Delete your data

Delete one conversation, wipe this browser, close a hosted account by request, every action that erases local work, and what deletion here cannot reach.

Browse documentation

Everything on this machine you delete yourself, in the browser, and it goes the moment you say so. The server side of a hosted account is closed by email from the address you signed up with. Self-hosted Open has no server side: deletion there is local, plus whatever database the operator provisioned. Cancelling a subscription leaves every copy where it is - Accounts, Pro, and billing.

One conversation

Delete it from the chat drawer, from a multi-select, or from the cleanup dialog. It leaves this device immediately. With cloud backup on, the deletion replicates: connected devices drop their copy at once, the rest as each comes online. The conversation stays recoverable for 90 days in the cloud trashcan below. Trashed content still counts against your cloud space until it ages out.

The cloud trashcan

Pro

Chats, personas and rambles stay on this device unless you subscribe to Pro: cloud backup and multi-device sync (1 GB). On Open there is no sync. Disabling sync never deletes local data.

The chat panel's Restore Deleted opens the cloud trashcan pro. Chats you delete are kept there for 90 days, and come back on every device. The protection is forward-only: it starts when you enable it, and chats deleted before then cannot be recovered. On a subscribed account, a chat you deleted because it should not exist stays recoverable for those 90 days. To have it never written down at all, go off the record.

Recovery works even over your cloud space: restoring something already stored costs nothing extra.

Wiping this browser

Warning

The browser's own clear site data is a full reset of the application. Every chat, persona, setting and API key on this machine goes, without the app ever seeing it happen. On Pro, your chats, personas and rambles survive in the cloud; everything else is gone. People do this by mistake - export a backup first.

Three controls, each removing more than the last. The sign-out card's own choice is on Accounts, Pro, and billing.

ControlWhat it removesWhat survivesIts warning
Sign-out card: Remove from deviceThis identity's chats and personas, plus the stored settings - model services and API keys with themOther browser profiles, and another identity's data herewith no cloud copy, a No cloud backup panel first: "Clearing will permanently delete all your chats and settings from this device."
Account -> Data -> Wipe Local Sync DataChats, personas, rambles, and other synchronized objectsSettings, models and credentials stay"Please backup your data to the cloud, or it will be forever lost."
The browser's own "clear site data"Everything this site holds, every identity includedNothing - Pro cloud copies exceptednone - the whole origin goes without the app ever seeing it

An in-app wipe reaches the current identity's databases only. Another account's chats stay on the machine. Sign in as that identity to clear them, or use the browser's own clear (Chats live in this browser).

Other dangerous things that empty a browser

Three of the four are ordinary browser behaviour, and none of them ask:

  1. Restoring a settings or whole-device file with a category ticked - Back up, restore, and import.
  2. The browser clearing site data - "clear browsing data" with site data or cookies, a browser reset, or an extension that sweeps storage.
  3. A private window, which starts empty and keeps nothing.
  4. A different browser or profile. Nothing was lost; it is in the other one.

Chats gone and you did none of this: Where did my chats go?.

Closing a hosted account

Closing a hosted account is a request you send, in two steps; there is no self-serve button.

  1. Wipe this browser with whichever control above matches what you want gone. Do the same on any other machine you used.
  2. Email a deletion request from the address on the account, which is how it is verified, to the address in the privacy policy. Ask for the account and its server-side content to be deleted. The acknowledgement and completion windows are published there too, with the retention that applies to billing records and to a cancelled subscription.

For a self-hosted deployment the controller is whoever runs it, so a request about that content goes to them. Your rights and the controller are on Confidential and regulated material.

Deletion does not reach:

  • Your AI service. Whatever you sent was received under their terms and their retention. Nothing here touches it - training and retention at your AI service.
  • Billing records. Payment and invoice records are kept as required record-keeping after an account is closed.
  • Anonymous product analytics. They carry no link to an account, so there is nothing to identify and remove for an individual.
  • Copies you made. Exported files, published links you have not taken down, and backups on other machines. Back up, restore, and import covers taking a link down.

© 2026 Token Fabrics·Built with passion in San Diego