On this page
There are two different situations on this page, and they have different answers. Read the one that describes you.
If you have a Publiq account — you signed up, you send email or you run channels through the platform — go to "Deleting your account". If you received a message sent through Publiq by some business, go to "If a business contacted you".
1. Deleting your account and its data
This applies to you if you hold a Publiq account.
Before you ask
Export anything you want to keep. Contacts, templates and message history can be exported from the application and through the API while your account is active. After deletion they cannot be recovered.
How to ask
- Send an email to [DPO EMAIL] from the address on your account, with the subject "Account deletion", naming the organisation you want deleted. Alternatively, open a support ticket from inside the application.
- We confirm receipt and verify that the request comes from an owner of the organisation. We may ask you to confirm from the account email or through the application; we ask for no more than the verification requires.
- We tell you what will be deleted, what we are legally required to keep, and the date on which the deletion will run.
Deadlines
- We acknowledge your request within 2 business days.
- We complete the deletion within 30 days of confirming the request, unless you ask us to delay it so you can finish an export.
- Copies in encrypted operational backups are overwritten within 90 days of the deletion, on the normal backup rotation. Until then they are not accessible for any other purpose.
What is deleted
- Your contacts, audiences, segments and custom fields.
- Your conversations and their message content, across every channel.
- Your email records, templates, broadcasts and automations.
- Your connected channels and every stored credential for them — access tokens, webhook secrets and integration API keys. Disconnecting a channel deletes its credentials immediately, before any of the rest.
- Your knowledge files and the embeddings computed from them.
- Your API keys, webhook endpoints and their delivery history.
- Your user profile, sessions and two-factor secrets.
What is kept, and why
Deletion is not the same as making the company forget every fact. A short, specific list survives, and each item survives for a stated reason:
| Kept | Why | For how long |
|---|---|---|
| Billing and tax records: invoices, payment identifiers, plan history | Required by Brazilian tax and commercial law. We cannot delete an invoice on request | The statutory record-keeping period |
| The audit trail of actions taken in the organisation | An audit trail that can be deleted by the person audited is not an audit trail | Retained; access restricted to security and legal purposes only |
| The organisation record itself, marked as archived | So that the billing and audit history above remains attributable. It carries no contact data and no message content once the deletion has run | Retained |
| The suppression list of addresses that opted out or were erased | It is the record that stops a person being contacted again. Deleting it would allow exactly what the person asked to prevent | Retained. It holds addresses, and nothing else |
| The record that you accepted the Terms and the Privacy Policy | It exists to show which edition you accepted and when. Deleting it would destroy the very thing it proves | Retained |
Nothing retained under this section is used for any other purpose, is sold, or is shared beyond what the law requires.
Deleting an account is not currently a self-service button in the application. It is done by request, through the channel above, so that we can verify the requester is an owner and confirm what will be lost before anything is destroyed. We do not treat cancelling a subscription as a deletion request — cancelling stops the billing, it does not erase the data.
2. Removing data received from Instagram, WhatsApp, Messenger, Facebook or TikTok
If you only want to stop us holding the data of a connected platform, you do not need to delete your whole account.
- In the application, open Channels, select the connected account and disconnect it. The stored access tokens and page or bot secrets for that channel are deleted at that moment, and we stop receiving anything further from the platform.
- You can also revoke our access from the platform's own settings — in Facebook or Instagram under Settings, Apps and websites; in TikTok under the connected-apps settings of your account. Revoking there has the same effect on future data.
- To have the conversation history and channel identities already stored deleted as well, email [DPO EMAIL] naming the channel and the account. We complete that within 30 days.
Where a request is made under the platform's own data deletion callback, we honour it the same way and on the same deadline.
3. If a business contacted you through Publiq
This applies if you received an email, a WhatsApp message, an Instagram or Messenger message, a Telegram message or a TikTok message that was sent using Publiq, and you want your data removed.
Publiq is only the processor of that data. The business that contacted you is the controller — it decided to collect your data, it decided to message you, and it is the one that must answer your request. We cannot delete a record on our own initiative without instructions from that business, because doing so would mean acting on data we do not control.
Step 1 — ask the business directly
Reply to the message, or write to the address in its privacy policy, and ask for your data to be deleted. Every business using Publiq has a one-click way to do it: it opens your contact record, uses the "Privacy (GDPR/LGPD)" panel and selects "Request deletion". That removes your name, email, phone, tags and attributes; redacts your address, the subject line and the variables that were interpolated into the message body — your name, an order number, a delivery address — from the related email records; and adds your address to a suppression list so you cannot be re-imported or contacted again.
If you only want the messages to stop, the unsubscribe link at the bottom of any marketing email does that immediately, and for messaging channels a reply asking to stop is honoured.
Step 2 — if that does not work, write to us
If you cannot identify the business, it does not reply, or it refuses, contact us at [DPO EMAIL] with the subject "Data deletion request". Include as much of the following as you can:
- The email address, phone number or platform username that was contacted.
- The name of the business, or the sender address the message came from.
- The approximate date of the message.
- A copy of the message, if you still have it — for an email, including the full headers helps us identify the sender account exactly.
What we do and how fast
- We acknowledge your request within 2 business days.
- We identify the customer that holds your record and forward your request to it, with a deadline to act.
- We suppress your address on our side straight away, so no further message can be sent to it by that customer while the request is being handled.
- If the customer does not act within 15 days, we escalate, and we may suspend its sending under the Acceptable Use Policy.
- We come back to you with the outcome within 30 days of your request.
You may also complain directly to the Brazilian National Data Protection Authority (ANPD) or, in the European Union, to your local supervisory authority, at any point.
4. What deletion cannot reach
Even without a request, message content does not sit here forever. The text of a conversation is redacted after 180 days without activity in it, and the subject, recipients and personalised variables of an email are redacted after 24 months. What survives is the record that the exchange happened, not what it said. The Privacy Policy sets out every term.
That said, we would rather state the limits plainly than let you assume more than is true:
- A message already delivered is on the recipient's device and in their mailbox or app. Neither we nor our customer can pull it back.
- The messaging platforms — Meta, TikTok, Telegram — keep their own copy of a conversation under their own policies. Deleting your data here does not delete it there; use that platform's own deletion process for its copy.
- Aggregate statistics that count events without identifying anyone — how many messages were delivered on a day, for example — survive deletion, because they no longer relate to an identified person.
- The suppression list keeps the address itself, precisely so it is never contacted again.
5. Contact
All requests on this page: [DPO EMAIL]. Controller: [LEGAL ENTITY NAME], [CNPJ], [REGISTERED ADDRESS]. Related documents: the Privacy Policy and the Data Processing Addendum.
This document is a template generated from how the product actually works. It is not legal advice and must be reviewed by a qualified lawyer before it is relied on with real customers.