User Data Deletion

    Last updated: April 25, 2026

    ML GROUP INVEST Sp. z o.o. ("we", "us", "our"), the operator of Mochu (mochu.io), respects your right to control your personal data. This page explains how you can request the deletion of your data and what happens when you do.

    Your rights are protected under Regulation (EU) 2016/679 (GDPR), the Polish Act on the Protection of Personal Data (Dz.U. 2018 poz. 1000), and other applicable data protection laws.

    1. How to Request Data Deletion

    You can request data deletion through any of the following methods:

    1.1 Disconnect Individual Social Media Accounts

    You can disconnect any connected social media account directly from the Service dashboard by navigating to Settings → Accounts and clicking the disconnect button next to the account you wish to remove. Upon disconnection, all data associated with that specific account will be permanently deleted from our systems within 30 days, including:

    • All synchronized comments, reviews, and moderation data
    • All direct messages and conversation history
    • All posts and media associated with the account
    • All advertising data linked to the account
    • OAuth access tokens and refresh tokens (immediately revoked and deleted)
    • Account settings, AI configuration preferences, and reply templates
    • Sync logs and sync state data

    1.2 Delete Your Entire Account

    To delete your entire account and all associated data, send an email to:

    Data Deletion Request

    Email: hello@mochu.io

    Subject line: "Data Deletion Request — [your email address]"

    In your email, please include the email address associated with your account. Pursuant to Article 12(6) GDPR, we may request additional information necessary to confirm your identity, but only to the extent proportionate to the request (e.g. confirmation from the e-mail address associated with the account, or an answer to a verification question relating to account activity). We do not charge any fee for processing such requests — pursuant to Article 12(5) GDPR, exercising the right to erasure is free of charge. A fee or refusal to act may be applied only in the case of manifestly unfounded or excessive requests (in particular due to their repetitive character).

    Upon receiving and verifying your request, we will permanently delete all your data within 30 days, including:

    • Your user account and profile information (email, name, avatar)
    • All organizations you own (including all member data within those organizations)
    • All connected social media account data (tokens, settings, content)
    • All synchronized comments, messages, posts, and reviews
    • All advertising campaign data and budget automation rules
    • All media files uploaded to the media library
    • All reply templates, post drafts, and AI configurations
    • All usage logs and analytics data
    • Security audit logs associated with your account

    1.3 Meta (Facebook & Instagram) Data Deletion Callback

    If you connected your Facebook or Instagram account to our Service and wish to delete your data, you can also initiate deletion directly from Facebook:

    1. Go to your Facebook Settings & Privacy → Settings → Apps and Websites.
    2. Find "Mochu" in your active apps.
    3. Click Remove.
    4. Facebook will automatically send a data deletion request to our servers via the Data Deletion Request Callback URL configured in our app.
    5. We will process the deletion and remove all data associated with your Facebook/Instagram account within 30 days.

    Note: This method only deletes data associated with your Facebook/Instagram connection. If you also connected other platforms (TikTok, LinkedIn, Twitter/X, YouTube, Google Business Profile), you must disconnect those separately from the dashboard or request full account deletion via email.

    Meta confirmation code: Upon receiving a request via the Meta Callback, our system returns a unique confirmation code and a status URL to Facebook, where you can check the deletion progress at any time. The status URL has the format https://mochu.io/data-deletion-status?id=<code>. The code is also sent to the e-mail address associated with the account once erasure is complete.

    1.4 Deletion of YouTube and Google Business Profile data (Google API)

    In line with the requirements of the Google API Services User Data Policy and the YouTube API Services Terms of Service, data obtained via Google OAuth (YouTube channels, YouTube comments, Google Business Profile reviews and posts, statistics) is erased:

    • Immediately after disconnecting the Google account from Settings → Accounts → YouTube/Google Business → Disconnect (OAuth token revocation).
    • Within 30 days, historical data (synchronized comments, reviews, posts, metrics) is permanently removed from the primary databases and from backups during the next rotation cycle.
    • You may also revoke application access directly at myaccount.google.com/permissions — this will invalidate the token and automatically trigger the data-deletion procedure on our side.

