Data deletion · Sitr by Dooplin Apps · effective 2026-09-15
Delete your data
This page applies to Sitr — Halal & Family Filter for Android and iOS and to the Sitr browser extension, all published by Dooplin Apps S.L. The short version: you delete your own data, from the app, in seconds, with no account and no request form. What follows is exactly what exists, where, and how it goes away. The full policy is on the privacy page.
What data exists at all
On your device only: your settings — which optional categories are on, the sites you personally allowed or blocked, whether protection is on, and, if you set one, the guardian PIN as a salted hash. On Android the filter also reads DNS hostnames in memory to decide block or allow; they are discarded immediately and never written anywhere.
On our server, only if you use Sitr Family: one end-to-end-encrypted blob of household settings — shared allow/block lists, category configuration, the PIN hash, and a random identifier each device chose for itself. It is tied to no account, name, email, or phone. The keys never leave your devices, so we cannot read it; for us it is ciphertext under a random ID.
Nothing else. No browsing history, no analytics, no crash reports, no advertising identifiers, no logs of what you visit. There is no account to close because there is no account.
How to delete it
Step 1 — leave the household (Sitr Family users). This removes the household's lists, its encryption keys, and the PIN from the device at once.
- Android: open Sitr → Sitr Family → Leave household (enter the guardian PIN if one is set).
- iOS: open Sitr → Sitr Family → Leave household.
- Browser extension: open Sitr's options page → Household → Leave household.
Step 2 — uninstall the app or remove the extension. Every remaining setting lives in the app's private storage, which the operating system deletes with the app. Nothing is backed up to the cloud: the Android app opts out of device backups and transfers, so there is no copy to chase.
Step 3 — nothing. There is no request to file and no waiting period for anything on your device. The deletion is complete the moment steps 1 and 2 are done.
The server blob, and what is kept
Kept, for a while: the encrypted household blob. Once every device has left the household, no key exists anywhere that can open it — for anyone, including us. The server deletes any blob that has not been written to for 18 months; this is enforced in the server's own code, which is public. It keeps no request logs and rounds its only timestamp to the day.
Immediate server-side deletion: the blob is filed under a random ID that the apps derive from your household secret and do not currently display, so we cannot find "your" blob by name or email — that is by design. If you want it gone before the 18-month expiry, email [email protected] from any address and we will walk you through providing the ID; we answer within 30 days, usually much faster. A self-service "delete from server" button is planned, and this page will say so when it ships.
Sitr Family subscriptions: the purchase itself is handled by Polar as merchant of record. The subscription token you paste into the app contains an expiry date and no identity, and leaving a household discards it. To delete your payment records, use Polar's own privacy process; we never receive them.
Questions: [email protected] (privacy & legal) · [email protected] (product & support) · Dooplin Apps S.L., Carrer de les Carretes 13 Bajo, 08001 Barcelona.