Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Since when logout comes with a "we'll delete your account if you don't log back in in 30 days"?

This is just an atrocious flow. A better approach would be a "temporary emergency block", and then give the user a week to sort it out, otherwise the account is automatically reinstated.



While 30 days sounds extreme, I’ve got plenty of warnings in the past 25 years from sites which wanted, and did delete my account because I didn’t visit their site in a specified timeframe, like half a year, or a year.


I got one from Discord a few days ago. I didn't check if it was real or phishing, and I didn't check my password manager. I can't remember why I would have created a discord account so I'll let it go. Maybe I was self squatting.


The 30 days thing is likely from GDPR requirements. You cannot keep user data longer than that after they request deletion.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: