Skip to document
CoulLegal & trust
Policy libraryData rightsTrustResearch
Log inStart free

Privacy controls

Data Rights & Account Deletion

How users and non-users can request access, export, correction, objection, deletion, appeal, social-token revocation, and removal of public-profile data.

Effective July 18, 202621 min readUpdated July 18, 2026
At a glance

Plain-language summary

Privacy rights vary by location and by Coul's role. This page explains the choices Coul must provide, what account and workspace deletion does, what can remain for a limited legal purpose, and which request controls still need to be activated before launch.

  • Account deletion, workspace deletion, social-account disconnection, and subscription cancellation are separate actions.
  • Coul's cleanup engine can remove core account data, media, AI records, tokens, caches, and vectors after a grace period, but no user-facing deletion request is live yet.
  • A person whose public profile appears in Coul must be able to request removal without creating a Coul account.
This summary helps with navigation. The full document below controls.

On this page

  1. 01Scope and Coul's role
  2. 02What is available today—and what is not
  3. 03Rights that may apply
  4. 04How a request must be submitted and tracked
  5. 05Access, knowledge, and source information
  6. 06Export and data portability
  7. 07Correction and disputed information
  8. 08Objection, restriction, consent, and opt-outs
  9. 09Profiling and automated decisions
  10. 10Deleting an item is not deleting an account
  11. 11Personal-account and workspace deletion
  12. 12Before requesting account deletion
  13. 13Grace period, restoration, and in-flight work
  14. 14What the cleanup engine removes or redacts
  15. 15Social OAuth tokens and connected platforms
  16. 16Subscription and billing records are separate
  17. 17Workspaces, shared templates, and external copies
  18. 18Non-user and public-profile removal
  19. 19Identity verification, agents, and guardians
  20. 20Timing, fees, extensions, and exceptions
  21. 21Providers, recipients, backups, and completion
  22. 22Refusals, appeals, and regulator complaints
  23. 23Mandatory launch controls and contact readiness
01

Scope and Coul's role

This page covers personal data associated with a Coul account or workspace and public-profile data about a person who does not use Coul. The Privacy Policy explains what Coul processes; this page focuses on how to exercise rights and what happens after a request.

Coul ordinarily acts as controller or business for account administration, its standardized public-profile intelligence, service security, billing records, and its own legal obligations. When Coul processes content solely on an organizational customer's documented instructions, Coul may act as processor or service provider; the organization remains responsible for receiving its members', workers', clients', or audience members' requests, and Coul must assist it as the law and contract require.

The applicable Coul controller must be the verified legal operator identified in the Service or transaction record. Its legal name, geographic address, jurisdiction, monitored privacy channel, and any appointed EU or UK representative or data protection officer must be published before launch rather than inferred from the Coul brand or an email domain.

02

What is available today—and what is not

The reviewed source supports changing a signed-in user's display name and, after mailbox verification, email address. It supports viewing and revoking sessions and disconnecting connected social accounts. Coul also has an administrator-triggered, checkpointed cleanup engine for personal and workspace contexts.

The reviewed product does not yet expose a user-facing complete privacy export, account-deletion request, deletion-status view, restoration control, appeal form, authorized-agent route, or global non-user public-data removal workflow. Existing profile exports are analytics exports, not a complete access or portability response. The Settings privacy controls are a non-transactional preview and must not be represented as saved preferences.

Until the monitored intake and identity, search, export, deletion, provider-propagation, status, and appeal controls below are implemented and tested, this page describes required launch behavior rather than claiming that a static email or interface mockup completes a request.

Rights intake is a launch gate

Coul must not invite public-profile collection or claim self-service deletion until users and non-users have a working, accessible, tracked route with a responsible human owner.

03

Rights that may apply

Depending on where a person lives, Coul's role, the data, and the reason for processing, rights may include confirmation and access; source and category information; a copy of specific data; portability; correction; deletion; restriction; objection; withdrawal of consent; opting out of sale, sharing, targeted advertising, or certain profiling; limiting certain sensitive-data uses; and freedom from unlawful discrimination for exercising a right.

