Delete your Holdfast account
Last updated September 20, 2026 · Applies to Holdfast on iOS and Android, published by Fremdly.
Use the in-app option first. It is the quickest way to verify ownership and remove the app-owned account data covered by the current deletion flow. The options below appear while you are signed in and the deletion cannot be undone.
Delete in the app
- iPhone or iPad: Open You and choose Delete my account. You can also choose Privacy and your data, then Delete my account.
- Android: Open You and choose Delete my account. You can also choose Privacy and your data, then Delete my account.
- Read the consequences, choose Continue, and complete the fresh sign-in check for the provider you used. If the app asks you to finish local cleanup after an interruption, follow that recovery screen.
If you cannot use in-app deletion
Email [email protected] from the email address linked to your Holdfast account. Use the subject Holdfast account deletion. Do not send a password, Scripture, prayer, note, recall, audio, or transcript content. We may need to verify account ownership before processing the request.
What the app deletes
- The Firebase Authentication account and the app's known account records in Cloud Firestore.
- The synced library and review schedule used for account backup and restore, along with the other account records covered by the current deletion sweep.
- Account-scoped local copies and related local account state, except the device security marker described below, on the device where the in-app flow runs. The app does not send your practice attempts, mistakes, notes, audio, or transcripts as part of this request.
Device-only private recordings, where that feature is available, are managed separately and are not part of cloud account deletion. Delete any retained recordings separately using the recording controls.
Passage removal without an account
You can remove one passage without deleting an account. In Library, open a passage and its more-actions menu. On iOS, choose Archive or Delete from the passage's ••• menu; the same controls are available in Discover → Manage library. On Android, choose Archive passage or Delete permanently from the passage's ⋮ menu, then confirm.
Archive moves a passage to Archived, where it can be restored. Delete permanently removes that passage from this device. For a signed-in account, the app also records the passage deletion for sync. This is separate from deleting the account.
Subscriptions and provider records
Deleting a Holdfast account does not cancel an Apple App Store or Google Play subscription. Cancel separately in your Apple ID or Google Play subscription settings. Apple, Google Play, and RevenueCat handle purchase and transaction records under their own policies; this page does not promise deletion of third-party billing records.
Deletion fence and local markers
The flow intentionally retains a server-side account-deletion fence keyed by the Firebase account identifier in its document path. It contains no Scripture, notes, or practice history and remains to prevent stale signed-in devices from writing records again. This server-side key is distinct from the one-way SHA-256 Firebase-user-ID digests retained locally for ownership and recovery. On iOS, the local deletion workflow also keeps a phase marker; after the local reset completes, sync metadata retains a content-free completed-deletion digest for account-isolation checks. Local markers contain no raw user ID or practice content.
Device security marker on Android
Android keeps a content-free marker showing that an account has previously used this app installation. The marker is a one-way SHA-256 digest derived from the first account's Firebase user ID, or an “unknown previous account” marker if ownership cannot be recovered. It contains no Scripture, notes, prayers, practice history, email address, or readable user ID. It stays on this device to prevent a later account's cleanup from erasing another person's preserved data.
This marker survives sign-out, account switching, in-app account deletion, and recovery resets. It has no timed expiry and remains while the app's local data remains. The Android app excludes its local data from Android cloud backup and device-to-device transfer.
Retention
When the in-app flow completes, it deletes and verifies the app-owned Firebase account records covered by the current sweep before it finishes. Matching quota records for the deleted account are removed by asynchronous cleanup and may finish after the in-app flow; unrelated records are untouched. This is not a promise of complete erasure of every provider, service, log, backup, or separately configured backend record. There is no single app-controlled retention period for those copies. Firebase, Apple, Google Play, and RevenueCat may retain records under their policies for purposes such as security, fraud prevention, billing, tax, legal compliance, or backup operations.
Contact
For a deletion request or question, email [email protected]. Do not include a password or any private practice content.