Google account access
Disconnect inside Windlord
Open Settings → Google accounts → select the account → Remove from this iPhone. This removes the device credential and that account’s encrypted local projection from this device; it does not revoke Google access on another device.
Revoke at Google
Remove Windlord from Google’s third-party access page. Google then rejects future token refreshes; Windlord marks the connection for reauthorization.
Open Google connectionsDisconnecting one account does not affect another. Actions already confirmed by Google remain part of your Gmail or Calendar until you reverse them there or through an authorized client.
Local mailbox and calendar data
Disconnecting a Google account deletes its cached threads, messages, labels, calendar data, search index, sync cursors, and credential through a crash-recoverable cascade. Deleting the app removes its application container. If encrypted multi-device sync is enabled, delete the Windlord account to erase hosted ciphertext and revoke other devices.
Google is the source of truth. Deleting Windlord’s local copy does not delete email or calendar events from Google. Use an explicit Gmail or Calendar action if that is your intent.
Agent access
Inspect
Settings → Agents lists the client identity, accounts, data classes, actions, risk ceiling, approval rules, content ceiling, creation time, and expiration for every grant.
Revoke
Select a grant → Revoke. Revocation closes derived sessions and prevents new requests. An in-flight provider attempt enters reconciliation; it is never silently replayed.
Reduce authority
Create a narrower replacement grant. Windlord does not mutate a grant in place or let renewal widen its authority.
Remove provider data
Deleting a Windlord grant cannot delete data retained by an external agent/model provider. Use that provider’s privacy controls separately.
Analytics controls
Native product evidence
In Settings → Product Evidence, choose Off or Keep evidence on this iPhone. The local engine stores only closed-schema, content-free events in the encrypted app database. You can prepare a JSON export and share it through the iOS share sheet; Windlord does not receive that file unless you deliberately send it to Windlord. Hosted sharing is unavailable in this beta, so the app does not upload Product Evidence to Windlord.
Public website
The website loads no Google Analytics or Microsoft Clarity code before you opt in. Use Analytics choices in any page footer to allow, decline, or withdraw website analytics. Withdrawal disables collection, removes accessible first-party analytics cookies, and reloads the page without either provider. Website consent does not change the app’s Product Evidence setting, and app consent does not change website consent.
Export data and receipts
The current private beta has no self-service hosted Windlord export control because customer hosted sync is not active. Mailbox and calendar source content remains available through Google’s export tools. If hosted sync is introduced, this page will describe the available export control.
Email team@supertrained.ai with an access or portability request. Support can explain what Windlord currently holds and help restore a trusted-device or recovery path, but cannot bypass device authority to decrypt hosted ciphertext.
Subscription controls
No paid Windlord subscription is active in the current private beta, so there is nothing to cancel and no Windlord billing-management path. Provider-specific cancellation and refund instructions will appear here only after the corresponding StoreKit, Stripe, or organization purchase surface is released.
Delete the Windlord account
To remove one Google connection and its local Windlord cache without changing other devices or revoking the provider grant, use Remove from this iPhone. To delete an active hosted Windlord account, open Settings → Windlord account → Delete Windlord account. That separate native two-step ceremony requires fresh device authentication with Face ID or device passcode plus typing DELETE, shows the exact effect, revokes every connected Google grant plus account devices and agents, deletes account-scoped hosted records and encrypted local data, and retains a signed deletion receipt on the device.
If the account has no active hosted record, there is nothing hosted to erase. If you lost every trusted device or the authenticated ceremony is unavailable, email team@supertrained.ai; support verifies account control and cannot bypass the deletion authority model.
Submit a privacy-rights request
Email team@supertrained.ai to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or an appeal. State your request and the minimum account identifier needed to locate the record. Never send passwords, OAuth tokens, recovery secrets, or mailbox contents.
We may request a device-signed challenge or other proportionate verification. We respond within the time required where you live and explain any denial and appeal route.