Delete Your Account and Data

Version 2.4 · Effective 4 August 2026 · Last updated 4 August 2026 · Matches Privacy Policy v2.7

What changed in 2.4. The deletion code changed and version 2.3 of this page still described the old behaviour. Three corrections, all in your favour except the last: an order you placed without an account is now deleted with the account whose verified email address placed it; your address is now taken out of the order of anyone who bought you a family place, and so is the one-click removal link's reach; and a family plan you paid for is not deleted — it survives emptied of you, so that the memberships on it run to the end of the term already paid for.

You can delete your Omnisio account yourself, from inside the app, at any time. Deletion is immediate and irreversible: there is no waiting period, no approval step, and no recovery window. This page describes exactly what the delete button does, what survives it, and why.

1. Delete From Inside the App

There are two ways to reach the control. They are the same control and do the same thing:

  1. Open Omnisio and go to the More tab.
  2. Open the delete control — either Privacy & Trust → Your Data, or tap your profile picture at the top right to open Profile & Settings and scroll to Data & Privacy.
  3. Tap "Delete Account" — described in the app as "Permanently deletes your account and all data".
  4. Confirm twice. The first alert ("Delete My Data") asks you to choose Delete Everything. The second ("Confirm Deletion") asks you to confirm once more. There is no third step — that second confirmation deletes. The app signs you out and returns to the welcome screen once the server confirms.

The in-app flow deletes the whole account, and we do not email you afterwards. It offers no category picker: it is all of it or none of it. We send no confirmation email and no reference number, because there is no request to track — by the time the app signs you out, the deletion has already happened. Controls that delete only part of your data exist separately and are listed in §5.

If you cannot open the app

If you have lost access to the app or your sign-in, write to dpo@omnisio.app:

To: dpo@omnisio.app
Subject: Account Deletion Request

I request the deletion of my Omnisio account and its data.

Account email: [your email address]
Full name: [your name]

I understand that this action is irreversible.

You can also send a signed written request to our registered address:

Oney Finansal Danışmanlık Turizm ve Dış Ticaret AŞ
Esentepe Mah. Kore Şehitleri Cad. Yonca Apt. No:1-3 Daire 6
34394 Şişli/İstanbul/Türkiye

We answer requests sent by email or post within 30 days (KVKK Article 13). Before deleting, we check that the request comes from the account holder — usually by replying to the address the account is registered to. The deletion we then run is the same one the in-app button runs.

2. What Gets Deleted

Deleting your account removes every record we hold that is keyed to you. The rows below are the actual categories the deletion sweeps, not a summary:

Data CategoryActionStatus
Account and profile (name, email, date of birth, biological sex, country, profile picture)Deleted from our database, and your sign-in is deleted from Firebase Authentication. If somebody bought you a place on a family plan, your address is taken out of their order in the same operation — out of the place itself and out of the frozen list of addresses behind it. Nothing of yours is left in their record. See §3Deleted
Sign in with AppleThe stored Apple token is deleted, and we ask Apple to revoke the sign-in grant. If Apple's endpoint refuses or is unreachable, the deletion still goes ahead and the attempt is recorded — you can always withdraw the grant yourself in Settings → Apple ID → Sign in with AppleDeleted
Wellness and wearable data (heart rate, HRV, sleep, activity, temperature), including imported history and every derived scoreDeleted, together with the cached calculations built from itDeleted
Blood test reports and the biomarkers read from themDeletedDeleted
Nutrition: meal analyses, food items, corrections, daily summaries, recommendationsDeletedDeleted
Daily plans, logs, streaks, achievements, workouts, runs (including GPS routes) and breathwork sessionsDeletedDeleted
Journal entriesDeletedDeleted
AI conversations and messages, daily insights, deep health reports, and your consent recordDeletedDeleted
Community: friendships, teams, challenges, cheers, shared metric values, and blocks — both blocks you placed and blocks placed on youDeletedDeleted
Paired devices, sync sessions and their payload archives, device replacement historyDeletedDeleted
Notification history and referral records (on both sides of a referral)DeletedDeleted
Data exports you requested, including the export file itselfDeleted — an export you downloaded yesterday leaves no copy on our serversDeleted
Credentials: API keys, OAuth tokens, authorisation codes and consentsDeleted — they stop authenticating immediatelyDeleted
Subscription records we hold (subscription state on your profile, RevenueCat subscription events)Deleted. We never store card numbers at all — see §6Deleted
Orders you placed with us — the order itself, its line items, the payment attempts and the payment provider's notification archive. An order from this shop carries no account at all, so what identifies it as yours is the email address your account has verifiedDeleted with the account, in the same sweep, keyed on that verified address. Where an account proves no verified address, this step does not run and the deletion receipt records that it was skipped — see §3. This is not the answer a statutory retention period would give, and the reason it is the answer today is set out in §3Deleted
A family plan you paid for — the order carrying between three and ten other people's membershipsNot deleted, and emptied of you instead. Your email address, your phone number, your name and your delivery address are erased from it, your own place on it is emptied, and the order can no longer be opened with the reference. The other members keep their memberships, their own addresses and their own data until the last day of the term you paid for; they are told that end date and never told about you. Nothing renews — there is no mechanism here that renews a membership by itself (Privacy Policy §14.6)Kept, emptied of you
Currency conversion stamps, acceptance timestamps, discount codes and stock reservations attached to those ordersDeleted with the order they sit onDeleted

Omnisio does not collect genetic or DNA data. Earlier versions of this page described a genetic-data deletion process, raw genetic files and partner-laboratory destruction certificates. None of that exists: no genetic data is collected, stored or analysed anywhere in Omnisio, so there is none to delete. The Privacy Policy §3 lists everything we do collect.

