Design Account Deletion and Data Export
Trust, Privacy & Ethics · privacy, trust, import/export
Updated 2026-07-28
- Make leaving possible without contacting support. A deletion that requires an email is a dark pattern wearing a process, and users recognise it.
- Offer export before deletion, in the same flow. Most people asking to delete want their data out first, and separating the two guarantees regret.
- Export in a format that is actually usable elsewhere, with the media included and a readable index, not a proprietary dump nobody can open.
- Say exactly what deletion removes and what it does not. Shared content, team-owned records, invoices kept for legal reasons, and backups all need naming.
- Distinguish deactivating from deleting. One is reversible and one is not, and users regularly choose the wrong one because the labels were vague.
- Give a recovery window and say how long it is. A grace period prevents the irreversible mistake without preventing the intent.
- Confirm proportionally to the consequence. Deleting an account justifies typing the account name, and the same friction on a draft does not.
- Confirm completion in writing, and stop all billing and messaging at the same moment. Marketing email arriving after deletion destroys any goodwill that was left.
- Never make the exit path slower than the signup path on purpose.
How a product handles someone leaving is the clearest signal of how it treated them while they stayed.
Related guides