Mobile Starter Kit

Account deletion

Activate the in-app and public deletion paths stores expect.

The starter includes both deletion entry points:

  • in app: Profile → Settings & privacy → Delete account,
  • public web: a bilingual email-verification flow in legal-site for store forms.

Deletion is more than removing a profile row. The included server path can clean up Auth, database rows, private images/audio, push tokens, Apple authorization, and the RevenueCat customer while recording a resumable receipt.

Prompt

Read agent-skills/wire-account-deletion.md and STORE-READINESS.md. Activate and
verify both the in-app and public deletion paths for my final providers. Extend
cleanup for any user data I added. Keep subscription cancellation separate.
Test partial provider failures and do not claim deletion completed without a
successful receipt.

Important product truth

Deleting the account does not cancel an Apple or Google subscription. The app must explain that and keep store subscription management available.

Public flow setup

The legal site needs the Supabase request/confirm function URLs, final brand and company details, a verified email sender, the deletion secrets, and a scheduled cleanup/retry job. Responses for existing and nonexistent emails must look the same so the endpoint does not reveal who has an account.

Verify before store submission

  • expired, reused, and cross-user confirmation tokens fail safely,
  • a repeated request is idempotent,
  • Auth, RLS rows, private Storage, push tokens, and provider cleanup are handled,
  • active store subscriptions remain manageable and are never described as canceled,
  • a provider outage creates a failed/retryable receipt instead of a false success,
  • the public URL works over HTTPS in English and Spanish.

Re-check the current Apple and Google account-deletion requirements immediately before submission; store rules and console forms change.

On this page