ONLINE PRIVACY CyberArtical Editorial Team

Pruning what your accounts have already collected about you

A phone screen showing a social network's Lock Your Profile setting, with a padlock icon above a green confirm button

There is a gap in the standard privacy checklist. It tells you how to stop new information being collected — settings, opt-outs, permissions — and says nothing about the ten or fifteen years of information your accounts are already holding. Locking the door is sensible. It does not empty the room. This is about the second job: going through the accounts you actually use and reducing what each of them knows, holds and shares.

Two different controls, often confused

  • FTC: browser and account privacy settings "give you some control over the information websites collect" — that is about future collection.
  • FTC: personalised-ad preferences are a separate control from privacy settings, and separate again from the operating system’s advertising opt-out.
  • CISA: consider "making requests to data brokers and other online platforms to delete your data to minimize the amount of information publicly available about you."
  • FTC: app permissions are set in the phone’s own privacy settings, not inside each app.
  • FTC: opting out of a people-search site "doesn’t delete your information from public records" — deletion has a hard boundary.

Locking an account is not the same as emptying it

A strong password and a good second factor stop someone else getting in. They do nothing about how much is inside, and the amount inside determines how bad a breach at that company is for you.

The two jobs also have different rhythms. Authentication is set once and left. Data reduction is periodic, because accounts accumulate — search history, location history, uploaded documents, saved payment methods, address books you synced once in 2016 and forgot.

CISA’s framing for people at elevated risk includes making deletion requests to online platforms specifically to reduce what is available about you. The same logic applies at ordinary risk levels, just with less urgency.

Start with the account that holds the most

That is almost always the account tied to your phone or your main email — the one that has been collecting since you first set up a device. Work through it in this order, because the categories differ in how much they matter.

  1. Saved payment methods. Remove cards you no longer use. Every stored card is an item in someone else’s breach.
  2. Location history. If the account keeps a timeline, decide whether you want it, and set an automatic deletion window rather than clearing it once.
  3. Search and activity history. Same approach: an auto-delete interval is more durable than a manual purge you will not repeat.
  4. Contacts and address books. Services you allowed to import contacts usually still hold them. This is other people’s data, not just yours.
  5. Files and photos. Scans of documents uploaded for a one-off purpose — passports, bank letters, medical forms — are the highest-consequence items in most accounts.
  6. Third-party connections. Revoke every application you no longer use. These often retain read access indefinitely.

Ad personalisation is a separate switch

Inside most large accounts there is a privacy section and, elsewhere, an advertising section. Changing one does not change the other. The FTC treats these as distinct throughout its guidance — browser privacy settings, the personalised-ads preference, the operating-system advertising identifier, and app permissions are four controls, not one.

So when you finish the privacy pages, go and find the advertising pages. Interest categories, inferred attributes and "activity from partners" live there, and they are usually on.

The accounts you stopped using

Dormant accounts are the worst of both worlds: they hold old data and nobody notices when they are breached. Closing one is usually a better outcome than tidying it.

Work from your password manager’s list or your email’s archive of "welcome to" messages. For each: close it if you can, and if closure is not offered, strip what you can from it and remove the payment method.

Before closing, check whether it is the login for anything else. Accounts used as sign-in providers for other services need untangling first.

Where deletion stops working

Deleting data from an account removes it from your view of that account. It does not necessarily remove it from backups, from analytics systems, or from anything the service already shared. Nor does it touch copies held elsewhere — the FTC’s point that opting out of people-search sites "doesn’t delete your information from public records" is the general shape of this limit.

That is an argument for pruning regularly rather than an argument against pruning. The realistic goal is to reduce what a future incident exposes, not to achieve a clean slate.

And if information from an account has already been used against you, the remedy is not in the settings menu. Report fraud to the FTC, and if it has become identity theft, IdentityTheft.gov generates a recovery plan and the letters that go with it.

Sources: FTC — How to protect your privacy online · CISA — Best practices against tracking technologies and spyware · FTC — What to know about people search sites · FTC — IdentityTheft.gov

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC and CISA. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories