Cancel yourself in billing settings, keep everything until the period you paid for ends, then thirty days where mail still arrives and nothing is deleted, then real teardown. Plus how to take your data out over the same standard protocols you were already using.
Most providers will tell you how easy it is to join. Far fewer will tell you what happens when you leave, which is strange, because the second question is the one that determines how much power they have over you.
So here is the whole thing: how to cancel, what happens on each day afterwards, how to take your data with you, and when it is genuinely gone from our systems. Written down in public, so you can hold us to it.
There is no retention call. There is no form that opens a support ticket that gets answered in three business days by someone whose job is to talk you out of it. Cancelling is a button in your billing settings, and an owner can press it.
When you do, nothing happens immediately, and that is deliberate. Your subscription is marked to end when the period you have already paid for ends. Until that date everything keeps working exactly as before, because you paid for it. We do not cut service the moment you decide to go and pocket the remainder.
Change your mind before that date and you can call it off yourself, in the same place, with no conversation.
On the date your subscription ends, three things happen together. Billing stops. Sign-in is locked. And a deletion date is set, thirty days out.
That middle month is the part worth understanding, because it is the difference between a company that is confident and one that is holding your data hostage.
Nothing is deleted during those thirty days. Not your mail, not your files, not your wiki, not your chat history.
Your mail is still received. Messages sent to your domain during the grace window still arrive, rather than bouncing. That matters because the most common way a migration goes wrong is a customer or supplier who did not get the memo, and thirty days is enough time to notice.
We built it that way because the panicked realisation happens in week two, not on the day. "We forgot about the invoices address" is a solvable problem if the mail is still arriving and an expensive one if it bounced.
One honest limit here: if you want to come back during the grace window, that takes us a moment rather than a click, because your billing subscription was closed and a new one has to be set up. Email us and we will sort it out. We would rather say that than pretend to a self-service button that does not exist.
After thirty days, the workspace is torn down for real, across every system: the mail server, the identity system, your drive, your wiki, your chat, and the billing record. Then the workspace row itself is deleted from our database.
This is not reversible, and it is not a flag set to "deleted" on a record that stays where it was. Because each customer's drive and wiki are their own instances with their own databases and their own storage, and each chat organisation is its own organisation, deletion removes whole objects rather than filtering rows out of a shared store.
The one thing we do not delete is your record at our payment provider, which holds the invoices and the mandate. That is retained on their side, partly because invoicing records have their own legal retention requirements. We would rather list the exception than claim a clean sweep that is not quite true.
Here is the part that makes the rest of this credible: there is nothing to negotiate, because your data was never in a format only we can read.
Your mail is reachable over IMAP and JMAP, the same as it always was. Point any mail client at it and copy the whole thing across, or drag folders from one account to another in Thunderbird. Your new provider can pull it directly over the same protocols. No export request, no ticket, no waiting for an archive to be generated.
Your calendars and contacts are CalDAV and CardDAV. Same story. Point a client at both accounts and copy.
Your files are reachable over standard protocols too, so you can sync the whole drive down to a folder on a computer and take it wherever you like.
We do not have a big "download everything" button, and honestly, the protocols are better than a button would be. A button gives you a single archive on our terms, in whatever format we chose, at whatever moment we generated it. Standard protocols let your new provider migrate you directly, incrementally, with your folder structure intact, using tools that already exist.
The best time to verify this is before you need it. Connect a normal mail client to your account and watch it download everything. That is your exit, and you can test it on a Tuesday afternoon with nothing at stake.
Because the whole argument for a sovereign workspace is about who holds power over your business. A provider that makes leaving vague is exercising that power whether or not you ever try to leave, and every renewal you sign under those conditions is signed slightly under duress.
We would rather compete on the product. Which means the exit has to be a documented, self-service, protocol-standard path, not a phone call. If you are going, we would like it to be because something else suited you better, not because we made staying easier than going.
And if you are evaluating us and this post is the reason you are taking us seriously, that is exactly why it exists. The migration guide covers the same journey in the other direction.