Skip to content

Leaving Nodrik

Leaving is one button, and it is the only irreversible thing in the product. This page says exactly what it does before you press it, because a destructive action nobody has described in advance is one people press either too readily or never at all.

Leaving is not the same as lapsing. Stopping paying puts you on a 30-day path with reminders, everything kept, and a way back — that is further down. Leaving happens the moment you confirm it, and there is no grace period behind it.

Leaving ends the money as well as the workspace. The subscription is cancelled at Stripe before anything is deleted, so it stops there and then: no renewal, no further charge, nothing to unpick afterwards.

Two consequences worth knowing before you press it:

  • The rest of the period you have paid for is not refunded. There is nothing left to use it in: the service account, the alert topic and every investigation are gone the moment you confirm. Cancelling at period end instead would only have meant paying on for a workspace that no longer exists.
  • If the cancellation fails, nothing is deleted. Stripe is asked first, and a teardown that cannot end the subscription stops there rather than half way — your workspace is left exactly as it was, the console says so, and you can try again. A deleted workspace that is still being charged is the one outcome this is built to make impossible.

If what you want is to stop paying but keep what you have until the period runs out, that is a different button: cancel from Usage, which opens Stripe’s own customer portal. Nodrik keeps working until the period ends, the plan then lapses onto the 30-day path, and you can leave from the banner that appears — or change your mind. Most people who reach for the danger zone want this one.

Settings ▸ Leave Nodrik, at the bottom of the page, and only for an admin. It is not dimmed for anybody else, it is not rendered at all: a danger zone somebody cannot use is a warning with no action attached to it. The roles are on Your team.

Confirming means typing your workspace id exactly. That is enforced in the console and again in the API behind it, because something irreversible should be hard to do by accident at every layer that can do it, not only at the pretty one.

Teardown runs immediately, in a deliberate order, and access goes first:

  1. The service account is deleted — the one identity that could read anything in your projects. From that instant Nodrik is blind to your estate whether or not the rest of the teardown finishes, and whether or not you ever remove the role bindings your side.
  2. Slack and GitHub are revoked at the source. Our Slack app is uninstalled from your workspace and our GitHub App installation is deleted — not merely forgotten our end. If either call fails, the teardown carries on and deletes your data anyway: your right to have it deleted cannot be held hostage to Slack being reachable.
  3. Your alert topic and its subscription are deleted, so the notification channel in your project has nothing left to publish to.
  4. The credential container is destroyed — the Slack bot token, and any credential you issued for your own tools.
  5. Every investigation goes, with the report and the transcript behind each one. That is the part actually derived from your telemetry.
  6. Your notifications, your mutes and your grant history go too. A notification names the projects it is about; a mute carries the cause you silenced and the words you typed to explain it; a grant run records which project was granted, by which Google account, and every step it took. All of it is about your estate, so all of it goes with your estate.
  7. Your configuration goes with it: declared tool sources, the sign-in links that admit people to the workspace, and every pending invitation — a live invitation left behind would be a working link into a workspace that no longer exists.
  8. The workspace’s audit log is deleted last, including the entry recording the teardown itself. We say we delete everything; a history of your workspace is not an exception we get to keep for ourselves.
  9. The tenant record itself is emptied, not merely marked closed. The name you gave the workspace, your monitored project ids, your Google organisation, the Slack workspace, the GitHub installation, the contact address and the Stripe customer and subscription ids are all removed from it in the same write. What is left is described below.

Then you are signed out, onto the sign-in screen rather than into a console where every page would now fail.

There is no undo, no confirmation email with a link that reverses it, and no window in which support can restore it. The data is gone rather than marked deleted.