These rights are not identical everywhere. Coul applies the right required by applicable law and may voluntarily provide a broader control, but a voluntary control does not change a statutory definition, exception, deadline, or regulator's authority. If Coul does not sell or share data for cross-context behavioral advertising, it should say so without removing a legally required opt-out if practices later change.

Official sourcesEU General Data Protection Regulation (opens in a new tab)California Privacy Protection Agency consumer-rights FAQ (opens in a new tab)Colorado Attorney General: Colorado Privacy Act (opens in a new tab)
04

How a request must be submitted and tracked

Coul must provide an accessible in-product route and an accountless monitored route for people who cannot sign in or do not have an account. A request should identify the right, relevant account email or workspace when applicable, and enough source information to find the data. Public-profile requests should include the platform and canonical profile or post URL, current and prior handle if known, and the type of concern.

Coul must acknowledge the request, assign a case identifier, record the received date and applicable deadline, prevent duplicate cases from creating inconsistent results, provide a secure way to exchange evidence, and show or communicate status and outcome. Marketing consent, subscription cancellation, security incidents, copyright complaints, and platform-support tickets need separate routing even when one message raises several issues.

A requester should not send a password, one-time code, session cookie, social OAuth token, full payment-card number, private key, or unrestricted copy of an identity document. Ordinary support messages and public issue trackers are not safe channels for sensitive request material.

05

Access, knowledge, and source information

Where applicable, an access response confirms whether Coul processes the person's data and describes the purposes, categories, sources, recipients or recipient categories, retention criteria, rights, transfers, and meaningful information about relevant automated processing. It provides the person's data in an intelligible form without disclosing another person's rights, trade secrets, authentication secrets, abuse signals, or security-sensitive system details beyond what law requires.

Coul must search systems reasonably likely to contain responsive data, including account and workspace records, sessions, connected profiles, uploads and media, transcripts, prompts and AI outputs, prediction and analytics records, calendars and publishing events, workflows and templates, support and rights cases, billing identifiers, public-profile intelligence, provider artifacts, object storage, vectors, caches, and relevant logs.

A screenshot of the profile page or a generic privacy-policy link is not a complete response when the right requires specific data or source information. Coul may provide information in stages for a large request if the method remains complete, secure, understandable, and timely.

Official sourcesUK ICO guide to subject access (opens in a new tab)
06

Export and data portability

A privacy export must be distinguished from Coul's analytics or profile-report exports. A complete response should include the categories required for the request and explain omitted data, while a portability file covers the narrower data and legal conditions applicable to portability. Where required, data must be structured, commonly used, machine-readable, and transmitted securely.

Before generation, Coul must freeze or version the export scope, prevent cross-workspace leakage, exclude active credentials and social tokens, and verify that download links are short-lived, single-purpose, access-controlled, and auditable. A large media archive can use separate encrypted parts, but the manifest must make completeness and checksums understandable.

Portability does not automatically include every inference, trade secret, or data about another person, and direct transmission to another provider is required only where legally applicable and technically feasible. Coul should explain any redaction or refusal and must not silently substitute an analytics CSV for the requested account archive.

Official sourcesUK ICO: right to data portability (opens in a new tab)
07

Correction and disputed information

Signed-in users can update a display name and can change an email after verification. Other corrections—including workspace roles, public-profile facts, source attribution, analytics provenance, and AI-derived summaries—need a tracked request when no safe self-service control exists.

A historic public metric may have been accurate when observed even if the live count later changed. Coul should preserve source and observation dates, correct a factual association or identity error, label genuinely disputed snapshots, and propagate the correction to active derived summaries and vectors where appropriate rather than rewriting history without provenance.

Correction does not require Coul to present a requester's opinion as an objective fact. Coul must consider supplied evidence, explain a denial, and restrict contested data while reviewing it where law requires or the risk warrants.

