How deletion works
You can delete your entire Modo Próspera account:
- In the app: Account → Data and privacy → Delete my account. (In Spanish: Cuenta → Datos y privacidad → Eliminar mi cuenta.) The app first shows a per-workspace deletion plan and requires exact confirmation text before anything is deleted.
- On the web: https://modoprospera.com/eliminar-cuenta/?lang=en describes the same steps and the external request path (email the support contact from the Google account address you use to sign in; requests are verified against your sign-in identity and completed within 15 days, unless a workspace you own is blocked by the member or shared/joint-account conditions below, in which case we tell you what is required).
What happens per workspace:
- A workspace you own with no other active members is deleted entirely, as described under Export And Deletion.
- A workspace you own that still has other active members cannot be deleted by full-account deletion in the current protected release. Remove each non-owner member through the household controls and retry. Deletion of a workspace with shared/joint accounts remains unavailable unless a separately reviewed flow is deployed; role management or ownership transfer does not make that flow available.
- A workspace where you are a member or View-only user is left, not deleted: your access, sessions, and pending invitations for that workspace end, and the beta feedback you wrote there is deleted, but the household's own data (closed months, transactions, audit history) remains with the household.
Household invitation, ownership transfer, and per-account permission controls remain unavailable until their hosted capability is activated and negotiated by the protected client. Source code or database schemas alone do not make a control user-visible. Multi-party deletion consent is not available in this release even when the other household controls are active.
After your workspaces are processed, all your remaining sessions are revoked. If nothing else references your account, the account record itself is deleted. If retained audit evidence in a household you left still references your account — which is always the case after leaving a shared workspace — Modo Próspera keeps a minimal account record as an opaque derived reference: its display name is replaced with the fixed internal placeholder "Cuenta eliminada" — Spanish for "deleted account"; the stored value is the same whatever language you use — and it contains no name or email. A later fresh sign-in with the same Google account can associate that pseudonymous reference with the new account lifecycle generation, but it does not restore deleted profile, membership, workspace, or financial data.
Modo Próspera's backend cannot delete your Google/Firebase sign-in record: after the backend confirms deletion, the app deletes your Firebase Authentication user from the device, asking you to sign in again first if Firebase requires a recent login. If that final step fails, the app signs you out, and you can also remove Modo Próspera's access from your Google account settings. For deletion requests made by email, the operator deletes the Firebase Authentication record manually from the Firebase console as part of fulfillment.
Deleting your account does not permanently block the same Google account from signing in later. A later sign-in is accepted only from verified Firebase authentication whose authentication time is after the latest completed deletion. It creates a new account lifecycle generation and a distinct default workspace. The old workspace tombstone is never cleared or reused, and the new generation does not restore the deleted account's profile, memberships, workspaces, or financial data. The permanent privacy-minimized lifecycle history described under Retention enforces that boundary.
Export And Deletion
An eligible effective owner can request an access-filtered export of the active workspace in the app, including its setup/domain data and eligible parsed compatibility/data-quality evidence, normalized annual-history data, versioned mapping templates, and the requester's unaggregated opt-in telemetry without raw tokens, original statement bytes, or sibling-workspace records. A separate cash-ledger export is available to any signed-in person with current export permission for a cash account. It is limited to that person's export-visible cash movements, append-only revisions, and period seals; owner status does not bypass a private holder's account boundary. A member or View-only user does not receive the in-app full-workspace export and can ask the support contact for a verified access copy of other personal data and records we may lawfully disclose to them. Household/business owners can delete the active workspace after exact confirmation. Deletion removes that workspace's setup/domain, account, invitation, feedback, import, month-close, transaction, and audit data while also removing its normalized annual-history evidence, mapping templates, telemetry consents, and unaggregated telemetry events, while preserving other workspaces. Already-created k >= 5 telemetry aggregates age out under the 13-month limit rather than becoming user-level export records. Signed-in users can also delete their entire account, as described under Account Deletion. A member or View-only user can instead leave a household through the standalone leave action, and an effective owner can remove a non-owner member. Either action revokes the affected person's household access and active household sessions, and removes that person's optional unaggregated statement-format telemetry and consent, closed-test statement enrollment, and authored mapping-template lineages, without deleting the household's own closed months, transactions, or audit history. It keeps that person's earlier feedback until the household is deleted or the feedback author deletes their entire account.
The records intentionally retained permanently after deletion are:
- the minimal deletion tombstone (workspace/household ID and deletion timestamp) described above;
- already-recorded provider cleanup obligation/attempt evidence, retained indefinitely as security and audit evidence as described under Retention;
- the privacy-minimized account-lifecycle history described under Retention, retained to fence old requests and prove the boundary between completed deletion and a later new account generation;
- if an encrypted statement artifact ever existed for the workspace, the minimal external-artifact cleanup record: the cleanup obligation, its attempt history, and the verified-absence proof, containing only opaque or digested storage-locator and safe-manifest identities, reasons, states, and timestamps — never a filename, key material, encrypted or plaintext content, or statement values. An annual-history import creates such a record, and it survives the deletion of the workspace it came from so that the pending external deletion can still be finished and proven; and
- the minimal opaque account reference kept when retained audit evidence in another household still references a deleted account, with its display name replaced by "Cuenta eliminada".
Temporary cleanup records are consumed when their work is complete.
Deleted household data may remain recoverable for a short period inside the hosted database provider's backup or restore window. If Modo Próspera ever restores the database from backup after a deletion request, we will reapply affected deletion requests before returning the service to beta users.