Everyday Privacy
How to Find and Delete Old Online Accounts
The short version
Every account you abandoned still holds your data, and it will leak on its own schedule - MySpace was breached around 2008, but nearly 360 million accounts only surfaced in 2016. Find your old accounts by searching your inbox for sign-up emails, auditing saved passwords, and checking the "sign in with" connections in your Google, Apple, and Facebook settings. Then delete them, worst first, using each service's own deletion page. What you cannot delete, empty out. An hour of digging plus a weekend of closing accounts removes years of accumulated exposure.
Why forgotten accounts are a security problem
A dormant account is not neutral - it is stored personal data with nobody guarding it. You no longer log in, so you never see warning signs, and the account almost certainly runs on an old password you have reused elsewhere. When Google announced its inactive-account policy, it said its internal analysis found abandoned accounts are at least 10 times less likely than active accounts to have 2-step verification set up.
The other problem is time. Breaches of dead services surface years late. MySpace was breached around 2008, but the data - almost 360 million accounts with email addresses, usernames, and weakly hashed passwords - only appeared publicly in May 2016. Whatever you typed into a service in 2012 is still sitting in a database somewhere, waiting on someone else's security.
How many old accounts you probably have
More than you think. Password manager NordPass's 2026 study of its users found the average person manages roughly 120 personal passwords, plus about 67 work ones - down from a peak of 168 personal passwords in its 2024 study, largely thanks to single sign-on and passkeys. Behind most of those passwords is an account.
Now add the accounts that are not in any password manager: the forum you joined once in 2014, the shop you bought a single gift from, the app you tried for a week. Each one holds, at minimum, your email address, a password, and whatever profile details it asked for. The scale of the problem is visible in the breach numbers: as of August 2026, Have I Been Pwned indexes over 17.7 billion breached email address records across more than 1,000 compromised sites.
Step 1: mine your inbox for sign-up trails
Your email is the most complete record of every account you ever created, because nearly every sign-up triggered a confirmation message. Search your inbox - including archived mail - for phrases like "welcome to", "verify your email", "confirm your account", "your account has been created", and "unsubscribe".
Work through the results and build a plain list: service name, the email you used, and whether you still want it. Do the same search in any old email accounts you still control - the Hotmail or Yahoo address you used in the 2000s is exactly where the oldest, most forgotten sign-ups live. If an old mailbox still exists, this is the moment to search it, before its provider's inactivity clock wipes it.
Step 2: audit saved logins and "sign in with" connections
Your browser and password manager hold the next layer of evidence. Open the saved-password list in Chrome, Safari, Firefox, or Edge, and in any password manager you use, and skim it end to end. Most people find dozens of logins they had completely forgotten, each one an account still holding their data.
Then check the accounts you created without a password at all. In your Google account, review the third-party apps connected via "Sign in with Google"; Apple and Facebook have equivalent lists for their sign-in buttons. Each entry is a live account at some service you may not have opened in years. Note them all on the same list.
Step 3: let breach records jog your memory
Breach databases are a surprisingly good account-discovery tool: if a service you forgot got breached, the breach record proves you had an account there. Checking your email against Have I Been Pwned lists the known breaches it appears in, and each named service belongs on your cleanup list.
RedactZero's free exposure scan runs that breach check for you and also shows public profiles tied to your username and the data brokers likely to list you, without storing anything you type. A breach hit does double duty: it names an account to close, and it flags a password that needs changing anywhere you reused it.
Step 4: delete, starting with the worst
With your list built, do not slog through it alphabetically - triage it. Delete first the accounts that hold payment cards, government ID, home addresses, health details, or private messages. Then kill anything using a password you have reused on accounts that matter. The one-time forum sign-ups can wait for a rainy day.
For the mechanics, JustDeleteMe is the standard shortcut: an open-source directory of direct links to each service's deletion page, with each one rated easy, medium, hard, or impossible. When a service hides deletion behind a support ticket, email its support or privacy address and ask plainly for account deletion. If you live in a state with deletion rights, say so - our guide to data deletion rights by state covers who can demand what.
Do not count on providers deleting for you
Some big platforms now delete inactive accounts on their own, but their clocks are cleanup policies, not a privacy plan. Google's policy allows deletion of a personal account unused for two years, with warning emails first and deletions possible since December 2023. Microsoft closes accounts after two years without a sign-in. Yahoo is the strictest of the three.
| Provider | Inactivity clock | What happens |
|---|---|---|
| 2 years | Personal account may be deleted, after multiple warning emails; accounts with purchases, subscriptions, or YouTube videos are excluded for now | |
| Microsoft | 2 years | Account considered inactive and closed, unless an active subscription, balance, or similar exception applies |
| Yahoo | 12 / 24 months | Mailbox untouched for 12 months has all mail, folders, and contacts permanently deleted; around 24 months without sign-in the account itself is scheduled for deletion |
Source: Google, Microsoft, and Yahoo inactive-account policy pages, checked August 2026.
Notice what these policies do not cover: the hundreds of smaller services with no inactivity policy at all. Those accounts persist until you delete them or the company folds - and a folding company's user database often gets sold or leaked rather than erased.
When you cannot delete: empty the account instead
Some services make deletion genuinely impossible, and some "deletions" are really deactivations. When you hit that wall, minimize instead: the goal is that whatever the service keeps is worthless. Before you stop, strip the account of everything it will let you remove.
- Delete saved payment cards, addresses, and phone numbers.
- Replace profile details with blanks or placeholders where the form allows it.
- Change the password to something long, random, and unique, so a future breach of the site exposes nothing you use elsewhere.
- Turn on 2FA if offered - an account you cannot delete should at least be hard to take over.
Then file the account under "check yearly" rather than pretending it is gone.
Keep the pile from growing back
A cleanup only sticks if new accounts stop accumulating. Two habits do most of the work. First, stop creating accounts you do not need - use guest checkout for one-time purchases. Second, when you must sign up, use an email alias per service, so any future leak is traceable and disposable.
Once or twice a year, repeat the short version of this audit: skim new saved passwords, re-run a breach check, and close anything you have not touched since the last pass. It pairs naturally with the broader weekend digital-footprint cleanup and with the data broker opt-out guides, because brokers and old accounts are the two big stores of your data that keep growing on their own.
Find what is already exposed
Run a free exposure scan to see which breaches include your email, what is public under your username, and which data brokers likely list you - no account, nothing stored.
Frequently asked questions
How do I find old accounts I forgot about?
Search your email for phrases like "welcome to", "verify your email", and "your account", then go through your saved browser and password-manager logins, and check the connected-apps lists in your Google, Apple, and Facebook settings. A breach check on your email address often surfaces accounts you had completely forgotten.
Should I delete old accounts or just leave them alone?
Delete them. An account you never touch still holds your data and still gets breached. Google's own analysis found abandoned accounts are at least 10 times less likely than active ones to have 2-step verification enabled, which makes them the softest targets you own.
What if a site has no delete option?
First check JustDeleteMe, which links directly to deletion pages and flags how hard each service makes it. If there is genuinely no self-serve path, email the company's support or privacy address and request deletion, citing your state's deletion rights if you have them. If they refuse, strip the account of real data instead.
Will Google or Microsoft delete my unused account automatically?
They can. Both companies' policies let them delete or close a personal account that has not been used for two years, after warning emails. Yahoo is stricter: a mailbox untouched for 12 months has its contents permanently deleted. Do not rely on these clocks - they are cleanup policies, not a privacy service.
Does deleting an account erase my data from past breaches?
No. If an account was breached before you deleted it, copies of that data are already circulating and deletion cannot recall them. What deletion does is stop future breaches of that service from including you. For past leaks, change any reused passwords and keep an eye on breach notifications.
Is it safe to use a deletion directory like JustDeleteMe?
Yes. JustDeleteMe is an open-source directory that links you to each service's own official deletion page - you never hand it your credentials. It also rates each service's deletion difficulty from easy to impossible, which helps you plan where the friction will be.
How long does it take to clean up old accounts?
Finding accounts takes an hour or two of inbox and settings archaeology. Deleting them varies: many services close an account in minutes, while some make you email support or hold the account in a reactivation window before it is finally removed. Treat it as a weekend project done in batches.
Why do I have so many accounts in the first place?
Because nearly everything online requires one. NordPass's 2026 study found the average person manages roughly 120 personal passwords, plus about 67 for work. Every one-time purchase, free trial, and forum question left an account behind, and almost none of them were ever closed.
Sources: Google's inactive account policy announcement and support page (blog.google, support.google.com); Microsoft account activity policy (support.microsoft.com); Yahoo inactive mailbox help page (help.yahoo.com); Have I Been Pwned (haveibeenpwned.com), including its MySpace breach listing; NordPass password study, 2026 (nordpass.com); JustDeleteMe (justdeleteme.xyz).