08

Objection, restriction, consent, and opt-outs

A person may object to processing based on legitimate interests, ask Coul to restrict use while accuracy or a legal objection is assessed, or withdraw consent for consent-based processing. Withdrawal applies prospectively and does not make earlier lawful processing unlawful. Coul must connect the choice to every relevant product path and provider, not merely change a label in Settings.

For a California sale or sharing opt-out and a recognized browser preference signal, Coul must not require identity verification or account creation. It may ask only for information necessary to apply the choice and must not use that request to collect unrelated personal data. Access, deletion, and correction requests can require proportionate verification because they may disclose, alter, or erase account data. Other targeted-advertising, sensitive-data, or profiling choices follow the verification rule applicable to that right and location. The current Cookie consent controls govern optional browser storage; clearing a browser does not delete backend account data, and deleting an account does not clear storage on every browser.

Coul must not retaliate, degrade unrelated service, or use dark patterns because a person exercised a right. A necessary service can stop if the requested restriction makes it impossible to provide, but Coul must explain that consequence before the choice where possible and preserve mandatory consumer remedies.

09

Profiling and automated decisions

Coul's viral scores, recommendations, content suggestions, and competitor patterns are decision-support features. They can be inaccurate or biased and are not intended to make a legal or similarly significant decision about a person. The AI Transparency page explains inputs, limitations, human review, and the absence of performance guarantees.

If Coul later uses personal data for a covered significant decision or legally regulated profiling, it must perform the required assessment, give point-of-use notice, provide an applicable opt-out and appeal, and enable meaningful human review with authority to change the result before that use begins. A nominal reviewer who merely accepts a model result is not meaningful review.

10

Deleting an item is not deleting an account

Deleting a media item, post draft, canvas, competitor, schedule, or connected profile addresses that product object under its own lifecycle. It may need to locate thumbnails, transcripts, AI outputs, analyses, provider artifacts, derived vectors, caches, references, and queued work linked to the item. It does not automatically close the account or workspace, cancel a subscription, clear every log, withdraw a platform post, or satisfy a request covering all personal data.

Coul must prevent a deleted source from remaining active through a duplicate reference, pending job, retained embedding, copied schedule, or cache. When a bounded record must remain for fraud, security, billing, rights defense, or a legal hold, it must be isolated from ordinary product use and retained only for the approved purpose and period.

11

Personal-account and workspace deletion

The implemented deletion engine distinguishes a person's context from a workspace context. Scheduling personal deletion disables the user and revokes Coul sessions and refresh tokens immediately. A person who is the last active owner of a workspace cannot schedule personal deletion until ownership is transferred or the workspace itself is placed into deletion; otherwise member data, billing, schedules, and organizational content could become orphaned.

When other owners remain, personal deletion can remove the person's membership and personal context while the customer-controlled workspace persists. Content created for an employer, agency, or client may remain under that organization's instructions, but personal identifiers and the organization's legal obligations must still be assessed. Coul does not decide private ownership or employment disputes through the deletion button.

Workspace deletion affects all members and organizational assets and therefore requires verified owner authority, warnings, export opportunity, billing reconciliation, active-job handling, and confirmation. An admin-only capability is not a user-facing right until authorization, notice, status, recovery, and support paths are connected.

Last-owner safeguard

Transfer the workspace or delete the workspace first. Coul must never leave a workspace, subscription, social connection, or scheduled publisher without an accountable owner.

12

Before requesting account deletion

Before confirming deletion, Coul must clearly tell the requester what will be disabled immediately, the grace period and exact purge date, what can be restored, what cannot be recalled, the workspace and billing effects, and which limited records may remain. The confirmation must identify the exact personal account or workspace and require fresh authentication appropriate to the risk.

  • Export content and data that must be kept; deletion is not a substitute for a complete privacy export.

  • Transfer ownership and billing responsibility for every workspace that should continue.

  • Review, cancel, or manually verify scheduled posts, automations, pending publishes, and provider jobs.