    1.5 Deletion of TikTok, LinkedIn, and Twitter/X data

    • TikTok (TikTok for Business / Login Kit): Disconnect the account in Settings → Accounts → TikTok → Disconnect. The OAuth token is immediately revoked and data (comments, messages, posts, metrics) erased within 30 days. You may also revoke application access in TikTok: Settings & Privacy → Security and login → Manage app permissions.
    • LinkedIn (Marketing Developer Platform): Disconnect the account in Settings → Accounts → LinkedIn → Disconnect. The token is revoked via the /oauth/v2/revoke endpoint and data erased within 30 days. The application can also be revoked at: linkedin.com/psettings/permitted-services.
    • Twitter/X (X API v2): Disconnect the account in Settings → Accounts → X → Disconnect. The OAuth 2.0 token is immediately revoked and data erased within 30 days. The application can also be revoked in Settings and privacy → Security and account access → Apps and sessions → Connected apps.

    2. What Data Is Deleted

    The following table summarizes what data is deleted depending on the type of request:

    Data CategoryDisconnect AccountFull Account DeletionMeta Callback
    Profile (email, name, avatar)Deleted
    Organization data & membersDeleted
    OAuth tokens (access/refresh)DeletedDeletedDeleted
    Comments, reviews & moderation dataDeletedDeletedDeleted
    Direct messages & conversationsDeletedDeletedDeleted
    Posts & mediaDeletedDeletedDeleted
    Advertising data & budget rulesDeletedDeletedDeleted
    Templates & AI configurationsDeletedDeletedDeleted
    Media library filesDeleted
    Usage logs & analyticsDeleted
    Billing & invoice recordsRetained*Retained*Retained*
    Security audit logsRetained*Retained*Retained*

    * Retained data: Billing and invoice records are retained for a minimum of 5 years as required by Polish tax law (Art. 112 Ustawa o VAT, Art. 86 §1 Ordynacji Podatkowej, Art. 74 Ustawa o Rachunkowości). Security audit logs are retained for up to 12 months for fraud prevention and legal compliance. Data necessary to establish, exercise, or defend legal claims may be retained for the applicable limitation period (up to 6 years under Polish civil law).

    3. Deletion Timeline

    • Acknowledgement of receipt: Without undue delay, no later than within 72 business hours, we will acknowledge receipt of your request.
    • OAuth tokens: Revoked and deleted immediately upon disconnection or acceptance of the request.
    • All other associated data: Permanently deleted within 30 calendar days of the request, in accordance with Article 12(3) GDPR. Where the request is complex, or where there are a large number of requests, this period may be extended by a further 60 days (up to 90 days in total) — in which case we will inform you of the extension and the reasons within the first month.
    • Encrypted backups: We operate a 30-day rotation of encrypted infrastructure backups (Supabase Point-in-Time Recovery + daily snapshots). After erasure from production systems, data may remain in encrypted backups for up to 30 days. Backup data is not accessible to the application or operators, is protected by keys managed by the infrastructure provider, and is automatically and permanently overwritten during the next rotation cycle. Backup data is not used for any purpose other than disaster recovery — if a backup is restored within the 30-day window after erasure, we will re-execute the erasure within 24 hours of the restoration.
    • Sub-processors: We will instruct our sub-processors (Supabase, OpenAI, Anthropic, Stripe, Paddle, Resend, Cloudflare, and others) to delete any data they hold on our behalf in accordance with the Data Processing Agreements (DPAs) concluded with them. The full sub-processor list is available in our Privacy Policy, Section 7.10, and the processing terms are described in Section 25 (Data Processing Agreement). We cannot guarantee the deletion timeline of sub-processors but will make commercially reasonable efforts and verify execution under each DPA.

    4. Data We Cannot Delete

    The following data cannot be deleted upon request due to legal obligations:

    • Invoices and billing records: Polish tax law requires retention for a minimum of 5 years. This includes invoice numbers, dates, amounts, company names, NIP/VAT numbers, and billing addresses.
    • Security audit logs: Retained for up to 12 months for fraud prevention, security monitoring, and compliance with legal requests from authorities.
    • Legal hold data: If we have received a legal hold, court order, or request from a competent authority regarding your data, we may be required to retain certain data until the hold is lifted.
    • Anonymized data: Data that has been irreversibly anonymized so that it can no longer identify you is no longer personal data under GDPR and may be retained indefinitely for statistical and analytical purposes.

    5. Data on Third-Party Platforms

    Important: Deleting your data from Mochu does not delete any data from the Third-Party Platforms themselves. Comments, messages, posts, and other content that exist on Facebook, Instagram, TikTok, LinkedIn, Twitter/X, YouTube, or Google Business Profile are managed by those platforms independently.

