Data export and service termination

How to get your data out, what happens when an account ends, and how long anything survives afterwards.

Version
0.2
Effective
2 September 2026
Last updated
2 September 2026
Draft — pending legal review. Written by the operator to be accurate about what the software does. It has not been reviewed by a lawyer, it is not legal advice, and nobody is asked to accept it while it says this.

Getting your data out

Export is available for as long as the account exists, without asking us and without anything having to be settled first. It is not withheld during a suspension: losing access to the dashboard must never mean losing the leads you already collected.

One button on the account screen produces a zip archive of everything the organisation holds. An owner can take it at any time; an editor can still export the leads of a project from its own screen.

What is in the archiveFormat
The organisation, including the billing identity you entered.JSON
Members and their roles, and who has access to which project.JSON
Every project: its settings, domains, retention and privacy mode.JSON
Every widget, with its content, design, triggers, rules, variants and custom code.JSON
A/B tests, and which widgets are in them.JSON
Integrations: which are configured and how, never the credentials.JSON
Every lead, including the consent wording each visitor saw.Newline-delimited JSON, in parts
Statistics, as the counters hold them.Newline-delimited JSON, in parts
The activity record for the organisation.Newline-delimited JSON, in parts
Acceptance records, and the full text of every document version.JSON and plain text
Use of the AI designer: model, tokens, cost. Never a prompt or an output.JSON
Every uploaded image, with a manifest naming its public URL.The files as uploaded
A manifest describing the format, its version, and what is in each folder.JSON

Four things are deliberately not in it: integration credentials, which are encrypted at rest and would be a liability in a downloaded file; API token hashes; passwords, which we never hold in a readable form; and the email addresses of other members, which belong to the sign-in service and are not readable by the application.

Folder names inside the archive are plain ASCII, with the real project name in the manifest. That is not a limitation of the format but of the unzip program shipped with macOS, and an export that will not open is not an export.

Ending your account

You can delete a project, or close the whole account, from within the product. Closing it is an owner's decision, shows what will go before it goes, asks for the organisation's name to be typed, and offers the export first.

It then deletes the organisation and everything scoped to it — projects, widgets, leads, statistics, invitations, memberships, the activity record and the acceptance records — and deletes your sign-in as well, unless you own another organisation, in which case you keep the account and lose only the one you closed. API tokens stop working first, before anything else is touched.

One row is kept: that a termination happened, the organisation's identifier, the date and how much was removed. It contains no name, address or user identifier. An account closure has to be accountable, and a record that keeps the person is not a record.

Removing the script tag from your website stops Popfinch loading at all, immediately, whatever else is true of the account.

Export first. Deletion is not reversible from your side, and the backups described below are for our disaster recovery rather than a way to undo a deletion you meant.

If we end it

We give 30 days' notice, except where the acceptable use policy is being broken, in which case it can be immediate. In either case you keep export access for 30 days from the notice, and we say why.

If the service were to shut down entirely, the same 30 days applies and the notice comes by email to every account owner.

What survives, and for how long

  • The live database: deletion is immediate.
  • Database backups: up to seven days, being the provider's daily backup retention. A deleted row can be inside one until it expires.
  • A project's own retention setting: if you set one, leads older than it are deleted nightly without anybody having to remember.
  • Records we are required to keep — an invoice, for instance — are kept for the period the law requires and no longer.

No document of ours will promise that a deletion has taken effect everywhere at once, because backups do not work that way and saying otherwise would be untrue.

Operator: Vielendark s. r. o., Cyprichova 2477/24, 831 53 Bratislava - mestská časť Rača, Slovakia. Registration number 55121250, tax number 2121872962, VAT number SK2121872962, registered in the Commercial Register of the Municipal Court Bratislava III, Section Sro, Insert No. 167007/B. Contact: hello@popfinch.com. Privacy: privacy@popfinch.com. Security: security@popfinch.com. Abuse: abuse@popfinch.com. Owner verification outstanding: these register details have not yet been checked against a current extract from the Commercial Register.

Plain text copy · All documents