Draft for owner and legal review · OWNER REVIEW REQUIRED

Data choices

Data deletion and disconnects

Disconnecting an institution and deleting dozzop data are different actions. No unauthenticated destructive deletion action is available on this page.

Draft effective and last updated July 28, 2026

Requesting deletion

A verified public request method has not yet been published. Until the owner provides one, this draft is not production-ready.

OWNER REVIEW REQUIRED: public support and deletion-request method.

When published, the process should ask for only enough information to locate the dozzop account and verify ownership. It must never ask for a bank password, Plaid token, access token, API key, magic link, or complete financial export.

Identity verification

Before deleting private application data, dozzop must verify that the requester controls the relevant account. Verification should use the existing authenticated account or another privacy-safe process—not institution credentials.

What may be deleted

  • Authentication/profile information, subject to provider process.
  • Notes, tasks, contacts, companies, and related authored records.
  • Authored Finance records, import data, connected-account records, normalized transactions, review decisions, and related audit material, subject to a reviewed safe deletion process.

Automated destructive account deletion is not implemented by this public-readiness phase.

Plaid disconnect versus dozzop deletion

A Plaid disconnect removes or invalidates the remote connection, deletes the encrypted access credential held by dozzop, and stops future synchronization. The current implementation retains normalized account and transaction history after disconnect so prior observations and owner-reviewed decisions remain understandable.

Deleting that retained history requires a separate, owner-verified dozzop deletion request. Disconnecting alone is not a complete dozzop data deletion.

Backups and limited retention

Deleted information may remain in protected backup copies until the applicable backup-retention period expires. Limited records may also need to be retained when reasonably necessary for security, fraud prevention, dispute handling, or a legal obligation. These qualifications are drafts for appropriate legal review, not a claim that a particular exception always applies.

Expected handling

  • Receive the request through the verified public support method.
  • Verify account ownership without collecting financial credentials.
  • Clarify whether the request is disconnect, deletion, or both.
  • Identify affected application and provider data.
  • Confirm completion and any qualified retention limitation.

For safe request guidance, review the Support page.