Delete your Ri-Hub account
You have the right to delete your Ri-Hub account and associated data at any time, in accordance with art. 17 GDPR ("right to be forgotten").
What gets deleted
- Immediately (within 30 days): user account, personal details, profile photo, preferences, active sessions, refresh tokens, cookie and marketing consents.
- Permanently anonymised: medical records (notes, history, assigned exercises), tax code, IBAN, residence/billing addresses, contacts, OAuth identifiers (Google/Apple).
- External propagation: automatic removal also from Stripe (invoice customer), Brevo (mailing list), internal CRM, MinIO (signed consent documents).
What is NOT deleted (legal obligations)
- Healthcare invoices and tax receipts: 10 years (art. 2220 of the Italian Civil Code + Italian Revenue Agency obligation). Documents are kept in pseudonymised form — no name/email visible — solely for accounting purposes.
- Healthcare access logs (who opened your medical record and when): 5 years (Provv. Garante 1/12/2017).
How to delete the account — 3 ways
1. Directly from the app (recommended, immediate)
- Open the Ri-Hub app or go to app.ri-hub.it
- Sign in with your account
- Tap the profile icon at the top right
- Go to Settings → Privacy and data
- Click "Delete account"
- Confirm with your password
You will receive a confirmation email. Deletion is scheduled for 30 days: within this window you can cancel it by writing to privacy@ri-hub.it.
2. Via web (if you have uninstalled the app)
Go to app.ri-hub.it/login and sign in. Then follow steps 3-6 above.
3. Via email (if you cannot sign in)
Write to privacy@ri-hub.it from the email of your account, indicating:
- First and last name
- Email associated with the account
- A sentence such as: "I request the complete deletion of my Ri-Hub account and associated data pursuant to art. 17 GDPR"
Reply within 30 days (art. 12 GDPR). A confirmation email will be sent once deletion is completed.
Want to export your data first?
You have the right to data portability (art. 20 GDPR): download a copy of all your data in JSON format.
- From the app: Settings → Privacy and data → "Export my data"
- Or write to privacy@ri-hub.it
Frequently asked questions
Can I cancel the deletion?
Yes, within 30 days of the request. Write to privacy@ri-hub.it. After 30 days the data is deleted and not recoverable.
What happens to future sessions already booked?
They are cancelled automatically. Any unused session packages are refunded 100% via Stripe (5-7 business days).
Does my physiotherapist still see my data?
No. Once the 30-day buffer has expired, the physiotherapist also loses access to any of your data (anonymised record).
What about my messages/feedback with the physio?
Anonymised: the message remains as aggregate statistical data, but detached from your identifier. It is not possible to reconstruct who wrote it.
Privacy contacts
For any request regarding the exercise of your GDPR rights (access, rectification, erasure, portability, restriction, objection) write to:
- Email: privacy@ri-hub.it
- PEC: ri-hub@pec.it
- Mail: Ri-Hub S.r.l. S.T.P., Corso Assarotti 19/1, 16043 Chiavari (GE), Italy
You also have the right to lodge a complaint with the Italian Data Protection Authority: www.garanteprivacy.it — Piazza Venezia 11, 00187 Rome.
For complete documentation on data processing, see our Privacy Policy.