Guest data on this device
Guest assessments and calculators are stored locally. Open Account & data > Health-processing choice > Clear health data from this browser, review the scope, and confirm Yes, clear local health data. You can also remove the app or clear this site’s storage through your browser/device settings. Device or cloud backups are controlled separately by your operating-system provider.
Signed-in account
Open Privacy & data > Delete account, review the scope, and confirm through the fresh authentication step. The product should immediately sign out other sessions, revoke persistent shares, stop sync, and show the deletion-job status. Identifiable profile, assessment, health-import, scenario, plan, reminder, consent, and not-yet-de-identified contribution records are removed through the documented workflow.
If you cannot sign in, contact [PRIVACY EMAIL] from the account email and write “Fitness Age account deletion.” Never send health measurements, authentication links, or tokens. The support process must verify identity without requesting excessive data.
Research withdrawal
Optional model-improvement contribution has its own withdrawal control. Withdrawal removes identifiable or not-yet-irreversibly-de-identified contribution records. Data already irreversibly de-identified may no longer be linkable to the account; the final public page must describe the approved production boundary.
Narrow retention and backups
Some limited billing, security, fraud, dispute, or legal records may be retained only when required under the published retention rule. Backups expire under the provider schedule. Any restore must replay deletion and withdrawal tombstones before restored records can be served.
Completion
The in-product job shows pending, completed, or failed status and a completion confirmation. Contact [PRIVACY EMAIL] if completion is not shown. The final page must state the production response timeline and regulator/escalation details required by applicable law.