Work / Chitragupt / Wiki / Decisions
2026-08-01-account-deletion-grace-period-7-days
Decisioncanonicalverified 2026-09-12
DECISION.2026-08-01.ACCOUNT-DELETION-GRACE-PERIOD-7-DAYSAccount-deletion grace period is 7 days, not 24 hours
Decision
ACCOUNT_DELETION_GRACE_MS is canonically 7 days. The backend constant (previously 24 hours)
was the wrong value — fixed to match the majority of existing user-facing copy and the
FAMILY_DISSOLVE_GRACE_MS precedent (also 7 days).
Why
A completeness audit of the website found the account-deletion grace window disagreeing across
three places: the landing FAQ said "7 days," the dedicated FAQ page and the Privacy page said
"24h," and packages/shared/src/config/timeouts.ts (the actual backend enforcement) was set to
24 hours. The raw wireframes themselves disagreed with each other, so there was no clean source
of truth to defer to. Confirmed with the user directly: 7 days is correct.
Impact
packages/shared/src/config/timeouts.ts:ACCOUNT_DELETION_GRACE_MSchanged from24 * HOUR_MSto7 * DAY_MS.- Canonical message updated to "7 days to cancel · permanent wipe within 24 hours after" —
matches the real architecture (
dailyAccountDeletionProcessorruns once daily, so the wipe lands within ~24h of grace expiring, not the old decision's invented "30 days"). apps/website/src/app/(app)/settings/privacy/delete/page.tsx: local hardcodedGRACE_MSconstant removed; now importsACCOUNT_DELETION_GRACE_MSfromshared.- Copy fixed across
apps/website/src/app/(marketing)/faq/FaqContent.tsx,apps/website/src/app/(marketing)/legal/privacy/page.tsx,apps/website/src/components/settings/privacy/PrivacyQuickDeleteCard.tsx,apps/website/src/components/settings/privacy-delete/PrivacyDeleteConfirm.tsx, andapps/website/src/components/settings/account/AccountActions.tsx. - Also fixed a separate but adjacent drift on the same privacy page: the DPDP-rights list wrongly
attributed the general "7-working-day" support SLA to the statutory DPDP §13 grievance
deadline (actually 30 days per copy-strings
COPY.DPDP-GRIEVANCE-DEADLINE). Corrected to "statutory 30-day reply per DPDP Act 2023 §13." - Deleted two orphaned dead components discovered while fixing this copy —
DataManagementDeletionSection.tsxandDataManagementExportSection.tsx— neither was imported anywhere; the live danger-zone UI isPrivacyQuickDeleteCard.tsx+/settings/privacy/delete. Removed the now-unuseduseAccountDeletionRequesthook along with them;useDataExportRequestin the samehooks.tsfile is kept (still used byPrivacyBulkActionsCard.tsx). apps/functions/src/profile/deletion.tsneeded no change — it already read the shared constant rather than hardcoding a value.- Mobile (
apps/mobile/src/i18n/locales/en.json) was deferred here — mobile was paused for V1 (see 2026-06-27-mobile-end-user-only). Closed 2026-09-12: the threesettings.privacy.delete.*strings said "24-hour grace" / "wipe within 30 days" and now carry the canonical wording. The two live mobile screens (settings/account-deletion.tsx,settings/privacy.tsx) were already correct — they renderACCOUNT_DELETION_GRACE_DAYSfromsharedrather than a literal. Note those i18n keys have no caller: nothing inapps/mobile/srcimports@/i18n, so every one of the 64 screens hardcodes its English. Thet()boundary its own header comment describes is not actually in place.
Status
Active.
Sources
- Product decision in chat 2026-08-01, following the website feature-completeness audit.
Every project of mine is written down like this.
Read the résumé