Account, export, and deletion
Your Ross account and your choices.
Your Apple identity authenticates you. Your active space membership authorizes what you can access. Neither an email address nor an OWNER role grants access to another member’s private information.
Sign-in identity
Ross uses Sign in with Apple and the stable Apple provider subject for account identity. Apple may supply a name and email on first authorization; Ross stores those values only when supplied. An email address does not create a membership and is not used to bind one person to another person’s Apple identity.
Private and shared data
Only-me Inbox records and evidence belong to the member who created or owns them. Shared records belong to the shared space and remain visible to active members according to server authorization and PostgreSQL row-level security. OWNER is an administrative role, not a privacy override.
Delete my Ross account
In the signed-in app, open the account destination in Space and choose Delete my Ross account. Ross shows an impact preview, requires you to type the exact destructive confirmation, and then requires fresh Sign in with Apple authentication.
After successful deletion, Ross:
- revokes active Ross sessions and Apple authorization material;
- removes provider credentials and pseudonymizes redeemed enrollment history;
- deletes that member’s private open loops and private evidence;
- removes the membership and clears the app’s Keychain session and selected space;
- returns the app to its signed-out state; and
- records only a minimal privacy-safe deletion receipt.
What happens to a shared space
Shared records are not erased unexpectedly when another active member still relies on them. Shared records created by the deleting member may remain, but direct personal creator attribution is removed or pseudonymized. Another member’s private data is not changed.
If the deleting person is the only member, Ross deletes the space and its content. If the person is the only OWNER while other members remain, the app requires an informed transfer to an eligible active member before deletion; Ross does not silently promote someone.
Current export path
Self-service export is not yet implemented in this private beta. To request an export, email support@our-os.app. Support will verify the requesting identity and arrange the current private-beta process. Never include an enrollment code, token, or private record content in the request.
A future package is intended to add a self-service export experience. This statement is a direction, not a claim that the feature exists today.