Request your data, or its deletion
Where to write, what actually exists to delete, and what the address does not yet cover.
Written By Dustin
Last updated 15 minutes ago
Write to privacy@tovio.dev.
What that address currently covers
Be aware of its scope. No production privacy-request intake is published yet. There are two working addresses: privacy@tovio.dev for requests about feedback-portal data, and security@tovio.dev for security reports. A production request channel, a response workflow, the responsible legal entity, and jurisdiction-specific notices are all still launch requirements. The privacy notice asks you not to submit production personal data under a draft, and that request is sincere.
Both addresses are Google Workspace groups, so mail sent to them is handled by Google as a mail provider.
What actually exists to delete
Less than you might expect, because there is no telemetry and no hosted service yet.
- Portal data — the contact record created when you sign in, post, comment, vote, or open a ticket on any of the vendor-operated portal hosts. This is the main thing, and a request covers all of it, not only the boards.
- Correspondence — email you have sent to a project address.
There is no usage data, because none is collected. Your repositories live on your own disks; they are not ours to hold or to delete.
Portal deletion
A request about portal data is a data-protection request, not a support ticket. It is closed by deleting the vendor contact within 30 days, the data-protection commitment stated in the privacy notice, and the date is logged. Nothing else in TOVIO holds portal identity, so there is nothing else to remove.
What deletion cannot reach
Posts you made that others have replied to or voted on may remain as content with the identity removed. If you want a post itself taken down as well as your account removed, say so explicitly — the two are separate requests.
Hosted accounts
When the hosted service exists, account closure has its own flow, including what is deliberately retained: immutable content-addressed objects, audit obligations, and legal holds may require a documented deletion or cryptographic-obliteration process rather than a simple delete. That flow is designed and recorded, but it is not something you can exercise today, because there are no hosted accounts.