Editorial note: This checklist covers the operational side of closing a home-security account. It is not legal advice and it does not promise that every vendor can erase every record immediately. Retention rules, active contracts, billing disputes, incident evidence, warranties, and local law can affect what a provider keeps. Ask the provider for its current policy in writing.
Short answer: Do not press Delete Account until you have exported the records you need, moved alarm and camera ownership, removed other users, ended paid services, preserved incident evidence, disconnected integrations, reset supported devices, and confirmed what the provider will retain. A clean exit is a sequence, not one button.
The NIST Privacy Framework treats data processing as something organizations should identify and govern. The FTC phone-security guidance also stresses account protection, updates, backups, and device erasure before disposal. For a household, the practical lesson is simple: inventory the account, data, people, devices, services, and recovery paths before removing access.
What this checklist is for
Use it when you sell a house, leave a rental, change security providers, retire a camera platform, close an unused account, separate a shared household, return hardware, or take over a system from someone else. The job is to leave neither a stranded device nor a former user with hidden access.
| Exit layer | Question to answer | Evidence to keep |
|---|---|---|
| Account | Who is the primary owner and who can recover it? | Owner email, deletion request, case number |
| People | Which residents, guests, installers, and responders still have access? | User and role inventory |
| Monitoring | When does monitoring stop and what happens to dispatch details? | Cancellation confirmation and effective date |
| Video and events | Which clips, alarm events, and access records must be exported? | Export manifest and secure storage location |
| Devices | Which hub, camera, lock, or sensor remains bound to the old account? | Serial list, removal state, reset result |
| Integrations | Which Apple Home, Alexa, Google Home, IFTTT, or partner links survive? | Connected-service inventory |
| Billing | Are subscriptions, financing, warranties, or returns still open? | Final invoice, refund, return tracking |
1. Name the owner and the exit reason
Write down the current account owner, security email, recovery phone, service address, hub identifier, and reason for closure. A move-out is different from a product return. A household separation is different from changing vendors. The exit reason determines who needs the data, who receives hardware, and when access must end.
If the current owner cannot sign in, stop. Use the provider’s documented recovery route and the password manager and recovery-code audit. Do not ask support to bypass identity checks or send credentials through an unsecured channel.
2. Freeze avoidable changes
Before exporting anything, pause nonessential edits. Do not rename devices, delete users, clear clips, change the service address, or factory-reset the hub while another person is collecting records. Record the time the exit process began and who is responsible for each step.
Keep the alarm operating until the household has an agreed handoff time. If monitoring is active, confirm how tests, cancellations, permit details, and emergency contacts should be handled during the transition. Never create a real alarm event to test a cancellation workflow.
3. Build a data and evidence manifest
List what the account may contain:
- alarm events, arming history, sensor names, and zone records;
- camera clips, snapshots, downloads, and shared links;
- door-lock users, codes, access records, and temporary schedules;
- household members, guests, installers, emergency contacts, and monitoring notes;
- automations, scenes, geofences, notification rules, and device groups;
- billing invoices, plan changes, support cases, return records, and warranty documents;
- hub, camera, lock, sensor, and accessory serial numbers.
Mark each item export, transfer, delete, or retain with reason. A vague “download my data” note is not enough when video, billing, support, and device records live in separate parts of an app.
4. Preserve incident evidence before deleting clips
If the system holds footage or events connected to a break-in, insurance claim, police report, neighbor dispute, or support investigation, ask the relevant professional what to preserve before deleting anything. Keep the original file where possible, note its source and export time, and avoid unnecessary editing or re-encoding.
Store the export in an access-controlled location. Remove public or guest links that are no longer needed. Use the clipboard, screenshot, and export privacy audit to find copies left in chats, downloads, photo libraries, shared drives, or temporary folders.
5. Export configuration needed for the next system
A new platform may not import the old configuration, but the household still needs a map. Record device locations, entry delays, named zones, contact lists, camera placement, privacy zones, network requirements, battery types, and automation intent. Do not copy old PINs or passwords into the replacement system.
Photograph physical placement only when the image does not expose private codes or recovery details. A plain room-and-device table is usually safer and easier to maintain.
6. Reconcile people before devices
Export or write down the user list and role of each person. Identify primary owners, backup administrators, residents, children, caregivers, cleaners, dog walkers, installers, and temporary guests. Decide who needs access until the handoff minute and who must be removed earlier.