Two things outlive the workspace on purpose, and both are things you can check rather than promises:

  • A hash of your estate, so a trial is one per estate. Your Google organisation, your monitored project ids and Stripe’s fingerprint of your card are each kept as a one-way hash, and nothing else — never the values themselves. If this were deleted with the workspace, anybody could tear a workspace down and start another free fortnight, which is the whole thing the check exists to prevent. Set out in full on Security and trust and, in the version you are entitled to rely on, in the privacy policy.
  • Your workspace id is retired rather than reused. A closed marker stays behind so the same id is never handed out again — including to you, if you come back. It holds the id and the fact that the workspace is closed, and nothing else: the id is itself a one-way hash of your Google account id, never a name you chose. It cannot be deleted without breaking the thing it exists for — Google reserves a deleted service account’s name for about thirty days, so a returning customer needs a new workspace id, and this marker is what makes them get one.

Nothing else about you is meant to remain. If you want the estate hash released as well — you are leaving for good, not pausing — ask us and we will delete it.

Stripe keeps its own record, and that is not ours to delete. As the merchant of record it holds your invoices, the card it charged, and the terms you accepted at checkout, for as long as its own retention and our accounting obligations require. That is the copy an accountant would ask for; we do not keep a second one, and the Stripe customer and subscription ids on our side go with the tenant record.

The four read-only roles live in your project, granted under your own authority, and nothing we can do reaches them. Deleting the service account leaves those bindings pointing at a principal that no longer exists, which is harmless but untidy, and the notification channel your alert policies use is left pointing at a topic that is gone.

The console shows you the exact command before you confirm, with your service account, your topic and every monitored project already filled in. It is the same revoke-nodrik-access.sh from the public nodrik-onboarding repository the connection paths use, and the block clones the repo rather than piping it into a shell so that you can read it before you run it — which is the point of that repo being public at all. Full detail, including the dry run: By script.

You do not have to run it for your data to be deleted. Our side of the teardown runs on our schedule and does not wait for yours. Running it removes the bindings and the notification channel; your alert policies keep working with whatever other channels they have.

You can sign up again with the same account. What you will not get is another trial: the estate check is exactly what the surviving hashes are for, so a fresh workspace on the same organisation, the same projects or the same card subscribes at the ordinary price, starting that day. You are told before you pay anything — see If the trial is refused.

Everything else starts from nothing. A new workspace means a new service account, so the grant has to be run again; Slack and GitHub have to be reconnected; and your old investigations are not there to come back to, because they were deleted.

If you think you have a real reason for a second trial on the same estate, tell us — releasing a claim is something we can do, and it is a conversation rather than a form.

Stopping paying is a different path from leaving, and a much softer one. It is worth knowing it exists before reaching for the danger zone, because most people who want to stop for a while want this rather than deletion.

A subscription lapses when a trial ends unpaid, or when Stripe gives up retrying a card. A card that is merely failing is not a lapse and changes nothing while the retries run. Then, for 30 days:

  • Everything is kept — monitored projects, Slack, GitHub, your configuration and your investigation history.
  • Nothing is investigated. The gate that decides whether an alert becomes an investigation needs an active plan.
  • Home carries one banner with Subscribe (your previous tier pre-selected, no second trial), Change plan, and Leave.
  • Reminders reach every admin on day 1, day 14 and day 27 — day 1 in case the lapse is a mistake nobody has noticed, and day 27 three days before anything is removed. Each one is also in the console’s notifications, so a closed inbox is not the only copy.

On day 30 the workspace is torn down, by exactly the steps above — bar the cancellation, because a lapsed subscription has already ended and Stripe is what told us so. Subscribing at any point in the window stops the clock and your setup is waiting.

A workspace that never chose a plan at all — signed up, skipped the trial, never came back — is removed on the same 30-day clock, counted from the day it was created.

Thirty days is the outer bound the data processing agreement commits to for deleting your data after you leave. The grace period and the deletion bound are deliberately the same number: if your data would be kept that long anyway, there is no reason to tear your setup down any sooner. More on the money side of it: Plans and billing.

Leaving because of noise is worth a pause. A cause you already understand can be silenced without ending anything — see When no card appears — and removing a single project from Settings ▸ Projects stops Nodrik watching it while everything else carries on. Both are reversible; this page is not.