Reclaiming Your Digital Life
Why I'm deleting old accounts and finding out how much control I actually have.
Reclaiming Your Digital Life

Over the past few weeks I've done something I had never seriously attempted before.
I've started deleting myself from the internet.
Not in a dramatic "I'm leaving technology" sense. Quite the opposite. I work in AI, visualization, and software. Technology is central to my research and my daily life.
What I am trying to leave behind is the assumption that every company should profile me and keep my personal data indefinitely because I once created an account. Or because I logged in with Google OAuth once and then forgot the service existed.
To date I have sent hundreds of GDPR erasure requests to companies whose services I no longer use. Some processed the request within days. Others required manual verification. Many sent me through broken forms, non-functional login systems, or support loops that looked almost designed to make leaving annoying enough that I would stop. Sometimes our email exchange would look like:
Person A: Please contact email/person B
Person B: Please contact email/person A
A surprising number simply never replied, ignored me, or thought I forgot. I had to fill in so many captchas, I actually got to the advanced captcha stage.
One request has involved more than 37 emails. Another has bounced between departments for weeks (five to be precise). Several companies pointed me toward forms that do not work, maybe never worked, and then asked me to use those same forms again. Others required me to repeatedly prove my identity just to delete an account I could no longer access because their own authentication systems were broken.
None of this should be normal.
And yet it is.
My process
The rules were simple. For every service I no longer use, I first try to delete the account through the web interface. If that fails, I look for a support address or data protection officer contact and request deletion of the account and associated personal data. Then I record what happened.
I expected three possible outcomes:
- The company deletes my account.
- The company explains why it legally cannot delete some data.
- The company asks me to verify my identity.
Instead I discovered a fourth possibility.
The process itself does not work.
Some observations after only a few weeks:
- Login systems no longer worked.
- OAuth authentication silently failed.
- Password recovery mechanisms were broken.
- Privacy forms redirected to dead links.
- Privacy policies had placeholder text that looked like it was never meant to be published.
- Some services had no public-facing privacy form or terms of service.
- Some privacy forms did not include the required information about data processing.
- Customer support redirected me to privacy, and privacy redirected me back to customer support.
- Departments repeatedly requested information they already had.
- Identity verification sometimes required more personal information than the account needed in the first place.
- Some companies never replied. Some listed email addresses bounced. Some ceased to exist. RIP
- Others handled everything professionally within a single day. Praise where it is due.
At the start I assumed going against the big companies was gonna be challenging, and to my surprise they had the most straight forward process and quickly resolved the requests. For data they were legally required to retain, they also gave clear explanations. The worst cases were often the smaller services or companies that seemed to have optimized account creation down to seconds and then never built a serious exit.
The funniest, in the bleak sense, was the automated "sad to see you go" email after a deletion request finally succeeded.
Sorry, not sorry. I am extremely fine being deleted from your service. Arrivederci!
What deletion reveals
Like most people, I have accumulated online accounts for years.
Some existed for a single purchase. Some were created to try a piece of software. Some existed because a website insisted that creating an account was the only way forward. Most of them had long disappeared from my memory.
Unfortunately, my data had not.
Every account leaves something behind: name, email address, billing information, support conversations, purchase history, device identifiers, IP addresses, location signals, analytics, telemetry, behavioral data. Most of it is uninteresting on its own. But connected at scale it becomes a profile of where I have been, what I tried, what I bought, what I asked for, and which systems I depended on.
This became my motivation:
If I no longer use a service, why should it continue storing my personal information?
GDPR gives me a mechanism to ask that question formally. Article 17 is useful because it turns "please delete my account" into a right that organizations have to handle; Article 12 says organizations generally have one month to respond.1 But the experience quickly stopped being only about legal compliance.
The law is not the part that surprised me. The organizational reality did.
Deletion is a useful stress test because it touches parts of an organization that account creation can ignore: old authentication systems, support ownership, retention policies, legal obligations, and the question of who is actually responsible when a user wants to leave.
This is not really a story about super evil companies hovering over a database. It is more boring, and probably more common: technical debt, fragmented responsibility, cheap storage, abandoned privacy pages, and internal processes that were never tested from the perspective of departure.
On the one side creating an account has been optimized because every additional click risks losing a potential user. However, on the other side deleting one's account often still feels like companies are doing you a favor (which they are not).
Beyond GDPR
At some point I realized that what I actually want to understand is where my personal data lives, who still holds it, why it is still being retained, and how much control I have over my own digital identity once the easy opt-out buttons run out.
That is my definition of digital sovereignty. Not disappearing from the internet. Not pretending every cloud service is bad. Not building a bunker out of self-hosted dashboards.
But just being more deliberate about the services I depend on, the accounts I leave behind, and the amount of trust I give to organizations that no longer provide me with value.
The AI angle makes this harder to ignore. Data that used to be treated as exhaust now has new uses: training, profiling, personalization, risk scoring, recommendation, automation. A support conversation or abandoned profile may be useless to me, but that does not mean it has no value to someone else. So maybe the following tips based on my experience might be useful to you. These are some things you can actionably do today.
Start small
You do not need to disappear from the internet overnight.
Start with one old account and treat it as a small audit.
Here is the checklist I would use now:
- Pick one low-risk account you no longer use. Do not start with banking, tax, university, health, or anything where losing access would be a genuine problem.
- Check how you logged in: password, Google OAuth, Apple ID, GitHub, Facebook, or something else. OAuth accounts are especially easy to forget because they may not have a normal password.
- Look for a direct deletion path in the account settings. If you cannot find it, check a directory such as JustDeleteMe before opening a support ticket.2
- If there is no usable deletion path, send a short erasure request through the privacy contact, DPO address, or a service such as Your Digital Rights.3
- Keep a simple log: company, account email, login method, request date, contact address, ticket number, response, and follow-up date.
- If the company asks for identity verification, check whether the request is proportionate. Deleting a throwaway account should not require handing over more data than the account ever had.
- If there is no reply after a month, follow up once with the original request date and ticket number. The point is to make the timeline visible.
- Check the email address in Have I Been Pwned, then rotate passwords and enable two-factor authentication where the account is worth keeping.4
- Review one service you actively use: privacy settings, ad personalization, public profile fields, connected apps, location history, and email notification settings.
- Replace one recurring service only if there is a better trade-off. Privacy Guides and EFF's Surveillance Self-Defense are useful starting points.5
- Before buying a new connected device or app, check whether someone has already reviewed its privacy behavior. Mozilla's Privacy Not Included is useful for that kind of first pass.6
The point is not to completely disappear and go off-grid. I still use cloud services and some proprietary software. I am trying to limit this and I will detail more of my experiences in the upcoming post.
But the important thing is that I want those choices to be choices.
For me, reclaiming my digital life starts there: with old accounts, broken deletion workflows, and the absurd realization that leaving the internet is often much harder than joining it.
This is the first post in a series about how I approached that process. Account deletion is just the visible edge. From there the questions start multiplying: which apps do I trust, which services do I depend on, what is my operating system doing in the background, what should I replace, and what is worth keeping because convenience still matters.
In other words, this is where the rabbit hole starts. I am going down it piece by piece, and I will write up the route as I go.
Notes & References
Below is a short list of resources referenced above.
-
European Commission - Dealing with requests from individuals
European Commission / EUR-Lex
https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/dealing-requests-individuals_en
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679
Explains response timing for data-subject requests and links to the official GDPR text for Articles 12 and 17. -
JustDeleteMe
JustDeleteMe community directory
https://justdeleteme.xyz/
A directory of direct account-deletion links and notes on how difficult different services make deletion. -
Your Digital Rights
noyb - European Center for Digital Rights
https://yourdigitalrights.org/
Generates access, deletion, and other privacy requests for organizations across different jurisdictions. -
Have I Been Pwned
Troy Hunt
https://haveibeenpwned.com/
Checks whether an email address appears in known public data breaches and can notify you about future breaches. -
Privacy Guides and Surveillance Self-Defense
Privacy Guides / Electronic Frontier Foundation
https://www.privacyguides.org/en/
https://ssd.eff.org/
Practical starting points for choosing privacy-respecting tools and understanding basic threat modeling. -
Mozilla Privacy Not Included
Mozilla Foundation
https://foundation.mozilla.org/en/privacynotincluded/
Consumer product privacy reviews for connected devices, apps, toys, cars, and other services.
[CITE THIS]
@misc{reclaimingyourdigita2026,
author = {Velitchko Filipov},
title = {Reclaiming Your Digital Life: Why I'm deleting old accounts and finding out how much control I actually have.},
year = {2026},
month = {august},
howpublished = {\url{https://velitchko.github.io/blog/digital-reclaiming-2026}},
note = {Blog post, keywords: privacy, digital-sovereignty. Accessed on August 22, 2026}
}Use this BibTeX entry to cite this blog post in your academic work.