deleting your account

Take your key out first. Then delete.

Deleting your account erases your profile, your catches and the identity behind them. It does not erase what is in your wallet, and it destroys the only key that opens it. Five minutes on the export page is the difference between an account you closed and money you cannot reach.

before anything else
step one

Your wallet dies with your account.

The wallet was made for you when you first signed in, and it is derived from that identity. Delete the identity and the key is not moved somewhere safe — it stops existing. Your tokens stay on Robinhood Chain, at an address that has no owner any more. That is not a policy we could soften; it is what a non-custodial wallet is.

Two ways out, and either one is enough. Do one of them now, while the account still works.

  1. 1. Export the key.

    Open your account on this site, find Export your keys, press reveal private key. The key is assembled in a window that belongs to Privy — we never see it and cannot see it. Paste it into any wallet and the address comes with you, tokens and all.

  2. 2. Or send them somewhere you already own. One symbol at a time.

    Same page, the Withdraw box. It moves one symbol at a time — pick a symbol, an amount, a destination address you control, send, then do it again for the next symbol. Empty means every symbol in the holdings row, not the first one. Once it is genuinely empty, losing the wallet costs nothing. More work than the export if you are holding several, and still the better option if you would rather not handle a private key at all.

if you signed in with apple

The website does not offer Apple sign-in yet, so an Apple-only account cannot get into the export page at all. Open the app, go to your account screen, and use Signing in on a computer to link Google or X. That adds a second door to the same account — same wallet, same catches, same address — and then this page works for you like it does for everyone else. Do not sign in on the site with a different provider instead: that creates a second, empty account, and the two can never be merged.

what is erased

Everything on this list, and not as a soft delete.

  • Your profile.

    Display name, avatar, bio. Everything you chose rather than everything we derived.

  • Your handle, and the page behind it.

    The handle is released back into the pool the moment it is deleted, so somebody else can take it. Your public profile stops resolving.

  • Your catch history and your leaderboard position.

    What you caught, where, and when, and the standing it earned you. The board closes over the gap; nothing is kept as a tombstone.

  • The Privy identity.

    The link between you, your Google or X or Apple login, and the wallet address. Privy deletes the user, and the embedded wallet goes with the user — which is the reason the top of this page exists.

what nobody can erase

The part that is already public.

  • The chain.

    Every drop you caught was an ERC-20 transfer on Robinhood Chain. The transaction, the amount, the block, the receiving address: public, permanent, readable by anyone with or without an account here. There is no request anybody can make that undoes it — not to us, not to Robinhood, not to the explorer. A public ledger has no delete key, and pretending otherwise would be the one lie on this page.

  • Whatever is in the wallet.

    Deleting removes our record of the address. It does not empty it. The tokens sit exactly where they were, in an address that nobody can open again unless the key left before you did.

  • What those tokens are, in case it matters to the decision.

    A Stock Token is a token representing a derivative contract with Robinhood Europe UAB that tracks the price of a listed share. It is not a share, it confers no shareholder rights, its value can fall, and it is not covered by any investor compensation or deposit insurance scheme. It is also not nothing, which is precisely why the order on this page matters.

the three things that outlive the account

Two of them run out. One only runs out of room.

The anti-cheat side of the server is not told when an account goes. Two of the three things it keeps are written with an expiry on them and clear themselves. The third is a forensic log with no expiry at all, and it is not anonymous: it is keyed to the wallet address — the same address this page tells you to put in the email.

  • Daily counters, for 24 hours.

    How many catches an IP address, a device hash and an eleven-metre square of pavement have produced today. The device hash is a one-way digest of your IP, your browser or app string, your language and your platform — it cannot be turned back into any of them, and it is never stored next to your handle. Every one of these keys is written with a 24-hour expiry.

  • Four recent positions, for seven days.

    Kept twice, once against the wallet address and once against the device hash, so that the same walker cannot appear in Lisbon and in Helsinki eleven minutes apart. Four fixes, seven days, then they are gone without anybody pressing anything.

  • The anti-fraud logs. No expiry at all.

    Three worldwide lists: the last 200 refusals, the last 300 acceptances, and the last 300 claims stopped by a cooldown or a cap. Every entry carries your wallet address in plain text and which drop it was — plus, on the first two, the shape of the attempt: how far from the drop you were, your accuracy, your timezone, the two motion numbers, the city your IP resolves to, 90 characters of User-Agent and 30 of Accept-Language; and on the third, the city of the drop and the reason it was refused. Those lists are trimmed by length and never by age. That is a cap on volume, not a clock: your entry leaves only once 200 or 300 newer ones have pushed it off the end, which on a quiet week is a long time. It is the weakest retention rule we have, the privacy page says so in the same words, and it needs a real expiry it does not have.

Ask for these in your request and they go too. The counters and the fix history are keys with your wallet address in them, so they are dropped in a second. The log entries are lines inside three shared lists, so they have to be found and pulled out one at a time. Both get done by hand, which is exactly why they have to be asked for rather than happening on their own.

how to ask, today

There is no button yet. There is a person.

The server has no deletion endpoint. Rather than put a control on this page that spins and then quietly does nothing — the one failure you would have no way to detect — deletion currently goes through a human who reads the message and does the work. That is slower and it is real.

  1. 1. Take the key out. Again, first.

    If you skipped the top of this page, go back to it. Nothing below can be undone, and this is the only step that has to happen before the others.

  2. 2. Send the request.

    The button below opens your mail app with the subject and a short form already written. Send it from whatever address you like — the wallet address inside the message is what identifies the account, not the envelope it arrives in.

  3. 3. We check it is yours, then we do it.

    One reply asking you to prove the address is yours, because a deletion request is an extremely convenient way to attack somebody else's account, and we would rather annoy you than hand your catches to a stranger. After that it is done, and you get one message saying so.

If the button does nothing, your device has no mail app configured. The address is support@touchgrass.family and the subject line is Delete my account.

your rights, and who you are asking

Article 17. Not a favour.

Erasure is your right under Article 17 of the GDPR, and we do not get to weigh it against how much we like having you on the leaderboard. The neighbouring rights come with it and the same address answers all of them: a copy of what we hold on you (Article 15), a correction of anything wrong (Article 16), a portable export (Article 20) and an objection to a use you did not want (Article 21).

The deadline is one month from the request, which is the law and is also the promise. It can be extended by two further months for something genuinely complicated, and if that ever happens to yours we have to tell you inside the first month and say why. In practice this is a very small operation and the answer comes back in days — but one month is what is owed, not what is typical.

data controller — [legal entity, registration pending]

There is no registered company behind Touch Grass yet. It is being set up, and until it exists we are not going to print a name, a registration number and a registered office that would all be invented. When it is real, this box carries those three things and it will appear here before it appears anywhere else.

Until then the controller is the individual who operates touchgrass.family, reachable at support@touchgrass.family. One address, read by a person, and the only support channel there is. Your right to complain to your national data protection authority does not wait for our paperwork either.

what is coming

One tap, in the app, finishing the job where you started it.

The row already exists in the app and the warning it shows is already the right warning. What is missing is the endpoint behind it. When that ships, the Delete row stops opening a browser, this page becomes a confirmation screen instead of a set of instructions, and the email route stays open for anyone who would rather write to a person than tap a red button.

No excuse offered for the order it happened in. The button should have shipped with something behind it.

Key first, then the account. What we collect and the terms you agreed to are their own pages.