Store policies (Google Play account-deletion requirement; Apple 5.1.1(v)) require both an in-app
deletion flow and an out-of-app route.
In the app
Profile → My account → Privacy & data:
Export my data — server-assembled personal-data package shared via the OS share sheet.
Delete account — request → 7-day cooling-off (cancellable in the same screen) → finalize. Facility OWNERS are blocked until ownership is transferred or wound down (in-product message). On finalize: memberships/professional profiles deactivated, staff records unlinked, private data (contact, payout accounts, privacy prefs, connections, notifications) deleted, display identity anonymized, sessions revoked. Retained data per DATA_RETENTION_SCHEDULE.md.
If you cannot sign in
Web route: this page — https://hoofbeat.app/delete-account. It describes the in-app flow and is the address to write to if you cannot sign in. It is also the URL given to the Play console as the account-deletion link.
Email route: support@hoofbeat.app with subject "Account deletion" — identity verified by a reply from the account email; processed through the RH-4 console using the same server lifecycle (request → cooling-off → finalize) so guarantees are identical.