Last updated: July 17, 2026

Data Deletion

Users can disconnect integrations and request deletion of account or integration data at any time.

Disconnect Google in OXPI

  1. Sign in to OXPI.
  2. Open the Calendar or Integrations page.
  3. Open Google connection settings.
  4. Click Disconnect Google.

Disconnecting Google revokes OAuth access with Google and removes stored OAuth tokens from OXPI. OXPI will stop creating, updating, or deleting Google Calendar events and will stop Gmail invoice monitoring after the integration is disconnected.

Disconnect Meta in OXPI

  1. Sign in to OXPI.
  2. Open the Integrations page.
  3. Open the Meta Campaigner integration card.
  4. Click Disconnect Meta.

Disconnecting Meta revokes OAuth access where available, removes stored Meta OAuth and Page tokens from OXPI, stops Lead Ads retrieval, stops asset synchronization, and disables new campaign, publishing, and reply actions for the disconnected Meta assets.

Delete imported Gmail invoice candidates

Users can request deletion of imported Gmail invoice-candidate metadata, including message metadata, snippets, selected headers, attachment filenames, invoice numbers, amounts, and customer match signals. Users can also request deletion of selected invoice or receipt attachment files stored by OXPI for invoice monitoring and accountant export. OXPI does not store full Gmail message bodies or unrelated Gmail attachments.

Revoke access from Google

Users can also revoke OXPI access directly from their Google Account security settings: https://myaccount.google.com/permissions.

Revoke access from Meta

Users can also revoke OXPI access directly from Meta Business Integrations settings: https://www.facebook.com/settings?tab=business_tools. Meta may notify OXPI through the deauthorize callback at /api/v1/meta/deauthorize; OXPI then clears stored Meta tokens, deselects connected assets, and requires the user to reconnect before using Meta features again.

Meta automated data deletion callback

Meta can send automated deletion requests to OXPI at /api/v1/meta/data-deletion. When OXPI receives a valid Meta signed request, OXPI removes stored Meta tokens for the matching Meta user and returns a confirmation code with a status URL.

Delete an OXPI user account or company workspace

  1. Sign in to OXPI and open Settings.
  2. Open Account & data deletion and choose either your user account or, if you are an owner, the current company workspace.
  3. Review the consequences and retained-record categories, enter the displayed confirmation phrase, and complete the password or recent sign-in verification step.
  4. OXPI immediately records the request, revokes the requesting user's active sessions and API tokens, and shows a request status and cancellation deadline after the user signs in again.

The default cancellation window is seven days. A request can be cancelled while it is still scheduled, awaiting manual review, or safely failed before destructive processing starts. The last active owner of a company cannot delete only their user account; ownership must first be transferred, or the owner must use the separate company-workspace deletion option. Company deletion is available only to an owner of that company.

Local processing removes or anonymizes the applicable account and company data, removes local integration credentials, and attempts deletion of private files held on local storage. Cleanup that requires a live third-party provider or remote storage is never reported as complete merely because local data was removed: it remains visible on the request as pending manual cleanup. If an active provider connection is detected, OXPI pauses before deleting local files, records, or credentials until provider revocation and local connection cleanup have been verified. Automatic destructive processing is also held for manual review wherever the approved production deletion policy has not been enabled.

Email support is an identity-verified fallback

If you cannot sign in, email support@oxpi.co.il with the subject line "Data deletion access help". Email alone does not authorize deletion. OXPI must verify account control and company ownership before an operator can create or advance a request.

Retention after deletion request

Tax and financial ledgers, payment and refund evidence, signed commercial evidence, consent records, and security/deletion audit evidence may be retained for legal, tax, fraud-prevention, security, or audit obligations. The configured outer retention period is seven years, subject to jurisdiction-specific legal approval and any shorter mandatory period. Direct account and contact identifiers are removed where the retained evidence permits it, and use is limited to the required purpose. Backup copies age out under the separately approved backup-retention schedule rather than being selectively rewritten in place.

Meta callback is not an OXPI account-deletion request

The Meta signed-request callback described above handles Meta-supplied integration data for the matching Meta identity. It is a separate provider callback and does not delete an OXPI user account or company workspace. Use the signed-in Settings workflow for general OXPI account or company deletion.