The accounts you forgot you had
Every dormant account is a copy of your data at a company that stopped caring about it.
Updated 2026-09-26
The average person has well over a hundred online accounts. Most were made once, for one purchase, and never opened again.
They matter because a dormant account is still a live copy of your data at a company that has stopped investing in protecting it. Almost every large breach is a company that forgot it had your details as much as you forgot you gave them.
Finding them
Search your email. This is where they all are:
- "welcome to"
- "verify your email"
- "your account"
- "thanks for registering"
Sort by oldest. It is an uncomfortable afternoon.
Your password manager or browser — whatever has been quietly saving logins for years.
"Sign in with Google" and "Sign in with Facebook." Both keep a list of every site you used them for. Google: myaccount.google.com, Data and privacy, Third-party apps. Facebook: Settings, Apps and Websites. People are routinely surprised by these.
Have I Been Pwned. Search your email address and it lists the breaches it appeared in — which is also a list of services you forgot you joined.
What to do with each
Delete, where you can. Fewer copies is the only thing that reliably reduces risk.
If you cannot delete, strip it. Replace the name with something neutral, remove the address and phone number, remove the saved card, then change the password to a long random one you never reuse.
Change the password first either way. If it was reused, that is the actual danger, and it is live right now. Our password checker tells you whether a password is already circulating in breach data, in your browser, without sending it anywhere.
Your right to deletion
Under your state's privacy law you can ask any company to delete your personal data, and they must respond within one month. It is free.
An email is enough:
> I am exercising my right to erasure under Article 17 of the your state's privacy law. Please delete all personal > data you hold about me associated with this email address, and confirm when this has been done.
Send it to their privacy or data protection address, which their privacy notice must list.
They can refuse in specific cases — mostly where the law requires them to keep records, such as financial and tax records for several years. A shop may legitimately keep an invoice while deleting your marketing profile.
If they ignore you, complain to the FTC, and your state attorney general. Free, and companies pay attention to it.
The ones to prioritise
Not all hundred. Start with these, which are the ones that actually hurt in a breach:
- Anything that ever held card details
- Anything with your home address
- Old forums and social accounts using a username you still use elsewhere
- Anything holding identity documents — a passport photo sent to a letting agent or an old employer
- Anything you signed up to with a password you still use
Then stop making new ones
Use guest checkout. Use your browser's built-in email masking, or a service that gives you a throwaway address, so a breach at a shoe shop does not hand anyone your real address. Not making the account is always easier than deleting it.
Check a password Free, and it needs no account.