    To delete data from those platforms, you must use each platform's own privacy settings, data deletion tools, or contact their support directly. The Provider has no ability to delete data stored on Third-Party Platforms on your behalf.

    Similarly, for non-EU/EEA users whose payments are processed by Paddle (Merchant of Record), billing and payment data held by Paddle must be deleted through Paddle directly. Contact Paddle at paddle.com/legal/privacy.

    6. Deletion Confirmation

    Upon completion of your data deletion request, we will send a confirmation email to the email address associated with your account (or the email from which the request was made) confirming that your data has been deleted. If you initiated deletion via the Meta Data Deletion Callback, you can verify the status using the confirmation code provided by Facebook.

    7. Consequences of Data Deletion

    Please be aware that data deletion is permanent and irreversible:

    • You will lose access to all synchronized comments, messages, posts, and analytics.
    • All reply templates, AI configurations, and automation rules will be lost.
    • All media files in your library will be permanently deleted.
    • If you delete your entire account, all organizations you own will be deleted, which will also affect other members of those organizations.
    • Active subscriptions will be cancelled (no refund for the current billing period).
    • We cannot recover any data after deletion. If you wish to use the Service again, you will need to create a new account and reconnect your social media accounts.

    Recommendation: Before requesting deletion, consider exporting any data you may need. You can download your media files from the media library and save any templates or configurations you wish to preserve.

    8. Your Rights

    Under GDPR Art. 17 (Right to Erasure / "Right to be Forgotten"), you have the right to request the deletion of your personal data, in particular where: the data are no longer necessary for the purposes for which they were collected; you have withdrawn consent to processing; you have objected to processing; the data have been unlawfully processed; or erasure is required to comply with a legal obligation.

    Exceptions to the right of erasure (Art. 17(3) GDPR): We may refuse deletion or delete data only in part, to the extent that processing is necessary:

    • for exercising the right of freedom of expression and information (Art. 17(3)(a) GDPR);
    • for compliance with a legal obligation requiring processing under EU or Polish law — in particular tax and accounting rules (Art. 74 of the Polish Accounting Act, Art. 86 §1 of the Polish Tax Ordinance, Art. 112 of the Polish VAT Act — 5-year retention) and AML/CTF rules (Art. 17(3)(b) GDPR);
    • for reasons of public interest in the area of public health (Art. 17(3)(c) GDPR);
    • for archiving purposes in the public interest, scientific or historical research, or statistical purposes (Art. 17(3)(d) GDPR);
    • for the establishment, exercise, or defence of legal claims — for the duration of the limitation period (up to 6 years under the Polish Civil Code, Art. 17(3)(e) GDPR).

    In any such case, we will inform you of the reasons for partial or deferred erasure and of the period after which the data will finally be deleted.

    You also have the right to lodge a complaint with the supervisory authority if you believe we have not handled your deletion request properly. In Poland, this is the President of the Office for Personal Data Protection (Prezes Urzędu Ochrony Danych Osobowych — UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

    For full details on all your data protection rights, please refer to our Privacy Policy. For the complete terms governing your use of the Service, see our Terms of Service.

    9. Contact

    For data deletion requests, questions, or concerns:

    • ML GROUP INVEST Sp. z o.o.
    • ul. Adama Mickiewicza 83, 48-100 Głubczyce, Poland
    • NIP: 7481587576 | KRS: 0000179753 | REGON: 381683570
    • Email: hello@mochu.io

    This Data Deletion Policy has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Polish Act on the Protection of Personal Data (Dz.U. 2018 poz. 1000), and Meta Platform Terms regarding Data Deletion Request Callbacks.

    © 2026 Mochu. All rights reserved.

    This website is not part of, endorsed by, sponsored by, or affiliated with Meta Platforms, Inc., ByteDance Ltd. (TikTok), LinkedIn Corporation (Microsoft), X Corp. (Twitter), Google LLC (YouTube, Google Business Profile), or Apple Inc. Facebook™ and Instagram™ are trademarks of Meta Platforms, Inc. TikTok™ is a trademark of ByteDance Ltd. LinkedIn™ is a trademark of LinkedIn Corporation. X™ (formerly Twitter) is a trademark of X Corp. YouTube™ and Google™ are trademarks of Google LLC. All other trademarks, logos, and brand names are the property of their respective owners.

    Używamy plików cookie do analityki, aby ulepszać Mochu. Możesz zaakceptować wszystkie lub zostawić tylko niezbędne. Szczegóły w Polityce prywatności.