Delete your account and your data
Here you can delete your ToyControl account and all the data attached to it, without signing in. That is deliberate: people very often want to delete their account precisely because they can no longer get into it.
Type the email address of the account. If it exists, we will send you a confirmation link. Opening it shows you exactly what will be deleted, and nothing is erased until you confirm there.
For security, this page answers exactly the same whether or not an account exists with that address.
What is deleted
- Your account and your profile. Email, name, avatar, preferences, the link with Google or Apple, the Home Assistant key and your session keys.
- Stored credentials and secrets. Your carmaker account password (stored encrypted), your Google Maps, Open Charge Map and TomTom keys, the two-step verification secret and its recovery codes. They go with the profile: they are never exported and never kept.
- Your vehicles. The whole garage: nickname, number plate, VIN, catalogue photos, capabilities and settings for every car.
- Trips, charging sessions and telemetry. Every trip with its route and consumption, charging sessions with their energy and cost, the history of readings from the car (battery, range, odometer, position) and the car loans you noted down (who you lent it to, when and at what mileage).
- Maintenance and expenses. Services, repairs and expenses you have recorded.
- Planned routes and shared trips. The routes saved in the planner and the public shared-trip links —both the ones sharing the plan and the ones showing where you are live—, which stop working immediately. Of the live sessions only the times they were opened and the addresses notified were ever recorded: your location is never stored in the database.
- Convoy mode. The convoys you created and your membership of other people's: the alias others saw you as, the join and leave times and the proposed meeting point. Your position during a convoy is never stored in the database: it lives in memory for a few minutes and vanishes on its own.
- Routines, smart charging and saved destinations. Your automations, the smart-charging setup of each car, your address book of destinations (home, work and favourites), your favourite chargers and the charging tariffs you have registered.
- Linked carmaker accounts. The Tesla or Mercedes-Benz OAuth grants and their access and refresh tokens. They are deleted from our server; revoking the grant in the carmaker's own portal, if you also want to do that, is a separate step only you can take.
- Notifications and devices. Alert preferences, browser subscriptions, mobile push tokens, signed-in sessions, QR pairings of the car browser and the copilot, and any pending links or codes to verify your email or reset your password.
- Activity and security log. Your event history, efficiency badges, the suggestions you sent, your charger reports and the failed sign-in attempts made with your address.
- Company fleet membership. Your membership of organisations, the driver assignment history and any invitations sent to your email address. The organisation itself and other people's cars are untouched: only your link to them disappears.
- API tokens and webhooks. Your personal read-only tokens (the name you gave them, their prefix and when they were last used; the token itself is never stored, only its fingerprint) and your outgoing webhooks with their URL, their events and their signing secret. Once deleted, any integration using them stops working immediately.
- Subscription and charges. Your subscription and the history of payment attempts. INVOICES already issued are not included: see below why.
- Server cache. The last known state of each car, which we keep in memory so we do not have to call the carmaker on every screen.
What is kept, and why
Promising a total wipe would be a lie. This is what survives:
- Invoices already issued. If you ever paid for a subscription, the corresponding invoice is kept as an accounting document, but DETACHED from your account: it is no longer linked to your user and can no longer be consulted from the app. It still contains the tax data the law requires an invoice to show (name or company name, tax ID, billing address and amount).
Why: An issued invoice is an accounting and tax document: deleting it would be a breach of the law, not a privacy improvement. — Legal basis: Article 30 of the Spanish Commercial Code and articles 66 to 70 of the General Tax Act; the GDPR recognises this as an exception to the right to erasure in article 17.3.b.
How long: 6 years from the date of issue. — When it applies: Only if you actually paid. If you never paid, there is no invoice. - The record that the deletion was carried out. One log line with the numeric identifier the account had, the cryptographic fingerprint (SHA-256) of your email address — not the address itself — and how many records were erased. It does not allow anyone to reconstruct who you were or to contact you.
Why: It is the only way to prove to an app store or to the data protection authority that your request was honoured, and to detect a deletion you did not ask for. — Legal basis: Legitimate interest in demonstrating compliance (GDPR article 5.2, accountability principle).
How long: Indefinite, in pseudonymised form (no readable personal data). — When it applies: Always. - Administrative record, pseudonymised. The admin panel's notes about your account (for example, when a licence was granted or revoked) and the notices the payment gateway sent us about your charges. They are kept, but deleting the account strips your identifier and your email address from them and replaces both with a cryptographic fingerprint. After that they cannot be traced back to you.
Why: Without the panel's notes there would be no way to justify why an account did or did not have a licence; without the gateway notices, the same charge arriving twice would be processed twice. — Legal basis: Legitimate interest in demonstrating compliance and in accounting integrity (GDPR articles 5.2 and 6.1.f).
How long: Indefinite, in pseudonymised form (no readable personal data). — When it applies: Only if an administrator acted on your account or there was any payment activity. - Backups taken before the deletion. Backups the administrator had downloaded BEFORE your request still contain your data until that copy is replaced or destroyed. They are never used to restore a deleted account.
Why: A backup is a sealed file: it cannot be edited without invalidating it as a backup. — Legal basis: Legitimate interest in service continuity; the GDPR accepts the technical delay of backup systems.
How long: Until the copy is replaced by one taken after the deletion, or deleted. — When it applies: Only if a copy existed before your request.
Deletion is immediate and final. There is no grace period and no way to recover the account afterwards. If you want to keep your data, download it first from the app (Settings › Account › Download my data).