Back
Blog
|

Dating Apps That Actually Delete Your Data in 2026

EU regulators found most companies can't say what happens to your data once you ask them to delete it. Here's exactly what Anketta removes, what survives, and why.
10 min read
A young woman pressing her phone face-down on a bright desk, already turning away
Closing something for good doesn't need ceremony. Neither does asking an app to actually let go of your data.

Very few say precisely what happens once you tap delete — and that's not a coincidence. The European Data Protection Board reviewed how 764 controllers across 32 national authorities handle erasure requests, and its 2026 report singled out two recurring failure points: companies can't say how long they keep your data, and they can't say what happens to it in backups European Data Protection Board (2026). That's the industry a dating app's privacy policy is written into.

Anketta's version is a single database transaction that runs the moment you confirm — not a support ticket, not a queued job that resolves "within a few weeks." What makes it worth writing about isn't the speed alone; it's that the transaction has a documented boundary. A handful of things survive it on purpose, and the honest move is naming them instead of pretending the drawer is completely empty.

Start a manuscript you can close as cleanly as you opened it

Because it's a legal ceiling, not a company's actual mechanic. Both Russian law (152-ФЗ) and EU law (GDPR) give an organization a maximum window — commonly cited as 30 days — to act once someone invokes their right to erasure. That's the outer boundary regulators enforce, the same way a speed limit describes the fastest you're allowed to drive, not how fast your particular car actually goes.

The mistake most privacy comparisons make is treating the statutory ceiling as if it were the company's own timeline — "your data is gone within 30 days" reads like a promise of speed when it's really just restating what the law already requires of everyone. A privacy policy that quotes the legal maximum hasn't told you anything about how the company you're actually using behaves. For the wider pattern across the industry, Anketta's look at dating-app data practices is a useful next read.

It means the account is gone by the time the confirmation screen loads, not gone by the time a job queue gets around to it. Here's the actual sequence, deliberately built to resist a stray tap:

  1. You open Danger Zone and type your own account email — not a single click, a typed confirmation that matches what's on file.
  2. The confirm button stays disabled until the email matches exactly, so a mis-tap can't trigger it.
  3. The request fires, and the purge runs as one database transaction on that request — never a queue entry, never a scheduled job for later.
  4. The stored card credential is deleted and any live subscription is cancelled with the payment provider before the purge itself begins, so nothing keeps charging afterward.
  5. When the confirmation returns, the account is already gone from every table the transaction touches.

That's a structurally different claim than "we'll process your request soon." There's no window in which the request exists but the data doesn't, because the deletion and the confirmation are the same event — which is also why it's reasonable to start a manuscript today without wondering what leaving later would actually involve.

Write knowing exactly what leaving looks like
A bright modern shelf with a clean empty gap in the middle of a row of belongings
What deletion actually looks like — a gap, and the few things that stay.

Almost everything tied to your presence on the app, not just the parts a company finds convenient to remove. Closing an Anketta account clears your matches and every message and reaction inside them, your swipes, the manuscript you wrote — sections, versions, and any hand-drawn blocks — your profile photos and the stored image files behind them, your reading-taste profile (the highlights and word preferences you left, including the ones on other people's manuscripts), your device records and saved passkeys, your connected logins, and the record of your own votes and reports.

That list isn't exhaustive — it's a picture of how much actually gets touched, from the obvious (photos, messages) to the parts most people never think to ask about (cached preference signals, device tokens, the drawings someone else's manuscript showed you). It's the difference between "we removed your profile" and a transaction that reaches into every table your account ever wrote to.