  • Disconnect social accounts and check the destination platform for permissions and actions already completed.

  • Cancel the subscription through the confirmed billing route and retain the cancellation and refund record.

  • Understand that downloads, recipients' copies, completed social posts, and independently duplicated public templates may not be retractable by Coul.

13

Grace period, restoration, and in-flight work

The implemented default grace period is 30 days; an administrator can configure a period from 1 to 365 days. Production must publish the actual period and exact timestamp shown to the requester rather than relying on this source-code default. During the grace period, the account or workspace is disabled and new ordinary processing must remain quiesced.

Restoration is possible only while a deletion is still scheduled and before the purge time. It is not available after processing begins. Scheduling personal deletion immediately revokes Coul sessions and refresh tokens; canceling the scheduled deletion does not revive those credentials, so the person must authenticate again. A restore must re-establish only the access and state that can safely be restored; it must not silently reactivate canceled billing, revoked external permissions, expired invitations, completed takedowns, or a schedule that is no longer safe.

Cleanup cancels queued or retrying jobs and waits for already-running work or provider processing to reach a safe boundary. Coul must show a delayed or failed state rather than claiming completion while a publish, AI provider, object deletion, or revocation remains unresolved.

14

What the cleanup engine removes or redacts

After the grace period, the implemented worker uses durable checkpoints to quiesce work, erase billing-provider customer data where configured, revoke and erase connected-account tokens, delete object-storage data, clear tenant Redis artifacts, delete tenant Qdrant collections, and delete or redact database records. It retries failures and records whether a deletion is scheduled, processing, retrying, completed, failed, or cancelled. Restoring an eligible scheduled deletion records cancellation of that deletion; there is no separate restored status.

The covered database data includes uploads and media, transcripts, analyses and virality records, prompts and AI call or output records, canvases and workflow state, ideas and personalization, social profiles and snapshots, reports and exports, schedules and publishing attempts, sessions and authentication records, and other linked operational data. Personal identifiers in users, audit data, billing records, and bounded deletion ledgers may be pseudonymized or redacted instead of erasing the evidence entirely.

This description reflects reviewed code, not a guarantee that every deployed provider, database table, log stream, cache, region, replica, or backup is configured. Production must maintain a tested inventory and reconciliation report and must notify the requester if an exceptional store prevents completion.

15

Social OAuth tokens and connected platforms

Disconnecting a social account disables Coul publishing for that connection, marks the active local token revoked, and queues provider revocation where supported. To complete that provider call, the implemented flow can retain a soft-deleted encrypted OAuth envelope in a restricted revocation outbox; physical deletion follows successful provider revocation. Account deletion also attempts provider revocation and erases active local secrets.

The reviewed revocation outbox does not yet show a bounded maximum-attempt policy or terminal-failure state. Before launch, Coul must define the narrow purpose, access, encryption, retry ceiling, maximum retention period, manual escalation, and deletion behavior for an envelope that a provider outage, rejection, or unsupported revocation prevents Coul from using successfully. Coul must report unresolved failures rather than imply that disconnect always means immediate provider-side revocation.

Disconnecting Coul does not necessarily delete the social-network account, content already published there, the platform's independent analytics, or authorization held by another app. The person may also need to use the social platform's connected-app settings and should check the destination before retrying a publish whose result is uncertain.

Coul must never include an OAuth access token, refresh token, session cookie, signing secret, or complete credential in a privacy export, support response, or deletion receipt.

16

Subscription and billing records are separate

Account deletion and subscription cancellation are separate legal and technical actions. Before deletion, Coul must state whether it will cancel the active Stripe subscription, when renewal and access stop, whether a withdrawal or refund applies, and which invoices, tax, fraud, dispute, or payment records must remain. An external recurring charge must never be left without an accessible cancellation path.

The cleanup engine can delete a Stripe customer and redact local billing identifiers, but a source-code path does not replace verified live cancellation, webhook reconciliation, receipt retention, and refund handling. The Subscription Policy controls recurring-charge and consumer-remedy details.