For a shared household or separation, use a named checklist and a witness where appropriate. Change the primary email and recovery details before removing the only person who can manage the account. Run the backup administrator drill if a second owner will continue operating the system.
7. End subscriptions without creating a coverage gap
Separate account deletion from subscription cancellation. They may be different workflows. Ask for the effective cancellation time, final billing date, refund or return treatment, monitoring end time, cellular-backup end time, video-retention change, and what unpaid functions remain.
Save the confirmation and case number. Compare it with the next invoice. If the old system must remain active until a replacement passes testing, schedule cancellation after the new alarm, notifications, and response chain have been proven. The subscription renewal audit helps separate features that disappear from features that continue locally.
8. Disconnect integrations in a controlled order
List every connected service and automation controller. That may include Apple Home, Alexa, Google Home, an automation platform, a voice assistant, a lock service, a garage controller, a router rule, a monitoring portal, or a shared calendar. Remove automations that could operate an old lock, garage door, siren, or alarm state after the primary account changes.
Test that the remaining home does not show stale tiles or trigger failure loops. If HomeKit accessories are being retired, use the HomeKit accessory decommission checklist for bridges, scenes, rooms, automations, and ownership.
9. Remove devices from the account before factory reset
Follow the vendor’s current order. Some products must be removed from the old account before a reset; others need an ownership-transfer process. Confirm each device is no longer bound to the old owner, then complete the supported reset and test whether the new owner can add it.
Do not assume a flashing light proves ownership was cleared. Verify in both the old account and the new setup path. Use the factory-reset checklist to preserve evidence, monitoring details, integrations, and recovery information before erasing hardware.
10. Change recovery channels and shared secrets
Remove old recovery phone numbers, app sessions, trusted devices, passkeys, authenticator registrations, backup codes, API tokens, and shared mailbox access. Rotate credentials on any retained network, lock, camera, or home-automation service that was shared with the departing account.
If the owner email changes instead of the account closing, follow the security-email change checklist. Confirm alerts, invoices, password resets, and monitoring notices reach the new address before removing the old one.
11. Submit the deletion request precisely
Use the provider’s official account or privacy channel. State the account identifier, service address if required, request date, categories of data involved, devices transferred or retired, and whether a separate subscription cancellation has already been completed. Ask for:
- the request or case number;
- the expected response window;
- which records can be deleted;
- which records must be retained and why;
- how long retained records remain;
- whether backups age out on a different schedule;
- whether third-party processors receive the request;
- how completion will be confirmed.
Do not send passwords, recovery codes, payment details, or full identity documents unless the official workflow clearly requires a specific item and you have verified the destination.
12. Verify closure from both sides
After confirmation, test the old login without triggering repeated lockouts. Check that old app sessions no longer open the account, shared users cannot see the property, integrations no longer expose devices, and transferred hardware works for the new owner. Confirm the final invoice and any refund or return.
Keep a minimal closure record: date, account, request number, confirmation, retained-data explanation, final invoice, device disposition, and person who verified the result. Do not keep full video exports or identity documents merely because they were part of the process.
45-minute home-security account deletion acceptance test
- 0–5 minutes: Confirm the named owner, reason, handoff time, and whether monitoring must stay active.
- 5–12 minutes: Review the data manifest and confirm required clips, events, invoices, and support records were exported.
- 12–18 minutes: Verify all residents, guests, installers, and recovery channels have a final disposition.
- 18–25 minutes: Confirm subscription, monitoring, financing, warranty, return, and billing outcomes in writing.
- 25–32 minutes: Remove integrations and test that no stale automation can operate an alarm, lock, siren, camera, or garage door.
- 32–38 minutes: Confirm each transferred or retired device was removed from the old account and completed its supported reset or transfer path.
- 38–42 minutes: Verify old sessions and shared access are closed without disturbing retained evidence.
- 42–45 minutes: File the case number, deletion confirmation, retained-data explanation, final invoice, and device disposition in a restricted record.
Stop conditions
Pause the deletion when any of these is true:
- an incident, claim, investigation, or dispute may require original evidence;
- the current owner cannot prove or recover account control;
- a replacement alarm has not passed a supervised test;
- monitoring cancellation time is unclear;
- a lock, camera, hub, or bridge remains bound to the old account;
- the only administrator or recovery channel is about to be removed;
- billing, financing, return, or warranty obligations are unresolved;
- the provider cannot explain what deletion does to devices and retained records.