A small number of things, kept for reasons that are legal rather than commercial — and this is where the honest answer actually lives, because most companies won't give you one this specific. A few examples:

  • Anonymised payment records. Subscriptions and payment events stay on file, unlinked from your name, because Russian tax law requires five years of transaction retention. This isn't Anketta's choice to make.
  • A tombstoned account row. Your account status flips to deleted, your email is rewritten to something unusable, and your name, city, gender, and age are wiped — but the row itself isn't removed outright. That's what frees your email for someone else to register later.
  • A moderation carry-over record, only if the account had unexpired strikes. An anti-evasion record (email plus device fingerprint) outlives the account so a fresh signup doesn't simply inherit a clean slate.
  • Encrypted backups on their own rotation. The database backup schedule keeps monthly snapshots for a year and annual ones for two, so a row can technically exist in an encrypted backup for up to two years after the live purge — untouched by anyone, on a schedule that runs independently of your request.
  • Login history, unlinked from you. The security audit log stays, but it's severed from your identity at the moment of deletion, and the rows themselves are swept 180 days later.

Those are examples of what survives, not a closed inventory — the point isn't the specific count, it's that the reasons are named and checkable rather than buried in a policy nobody reads.

Because specificity creates exposure, and vagueness doesn't. Academic research on account deletion backs this up directly: a peer-reviewed study that analyzed 490 deletion-related screens across the top 20 U.S. social platforms found that over a third of deletion attempts were never completed by the people who started them, and that platforms routinely left users unclear about what actually happened to their data afterward Schaffner, Lingareddy & Chetty (2022). Confusing language and buried settings aren't accidents in that data — they're a pattern.

Enforcement backs it up too. When the FTC settled with Match Group and OkCupid in 2026 over data shared with a facial-recognition company, the order permanently barred both companies from misrepresenting the extent to which they "collect, maintain, use, disclose, delete or protect" personal information Federal Trade Commission, via BiometricUpdate (2026) — a settlement significant enough that it needed a specific clause about deletion claims.

That's the backdrop a "we delete your data" line sits against. Anketta's own comparison against OkCupid goes into how the two products differ beyond privacy mechanics, if you want the fuller picture.

Look at what the policy actually tells you, not whether it uses the word "privacy." The table below sorts the approaches you'll actually run into, from vaguest to most specific.

ApproachWhat the policy tells youWhat happens when you ask
No public deletion policyNothing specificUnknown — you're guessing
Generic "up to 30 days" languageA legal ceiling, not a mechanicAmbiguous; may or may not be a queue
Deletion request goes to a support queue"Your request has been received"Manual, no fixed timeline in practice
Immediate purge with named survivorsWhat's kept, and the legal reason for eachGone by the time confirmation returns; a few explicit exceptions remain

None of the first three rows are lying, exactly — they're just not saying much. The fourth row is the only one that gives you something to actually check.

Does Anketta really delete my account, or just hide my profile?

It deletes it. The request runs as one database transaction against the live tables — matches, messages, manuscripts, photos, and more — the moment you confirm. It isn't a status flag that hides your profile while the data stays intact underneath.

How long does deletion actually take on Anketta?

The purge runs on the request itself, in one transaction, with no queue and no scheduled job behind it. By the time the confirmation screen appears, the deletion has already happened.

Can I get my account back after I delete it?

No — a self-serve delete is final. The account row becomes a tombstone (status deleted, email and identifying fields wiped), which is different from a temporary deactivation; it exists mainly so your email address can be reused later, not so the account can be restored.

Does Anketta keep my messages or matches after I delete my account?

No. Matches, and every message and reaction inside them, are removed as part of the same transaction that deletes the rest of your data.

Why does Anketta keep any of my data at all?

For reasons that are legal, not commercial — anonymised payment records under Russian tax retention law, an unlinked login-history sweep at 180 days, and a few similar cases. None of it is linked back to you as a person once the account is gone.

What if I had a moderation strike on my account before deleting it?

An anti-evasion record (email and device fingerprint, not your profile) can outlive the account if strikes were still active, so a fresh signup under a new email doesn't automatically start with a clean slate.

Unsure about writing? Try reading first.

A drawer that actually closes doesn't need a countdown taped to the front of it. It just closes. Anketta's confidential-by-design privacy layer works on the same principle while you're still writing — specific, checkable rules instead of a vague promise — and the deletion flow is simply that same idea applied to the day you decide to leave.

v0.65.10