Your data (export and deletion)
A signed-in user downloads their data and deletes their account from Settings → Privacy & data at app.vulnify.io/settings/privacy. Owners and admins can export the organization’s data; only an owner can delete the organization. In Portuguese the section is Privacidade e dados. The path is /settings/privacy in both languages.
The app shows the section only when GET /me/data-rights returns HTTP 200 and JSON with boolean fields export, deleteAccount, and deleteOrganization. A missing session (HTTP 401), any other status, or a network error hides the section. The app shows no error banner in that case. A 200 body that lacks those three booleans is treated the same way.
These routes use the session cookies __Host-vln_at and __Host-vln_rt, the same way the rest of the app does. See Security and compliance for the cookie attributes, the one-version read of the previous vln_at and vln_rt names, and logout. They are omitted from the public /v1 contract and from https://api.vulnify.io/openapi.json.
export turns on the account download. deleteAccount turns on account deletion. deleteOrganization is true for an owner of the current organization and turns on organization deletion. When none of those flags enable an action, the screen says that no data actions are available for this account.
Download your data
Section titled “Download your data”Your data asks for GET /me/export. A successful response is HTTP 200, Content-Type: application/json, and Content-Disposition: attachment with the file name vulnify-account-<yyyy-mm-dd>.json. The JSON format is vulnify.account-export/v1. This download is JSON only.
The file is your profile, your memberships, and your activity. Passwords, secrets, and access tokens are left out. The app saves the file under the name from that header.
More than 5 of these requests in an hour returns HTTP 429 and {"error":"rate_limited"}. The app asks you to try again later.
Delete your account
Section titled “Delete your account”Delete account opens a confirmation dialog. Type DELETE in capital letters, enter your password, and, when MFA is on, an authenticator code or a recovery code. The app sends DELETE /me. confirm is exactly DELETE, with no space before or after the word. mfaCode is included when MFA is on.
{ "password": "...", "confirm": "DELETE", "mfaCode": "..." }If you are the only member of an organization you own, deleting the account deletes that organization too. That deletion is irreversible. The API cancels that organization’s active subscription immediately, before it deletes the organization, with no refund and no prorated credit, except where the law requires one. DELETE /organization cancels in the same way, before the organization is removed. If a subscription exists and cancelling it fails, the response is HTTP 503 {"error":"unavailable"} and nothing is deleted.
HTTP 204 clears the session cookies (__Host-vln_at and __Host-vln_rt). The app then clears its local session and opens /login?notice=signed-out. That page says “You have been signed out.”
| Status | Body | What you do |
|---|---|---|
| 400 | {"error":"validation_error","fields":{...}} |
confirm is missing or is not exactly DELETE, or another field is invalid. The app shows the field messages. |
| 401 | {"error":"invalid_credentials"} |
The password or the code is wrong. |
| 403 | {"error":"forbidden"} |
The demo sandbox cannot be deleted. Outside the sandbox, 403 means you do not have permission. |
| 409 | {"error":"sole_owner","organizations":[{"id":"...","name":"..."}]} |
You are the only owner of these organizations, and they still have other members. The app lists the names and links to Team. Transfer ownership there, or delete the organization, before deleting the account. Nothing is deleted. |
| 429 | {"error":"rate_limited"} |
Try again later. |
| 503 | {"error":"unavailable"} |
A subscription exists and cancelling it failed. Nothing is deleted. |
Download an organization
Section titled “Download an organization”Owners and admins can export the organization’s data with GET /organization/export. Only an owner can delete the organization. The Privacy & data screen shows that download to both.
A successful response is HTTP 200 JSON, attached as vulnify-organization-<yyyy-mm-dd>.json. The format is vulnify.organization-export/v1. This download is JSON only, as is GET /me/export. Neither route returns CSV.
Secrets, hashes, and billing identifiers (including Stripe ids) are left out. Events and audit evidence are not in this file. Owners and admins export that evidence from Compliance with GET /compliance/export. Omitting format returns JSON. CSV is only GET /compliance/export?format=csv. See Audit log.
A caller who is not an owner or an admin receives HTTP 403 and {"error":"forbidden"}. More than 5 requests an hour returns HTTP 429 and {"error":"rate_limited"}.
Delete an organization
Section titled “Delete an organization”Delete organization is for an owner of the current organization. The dialog asks you to type the organization name exactly, then your password, and an authenticator or recovery code when MFA is on. The app sends DELETE /organization. confirmName is the organization name exactly, with no extra space. mfaCode is included when MFA is on.
{ "password": "...", "confirmName": "the organization name", "mfaCode": "..." }confirmName must equal the organization name. Otherwise the response is HTTP 400 and {"error":"validation_error","fields":{...}}. A wrong password or code is HTTP 401 and {"error":"invalid_credentials"}. HTTP 403 and {"error":"forbidden"} cover a caller who is not an owner, and a demo or sandbox organization. The app says the demo sandbox cannot be deleted when you are in that sandbox, and that you do not have permission otherwise. HTTP 429 is {"error":"rate_limited"}.
An active subscription is cancelled immediately, before the organization is removed, with no refund and no prorated credit, except where the law requires one. The deletion is irreversible. If a subscription exists and cancelling it fails, the response is HTTP 503 {"error":"unavailable"} and nothing is deleted.
HTTP 204 means the organization is deleted. The web app then clears its local session flag and opens /login?notice=signed-out. That page says “You have been signed out.” The API clears __Host-vln_at and __Host-vln_rt only when the deleted organization was the caller’s last organization. If the caller still belongs to another organization, those cookies are not cleared. The previous access token then returns 401, and the next sign-in opens the remaining organization.
Backups
Section titled “Backups”Customer data is removed from the running service when the account or the organization is deleted, except what the law requires Vulnify to keep. That exception applies to the live service.
The production database is backed up automatically every day at 03:00 BRT (Brasília time). Each backup is encrypted with age before it leaves the database host. The decryption key is held only by Vulnify. The encrypted files are stored in Cloudflare R2. Cloudflare only holds those encrypted files and cannot read them. Backups are kept for at most 30 days, then deleted automatically. Deleted data can remain in a backup until that copy expires, at most 30 days. A restore of a full copy of the production database was tested on 2026-10-02, with row counts verified for every table. Restore drills are scheduled monthly.
DELETE /me and DELETE /organization do not remove contact-form leads or the email suppression list. Contact-form leads are kept for 12 months. The suppression list is kept so an address that permanently bounced, or that filed a complaint, is not mailed again.
Decision events are deleted automatically after your plan’s retention window (Developer 7 days, Team 30 days, Business 365 days). The deletion job runs regularly. Enterprise retention follows your contract; there is no automatic deletion unless agreed. When an event is deleted, its audit-log entry (the decision, risk score and related metadata) is kept for as long as the organization exists, because the audit log is append-only. Deleted data can remain in encrypted backups for up to 30 days. See Security and compliance.
Other requests
Section titled “Other requests”Correction, and any request the screen does not perform, goes to privacy@vulnify.io. That mailbox does not receive mail yet. You can also write through vulnify.io/contact. The Privacy Policy is the legal statement of personal-data handling. You can also complain to the ANPD or your local authority. See Your rights on the security page.

