01Pulse · Account management

Delete your Pulse account.

This public Ward & Raven page explains how to request permanent deletion of your Pulse account and what happens to the associated data.

From the Pulse app

This is the most direct process. It lets you initiate deletion without a phone call or a support conversation.

  1. 1Open Pulse and go to Profile.
  2. 2In the Account section, select Delete account.
  3. 3Read the warning, then confirm deletion.
  4. 4Pulse asks you to confirm your identity again using your sign-in method: password in the app, Google or Apple.

Pulse shows Deletion in progress while processing, Deletion complete only after personal-data purge, any applicable Apple revocation and Firebase Auth deletion, or Deletion incomplete with a request reference and a retry option. No final confirmation is shown before every step finishes.

If you no longer have access to the app

You can send a request to Ward & Raven from the Web. The link below opens a pre-filled email to the address actually designated for personal-data requests.

  • Send the request from the email address associated with your Pulse account.
  • Explicitly confirm that you are requesting permanent deletion of the account and associated data.
  • Never send a password, identity document or sensitive data in your message.
Send the deletion request

Ward & Raven will never ask for your password. The contact address is contact@wardandraven.com, which is already published as the personal-data contact.

Identity verification

For a Web request, Ward & Raven compares the address used with the Pulse account address and sends confirmation to that same address. Deletion starts only after confirmation from the associated address. This verifies control of the email address; no password is requested.

02

Data deleted

The Pulse server function first purges personal data, then revokes Apple authorization when that sign-in method is linked, and deletes the Firebase Auth user last. The Firebase deletion trigger remains a safety net. The purge covers the following categories when the account has such data.

Account and profile

Firebase Authentication account, Pulse user profile, preferences, Ward & Raven codes, invitations, community-interest requests and personal progress states.

Contacts, alerts and mutual aid

Trusted contacts, reciprocal links to the account, received or authored alerts, mutual-aid responses, safety reports, blocks and associated technical notifications.

Files and communications

Avatar, report photos, files attached to a deleted household, queued messages and email-delivery audits associated with the account.

Email preferences

The corresponding email contact is deleted from Brevo so that account deletion does not leave an active address on Ward & Raven’s communication list.

03

Shared, anonymized or temporarily retained data

Some data is not deleted at the same moment when it is shared with other people or has already been transformed into measurements without an account identifier.

A household shared with other members

Duration
Until the shared household is deleted by its remaining members.
Reason
Keep common data required by the household’s other members.

Pulse removes your identifier from the member list, reassigns administration if needed, deletes your functional-needs share and removes your identifier from locations or completions you created. The household and its shared data remain available to other members. If you were the household’s last member, the household, its subcollections and files are deleted.

A citizen report created in Pulse

Duration
Until 30 days after the report’s expiry date, followed by deletion in a daily cleanup job.
Reason
Close the report and consistently remove its copies, responses and technical records.

As soon as the account is deleted, the report is closed and removed from the map. Free text, precise address, author identity and photos are deleted. Only a de-identified structured version — generic title, risk type and approximate location — may remain temporarily before full deletion.

Household Resilience Pathway measurement events

Duration
No more than 90 days after event creation; pseudonymized contributions expire 180 days after the start of their measurement period.
Reason
Produce private measurements, prevent duplicate counts and apply privacy thresholds.

The user identifier, household identifier and path, and session identifier are removed on deletion. Remaining aggregate metrics contain no individual identifier, and groups with fewer than 10 households are suppressed.

Current state of a shared action

Duration
For the life of the shared household; the associated historical event expires 90 days after creation.
Reason
Keep the shared state useful to other members without retaining the deleted person’s identity.

For shared organization actions, Pulse removes the identifier of the person who completed the action and marks the actor as deleted. The common state may remain attached to the household without an account identifier.

Messages for a request submitted from the Web

Duration
30 days after the request is closed.
Reason
Allow follow-up on a late confirmation or correction of a processing incident.

The complete emails, any attachments and verification messages are then deleted. Ward & Raven does not request a password, identity document or sensitive data for this process.

Minimal record of a Web request

Duration
5 years after the request is closed, then deletion.
Reason
Demonstrate that the request was handled and allow the establishment, exercise or defence of legal claims in the event of a dispute.

This restricted-access intermediate archive contains only the request identifier, its receipt, verification and closure dates, its outcome, the version of the process applied, and pseudonymized HMAC values for the email address or account identifier. It contains no plain-text email address, message body, attachment or Pulse data.

Data shared with contacts

Trusted contacts stored under your account are deleted. Reciprocal references to your account are also deleted from linked contacts. Copies of alerts previously sent to them are deleted using the server-side recipient list.

Reports that were publicly visible

A citizen report is not kept public under your identity. It is immediately disabled and hidden from the map, and its private data is deleted. The temporary de-identified version described above is then deleted under the 30-day-after-expiry window.