Data deletion instructions
Last updated 23 August 2026
Disconnecting a social account in the dashboard erases its stored credentials immediately. Closing your organisation deletes everything Rutba holds about you. If you would rather we did it, email privacy@rutba.io and we will, within 30 days.
1. Three ways to remove data
Rutba Social Relay stores three separable things: the credentials for each social account you connect, the posts and delivery records produced by using it, and your account and organisation. Which route you want depends on how much of that you mean to remove.
- Disconnect one social account — removes that platform’s credentials and stops publishing to it. Everything else stays.
- Revoke from the platform — the same outcome, initiated from Facebook, Google, TikTok, X and the rest.
- Delete your organisation — removes all of the above plus your posts, media, audit trail and account.
2. Disconnect one social account
- Sign in at https://app.relay.rutba.io.
- Open Connections.
- Find the account and choose Disconnect.
- Confirm.
The stored access and refresh credentials for that connection are erased at once, any delivery still queued for it is cancelled, and the service can no longer reach that account. The record that the connection once existed remains in your audit trail until the organisation is deleted, because an audit trail you can edit is not an audit trail.
3. Revoke from the platform itself
Every platform lets you withdraw an application’s access from its own settings, which has the same effect from the platform’s side and does not require you to sign in here:
- Facebook and Instagram — Settings & privacy → Settings → Apps and Websites, then remove the app.
- Threads — Settings → Account → Website permissions → Apps and websites.
- Google and YouTube — Third-party apps & services, then remove access.
- TikTok — Settings and privacy → Security & permissions → Manage app permissions.
- X — Settings → Security and account access → Apps and sessions → Connected apps.
- LinkedIn — Settings → Data privacy → Permitted services.
- Pinterest — Settings → Security → Apps.
- Reddit — Preferences → Apps → Revoke access.
- Discord, Slack, Telegram, Mastodon, Bluesky, WordPress — remove the app or revoke the token in that service’s own connected-apps or app-password settings.
Revoking there stops the service publishing immediately. To also erase what we hold about that connection, disconnect it here as well, or ask us — see below.
4. Delete your whole organisation
- Sign in at https://app.relay.rutba.io as an owner.
- Open Settings → Organisation.
- Choose Close account and type the organisation name to confirm.
This cancels the subscription and deletes the organisation and everything owned by it — members, connections and their credentials, API keys, posts, deliveries, uploaded media, webhooks and audit entries — by cascade. It cannot be undone. Export anything you want to keep first; posts, deliveries and the audit trail are all readable through the API with a key.
5. Ask us to do it
If you cannot sign in, no longer have an account, or want confirmation in writing, email privacy@rutba.io from the address on the account with:
- the organisation name or slug, if you know it;
- the platform and handle of any specific connection you want removed, or “everything”;
- enough detail for us to verify you are entitled to make the request.
We may ask a verifying question before acting — deleting an organisation on an unverified request would itself be a security failure. There is no charge.
6. What is deleted, and what is not
Deleted: access and refresh tokens, connection records, posts and their content, per-destination delivery records, uploaded media, API key hashes, webhook endpoints and secrets, sessions, members and the organisation itself.
Not deleted: posts already published to a social platform. They live on that platform, and removing them is done there — this service has no ability to un-publish. Also retained: invoices and tax records we are legally required to keep for six years, held in isolation and used for nothing else.
Deletion propagates to backups as those backups age out on their normal 35-day cycle; backups are not restored into service after a deletion in a way that would resurrect deleted data.
7. How long it takes
Self-service deletions are immediate. Requests by email are completed within 30 days and confirmed in writing when they are done.
Further detail on what is stored and why is in the privacy policy.