Where things stand today
THE HELM keeps your account data on secure infrastructure so your Watch, Career and Crew work across devices. A full deletion flow — one that permanently removes your personal data, your profile photo and your sign-in identity — is under active development and is not live yet.
In the app you can sign out today. Sign-out flushes pending progress, ends your session, and clears local caches and scheduled reminders on that device. It does not delete your account or remove your data from the server.
What account deletion will do
When the deletion flow ships, confirming it will permanently remove, from the active application systems:
- your sign-in identity and email;
- your display name, avatar and profile photo;
- your habits, Today’s Orders, logs, screen-discipline entries and Logbook;
- your XP, Career state, Doubloon balance and ledger, Voyages and Standing Orders;
- your Cabin, companion, Bond and Companion Quest history;
- your Crew membership, and the messages, reactions and content you authored or that identified you.
Deletion is different from leaving a Ship. Leaving or being removed from a Crew ends that membership and its shared visibility but keeps all of your personal progression. Deletion removes the account itself.
If you are a Captain
A Captain whose Ship still has other members must Transfer Command to another member first. There is no automatic succession. Once command has been transferred, or if you are the last person aboard, you can proceed.
What may remain
Other members keep their own history and rewards. Some minimal, justified records may persist for a limited time — for example a short-lived note so a restore-from-backup cannot silently resurrect a deleted account, and your Crewmates seeing that a former member has left. Provider logs, authentication audit records and backups follow each provider’s own retention, which is [ TODO: LEGAL REVIEW ]. We will not claim that every copy disappears instantly everywhere.
How to request deletion
The request path is being built alongside the backend. As designed, it will work like this:
- In the app. A “Delete account” action in your profile settings will show you the consequences above, ask for a deliberate confirmation, and — for a Captain — require the Transfer Command step first.
- If you cannot open the app. This page will offer a “Request account deletion” step that collects only the account email needed to start verification. Opening this page, loading a link, or sending an email will never delete anything on its own.
- Verification. We will send a one-time code to the email already on the account. Entering it — a deliberate action, not a link click — establishes a short-lived, deletion-only session. No account is created, and a different email is never accepted as proof.
- Confirmation and receipt. You confirm, and you get a plain receipt showing whether the request is pending or complete. If we cannot verify that you control the account, we route you to support rather than deleting anything.
This is a narrow, deletion-only verification path. It is not a browser version of THE HELM: there is no web Watch, Crew, Career or Cabin, and no general account management on the web.
Related
- Privacy Policy — what we hold and why.
- Terms of Use — suspension and termination.
- Support — everything else.