Data Deletion Policy
Last updated: April 5, 2026
This policy describes how M&R Edge Studio (operated by Michelle & Rich Essence Ltd) handles data deletion requests, account closure, and platform-initiated data removal. We comply with UK GDPR (Right to Erasure, Article 17), Nigeria's NDPA, and platform-specific requirements from Meta and TikTok.
1. User-Initiated Deletion
Users can request data deletion through several channels:
- In-app — Navigate to Settings → Account → Delete Account. This initiates a full account deletion including all projects, media, and personal data.
- Data Deletion page — Visit /data-deletion for guided instructions.
- Email request — Send a request to privacy@mredgestudios.com with the subject "Data Deletion Request".
All deletion requests are processed within 30 days as required by UK GDPR.
2. Scope of Deletion
When an account is deleted, the following data is permanently removed:
| Data | Action |
|---|---|
| User profile & credentials | Permanently deleted |
| Projects, scripts & storyboards | Permanently deleted |
| Uploaded media (images, audio, video) | Permanently deleted from storage |
| Brand kits & templates | Permanently deleted |
| Social platform connections & tokens | Tokens revoked and deleted |
| Analytics & usage data | Anonymised or deleted |
| Notifications & comments | Permanently deleted |
| Credit balance & transaction history | Deleted (financial records retained per legal obligation) |
| Streaks, achievements & gamification | Permanently deleted |
3. Platform-Initiated Deletion
Third-party platforms can trigger data deletion through automated mechanisms:
- Meta Data Deletion Callback — When a user removes our app from their Meta/Facebook settings, Meta sends a signed request to our automated callback endpoint, which deletes all associated platform data.
- TikTok Deauthorization Webhook — When a user revokes access via TikTok settings, our webhook handler automatically removes all stored TikTok tokens and platform identifiers.
- App Uninstall Events — Platform uninstall webhooks trigger immediate cleanup of the corresponding connection data.
4. Deletion Timeline
Immediate (0–24 hours) — Account deactivated, sessions invalidated, OAuth tokens revoked, user can no longer log in
Within 7 days — All personal data, projects, and media files permanently deleted from live database and storage
Within 30 days — Data removed from all backups through natural backup rotation
Exception — Financial records required for tax/legal compliance may be retained for up to 7 years in anonymised form
5. Deletion Verification
- Upon completion of deletion, a confirmation email is sent to the user's registered email address
- For Meta-initiated deletions, a confirmation URL and code are returned via the callback for the user to verify
- All deletion events are logged in our audit system (without personal data) for compliance verification
- Users may contact privacy@mredgestudios.com to request verification that their data has been fully removed
For questions about data deletion, contact privacy@mredgestudios.com.
© 2026 Michelle & Rich Essence Ltd. All rights reserved.