Delete your P2PChat account and associated data
P2PChat is a non-custodial crypto wallet and messenger. This page explains how to delete your account and the data attached to it — from inside the app, or without installing it — what exactly is deleted, what we are required to keep, and for how long.
This is the fastest route: deletion takes effect immediately and no correspondence with support is needed.
- 1Open P2PChat and unlock it with your PIN or biometrics.
- 2Go to Profile → Edit profile.
- 3Scroll to the bottom of the screen and tap «Delete account».
- 4Read the consequences and confirm. Your sessions end at once and the account is deactivated on our servers immediately.
If the app is already uninstalled, or you cannot sign in, send us a deletion request. We accept a request from anyone who can prove control of the account's public wallet address — installing or reinstalling the app is not required.
You can also send the same details by email to [email protected]
Deletion is irreversible, so we do not act on a request until we know it comes from the account holder. Verification uses public data and a signature only — never a secret.
- 1You send the request with the account's public identifiers: the wallet address, and the username if you remember it.
- 2We reply from our privacy address with a one-time verification phrase, valid for 72 hours.
- 3You sign that phrase with the wallet that owns the address and send us the signature. Signing a message proves control of the address and never reveals your private key. If the app is still installed, confirming the request from that account inside the app is accepted instead.
- 4Once the signature checks out we start the deletion and confirm by email when it is complete.
Once ownership is confirmed, the following is deleted from our systems within 30 days:
- your P2PChat account and its authentication records;
- your profile — username, first and last name, bio, city and country, the phone number if you added one, and your avatar;
- active sessions, device identifiers and push notification tokens;
- your messages, and the media and documents you uploaded;
- the notification encryption key stored for your devices;
- the identifier that links diagnostic reports to your account.
A few records cannot be removed on request: either the law requires us to keep them, or they protect other users. Such data is isolated from the ordinary operation of the service and is never used for profiling or advertising.
| Data | Retention period | Why it is retained |
|---|---|---|
| Transaction records and identity verification (KYC) results | 5 years | Required by the financial, anti-money-laundering (AML) and fraud-prevention rules that apply to us. |
| Security and moderation records — abuse reports, blocks, incident logs | 36 months | Protects other users from repeat abuse and lets us investigate incidents after the fact. |
| Archived record of the wallet address (public address only) | 12 months | Prevents a deleted account's address from being registered again while security holds still apply. No balances, keys or transaction history are stored with it. |
| Backup copies of our databases | up to 14 days | Backups rotate on a 14-day cycle: deleted data disappears from them as the cycle completes and is never restored into the live service. |
Some data is not stored on our servers at all, or is handled by a separate provider. Here is what happens to it when the account is deleted.
| Where the data is | What happens on deletion |
|---|---|
| Wallet backup in Google Drive or iCloud | The backup lives in your own cloud account and is encrypted with a password only you know, so we have no access to it and cannot delete it for you. Delete it yourself: on Android, the P2PChat backup file in Google Drive; on iOS, the P2PChat backup in your iCloud storage. |
| Identity verification (KYC) | The image of your document and your selfie are processed by our verification provider, Didit; we receive only the verification result, which is retained for 5 years as set out above. To have the images deleted on the provider's side, send Didit a request under their own privacy policy. |
| Messages and media | The messages you sent and the files you uploaded are deleted from our servers together with the account. Copies that other participants already received stay in their chats: we cannot remove a message from someone else's account or device. |
| Voice calls | Call audio is never recorded or stored, so there is nothing to delete. Records of the fact that a call took place fall under the security records above. |
| Push notifications (Apple APNs, Google FCM) | The device token is deactivated at once and deleted with the account. Apple and Google discard invalidated tokens on their own side. |
| Diagnostics (Sentry) | Crash and error reports are collected without message content and without wallet secrets, and are kept by Sentry for no longer than 90 days, after which they are deleted automatically. The identifier that links those reports to your account is removed together with the account. |
- Privacy and deletion requests
- [email protected]
- Operator
- Private Company «Mervey Ltd.», Astana International Financial Centre, 010000, Astana, Esil district, 29 Alikhan Bokeikhan, office 42.
- Related document
- P2PChat Terms & Privacy Policy