records may be kept for a limited period for operational, security or legal reasons:
- Anonymized technical logs for errors and security: up to 90 days. They contain no personally identifiable information.
- Accounting records of purchases made via Google Play Billing: kept by Google and reflected in financial reports under Spanish tax regulations (up to 6 years).
- Encrypted Firestore backups (Firebase): automatic retention up to 30 days before final purge.
These residual records cannot rebuild your account nor link to personal data once deletion has completed.
5. Delete data without deleting the account
If you only want to remove part of your data without deleting your account, you can do it from inside the app:
- Leave a group — Group tab → menu → Leave group. Your contributions to the group (routines, expenses, etc.) remain visible to the rest of the members but are no longer attributed to you.
- Delete specific content — you can individually remove medications, appointments, tasks, expenses, notes or documents you created, provided your role in the group allows it.
- Sign out — disconnect the device without deleting your account. You can sign back in whenever you want.
6. Export your data before deleting
If you want to keep a copy of your data before deleting the account, export it from Settings → Export my data. You will receive two files:
- PDF — human-readable format.
- JSON — structured technical format, in compliance with GDPR Art. 20 (right to portability).
Both files include your profile, groups, routines, appointments, expenses, documents, notes and records. Once exported you can proceed with account deletion without losing your information.
7. Contact
For any question about account deletion or your GDPR rights, write to info@utilitylabstudio.com.
You can also consult our Privacy Policy and our Terms of Service for more information.