← All news

Data portability on Seldeo: export, delete, and take control

The two levers you have

Every Seldeo account has two hard levers that put you in control of your data:

  1. Export. Under Settings → Privacy → Download your data, you can request a ZIP export of everything on your account that we can hand back to you.
  2. Delete. Under Settings → Account → Delete account, you can start a thirty-day countdown to permanent deletion. Nothing about the deletion is reversible after the countdown ends, and nothing about the deletion requires you to talk to a support agent to complete it.

The rest of this post is the honest version of what those two buttons actually do.

What's in your export

The ZIP export includes:

  • Posts — every post you've published, with its media files, audience, timestamp, and reactions.
  • Stories & reels — every story or reel you posted, with their music track licence information where a licensed track was attached.
  • Comments — every comment you left on your own posts and on others'.
  • Direct messages — the plaintext of messages your currently paired devices could decrypt at the time of export. Messages your devices could not decrypt (older sessions on now-lost devices) cannot be exported, because we cannot decrypt them either.
  • Profile — display name, bio, profile photo, links, language and region preferences, and every version of these fields you've had over the account's history.
  • Circles — the names and memberships of every Circle you've defined.
  • Reactions & saves — a list of posts you reacted to or saved.
  • Call history — start and end times, participants, and whether the call was voice, video, or a screen share. Call audio and video is not recorded and cannot be exported.
  • Consent history — every time you changed a consent- affecting setting (personalised ads, cookies, discoverability, memorial-contact designation), with a timestamp.
  • Advertising history — the aggregate of what advertising identifiers we've associated with your account (short answer: as little as we can, subject to your consent state).

Formats

  • Post bodies and comments: Markdown.
  • Metadata: JSON, one file per top-level category.
  • Media: original binary. If you uploaded a JPEG, you get a JPEG back; if you uploaded a 4K H.265 clip, you get a 4K H.265 clip back.
  • Voice notes: original codec (usually Opus at 32 kbps).
  • Everything is packaged into a single ZIP with a top-level README.txt describing the layout.

The export is generated by an on-demand job. For most accounts it completes within a few minutes; for larger accounts (a lot of media, especially video) it can take several hours. You'll get an in-app and email notification when the archive is ready to download, and the archive stays available for seven days after that. Downloads are one-per-request; you can start a new request as soon as the previous one has completed.

Deletion

Settings → Account → Delete account starts a thirty-day countdown. Between the moment you press the button and the end of the thirtieth day:

  • The account is hidden from friends and search.
  • You cannot post, message, or call from the account.
  • Signing in from any device unblocks the account and cancels the deletion. This is the only path to reversal.

On the thirty-first day:

  • Posts, stories, reels, comments, reactions, and profile data are permanently deleted from primary and secondary storage.
  • Media files are permanently deleted from object storage.
  • Direct message ciphertext is deleted from our servers. On the paired devices of your contacts, the plaintext they hold remains, because we cannot reach into another person's device to erase content they've received. This is a real privacy limitation of any end-to-end-encrypted system, and we describe it plainly rather than pretending it isn't there.
  • Aggregated telemetry that was already anonymised at collection time (region-level engagement counts, and so on) is not deleted, because it does not identify you.
  • The deletion is logged in our transparency log, with your account ID replaced by an irreversible hash.

Deletion is complete and permanent by day 45 across all backups.

Why thirty days, not ninety

The industry convention for accidental-deletion protection is 14 to 90 days, and most large networks sit at the top of that range. Ninety days gives support teams more time to help a user recover an account they didn't mean to close.

We chose thirty days because:

  • Thirty days is enough time for someone who accidentally hit the delete button (a real, recurring event) to change their mind. We looked at the industry data on account-recovery requests: the vast majority happen within the first seven days after deletion, and after 21 days the tail is effectively empty.
  • Ninety days is not enough time for the industry-standard argument (support recovery) but is enough time for something much worse: giving state actors a wide window to compel the reactivation of a deleted account. A shorter deletion window narrows that surface.

If you know you want to delete and you want to skip the countdown entirely, email deletion@seldeo.com from the address on file and ask for immediate deletion. We honour that request within 24 hours.

What we keep after deletion

We retain a small amount of data even after account deletion, each item for a specific reason:

  • Account ID (hashed). So we know the account existed and cannot be trivially re-created with the same identifier.
  • Ban and safety history. If the account was terminated for a Community Guidelines violation, we keep the record so a re-created account with the same person on the other side of it can be linked. Post content itself is deleted; the record is a boolean plus a category.
  • Financial and legal records. In the small number of cases where the account was a party to a monetized relationship (creator payouts, refunds, or law-enforcement matters), we retain the transaction record for the statutorily required period, then delete it.

Nothing else is retained.

Portability to other services

The export format is designed to be transferable. The Markdown

  • JSON layout means you can re-import your posts into a Markdown-friendly blog engine, a static site, or a personal archive tool with a few hours of scripting. If you want to take your account somewhere else, we support you doing it, and we won't try to lock you in by using proprietary formats.

If you're building a portability tool for Seldeo exports and want feedback on the format, email developers@seldeo.com with a prototype. We publish the export schema on request.

What we still owe you

  • Continuous exports. A future feature that lets you auto-export your account to your own storage on a schedule.
  • Partial deletion. Delete just direct messages, just posts older than a certain date, or just call history — without deleting the whole account.
  • Faster archives for large accounts. Our engineering team is working on parallelised archive builds so a large-media export completes in minutes instead of hours.

The point of Seldeo is to be a place you choose. If you choose to leave, we want the door to be as clearly marked and as easy to walk through as the door in.