Deleting your account is immediate and permanent. There is no grace period and no restore. Export your logbook and schedule first if you want to keep them — Settings > Data & Storage > Export Data Archive.
Read both lists below before you confirm. They describe what this action actually does, which is not the same as "everything about you is erased".
- Your server backup
Profile (name, employee ID, base, seat, hire date), schedule and sequence backups, DECS imports, logbook backup, calendar events, and any shared calendar feed link you had published — including anything that was set aside if your employee number was ever reassigned to another account.
- Your identity binding and usage records
The employee number bound to this account, your authorised-user record (email and display name), and the presence and app-usage telemetry rows keyed to your sign-in account.
- The server's access log for your account
The API writes one row for every authenticated request, carrying your account, the email on it, the network address it came from and the device's user agent. Every one of those rows is deleted, including the one written by the deletion request itself.
- Your cloud account
Your Cloud Firestore profile document and your crew directory entry, then your Firebase sign-in account itself.
- This phone's app storage
Profile, schedule, logbook, snapshots, calendars, saved settings, the messages cached on this device, this device's message encryption keys, and the employee number the DECS terminal keeps. Uninstalling the app afterwards clears anything Android still holds for it.
You are entitled to know this before you delete, not after.
- Proof that you accepted the legal documents
Which document versions this account accepted and when. Your employee ID is cleared from those rows on deletion; what remains is a one-way hash, the document type, the version and the date. It is kept as evidence that consent was given, and it cannot be deleted.
- Records of an employee-number claim
If your employee number was ever taken off another account, or taken off yours, that record names both accounts and stays. It is evidence about the other pilot as well, so it is not yours alone to erase. For almost every account there are none of these.
- Security incident records
Failed or anomalous authentication attempts are logged by network address, and a few name the account that made them. An account cannot erase the record of its own attempt to reach something it was refused. For almost every account there are none of these.
- Messages you already sent
Base channel posts (ORD, DFW, MIA, PHX) are a shared bulletin board and stay in the channel. Direct messages are stored as ciphertext the server cannot read, but deleting your account does not remove those stored copies.
Deleting your account here does the same thing as Settings > Legal & Privacy > Delete Account inside the app.