There is a version of you on the internet that you did not write. It is assembled out of forms you filled in fifteen years ago, a mortgage record, a leaked customer database, a forum signature, a relative’s public friends list and a county clerk’s scanned PDF. Nobody built it deliberately. It accumulated.
Most people only notice when something forces them to look: a job application, a stalker, a divorce, a spike in spam calls, or the queasy experience of searching their own name and finding an address they left in 2014 sitting on page one. The question that follows is always the same. Can I delete this?
Partly. Honestly, partly. Some comes down permanently in ten minutes. Some comes down and creeps back within a year. Some is a public record that will outlive you. The skill is knowing which category each piece of exposure falls into, then spending effort where it changes the result. This guide walks the full sweep in the order that produces the most relief per hour, ending with a prioritized action plan and a frank section on what cannot be deleted at all.
Do not start deleting. Start looking. People who skip the audit spend three hours opting out of two people search sites while a resume with their home address sits in an open cloud folder, indexed and ranking. Open a spreadsheet with four columns: what was found, where it lives, whether you control it, and how sensitive it is.
Searching your name once is not an audit. Run a matrix: full legal name, name in quotes, name plus city, name plus employer, name plus street, any former or maiden name, nicknames, your usual username, your phone number in three formats, and every email address you have used. Do it logged out, in a private window, because personalized results will flatter you.
Go five pages deep on the important queries, then repeat on Bing and DuckDuckGo, which rank differently and often surface broker pages Google has already demoted. Check the image and news tabs separately.
Google’s Results about you tool, reachable from your Google Account or the Google app, scans Search for your contact details and tells you where they appear. Google’s documentation describes it as covering home address, phone number and email address, with nicknames and maiden names addable so monitoring catches variants, and it offers a one-tap path to request removal.
It is a useful discovery tool and a mediocre deletion tool, for a reason worth understanding early: it removes results from Google Search, not information from the web. Set up Google Alerts for your name and your name plus your city while you are here.
Some of the most exposing material is self-published and forgotten. Search your name restricted to file types, which catches PDFs and spreadsheets uploaded to a club site or school newsletter. Check whether cloud folders are set to “anyone with the link,” and whether an old site or domain registration still carries your home address in public WHOIS.
Dormant accounts are the quietest exposure on this list. Each holds a name, an email, usually a phone number, often an address and a partial payment method, on a server run by a company that may have stopped patching it years ago. Nobody is monitoring them for you.
You will not remember them. Reconstruct them from four sources:
Abandoning an account leaves the data in place. Deleting it is the point. Many services bury the option deliberately, and JustDeleteMe (justdeleteme.xyz) exists for this: a directory of direct deletion links rated easy, medium, hard or impossible, with the route for each service. The “impossible” rating is not hyperbole: some platforms have no deletion mechanism at all.
Before you delete, strip the account: overwrite the address, phone number and biographical fields with junk, remove saved payment methods, save, then delete. Some companies retain a record after closure, and you would rather it be nonsense. Take a data export first if you want your content back.
If a service hides or refuses deletion and your state has a comprehensive consumer privacy law, you have a statutory route. Around twenty states now have such laws on the books according to legislative trackers, with Indiana, Kentucky and Rhode Island effective January 1, 2026, and most include a right to request deletion. Send it in writing to the privacy contact named in the privacy policy, cite your state’s law, and keep the correspondence.
Social platforms are the largest volume of personal information most people have published, and the only large category where you hold the delete button yourself.
Change the defaults first, because that stops the bleeding while you work the backlog. On every platform, look for four things:
Then deal with history. Facebook’s Manage Activity feature allows bulk archiving and deletion of old posts filtered by date and by person, turning an impossible manual task into an afternoon. Check for a native bulk tool on other platforms before reaching for a third-party deletion app, which requires broad account access and is itself a privacy trade.
Prioritize by exposure, not by age. The posts that matter show a house exterior, a street sign, a license plate, a school uniform, a boarding pass or an invoice, or carry preserved location metadata. Old political arguments are embarrassing. A photo of your front door with the street number visible is operational. And deleting a post does not delete other people’s screenshots or reposts. Deletion reduces the surface, it does not guarantee erasure.
This is the layer that surprises people. You never gave these companies anything. They bought it, scraped it or pulled it from public records, then published your name, age, current and previous addresses, phone numbers, relatives and neighbors on a page that ranks for your name.
Two overlapping populations are involved: the consumer-facing people search sites you can see, and the larger data brokers behind them that sell to marketers, insurers and each other, and that feed the visible sites.
The pattern is consistent. You find your own listing, copy its URL, submit it to an opt-out form, confirm by email, and wait. Some sites verify by phone, some want an emailed request, and a few demand an identification upload, which is worth thinking about before complying.
We publish step-by-step guides for individual sites, including TruePeopleSearch and Spokeo, because each has its own quirks. Work the ones that rank for your name first, straight from your audit spreadsheet, not alphabetically through a list of two hundred.
Two realities up front. You will often find several listings for yourself on one site, under variant spellings and old addresses, and removing one does not remove the others. And relisting is normal, because these sites reacquire data on a cycle. Opting out is maintenance, not a one-time fix.
