Account deletion
How to request deletion of your Spicy Dare account and of the associated data — from inside the app, or by a simple email, with no account and without installing the app.
Last updated: 4 August 2026
App and publisher concerned
App: Spicy Dare (also written “SpicyDare”)
Android identifier: fr.iitech.spicydare — iOS identifier: fr.iitech.spicydare
Publisher and data controller: INTIMATE INNOVATIONS TECHNOLOGIES (short name
IITECH), a French simplified joint-stock company (SAS) with share capital of €14,100
Registered office: 5 place du Onze Novembre 1918, 13280 Arles, France
SIREN: 942 003 286 — SIRET (head office): 942 003 286 00013 — Trade register: RCS Tarascon 942 003 286
Contact: contact@iitech.fr
Request deletion by email — no account, no app install
This is the main route, and it requires neither an account, nor the app, nor any form:
- Write to contact@iitech.fr, with “Account deletion” as the subject line.
- State the email address the account was created with — the one that receives the sign-in link, or the one attached to your Apple or Google identifier. That is the only thing we need in order to find the account.
- If you also want the retained record described below to be physically destroyed, say so explicitly, for example: “I request the permanent deletion of my data”.
We reply to that same address. No supporting document is required by default; we may ask you to confirm from the address concerned if there is any doubt about who is making the request.
Deleting from inside the app
If the app is installed and you are signed in:
Settings → Data and account → Danger zone section → Delete my account, then type the word DELETE to confirm.
The action is immediate and irreversible: it erases the local data listed below and sends the account deletion request to the server.
What is erased on your phone
Most of what you entrust to Spicy Dare exists only on your device, encrypted with AES-256. Deleting your account from inside the app erases, immediately and permanently:
- your local account profile and every participant profile (nicknames, avatars);
- practice preferences and their directions, as well as declared anatomy (GDPR Article 9 data);
- recorded consents and the record of your acceptance of the terms of use;
- the evening notebook and memory, the current evening state and the list of evenings;
- profile lock credentials (PIN, pattern) and the local audit log;
- the session token, which signs you out.
None of this data is on our servers: we have never held a copy of it. An email request therefore cannot reach it — that is to your advantage, but it means that only the in-app action above, or uninstalling the app, makes it disappear. We cannot do it on your behalf.
What is deleted on the server side
Our servers hold only what the account strictly requires: an internal identifier, your email address and nickname (encrypted), the sign-in method used, technical dates and the version of the terms you accepted. No game data and no GDPR Article 9 data is stored there.
Upon receipt of the request, the account is neutralised: it is time-stamped as deleted and becomes invisible to the service. In practice, signing in is no longer possible, the account record can no longer be read, and both export and rectification stop responding.
What is retained, why, and for how long
The neutralised account record — internal identifier, email address and nickname
encrypted (AES-256-GCM, with the key wrapped by a key management service hosted in France),
sign-in method, creation, last sign-in and deletion dates, plus the version of the terms accepted and
the date of acceptance.
Reason: evidence of performance of the contract and of acceptance of the terms of use
(GDPR Article 17.3.e — establishment, exercise or defence of legal claims).
Stated duration: 3 years at most after deletion.
Server technical logs — calling IP address, X-Forwarded-For header, method
and path called, response code, processing time and user agent. These logs are not anonymised and
contain no game data.
Reason: security, incident diagnosis and abuse detection (legitimate interest).
Duration: 13 months at most.
Billing records, if a payment was made — these are held by the App Store or Google Play
and by our accounting.
Reason: French accounting obligation.
Duration: 10 years.
What we owe you in plain terms
Neutralising the account is immediate and automatic. The physical destruction of the retained record, however, is not automated today: no scheduled job triggers it, and it is carried out manually by our team. We would rather tell you this than advertise an automatic purge that does not exist.
Two practical consequences, and both are in your hands:
- if you want the record destroyed without waiting, ask for it explicitly in your email: we then delete it permanently, within the time frame stated below;
- without that request, the record remains stored in its encrypted, inaccessible form, within the stated retention limit above.
Processing time
- From inside the app: local erasure is immediate, account neutralisation is immediate.
- By email: processed within 30 days at most, in accordance with GDPR Article 12.3. In practice, requests are handled within a few working days, and we confirm by return email what has been deleted.
Your other rights, and complaints
Deletion is only one of your rights: you also have rights of access, rectification, restriction, objection and portability. They are exercised at the same address contact@iitech.fr, or from within the app (“Settings → Data and account”). The details of our processing are set out in our privacy policy (in French).
If our answer does not satisfy you, you may lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr).