A forgotten account is worse than an active one. You are not watching it, you would not notice a login from somewhere strange, and you probably used a password you have since reused on something that matters. This guide is about that specific pile: the accounts you cannot name, cannot get into, or that belong to companies that no longer exist — and what can actually be done about each.
What makes a dormant account dangerous
The risk is not that someone reads your abandoned forum posts. It is three concrete things:
- It is a password oracle. If a dormant service gets breached and you reused that password, the attacker now has a working credential to try everywhere else. They do not need your old account — they need the password it was protecting.
- It is still holding a snapshot of you. Name, old address, phone number, date of birth, sometimes a partial card. That data does not age out. It gets breached, sold in an acquisition, or exposed by a misconfigured database years after you stopped caring.
- Nobody is watching it. A takeover of an account you use gets noticed. A takeover of one you forgot gets used — to send spam under your name, to pass identity checks, or to reset something else via a linked email.
The four kinds of forgotten account
How you deal with one depends entirely on what kind of access you still have. Sort yours into these four before you start, because the effort involved is wildly different.
| Situation | Difficulty | Route |
|---|---|---|
| You can still log in | Easy | Delete it in the account settings. This is 80 percent of them. |
| You know the email, not the password | Easy | Password reset, then delete. Takes two minutes. |
| You no longer control the email on the account | Hard | Support ticket with identity proof, or a formal erasure request under GDPR or CCPA. |
| The company shut down or was acquired | Varies | Find who holds the data now and send the request there. Sometimes there is nobody to ask. |
Finding the ones you cannot name
The full enumeration process is in how to find every online account linked to your email address — inbox sweeps, connected-app lists, password manager exports. Here are the signals that specifically surface *dormant* accounts, which those general methods tend to under-report.
the_dormant_sweep
- 01
Read twelve months of bank and card statements
Filter for anything recurring that you cannot immediately explain. A live subscription means a live account, and it is the one category of forgotten account that is costing you money right now. Check any card you have replaced too — the merchant usually still has the account even after the charge fails.
- 02
Open your app store subscription list
On iOS: Settings, your name, Subscriptions. On Android: Play Store, your avatar, Payments and subscriptions. Both list active and recently expired subscriptions, including ones from apps you have long since deleted.
- 03
Scroll your old app installs
iOS: App Store, your avatar, Purchased, "Not on this iPhone". Android: Play Store, Manage apps and device, then Manage, filter to "Not installed". This is a decade-long list of every app you ever installed, and most of them made you an account.
- 04
Look at saved shipping addresses
Check autofill addresses in your browser and in PayPal, Amazon and Shop Pay. An old address you have not lived at in years usually points at a shopping account you forgot — and that account still has that address on file.
- 05
Check your email aliases and plus-addresses
If you ever used
[email protected]or an alias from iCloud, Proton or Fastmail, search your inbox for mail addressed to each one. The alias was almost certainly created for exactly one signup, which makes it a perfect index. - 06
Search your phone number
Some accounts were registered to a number rather than an address, and your carrier account, old SMS threads and two-factor codes in your message history will name them. Search your texts for
code,verifyandOTP.
Deleting an account when you cannot log in
This is the case that stops most people. It is slower, but it works more often than you would think — data protection law is on your side, and support teams generally prefer deleting a record to arguing about it.
locked_out_route
- 01
Try the reset anyway
Request a password reset even if you no longer have the inbox. Some services will show you a masked version of the email on file ("j•••@g•••.com"), which tells you which of your addresses to go dig out. Some offer SMS or security-question recovery as a fallback.
- 02
Use the account recovery flow, not the password reset
Large platforms have a separate identity-verification path for exactly this: no access to the email, no access to the phone. Search for the service name plus "account recovery form". Expect to provide a government ID or a selfie.
- 03
Email support with everything that identifies the record
Give them the username, the email you believe was used, the approximate signup year, any order numbers, and the last four digits of a card if you ever paid. Ask explicitly for deletion of the account and the personal data attached to it, not just deactivation.
- 04
Escalate to a formal erasure request
If support stalls, invoke the law. Send the template below to the privacy or data protection contact listed in the privacy policy. A statutory request goes to a different queue than ordinary support, and it has a legal deadline attached.
- 05
Keep the paper trail
Save every reply, with dates. If a company subject to GDPR misses the one-month deadline, the escalation path is a complaint to your national data protection authority, and they will ask for the correspondence.
An erasure request you can copy
Send this to the privacy contact in the company privacy policy, from the closest email address you have to the original. Replace the bracketed parts. Keep it short — long letters get read slowly.
Subject line: Data subject erasure request — [your name]
When the company no longer exists
Shutdowns and acquisitions are where forgotten accounts go to become somebody else problem. Your data did not evaporate when the website went dark — it was almost certainly transferred, because customer databases are an asset in a sale.
- Find out who bought them. Search
"[company name]" acquiredand check the last version of their site on the Wayback Machine — shutdown notices usually name the acquirer and the data handling. - Send the erasure request to the acquirer, naming the original service. Their privacy team is obliged to deal with data they inherited.
- If the shutdown notice says the data was deleted, screenshot it and move on. That is the best outcome available.
- If there is genuinely nobody left — a liquidated company, a dead domain — there is no one to serve a request on. Treat any password used there as burned, and make sure it is not in use anywhere else.
the_usual_suspects
Stop the pile rebuilding itself
You will do this whole exercise again in five years unless the next five years of signups are easier to audit. Four habits do most of the work:
- Put every new signup in a password manager. Not for the passwords — for the list. The list is the thing you cannot reconstruct later.
- Use a unique alias per service. Hide My Email on iCloud, Proton aliases, Fastmail masked addresses, or just
+serviceon Gmail. Each signup becomes self-labelling, and a leak tells you exactly who leaked it. - Prefer email signup over "Sign in with Google". Social login is convenient and it makes the account invisible to every audit method except the connected-apps list, which only shows what is still connected.
- Do a yearly pass. Twenty minutes with your statements and your app store list, once a year, prevents the two-day cleanup.
Doing the discovery part automatically
The deletion work above is manual by nature — only you can prove you are you. Discovery is the part that does not have to be. Tracebase takes your email addresses and usernames, checks supported platforms for matching accounts, and checks your verified addresses against the public breach corpus, so the list you are working from is not limited to what you happened to remember or still have the mail for.
For anything it finds on one of the 100 platforms we have documented, you get the deletion page and the exact steps alongside the result. Platforms outside that set are reported as found, but we will not pretend to have a guide we have not written.
common_questions
How do I delete an old account without the password or the email?
Start with the password reset anyway — many services show a masked hint of the email on file, which tells you which old address to recover. If that fails, use the account recovery form (not the password reset) and expect to prove your identity, or send a formal erasure request to the privacy contact in the privacy policy. The template above covers the wording.
Can I force a company to delete my account?
If you are in the UK or EEA, or California, largely yes — GDPR Article 17 and the CCPA/CPRA give you an enforceable right, with a one-month deadline under GDPR. There are exceptions where the company has a legal obligation to retain records. Outside those jurisdictions it is a request, not a demand.
What happens to my data if a company gets acquired?
It transfers with the business, which is explicitly permitted in nearly every privacy policy you have ever agreed to. The acquirer inherits your erasure rights along with the record, so send your request to them and name the original service.
Is deactivating the same as deleting?
No, and the difference is deliberate. Deactivation hides your profile and keeps the data, usually so you will come back. Deletion is supposed to remove the record, often after a grace period of 14 to 30 days during which logging in cancels it. Always confirm which one you have actually triggered.
Should I delete the email address an old account used?
Not until the accounts on it are closed. Once the mailbox is gone you lose the only recovery route, and with a custom domain someone else could eventually register the address and reset those accounts. Close the accounts, then retire the address.
How long until a deleted account disappears from Google?
Weeks, typically, and only once the page itself actually 404s. Backups, caches and archive sites can outlive the deletion entirely. Removing personal information from Google covers the request process for pages that linger.