This page explains how to delete your account in the WiraPass authenticator app (com.wiraapps.pass) and its data. WiraPass is developed by WIRA Code Indonesia.
If You Can Still Sign In
- Open the WiraPass app on your phone and sign in.
- Go to Settings, then Delete WiraPass account.
- Type DELETE to confirm, then unlock with your fingerprint or screen lock if the app lock is on.
- If your account has an active approval phone, the deletion must be done from that phone. This protects you from someone who stole your password: without this rule they could delete the account and register it again with their own phone.
Deletion takes effect at once and cannot be undone. All sign-in sessions on every phone end immediately, and the codes on the phone where you delete are removed too. Before deleting, make sure every service you protect still has another way in, such as that service’s recovery codes.
If Your Approval Phone Is Lost
- Install WiraPass on a new phone and sign in with the same account.
- Register the new phone for approvals, then choose Old phone lost.
- The new phone becomes active after a 24-hour waiting period. During that time the old phones are told and can still refuse it, and we also email your account address.
- Once the new phone is active, delete the account from it with the steps above.
By Email, If You Cannot Use the App
Send a request from your WiraPass account’s email address to support@wiracode.com and state the email address of the account to delete. We make sure the request comes from the account owner, delete the account within 3 × 24 hours, and let you know when it is done.
Data That Is Deleted
- The account: email address, display name, creation and last sign-in time.
- All linked sign-in methods (Google, Apple, email) and their account IDs.
- If you signed in with Apple: the Apple token is revoked with Apple, so WiraPass no longer appears under Sign in with Apple in your Apple account.
- The encrypted code vault backup on the server.
- Approval phones: names, public keys and notification tokens.
- Approval requests and their details.
- The backup code secret.
- The security log, including IP addresses and User-Agents.
- All sign-in sessions.
After the deletion we send one confirmation email to that account address.
What Is Not Deleted, and for How Long
- One record that an account was deleted, with no ID, email or IP address.
- Encrypted database backups (AES-256): your data can stay in them until they are removed. Hourly backups are kept for 48 hours, daily ones for 30 days and the off-server copy for 90 days, so at most 90 days. Backups are only used for disaster recovery.
- Codes on another phone that still has WiraPass installed (or on any phone if the account was deleted by email) stay on that phone until you sign out of WiraPass or uninstall the app.
- Records an integrated system keeps on its own side, such as the results of approvals you gave, are governed by that system.
Details of the data WiraPass processes are in the WiraPass Privacy Policy.