Disconnect, Consent Withdrawal & Data Deletion

CalendarGuardian connection and account controls · Updated September 5, 2026

Pause the calendar filter

Turn Calendar filter off to remove the provider change-notification subscription and stop automatic scans and actions. CalendarGuardian keeps the encrypted provider authorization, settings, and history so protection can resume without a new sign-in.

Disconnect and withdraw consent

Use Disconnect Calendar & Withdraw Consent to remove the provider notification subscription, delete CalendarGuardian's stored OAuth token, clear the signed-in session, and record the connection as disconnected. Settings and history remain so they can be available if the same account reconnects.

For Google, CalendarGuardian calls Google's OAuth token-revocation endpoint. Microsoft does not provide an equivalently narrow delegated-grant revocation endpoint, so CalendarGuardian deletes its stored Microsoft token. Users who want an additional Microsoft-side removal can remove CalendarGuardian through Microsoft account or organization application-permission settings.

Delete the account and all service data

Use Delete Account & All Data to first close recorded Stripe checkout sessions and immediately cancel active CalendarGuardian website subscriptions, then disconnect every Microsoft and Google account linked to the CalendarGuardian profile and permanently delete the shared tenant-scoped service account records in PostgreSQL and the migration safety mirror, stored OAuth material, settings, trusted/blocked rules, review/removal records, detections, actions, queued jobs, provider subscriptions, and sessions. If Stripe cannot confirm closure, deletion stops and reports an error; prior charges are not automatically refunded. Apple App Store and Google Play subscriptions are managed separately. CalendarGuardian retains one-way hashes of prior Stripe resource identifiers for up to approximately 90 days solely to reject delayed billing webhooks; those hashes cannot recover the deleted identifiers.

Delete Apple or Android native-app data

The current native apps keep their exact-sender rules and up to 100 removal-history records only in app-private storage on the device. They do not upload that native history to the CalendarGuardian service. On iPhone or iPad, remove CalendarGuardian to delete its local app data, and use Settings → Privacy & Security → Calendars to revoke Calendar access without uninstalling. On Android, use the system's App info → Storage & cache → Clear storage control to delete local rules/history, use Permissions to revoke Calendar access, or uninstall the app. Service-side account deletion does not clear a separately installed native app's local data.

What these actions do not delete

Pausing, disconnecting, or deleting CalendarGuardian does not delete your Microsoft, Google, Apple, Android-device, or other calendar-provider account. It does not delete unrelated calendar data. Events CalendarGuardian previously removed may not be recoverable as the original meeting relationship.

Request deletion by email

If you cannot use the in-app control, email privacy@dealdoctor.pro from the account address or provide sufficient information for us to verify the request. Do not send passwords, authorization codes, access tokens, refresh tokens, or client secrets.

Backups and legally retained records

Deletion from active systems may not immediately remove data from ordinary-course backups or records that DealDoctor must retain by law, contract, fraud prevention, or security requirements. Such data remains protected and is not used for unrelated purposes.