17

Workspaces, shared templates, and external copies

An organization may retain customer-controlled content after an individual member leaves or deletes a personal context, subject to its instructions, contract, legal basis, and the individual's applicable rights. Coul should forward or coordinate a request when the organization is responsible and separately answer for data Coul controls itself.

A private or unlisted template should stop being accessible according to its visibility and deletion rules. A person who lawfully duplicated a public template can retain a separate copy under the Community License, while a valid copyright, privacy, impersonation, or safety complaint can require broader containment. Removing an author's account cannot guarantee recall of a lawful download, export, completed post, screenshot, or third-party copy.

Deletion must minimize or remove private author identifiers from surviving records where no longer needed, preserve only bounded provenance necessary for license or rights handling, and avoid exposing private media, credentials, competitor identifiers, or unpublished workspace state through a surviving template.

18

Non-user and public-profile removal

A person whose public Instagram, TikTok, X, or future supported profile appears in Coul must be able to request access, source information, correction, objection, restriction, deletion or removal, and appeal without creating a Coul account. A workspace user deleting a competitor removes only that workspace reference and is not a global profile-owner request.

A valid global request must pause refresh, find the profile across every tenant and source identifier, address raw provider artifacts, normalized profiles and posts, snapshots, media references, derived Gemini summaries, Qdrant embeddings, caches, pending jobs, and provider copies, and create the minimum secure suppression record needed to prevent routine re-import. Handle changes and reassignments require stable external identifiers and known URLs where available; a handle-only block is not enough.

The repository does not yet contain this global intake, cross-tenant search, provider propagation, or suppression registry. Coul must implement and test it—including a known-child or guardian escalation—before presenting non-user removal as an active workflow. If Coul is a covered California data broker, it must also implement applicable DROP retrieval, deletion, reporting, contractor, and suppression duties.

Official sourcesCalifornia CPPA: Delete Request and Opt-out Platform (opens in a new tab)
19

Identity verification, agents, and guardians

Coul verifies a request in proportion to the risk and data involved. A signed-in request may use fresh authentication and an account-email challenge. A non-user public-profile request may use a source-profile control challenge, publicly listed creator contact, or minimal evidence of a deleted or renamed profile. Coul should avoid government identification unless necessary, mask it during review, restrict access, and delete verification evidence when no longer needed.

An authorized agent must provide appropriate authority, but Coul must not impose notarization or extra friction unless law and risk justify it. Coul may separately verify the person's identity or permission where allowed. Parents, guardians, representatives of an estate, and organization representatives need a route tailored to their authority and the subject's circumstances.

Verification must not require a non-user to create an account, collect more data than the request warrants, reveal whether an unrelated person's account exists, or become a reason to ignore an urgent child-safety, token-compromise, impersonation, or intimate-content report.

20

Timing, fees, extensions, and exceptions

Coul applies the deadline governing the requester and request. Under GDPR and UK GDPR, the ordinary response period is one month and can be extended by two further months for complexity or number of requests with timely notice. California generally requires confirmation within 10 business days and a substantive response to know, delete, or correct within 45 calendar days, extendable once with notice. Colorado generally requires 45 days and permits one additional 45-day extension with timely notice.

Requests are ordinarily free. Coul may charge or refuse only where applicable law permits it, such as a manifestly unfounded or excessive request, and must explain the basis and available appeal or complaint route. Repetition alone is not automatically excessive when data or processing changed.

Deletion and access rights are not absolute. Narrow exceptions can cover another person's rights, legal obligations, tax and transaction records, security and fraud, legal claims, expression and information, public-interest tasks, research or archives, or a documented legal hold. Excepted data must be minimized, access-restricted, unavailable for ordinary product use, deleted when the exception ends, and identified to the requester to the extent lawful.

