Export and deletion
Download everything Kiste stores about your account, delete Kisten, or delete the whole account.
Last updated: 6 October 2026
Export your data
In the console, open Account → Download my data, or
run kiste account export (CLI 0.1.1 or later), or call the API
(Export your data). Step by step:
Download your data.
You get one JSON file with every record Kiste keeps about your account: profile, settings, quotas, sign-ins, devices, billing and usage, Kisten, snapshots, environments, published services, commands and events. It leaves out password hashes, token hashes, ciphertexts and key material. They are useless to you and would only make the file dangerous to keep. The download link is valid for 10 minutes, works only for your own signed-in account, and the export is built when you download it. Nothing is stored.
The contents of your Kisten are yours to copy at any time with kiste scp, SSH or kiste exec.
Delete a Kiste
kiste delete <name> or the console stops the Kiste and deletes its disk, its memory snapshot
and its local checkpoints. Its off-site checkpoints lose their last reference and are collected by
the garbage collector. Named snapshots of the Kiste are listed before you confirm, and you can
keep them.
Delete your account
In the console, open Account → Delete account, or
run kiste account delete (CLI 0.1.1 or later), or call the API
(Delete your account).
You confirm with your password and by typing your e-mail address (step by step: Delete your account). There is no grace period: once confirmed, the deletion starts and cannot be undone.
At once: every browser session, CLI token, API key and registered computer of the account is deleted, open desktops and terminals are closed, and nothing can sign in as the account any more.
Kisten: every Kiste and every local snapshot on every compute server is deleted. No final checkpoint is taken.
Rolling out
The automatic clean-up on the compute servers (this step and the next) is being rolled out. Until it is live, a deletion request still takes effect at once (step 1: nothing can sign in as the account any more) and then waits at this step. The request is kept and resumes on its own as soon as the compute side is updated; the steps after it run then in order.
Backups: the account's backup key is deleted. From that moment every off-site checkpoint of the account, in both locations, is undecryptable (crypto-shredding). The encrypted objects themselves are then removed by the garbage collector. Backup buckets are locked against deletion for 30 days to protect against ransomware, so the last ciphertext can remain for up to about 31 days. Nobody can decrypt it, because the key no longer exists.
Billing: a running subscription is cancelled and the customer record at Stripe is deleted. Stripe keeps the invoices and payments it is legally required to keep. Kiste keeps its own payment records for the statutory period, without your e-mail address.
Records: the account and everything attached to it in the account database is deleted. One audit record that a deletion took place is kept, with no account id.
Logs are not rewritten. They carry only the random account id, never your e-mail address, and they expire after 7 days (edge) and 30 days (compute server).
Every step resumes automatically if a part of the system is briefly unreachable, so a deletion always completes.
If you can no longer sign in, write to the address on kiste.run/imprint. After checking that the request comes from the account holder, we start the same deletion for you and confirm it in writing.
Other requests
| You want to | How |
|---|---|
| Correct your e-mail address | Write to us. Self-service e-mail change is not available yet. |
| Restrict processing of your account | Write to us. There is no self-service switch yet. |
| Object to processing | Write to us. The privacy policy explains which processing relies on legitimate interest. |
We answer every request within one month. The privacy policy at kiste.run/privacy describes your rights in full.