Delete Your Moogoose Account
Last updated: 1 September 2026
This page explains how to delete a Moogoose account provided by Moogoose Limited. Your Moogoose account authenticates cloud-powered features and owns its available credit balance. It is separate from the local Writing Profile that Moogoose uses to personalise writing across your apps.
Delete Your Account in the App
Open Manage Moogoose → Delete Moogoose Account. The app asks for separate confirmation, obtains fresh Firebase ID and App Check tokens, and sends the deletion request to the Moogoose backend.
The backend verifies the request, disables the account, creates a durable deletion job, and returns an exact pending acceptance. Only that exact acceptance lets Android clear app-owned local data and sign out. An unavailable server, invalid token, denied request, network failure, or unclear response does not let Android assume that the request was accepted.
What Happens After Acceptance
A protected, bounded server worker continues the deletion even if the app closes or is uninstalled. It removes the environment's known user document and known subcollections, including protected AI and public-business research request records, encrypted replay children, journey guards, action claims, AI reports, the content-free report-rate record, the current credit wallet, available balance, welcome, promotional and paid lots, reservations, settlement evidence, and user-linked ledger. It also removes the separate welcome-credit eligibility claim. It then deletes the linked Firebase Authentication user.
Before removing the user-linked financial records, the backend retires the old random Google Play account generation and removes the Firebase user ID and Play account identifier from the limited retained financial record. If a new account is created later, it receives a new account generation. An old delayed Google Play notification cannot add credits to the new account.
Deletion is complete only after the worker verifies those steps. The job and its account-recreation lock are then removed.
Request Deletion Without App Access
Email hello@moogoose.com with the subject Moogoose account deletion request. Where possible, write from the email address associated with the Google Account used for Moogoose.
Moogoose Limited will verify that the request relates to the Firebase-linked account before initiating deletion. Verification may require a fresh supported sign-in or another proportionate check that demonstrates control of the account. We will never ask for your Google password, two-factor authentication code, Firebase token, or App Check token by email.
What Account Deletion Removes
- The Moogoose user document and its known subcollections in the relevant environment.
- Protected request records, Quick Profile version 4 encrypted replay children, journey guards, action claims, submitted AI reports, and the content-free report-rate record linked to the account.
- The welcome-credit eligibility claim linked to the account.
- The current credit wallet, available balance, all unused welcome, promotional and purchased credits, credit lots, reservations, settlement evidence, and user-linked ledger.
- The old random Google Play account generation, after the backend removes direct account identifiers from the limited retained financial record.
- The linked Firebase Authentication user after the known server-side account records have been removed.
- App-owned local data on the requesting device after exact in-app acceptance, including the version 4 session and pending-audio data, followed by sign-out.
The protected identity record contains only createdAt, identityProvider, lastSeenAt, schemaVersion, and status. It does not contain your email, name, profile photo, Writing Profile, conversations, screen content, audio, prompts, or replies.
Temporary Job, Lock, and Manual Review
The temporary deletion job contains the Firebase user ID and bounded deletion state only while they are needed to complete deletion. To prevent account recreation during that process, the backend also uses a temporary keyed hash of the Google provider subject. It does not store the raw provider subject in the lock.
The worker deletes only the known account structure. Unexpected server data stops broad deletion and can delay completion for manual review rather than being deleted blindly. The job and lock are removed after verified completion.
What Is Not Deleted
- Your underlying Google Account is not deleted.
- Deleting a Moogoose account does not cancel or refund a Google Play purchase. Applicable Google Play refund processes and statutory consumer rights continue to apply.
- Limited pseudonymous purchase, refund, void, accounting, and fraud evidence can remain for the financial and legal purposes described below.
- Clear All Data and uninstall remove local app data but do not delete the Firebase Authentication account or Moogoose server record.
- An email deletion request cannot directly clear Moogoose data stored on your devices. Use Clear All Data or uninstall Moogoose on each device where local data remains.
- Copies of diagnostic files or other information you previously chose to share with another recipient are controlled by that recipient.
- Google's limited authentication retention and security or legal records governed by Google's terms are not erased directly by the app.
All unused Moogoose credits are permanently lost when the account is deleted. The welcome-credit eligibility claim linked to the account is also deleted.
Retention After a Request
Quick Profile request parents, journey guards, and action claims have the logical expiry periods described in the Privacy Policy, and encrypted replay children become unavailable after 30 minutes. Firestore TTL physical deletion can occur later. An accepted account-deletion job removes these known records sooner as part of the durable process.
After account deletion, Moogoose retains only the limited pseudonymous purchase, refund, void, accounting, and fraud evidence needed for the stated financial or legal purpose. These records contain no email address, Firebase user ID, Google Play account identifier, Writing Profile, messages, screen content, or audio. They become eligible for automatic deletion seven calendar years after the relevant financial event. Automated Firestore TTL makes each record eligible for physical deletion after that date.
An unfulfilled Google Play purchase keeps no retained purchase token and remains unconsumed for Google Play cancellation or refund. If credits were delivered but Google Play consumption is incomplete, only a Cloud KMS-protected purchase token can remain until bounded reconciliation consumes the product and clears the token. Purchase tokens and direct account identifiers do not enter diagnostic logs or exports.
Firebase Authentication information is handled under Google's retention practices. Google states that logged IP addresses are normally retained for a few weeks and that deleted account information may take up to 180 days to be removed from live and backup systems.
Google Cloud Logging retains ordinary service and request logs for the configured operational period. Google's _Required audit bucket retains required administrative and system records for 400 days. These records are not used for advertising.
Contact
Moogoose Limited
Registered in England and Wales · Company number 17333615
Registered office: 75 Charlton Close, Bournemouth, BH9 3PS, United Kingdom
Email: hello@moogoose.com
For more information about local data, Firebase Authentication, diagnostics, and your data-protection rights, read the Moogoose Privacy Policy.