Deleting your Emberlodge account and data

Last updated: 12 August 2026 Applies to: the Emberlodge apps for Windows and Android, and the Emberlodge web app.

Emberlodge is made by Three Blades Data, a sole trader in Australia. This page explains how to delete your account and everything in it, what gets erased, and what survives for a short time in backups.

You do not need to install anything or ask us for permission. You can do all of this yourself, from inside the app.


The short version

Open Settings → Your data → Delete all my data, and press it twice.

That erases your records from the device you are on and from our database, then deletes the login itself. It is immediate and it cannot be undone.

Deleting from inside the app

The same place on every version:

Where you areWhat to do
AndroidSettings → Your data → Delete all my data
WindowsSettings → Your data → Delete all my data
WebSettings → Your data → Delete all my data

It takes two deliberate presses. The first press changes the button to read "Tap again to permanently delete" — a second, different label rather than a colour change, so it cannot be clicked through on autopilot. There is no third confirmation and no undo.

If you are offline, the data on your device is still erased. Someone who has decided to be forgotten should not be left holding their own health records because the network was down. The app then tells you plainly which parts succeeded rather than assuming — if the login itself could not be removed, it says so and tells you to contact us.

If you cannot use the in-app tools

Email ⚠️ TO BE SET — the contact address from PRIVACY.md §1 from the address you signed up with, and ask us to delete your account. We will confirm when it is done, and in any case within 30 days.

We may ask you to confirm the request came from you. That is not an obstacle — it is how we avoid deleting somebody's health records because a stranger asked us to.

What is deleted

Everything. There is no partial delete and nothing is kept back for analytics.

Your records — 23 collections, removed by the app itself:

chains, checkins, clients, content_lists, countdowns, device_tokens, history, linked_accounts, messages, notes, pills, pomodoro_session, reminders, routine_runs, routines, settings, streak, tasks, timeblock_blocks, timeblock_subjects, timelog, web_push_subscriptions, work_timer

In plainer terms: your daily check-ins and every wellbeing field in them, your medications and the log of doses you marked taken or missed, your tasks, routines, reminders, time-tracking entries and client names, your reading and content lists, your countdowns and what you named them, which step of a routine you were on, streaks, timers, your conversations with Kuro, your settings, and the notification registration for your devices.

Three more collections that the app deliberately has no permission to touch, removed by our server on your behalf:

CollectionWhat it holds
ai_usageA per-day count of assistant calls, for cost control. Never any content.
oauth_tokensAccess tokens for a Google or Microsoft account, if you connected one
web_nag_stateReminder bookkeeping for the web app

And then the login itself, so the account no longer exists.

The order matters and is deliberate: records first, login last. Doing it the other way round would leave data behind that nobody could then attribute to anyone or reach to remove. For the same reason, if any collection fails to delete, we keep the login on purpose so you can sign back in and try again rather than being locked out of your own leftover data.

On your device, local files are erased in the same action — the app does not wait for the network to clear what is already in your hands.

What is not immediately gone

Encrypted backups. Our database host keeps rolling backups for disaster recovery. Your records are removed from the live database straight away, but a copy can persist in a backup for up to ⚠️ TO BE SET — confirm your host's backup retention days, after which it rolls off on its own. We do not restore deleted accounts from backups.

Nothing else is retained. We keep no shadow copy, no anonymised profile, and no record that your account existed. We do not sell data, we do not use it for advertising, and we do not use your health information to train AI models.

Deleting some of it instead

You do not have to delete everything to remove something. Every record in Emberlodge can be edited or deleted individually in the app, and every health field is optional in the first place. If you only want a particular check-in or medication gone, delete that.

Export first if you want a copy. The app exports your check-in history to a file you choose. Do that before deleting — once it is gone we cannot get it back for you.

Questions

Contact us at the address in our privacy policy, which also explains what we collect and who else ever sees it. We respond within 30 days.

If you are not satisfied with how we handle a privacy request, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au · 1300 363 992.