Initiate deletion in the app

Open Account settings and choose Delete Account. The app authenticates the request and shows the scheduled deletion date before submitting it. A webpage or support email is not a substitute for the in-app action.

Before requesting deletion, move any assets you do not want to recover later and preserve independently usable recovery information for Funding, Spot and Personal Gas. Final cleanup destroys Orrerie’s server co-signer; it does not transfer assets, sign a transaction or erase a blockchain wallet.

30-day cancellation window

The 30-day period begins when the server accepts the request. You can cancel in the app before cleanup begins; signing in alone does not cancel it. After the window ends, Orrerie starts account cleanup automatically.

A submitted transaction or provider action with an unknown outcome must be reconciled before related records are discarded. That can delay final completion, but merely having configured a wallet is not a blocker. The app shows the current status and Orrerie checks unresolved outcomes again.

Your blockchain wallets remain

Deleting the Orrerie account removes the Orrerie login, server-held wallet descriptors and server co-signing material. It does not call a blockchain, move assets, change an on-chain wallet or erase a public address or transaction history.

After completion, access to any assets left in a two-of-three asset wallet depends on the remaining phone and offline-card owners and the recovery material you control. Personal Gas remains recoverable only with its separate phone-held phrase and the correct network derivation paths for its EVM, Solana and TRON addresses. Keep those records before deletion completes. Export a Recovery kit from the app first and keep it with them: the Orrerie Recovery tool uses it to find these wallets and, without Orrerie’s servers, sign asset transfers with your phone and offline-card words and Personal Gas transfers with the gas phrase.

What Orrerie removes

Cleanup removes the live Orrerie account, messages and attachments, synced account content, exports, active sessions, eligible provider attribution and server credentials within the documented workflow. Phone-held keys and recovery data remain on devices or physical backups and must be removed by their owner.

Public blockchain records, recipient copies and records independently held by providers remain outside Orrerie’s ability to erase. Orrerie retains only the narrow records described below or records required for a documented legal, security or unresolved-transaction purpose.

Retained records

Minimal permanent closure and public-handle reservation records remain to prevent an erased identity or public handle from being silently reused. Narrow lifecycle and security evidence can remain where needed to prove deletion state, prevent misuse or resolve an unknown operation. These records do not preserve the deleted account’s messages, recovery secrets or reusable login sessions.

The temporary completion-email contact expires no later than 30 days after it is captured and normally clears after the confirmation attempt. Access to the deletion receipt expires 30 days after completion. Expiry of receipt access does not erase the minimal closure record described above.

Backup expiry

Encrypted whole-account archives become eligible to hide 29 days after upload and for deletion one day after hiding. The period runs from each archive’s upload, not from your deletion request. Provider processing, maintenance, object locks or legal holds can delay physical expiry. Selective removal from an existing encrypted archive and physical deletion at an exact hour are not promised.

Help and privacy requests

The in-app deletion screen remains the primary control. For an access, correction or deletion question, use the Privacy Requests page or hello@orrerie.com. Never send wallet secrets or recovery material.