> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Export and deletion

> Download everything Kiste stores about your account, delete Kisten, or delete the whole account.

## Export your data

In the [console](https://console.kiste.run/app/account), open **Account → Download my data**, or
run `kiste account export` (CLI 0.1.1 or later), or call the API
([Export your data](https://docs.kiste.run/api/account.md#export-your-data)). Step by step:
[Download your data](https://docs.kiste.run/account/data-export.md).

You get one JSON file with every record Kiste keeps about your account: profile, settings, quotas,
sign-ins, devices, billing and usage, Kisten, snapshots, environments, published services,
commands and events. It leaves out password hashes, token hashes, ciphertexts and key material.
They are useless to you and would only make the file dangerous to keep. The download link is
valid for 10 minutes, works only for your own signed-in account, and the export is built when you
download it. Nothing is stored.

The contents of your Kisten are yours to copy at any time with `kiste scp`, SSH or `kiste exec`.

## Delete a Kiste

`kiste delete <name>` or the console stops the Kiste and deletes its disk, its memory snapshot
and its local checkpoints. Its off-site checkpoints lose their last reference and are collected by
the garbage collector. Named snapshots of the Kiste are listed before you confirm, and you can
keep them.

## Delete your account

In the [console](https://console.kiste.run/app/account), open **Account → Delete account**, or
run `kiste account delete` (CLI 0.1.1 or later), or call the API
([Delete your account](https://docs.kiste.run/api/account.md#delete-your-account)).

You confirm with your password and by typing your e-mail address (step by step: [Delete your account](https://docs.kiste.run/account/delete-account.md)). There is no grace period:
once confirmed, the deletion starts and cannot be undone.

1. **At once:** every browser session, CLI token, API key and registered computer of the account is
   deleted, open desktops and terminals are closed, and nothing can sign in as the account any more.

2. **Kisten:** every Kiste and every local snapshot on every compute server is deleted. No final
   checkpoint is taken.

   > **Info:** Rolling out
   >
   > The automatic clean-up on the compute servers (this step and the next) is being rolled out. Until
   > it is live, a deletion request still takes effect at once (step 1: nothing can sign in as the
   > account any more) and then waits at this step. The request is kept and resumes on its own as soon
   > as the compute side is updated; the steps after it run then in order.

3. **Backups:** the account's backup key is deleted. From that moment every off-site checkpoint of
   the account, in both locations, is undecryptable (crypto-shredding). The encrypted objects
   themselves are then removed by the garbage collector. Backup buckets are locked against deletion
   for 30 days to protect against ransomware, so the last ciphertext can remain for up to about 31
   days. Nobody can decrypt it, because the key no longer exists.

4. **Billing:** a running subscription is cancelled and the customer record at Stripe is deleted.
   Stripe keeps the invoices and payments it is legally required to keep. Kiste keeps its own payment
   records for the statutory period, without your e-mail address.

5. **Records:** the account and everything attached to it in the account database is deleted. One
   audit record that a deletion took place is kept, with no account id.

6. **Logs** are not rewritten. They carry only the random account id, never your e-mail address, and
   they expire after 7 days (edge) and 30 days (compute server).

Every step resumes automatically if a part of the system is briefly unreachable, so a deletion
always completes.

If you can no longer sign in, write to the address on [kiste.run/imprint](https://kiste.run/imprint).
After checking that the request comes from the account holder, we start the same deletion for you
and confirm it in writing.

## Other requests

| You want to | How |
| --- | --- |
| Correct your e-mail address | Write to us. Self-service e-mail change is not available yet. |
| Restrict processing of your account | Write to us. There is no self-service switch yet. |
| Object to processing | Write to us. The privacy policy explains which processing relies on legitimate interest. |

We answer every request within one month. The privacy policy at
[kiste.run/privacy](https://kiste.run/privacy) describes your rights in full.

## Related topics

- [Security and trust](https://docs.kiste.run/security.md)
- [Isolation](https://docs.kiste.run/security/isolation.md)
- [Network](https://docs.kiste.run/security/network.md)
- [Encryption](https://docs.kiste.run/security/encryption.md)
- [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md)
- [Data location](https://docs.kiste.run/security/data-location.md)
- [Subprocessors](https://docs.kiste.run/security/subprocessors.md)
- [Logging and retention](https://docs.kiste.run/security/logging-retention.md)
- [Incidents and status](https://docs.kiste.run/security/incidents-status.md)
- [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
- [Compliance](https://docs.kiste.run/security/compliance.md)
- Previous: [Logging and retention](https://docs.kiste.run/security/logging-retention.md)
- Next: [Incidents and status](https://docs.kiste.run/security/incidents-status.md)