California residents have something no other state offers. Under the Delete Act, the California Privacy Protection Agency operates DROP, the Delete Request and Opt-Out Platform, which lets a consumer submit one verified deletion request that registered data brokers must honor. The agency’s published timeline has consumers able to register and submit from January 1, 2026, and brokers required to begin accessing and processing those requests from August 1, 2026, checking at least once every 45 days thereafter.
The limits matter: it reaches brokers registered with California, not every site holding your data, and it is a California residency mechanism. For anyone eligible it is the best effort-to-result ratio in this guide.
Doing this manually is free, effective and tedious, and the tedium is why most people quit halfway. Paid services automate the submission and resubmission cycle. They are worth considering if maintenance is what defeats you, and they are not magic: coverage counts are marketing claims, and canceling generally means relisting resumes. We compare the category in our roundup of personal data removal services, and go head to head on the two most searched options in DeleteMe versus Incogni.
If your concern is specifically your home address, that has its own playbook, set out in our guide to removing your address from the internet.
This is the most misunderstood distinction in the subject, and getting it wrong wastes enormous effort. A search engine does not host your information, it points at a page that does. Removing a result from Google means the page no longer appears in Google Search. The page is untouched: still live, still reachable by direct link, still indexed by Bing, still scrapeable by the next broker. Google’s help documentation is explicit that removal affects Search results and not the source website.
So: source first, search second. Fall back to search removal only when the source will not cooperate.
Find the site’s contact, privacy or webmaster address, or its WHOIS registrant contact if the page offers nothing. Write short, specific and unemotional. Name the exact URL and the exact information you want removed, and give a reason about the information rather than your feelings. Legal threats to a small publisher often produce a defensive refusal, sometimes a blog post about the threat. A person asking for their home address to come off a page has a surprisingly good hit rate.
Google has three distinct paths, and people routinely file in the wrong one.
If you own the site, the Search Console Removals tool blocks a URL from results, but Google states the block is temporary and lasts only about six months. It buys time to implement a permanent fix such as deleting the page or applying noindex, it is not the fix itself.
Where nothing can be removed, the remaining lever is suppression: building accurate pages you control until they outrank the ones you do not. That is slow, never guaranteed, and the core of professional reputation management work.
Underneath the brokers sits the bedrock: government records that are public by law. Property deeds and assessments. Voter registration, depending on the state. Business filings and registered agent addresses. Professional licenses. Civil and criminal court dockets. Marriage, divorce and probate filings. Campaign contributions. Bankruptcy filings.
These are not privacy failures, they are deliberate transparency, and the system will not delete them because you find them inconvenient. They are also the original source for much of what people search sites publish, which is why broker listings keep regenerating.
There are real ones, but they are narrow and jurisdiction-specific. Many states operate address confidentiality programs for survivors of domestic violence, stalking, sexual assault and human trafficking, giving participants a substitute legal address. Many allow judges and law enforcement officers to petition for redaction of home addresses from property and voter records. Some court records can be sealed or expunged. All run through a state or county process with its own eligibility rules, and none is a general-purpose privacy tool. If one might apply to you, that is a conversation with the relevant clerk’s office or an attorney in your state.
One structural fix works for some people: moving identifiers out of your own name. A registered agent service keeps a home address off future business filings. A trust can hold property. A PO box or commercial mail receiving agency can absorb the address you hand to every form from now on. None of this rewrites records already filed, but it stops adding to them.
Breached data is a different animal. It is not on a page you can ask to have edited. It is a file, copied indefinitely, traded in places you cannot petition. There is no delete button, and any service promising to remove your data from the dark web is selling something that does not exist. What you can do is find what is exposed, then defuse it.
Have I Been Pwned (haveibeenpwned.com) checks an email address against its collection of breached records for free, notifies you when your address appears in a future breach, and provides a password checker and a domain search. Run every address you have used, not just your current one. Note that Google’s free Dark Web Report, which many people relied on for this, was retired in early 2026 according to Google’s notices and reporting at the time, so if that was your monitoring you need a replacement.
Exposure converts into harm through reuse. Change the password on every breached account and never reuse one, which in practice means a password manager. Turn on two-factor authentication everywhere, preferring an authenticator app or hardware key over SMS, because SMS codes fail to a SIM swap and a SIM swap needs only the phone number a breach already leaked.
If identifiers such as a Social Security number were exposed, freeze your credit. A security freeze at each of the three national credit bureaus is free by federal law, blocks new accounts in your name, and can be lifted temporarily when you need credit. The FTC’s consumer advice pages walk through it, and identitytheft.gov is the official route if something has already happened. Finally, stop feeding the problem: answer security questions with invented strings stored in your password manager. Your mother’s maiden name is not a secret.
Your email address and phone number are the keys that join every other record together. A broker links an old address to a current employer because the same phone number appears in both datasets. Reducing that linkage is often worth more than another round of opt-outs.
You cannot un-give an address you have handed out for twenty years, but you can stop the next twenty. