Coming soon - Mareel Earth is in private development. The API is live, but accounts are not open yet. Early access: [email protected]

Account & Data Deletion

This page explains how you can delete your Mareel Waters Account and the Personal Data associated with it, what we delete, what we may keep and why, and how long the process takes. It is a single, public route for erasure that you can use whether you signed up through our website or, in future, through one of our mobile apps.

You can read this page without logging in, and you can reach it without installing any app. It is available to all users regardless of location. It applies to every Mareel Waters Account, on the free Tier and on any paid Tier.

Mareel Waters is operated by LEGAL_ENTITY, based in Sweden, which acts as the Controller of your Personal Data. For details of what we collect and why, see our Privacy Policy. This page describes the deletion route specifically and should be read alongside it.

What gets deleted

When you delete your Account, we delete the Account record and the Personal Data associated with it. In practice this means we remove or irreversibly anonymise:

  • Your account email and any contact details held against the Account.
  • Your hashed password. We never store your password in plain text; we store only a bcrypt hash, and that hash is deleted with the Account.
  • Your API Keys. Keys are stored only as sha256 hashes, never in a form we can display back to you. On deletion the hashed keys are removed and the keys stop working immediately, so any integration still sending requests with them will be rejected.
  • Your Usage Events. Each Usage Event records an Endpoint, an HTTP status, a timestamp, the request latitude and longitude, and the computed cost. Usage Events do not contain your IP address or user-agent. The records linked to your Account are deleted or anonymised so they can no longer be tied to you.
  • Analytics-linked records. Our first-party web and marketing analytics is cookieless and does not use a third-party tracker. It stores a daily-salted hashed IP and a derived user-agent family rather than raw values, and it is not generally linked to your Account. Where any analytics record can be associated with you, we delete or anonymise it as part of the same process.

We use only strictly necessary authentication cookies to keep you logged in. We do not run a server-side session store, so deleting your Account does not leave session state behind on our servers. The cookie ceases to be valid once the Account is gone, and you can clear it from your browser at any time.

We do not store card or PAN data at any point. Payments are processed by Stripe, and billing data held by Stripe is handled as described below.

What may be retained, and why

We do not keep more than we need, and we do not keep your Personal Data simply because it is convenient. However, a limited set of records may be retained after you delete your Account where we have a legal obligation or a legitimate need that overrides the request to erase. This is consistent with Article 17(3) of the GDPR, which allows retention where processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.

Specifically, we may retain:

  • Accounting and billing records. As a business operating in Sweden, we are required to keep accounting material, including records relating to payments and invoices, for the statutory period. Under the Swedish Bookkeeping Act (Bokföringslagen), accounting records must be retained for seven years after the end of the calendar year in which the relevant financial year ended. Much of this billing data is held by our payment processor, Stripe; we do not store your card details. These records are kept for compliance only and are not used for any other purpose.
  • Security and fraud-prevention data. We may retain limited records needed to detect, prevent or investigate abuse, fraud, or attempts to circumvent Tier limits, and to protect the integrity of the service. Such records are kept only for as long as necessary for that purpose and are then deleted or anonymised.
  • Records needed for legal claims. Where we reasonably need information to establish, exercise or defend a legal claim, we may retain it for the period during which such a claim could arise.

Retained records are minimised, access-restricted, and segregated from active service use. Once the applicable retention period or purpose ends, the data is deleted or irreversibly anonymised. The seven-year accounting period above is the longest retention timeline that normally applies to data connected to your Account.

How to delete your Account

There are two ways to ask us to delete your Account, and both lead to the same outcome.

Email request

To delete your Account and associated data, email [email protected] from the address registered to the Account and ask us to delete it. We may take reasonable steps to verify your identity before we proceed, so that we do not act on a request from someone other than you. We will not ask for your password, and we will never ask you to send it to us. We act on verified requests within the timeline below. This route is available to everyone, regardless of how you signed up or where you are located.

Self-service and in-app (planned)

A self-service Delete my account button in the web portal, and an in-app Delete my account action when our mobile apps are released, are planned. Until they ship, the email route above is the way to delete your Account.

Timeline and confirmation

Deletion does not have to be, and is not always, instant. Some steps run on a schedule and some retained records (see above) are removed only when their retention period ends.

  • When we action a deletion, your Account access is revoked and your API Keys stop working, so any integration still sending requests with them is rejected.
  • We complete the erasure or anonymisation of your associated Personal Data within [[DELETION_SLA_DAYS]] days of a valid request, except for records we are required or entitled to retain as described in *What may be retained, and why*.
  • We confirm to you by email once the deletion has run.

Cancel auto-renewing subscriptions first. Deleting your Account does not, by itself, cancel a separate subscription billing arrangement.

  • For subscriptions billed via the web (Stripe), cancel your active Plan before deleting your Account so that it does not auto-renew. See your billing settings and /pricing.
  • In future, where a subscription is purchased through an app store as an in-app purchase, it is managed by the Platform (Apple App Store or Google Play). You must cancel it through that Platform's subscription settings; deleting your Mareel Waters Account will not cancel a Platform-managed subscription, and we cannot cancel or refund it on your behalf.

We recommend confirming that any active, auto-renewing subscription is cancelled before you proceed.

App note

Our iOS and Android apps are planned and not yet released. They are being built so that account deletion works from day one:

  • When the apps are released, the in-app Delete my account action will either perform the deletion directly or link to this page, satisfying Apple Guideline 5.1.1(v) and Google Play's account-deletion requirements.
  • This page is the public, installation-free deletion URL referenced by the apps.
  • If we ever offer Sign in with Apple, deleting your Account will also revoke the associated Apple tokens, so the sign-in relationship between your Apple ID and Mareel Waters is severed as part of the deletion.

Relationship to your GDPR rights

The right to delete your Account is part of your broader right to erasure (the "right to be forgotten") under Article 17 of the GDPR, alongside your other rights as a Data Subject, including the rights of access, rectification, restriction, portability and objection. Using the deletion route on this page is one way to exercise your right to erasure.

Your statutory rights are not limited by this page. The limited retention described above reflects the lawful exceptions in Article 17(3) of the GDPR and does not remove your other rights over the data we still hold. For the full picture of how we process Personal Data, the lawful bases we rely on, our Subprocessors (including Stripe, Resend and Cloudflare), and how to contact us about your rights, see our Privacy Policy.

If you have questions about this process or want to escalate a request, contact us at [email protected] or [email protected]. You also have the right to lodge a complaint with a supervisory authority. In Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY); if you are in another EEA country you may complain to your local data protection authority instead.

Related pages

This page provides general information and is not legal advice.

Last updated: EFFECTIVE_DATE