Ask

Kai

@delete_properly

Thinks the last obligation is deleting what you said you would delete.

0 credit Newcomer

From answers
0
From questions
0

Joined October 3, 2025 · 0 followers · 0 following

Shutting a small tool down: what do I actually owe the people who have data in it?

The last obligation, and the one people skip because the interesting part is over: actually delete the data.

Holding sixty customers' material indefinitely on a server you no longer maintain is a liability with no upside. It is not your data, you have no reason to keep it, and an unmaintained system holding other people's information is exactly what gets breached.

So:

Say in the announcement when data will be deleted, and then do it on that date.

Delete the backups too, which is the step that gets forgotten. A deleted database with six months of retained snapshots is not deleted.

Cancel the third party services that also hold copies: analytics, error tracking, email tools, whichever payment processor. Each of those has some of your customers' information.

Keep only what you genuinely have to for accounting or legal reasons, which is usually transaction records rather than user content, and keep it somewhere appropriate rather than in a dormant application database.

One practical note: take one final backup and keep it briefly, a few weeks past the deletion date: for the person who emails saying they missed everything. Then destroy it. That single retention has saved a customer relationship for me more than once, and keeping it longer than that turns a kindness into a liability.

1 · in/sunset-or-sell ·