Delete the account without erasing the facts.
This is source guidance, not a live deletion endpoint or a published policy. BriefHarbor has no verified public domain, operational support mailbox, hosted authentication boundary, or provider-retention receipts. Do not submit this draft as App Store or customer-facing deletion evidence.
What the product is designed to do
In the authenticated web operator, a verified human session can open Settings → Account privacy, enter DELETE MY ACCOUNT, and save the export and support receipts before sign-out. The server-side design revokes BriefHarbor session bridges, personal-access tokens, provider access records, and memberships for that account.
For a workspace owned only by that account, the design queues a private-media and metadata purge. In a shared workspace, other members retain the shared work; deleting an account is not a claim that another member’s workspace was erased.
What a receipt means
A local receipt records the requested action and its known BriefHarbor state. It is not proof that Better Auth, Apple, RevenueCat, Stripe, Cloudflare backups, Fal, LightReel, social platforms, email systems, or legally retained records have deleted data. Each external system needs its own authenticated retention and deletion evidence.
Native Delete local library clears the local device’s media and queued local work after cancellation. It neither deletes a web workspace nor withdraws an already completed handoff from a destination app.
Before this becomes operational
BriefHarbor must publish approved privacy and terms documents at a controlled HTTPS origin, verify the support mailbox and response owner, deploy and test the authenticated deletion route, confirm Cloudflare storage/queue purge behavior, and capture provider, billing, Apple, and backup-retention outcomes. Until then, this page is a transparent launch hold, not a request channel.