3. What We Do Not Delete, and Why

Three things survive account deletion because we keep them on purpose. Four more situations sit outside the delete button's reach for reasons that have nothing to do with what we would prefer, and they follow the table. We list them all because "delete" should not need footnotes.

RecordWhy it staysStatus
Moderation reports — reports you filed, and reports filed about youA safety record that disappears the moment its subject deletes their account is not a safety record: harass, get reported, delete, register again with a clean queue. Once your account row is gone, the identifiers in those reports point to nobody. Blocks are not in this category — they are deleted with your account. See Privacy Policy §8.3.Retained
Credential audit log (API key and OAuth events: which key, what happened, when)It carries no email, no token and no health data, and it is the trail that protects every other account from credential abuse. Deleting it on request would make that protection erasable by the person abusing it.Retained
The deletion receipt: your former account identifier, the time, and whether the Apple grant was revokedIt is the only proof the deletion happened. It contains no wellness data. Deleting it with the account would leave us unable to show that we honoured your request.Retained

If you believe a moderation record about you should be erased, write to privacy@omnisio.app. We weigh the request against the safety interests above and give you an answer.

The statutory retention, and why nothing is sitting under it today

Turkish tax and commercial law require an invoice, and the commercial books behind it, to be kept for a fixed number of years — five under the Tax Procedure Law, ten under the Commercial Code, and where the two point at the same document the longer one applies. That obligation does not bend to an erasure request, from you or from anyone. The ten years are also not counted from the day you order: Article 82/6 of the Commercial Code runs the period from the end of the calendar year the record was made in, so an order placed in March 2026 would be kept until the end of 2036, not until March 2036.

None of that is holding anything back today, and we would rather say so than let the paragraph above imply otherwise. We do not issue invoices ourselves yet — the accounting and e-invoicing integration is not connected — so there is currently no document under that lock. That is why an order attached to your account is deleted with your account rather than kept, and why §2 lists it as deleted. On the day we start issuing invoices, the invoice and the order behind it stop being deleted with an account, and this page will say so in that release, not before it. The Privacy Policy §18 carries the same split, field by field.

If you ordered without an account

You can buy from us without creating an Omnisio account, and every order from this shop is placed that way — no order carries an account. Account deletion now reaches one anyway, and until this version this page said it did not. The route in is the email address your account has verified: an order placed with that address is yours, and deleting your account deletes it, together with its line items, its payment attempts and anything a provider sent back with it.

One order is not deleted, and it is the one that is not only yours: a family plan you paid for. Other people's memberships sit on it and run to the end of the term already paid for, so the order survives with everything that identified you erased from it (Privacy Policy §14.7). A family checkout that never took money has nobody on it, and it is deleted like any other order.

Where there is no verified address, none of this runs. The account and everything attached to it still go, and the deletion receipt records that the address-keyed step was skipped — we would rather leave an order behind and tell you than erase somebody else's because an unproven address happened to match. In that case, or for an order placed under a different address, write to privacy@omnisio.app with the order reference. What we can then do is bounded by the same retention as any other order (the statutory retention above, and Privacy Policy §14.7): what is not part of a record we are required to keep, we remove.

If someone bought you a place on a family plan

On a family plan, the person paying enters the email addresses the places are for. If yours was one of them, your address was written into their order as well as into the place itself.

Deleting your Omnisio account now takes it out of their order too, and until this version this page said the opposite. Both copies go in the same operation: the place, and the frozen list of addresses their order was built from. Nothing of yours is left inside their record, and there is nothing left for you to write to us about separately. They are left with a place carrying no address and no reason for why it emptied. What the person who paid sees, then and afterwards, is the status of the place — never your name, never your address, and never any of your wellness data (Privacy Policy §14.6). This runs off the email address your account has verified; where an account proves none it does not run, and you can write to dpo@omnisio.app to have it dealt with as its own request.

If you were invited to a family plan and never signed up

You may be reading this because an email arrived saying somebody bought you an Omnisio membership, and you have no account with us and do not want one. You have rights here and they do not depend on becoming a customer — but none of them run through this page's delete button, because you have nothing to delete with it.

The full account of what we hold about an invited person, and on what legal basis, is in Privacy Policy §17.1.

Two more things are outside the reach of the delete button, for different reasons. Heart signal readings stay on your phone and never reach our servers, so deleting your account does not remove them — delete them in the app or remove the app (Privacy Policy §10). Copies held by other services — Apple Health, your wearable's own app, your App Store purchase history — belong to those services and must be managed there.

4. Timeline

Immediately — the account is erased

The purge runs as a single database transaction when you confirm. Your sign-in is deleted, we ask Apple to revoke any Sign in with Apple grant, and the deletion receipt is written — including whether that revocation succeeded. This takes seconds, not days.

Within 30 days — requests sent by email or post

Requests that do not come through the app are answered within 30 days (KVKK Article 13), after we verify that you own the account.

Encrypted infrastructure backups

The deletion above removes your record from the live service straight away. Where an encrypted infrastructure backup still holds a copy, that copy sits outside the live service: it is not used to run the app, to sign anyone in, or to answer a request about you, and it is overwritten as that backup ages out of its retention cycle. For the retention period that currently applies to those backups, or for written confirmation that your deletion was carried out, contact dpo@omnisio.app.

5. Deleting Only Part of Your Data

The account-deletion button has no scope picker, but several controls in the app delete one kind of data while your account stays active:

There is no separate control for deleting blood test results, sleep data or nutrition logs as categories. If you want one of those erased without deleting your account, write to dpo@omnisio.app and we will do it manually.

6. Before You Delete

7. Contact

For questions about deletion: