Privacy & your data
Deleting an online account properly
Closing an account is the single most effective privacy action available to you — and the easiest one to get wrong. What to export first, what deletion actually removes, the safeguards a decent deletion flow should have, and what to do if the account was deleted without your consent.
Most privacy advice asks you to configure something. Deletion is the rare piece that asks you to remove something, and it outperforms almost everything else you could do. A closed account cannot be breached, cannot be scraped, cannot be repurposed for advertising, and cannot be taken over three years from now by someone who bought a credential list.
It is also the action people most often botch. They delete the wrong thing, lose material they wanted, discover a week later that four other logins depended on it, or find that "delete" meant something much narrower than they assumed.
This guide covers the whole sequence: deciding what to close, what to save first, what deletion actually does, what a trustworthy deletion process looks like, and what to do if an account disappears without your having asked.
Why closing accounts matters more than tightening settings
Every account you hold is an independent copy of some part of your life, sitting on someone else's infrastructure, governed by a privacy policy that can change, and owned by a company that can be acquired.
Three things follow.
Dormant accounts are the worst kind. You are not watching them. You will not notice the breach notice, the suspicious sign-in, or the terms update that started sharing something new. A service you last used in 2019 still holds your email address, your date of birth, whatever you uploaded, and often a payment card — and it is defended by a password you probably reused.
Settings decay; deletion does not. A privacy toggle is a promise about the present. Products get redesigned, settings get migrated, and defaults quietly reset. Deleted data has none of those failure modes.
Old accounts are how identity fraud starts. Attackers do not usually break into your bank. They break into something forgotten, find your address, your old phone number, your mother's maiden name in an ancient security question, and then use that to talk their way past someone else's support desk. Our guide on recognising social engineering goes into how that conversation actually plays out.
If you only do one thing after reading this: open your password manager, look at the list, and close the five oldest entries you no longer use.
Deactivation is not deletion
Nearly every large platform offers both, and the difference is material.
Deactivation hides your profile. Your data stays intact, your account can be restored by signing in, and in most cases nothing is erased at all. It is a pause. It is genuinely useful if you want a break, and it is the right choice more often than people think.
Deletion starts an erasure process. It is meant to be permanent, usually after a grace period.
Some services present deactivation first, use softer language for it, and bury deletion a few screens deeper. That is a design choice you should read as a signal, not a technical constraint. If you intend to delete, check afterwards that you actually did — sign out, then try to view your own profile in a private browser window a day or two later.
Export before you delete
This is the step people skip and regret. Deletion is designed to be irreversible, and support cannot undo it for you once the window has closed.
Before you confirm anything, take an export. Most services offer one under privacy or account settings; in the EU, UK, Brazil, India, and much of the US you have a legal right to it, and our guide to exercising your data rights explains how to force the issue if the button is missing.
A few things worth pulling out specifically:
- Photos and video. Frequently the only copies in existence.
- Message history, if the conversations matter to you or to anyone else.
- Contacts and connections — you will not be able to reconstruct the list from memory.
- Purchase, subscription, and warranty records, especially anything you might need for tax or a claim.
- Anything you wrote. Reviews, posts, long comments.
Exports are often produced asynchronously and expire after a few days. Start the export, wait for it to arrive, verify that you can actually open the archive, and only then delete.
Untangle the account before you close it
This is the failure mode that causes the most damage, and it is entirely avoidable.
Check what uses it to sign in. If you have ever clicked "continue with Google", "sign in with Apple", or "log in with Facebook", that account is now a key to other accounts. Delete the key and you can be locked out of everything behind it — sometimes permanently, because the recovery path for those services runs through the identity you just destroyed. Before closing any account you have used this way, go through the connected-apps list and move each dependent service onto its own email address and its own credential.
Check what it receives. Password resets, two-factor codes, billing notices, and recovery links all go somewhere. If the account you are closing is an email account, work through securing and migrating your email first; email is the root of most people's identity and should be the last thing you touch, not the first.
Cancel the money. Deleting an account does not always cancel a subscription attached to it, particularly where billing runs through an app store or a third-party processor. Cancel explicitly, confirm the cancellation, and keep the receipt.
Warn anyone affected. Shared albums, group conversations, family plans, and anything you administer for other people will change or break. If you are the only administrator of a shared space, hand it over before you go.
What deletion actually removes — and what it does not
"Delete my account" is not a single technical event, and honest services say so plainly. Expect the following.
Removal from the live service is usually quick. Your profile and content stop being reachable within a short window.
Full erasure takes longer. Backups exist for disaster recovery and roll off on a schedule rather than being edited in place. A commonly stated figure is thirty to ninety days after the deletion date. This is normal, and a policy that claims instantaneous total erasure everywhere is describing something implausible.
Some records are retained by law. Payment and tax records, security-incident logs, and enforcement history are usually kept for defined periods because a regulator requires it. A good policy names the categories and the durations. A vague one is a warning sign.
Other people's copies are not yours to delete. Messages you sent live in the recipient's account too. Anything public may have been quoted, saved, archived, or indexed. Deletion is authoritative over the platform's copy and nothing else. If material about you is circulating beyond your own account, that is a different problem, and the guide on personal information posted online is the better starting point.
Anonymised aggregates generally remain. Counts and statistics that cannot be traced back to you are not personal data and are not covered by an erasure request.
What a decent deletion process looks like
Since you cannot inspect what happens after you press the button, judge the parts you can see. These are the features that separate a service treating deletion as a right from one treating it as churn to be prevented.
A grace period, and a clear one. Deletion should not take effect the instant it is requested. A cooling-off window — thirty days is the common convention — costs the service nothing and protects the user from a decision made at two in the morning, in anger, or by mistake. The date the deletion lands should be stated in plain language, not implied.
Re-authentication at the point of deletion. Being signed in should not be enough. Deleting an account is the most destructive action in any product, and it should require a fresh proof of identity at the moment of the request — the same standard you would expect before a large bank transfer. Without it, anyone who picks up an unlocked phone can end your account.
A confirmation that is specific. "Are you sure?" is not informed consent. The screen should tell you what is being deleted, what is being kept, how long each takes, and what cannot be undone. If it does not, you are being asked to agree to something nobody has described.
A visible, reversible pending state. During the grace period you should be able to see that a deletion is scheduled, see the date, and cancel it in one step. A pending deletion that is invisible until it fires is a trap.
Notification on an independent channel. The request should generate a message to your registered email or phone — somewhere an attacker who has your session but not your inbox cannot suppress it. This is the single control that turns a silent, hostile deletion into one you can catch and reverse.
An honest retention statement. Named categories, named durations, no "as long as necessary for business purposes" as the whole answer.
No dark patterns on the way out. Guilt-tripping copy, a deletion option greyed out until you scroll, a confirmation button that is deliberately harder to find than the cancel button, or a path that requires contacting support when signing up took ten seconds — all of these are choices, and all of them tell you how the service regards you.
A route for people who cannot sign in. Losing every device should not mean losing the ability to close an account. There should be a documented, identity-verified process by email or web form, and any identity documents collected for it should be destroyed once the request is closed.
Accidental and unwanted deletion
Deletions people did not intend fall into four groups, and each has a different remedy.
Regret. You meant it at the time and changed your mind. This is what the grace period is for — sign back in before the deadline and cancel. Note that some services offer an immediate, irreversible option alongside the scheduled one; if you are at all uncertain, take the scheduled path.
Misclick or misunderstanding. Usually caused by a confirmation screen that did not distinguish between deleting one item, deactivating, and closing the account entirely. Read the heading before you type your password.
Someone else, on your device. A child, a flatmate, a partner during an argument. Device-level protections are the real fix here: a screen lock everyone actually uses, separate profiles on shared computers, and never leaving an unlocked phone where the subject of a disagreement can reach it.
Someone else, remotely. Deletion is a recognised tactic in account takeover — an attacker who cannot monetise the account destroys it to cover their tracks, and in coercive relationships it is used to cut someone off from their friends and their history. If you receive a deletion notice you did not initiate, treat it as a compromise in progress: sign in immediately if you still can, cancel the pending deletion, revoke every active session, change the credential, and contact support in writing. The window is short, so speed matters more than diagnosis.
The defence against the last two is the same one that defends everything else: phishing-resistant sign-in, covered in passkeys explained, and a fast response to a lost device, covered in lost or stolen phone.
When the account is not yours to delete
Two situations need different handling.
A deceased person's account. Deleting outright erases photographs and messages that surviving family may not have anywhere else, and it is not reversible. Memorialisation is usually the better first step, and the decision belongs to the family rather than to whoever happens to know the password. See digital legacy planning and memorialising accounts.
An account you administer for an organisation. Closing it may destroy records the organisation is legally required to keep. Transfer ownership rather than delete.
If the service will not delete
You are not out of options.
- Submit a formal erasure request in writing, citing the applicable law — GDPR Article 17 in the EU and UK, the CCPA in California, the LGPD in Brazil, the DPDP Act in India. Send it to the privacy or data-protection contact, not to general support.
- Keep the paper trail. Date, channel, what you asked for, what came back.
- Escalate to the regulator if the statutory window passes with no substantive response. Complaints are free, and in most jurisdictions the supervisory authority will chase the company for you.
The detailed mechanics — what to write, which deadlines apply, and what a lawful refusal looks like — are in exercising your data rights.
A short checklist
- Decide: pause, or close? Deactivation is not deletion.
- Export everything you want to keep, and open the archive to confirm it worked.
- List what signs in through this account and move those services off it.
- Cancel subscriptions and hand over anything you administer.
- Delete through the account's own settings; prefer the scheduled option over the immediate one.
- Save the confirmation email and the stated deletion date.
- After the window closes, check your profile while signed out.
- If nothing happened, send a written erasure request and escalate.
None of this takes long. The part that takes long is reconstructing a photo library, or regaining access to six services that all depended on an identity you closed on a Tuesday evening. Spend the hour first.
An annual pass over everything you still hold is the natural companion to this — the annual privacy audit is the checklist for that.