Official sourcesUK ICO: right to erasure (opens in a new tab)California Privacy Protection Agency response-time guidance (opens in a new tab)
21

Providers, recipients, backups, and completion

Where required, Coul must notify relevant processors, service providers, recipients, and workspace customers of a correction, restriction, opt-out, or deletion and require appropriate downstream action. A completed request record must distinguish deletion Coul directly verified from an instruction sent to a provider, a platform action Coul cannot reverse, and a lawful exception.

The reviewed repository does not establish an end-to-end backup-expiration period. Coul must not promise immediate removal from every backup. Before launch it must document encrypted backup locations, access restrictions, restoration controls, maximum overwrite or expiration periods, and a tombstone or replay control so deleted data does not silently return to production after recovery.

A provider outage, retry, terminal failure, legal hold, or unmatched identifier can delay one step. Coul must keep the case open or clearly identify partial completion, retry safely, escalate terminal failures, and send a final response only when reconciliation supports the stated outcome.

22

Refusals, appeals, and regulator complaints

If Coul denies or limits a request, it must identify the request and data involved, give a clear reason without exposing protected security or third-party information, state what was completed, and explain how to appeal. An appeal must be reviewed by a sufficiently independent person with authority to change the result, tracked separately, and answered within the applicable period.

Where required, an unsuccessful appeal must explain how to contact the appropriate attorney general, privacy protection agency, data protection authority, or other regulator. Exercising a right, appealing, or complaining to a regulator does not waive another non-waivable remedy and must not result in unlawful discrimination.

23

Mandatory launch controls and contact readiness

The following controls are implementation requirements, not claims that a policy page alone provides them. Coul must assign owners, test representative personal, workspace, non-user, agent, guardian, failed-provider, and backup cases, monitor deadlines, and re-test after material data or vendor changes.

  • Verify the controller's legal name and address, privacy contact, representatives, case owners, escalation coverage, and regulator map.

  • Launch accessible signed-in and accountless intake, proportionate verification, authorized-agent and guardian routes, status, secure evidence exchange, refusal reasons, and independent appeal.

  • Build complete access and portability inventories and secure exports that cannot leak workspace, credential, third-party, or security-sensitive data.

  • Connect account and workspace deletion confirmation, last-owner handling, grace and restoration states, job quiescence, every cleanup store, terminal-failure escalation, and completion receipts.

  • Reconcile deletion with social revocation, scheduled publishing, Stripe cancellation and refunds, shared templates, provider copies, legal holds, audits, and backup replay prevention.

  • Set and enforce a bounded retry, terminal-failure, escalation, and maximum-retention policy for encrypted OAuth revocation envelopes; verify physical deletion after success or approved terminal handling.

  • Implement global non-user search, source-ID suppression, provider propagation, child escalation, stale/private-source retirement, and any applicable California DROP workflow.

  • Replace prototype privacy settings with real state or clearly disabled preview labels; never display Enabled, Private, exported, deleted, or completed without verified backend state.

  • Until privacy@coul.app is verified, monitored, secured, tracked, and tested, displaying it on this draft does not establish an operational rights channel.

Contact

Need to exercise a data right?

Before launch, Coul must verify and monitor this address, connect it to a tracked case system, and publish the controller's legal identity and geographic address. Do not send passwords, OAuth tokens, payment-card numbers, or unnecessary identity documents.

privacy@coul.app

Keep reading

Related Coul policies

Privacy PolicyPublic/Competitor Data NoticeCookie PolicySubscription, Trial, Cancellation & Refund PolicySecurity/Trust

Policy library

  • 01Terms
  • 02Privacy
  • 03AI transparency
  • 04Public data
  • 05Acceptable use
  • 06Content & AI output
  • 07Copyright & DMCA
  • 08Community
  • 09Cookies
  • 10Subscriptions
  • 11Data rights
  • 12Security
  • 13Accessibility
CoulLegal & trust
  • Terms
  • Privacy
  • Cookies
  • Cookie settings
  • Security
  • Accessibility
© 2026 Coul