Spitfire mobile app: account and data deletion
Effective: 9 October 2026
This page explains how the account and data of people using the Spitfire Android app (tr.spitfire.app) are deleted. The app is a client that connects to the Spitfire controller your organization runs on its own server: no account is created in the app, and your account is not held by Spitfire (us) but on your organization's controller.
Where your account comes from
Your organization's Spitfire administrator creates your account on the controller. If your organization uses single sign-on (OIDC or LDAP) and turned on "Create the account on first sign-in", the account is created on the controller by itself the first time you sign in with your organization's identity provider; that too is your organization's choice and happens the same way when you sign in on the web. The app has no sign-up screen.
Deleting the data on the phone (you do it)
- More › Sign out: deletes that server's session tokens and notification key from the phone; if notifications are on, it also removes the phone's notification registration from the controller.
- Turning off More › Notifications › Get notifications from this server removes the phone's notification registration from the controller and its key from the phone.
- Servers › (server) › Remove: also deletes the server's name, address and trusted certificate fingerprint from the phone.
- Uninstalling the app (or Android settings › Spitfire › Storage › Clear data) deletes all data on the phone: servers, language and theme choice, session tokens, notification keys. This does not remove the notification registration on the controller at once; the controller removes it itself when, at the next notification, Google's messaging service reports that the app is no longer installed. Signing out first removes it at once.
Your password is never stored on the phone.
Deleting your account and data on the controller
Spitfire (we) cannot delete your account or your data on the controller: the controller is your organization's server, we have no access to that data, and your organization is responsible for it. Send your deletion request to your organization's Spitfire administrator.
- The administrator disables your account on the Users page of the web UI. A disabled account cannot sign in, its open sessions cannot be renewed and it gets no notifications.
- Spitfire's web UI disables a user record rather than deleting it; deleting the record (e-mail, name, role) and the data below completely is done by your organization on its own database.
What the controller keeps, and for how long
These are Spitfire's defaults; your organization's administrator can change some of them in the Data retention settings.
- Account record (e-mail, name, role, your identity at the identity provider for single sign-on): until your organization deletes it.
- Sessions (a hash of the session token, the browser or app identification): valid for at most 30 days, deleted a day after they expire. Signing out invalidates them.
- Notification registration (device name, Firebase device token, notification public key, chosen events): deleted when you sign out, turn notifications off, or the app is uninstalled and the messaging service reports it. Encrypted notifications that could not be delivered are deleted when they expire.
- Password reset requests: deleted 7 days after they expire.
- Audit log (who did what and when, with the e-mail address, IP address and browser or app identification): kept indefinitely by default; the administrator can set a retention of 30 days or more.
- Runs you started and their results: kept indefinitely by default (the administrator can set 7 days or more); the runs' per-second measurements 90 days by default (a license may set a shorter period). Runs belong to your organization and may stay as its records after your account is deleted.
Data held by Spitfire (us)
No account or personal data reaches us from the app. Our notification server (relay.spitfire.tr) does not store your device token and cannot read the notifications; it only keeps a record of the Spitfire installations that send notifications. So there is no app account of yours with us to delete. Details: mobile app privacy policy.
Contact
If you cannot reach your administrator, or for questions: the contact address at the bottom of the page. As we have no access to your organization's controller, we help you take the request to your organization.