Skip to main content
Reflecto
How it works Privacy Developers FAQ
Add to Chrome

Delete Your Data

Last updated: August 9, 2026

Reflecto is designed with privacy at its core. We use end-to-end encryption and do not maintain user accounts — your identity is tied solely to your device pairing, not to an email address or personal information.

Below you'll find how to delete your data and what gets removed.

Delete Data from the App (Recommended)

The fastest way to delete all your data is directly within the Reflecto app:

  1. Open the Reflecto app on your Android device
  2. Go to Settings
  3. Open the Danger zone section and tap Disconnect
  4. Confirm the disconnection

This immediately and permanently:

  • Revokes your device record on our server
  • Deletes your encryption keys from the device
  • Removes your FCM push token and any Web Push subscription
  • Clears all local preferences and app filter settings
  • Disconnects your paired devices (Chrome extension, web app, and any others)

After disconnecting, our server can no longer associate any data with your device. No residual data remains.

What data does Reflecto store?

On our server (api.reflecto.dev)

  • A server-assigned device ID (random identifier, not tied to your name or email)
  • Your device's public encryption key (used to route encrypted messages)
  • Your FCM push token and/or Web Push subscription (used to deliver commands to your devices)
  • Encrypted notification, clipboard, and file-transfer data in a temporary queue (auto-deleted within 24 hours, or sooner once delivered and dismissed — large clipboard images and in-progress file transfers use their own short-lived, similarly temporary storage)

All notification, clipboard, and file content is end-to-end encrypted. Our server cannot read it — it only stores opaque ciphertext until your other device picks it up.

On your device

  • Your encryption key pair (stored in Android Keystore-backed encrypted storage)
  • Your paired devices' public keys
  • Your app filter settings (which apps to mirror)
  • Onboarding progress flags

On Firebase (Google)

  • Your FCM token (for push notification delivery)
  • Anonymized crash reports via Firebase Crashlytics (stack traces only, no notification content or personal data)

Lost or no longer have your device?

If you can't access the app, here's what happens automatically:

  • If the app was uninstalled or the device was factory reset: Your encryption keys are permanently destroyed on the device. Without those keys, the encrypted payloads on our server are cryptographically unrecoverable. They will also auto-delete within 24 hours.
  • All notification, clipboard, and file content was already end-to-end encrypted before it ever reached our server. We cannot read it, and it becomes permanently inaccessible once your keys are gone.
  • Your device record (device ID, push token, public key) will persist on our server in an orphaned state but cannot be linked to you in any way — Reflecto has no accounts, no email addresses, and no personal identifiers. It is a random identifier with no associated personal data.

In short: if you no longer have the device, the data is already effectively deleted. There is nothing further for you or us to do.

After deletion

Once disconnected via the app:

Data Status
Device record Immediately revoked
Queued encrypted notifications, clips, and file transfers Deleted (or auto-expire within their retention window)
Push token / subscription Deregistered from our server
Crashlytics data Retained by Firebase per Google's policy (anonymized, no personal data)
Local encryption keys Destroyed
Local preferences Cleared

You can re-pair at any time by setting up Reflecto again. A new device ID and new encryption keys will be generated — there is no continuity with the previous session.

Crash report data (Firebase Crashlytics)

Reflecto uses Firebase Crashlytics for crash reporting in release builds. This data is:

  • Fully anonymized (no notification content, no personal identifiers)
  • Limited to stack traces and non-sensitive log breadcrumbs
  • Managed by Google under their data retention policies

To opt out of Crashlytics data collection, disable "Usage & diagnostics" in your Android device settings (Settings > Google > Usage & diagnostics).

Questions?

Contact us at support@reflecto.dev

Reflecto
Google Play Web App Chrome Extension API Docs Contact Privacy Policy Delete Your Data
© 2026 Reflecto. All rights reserved.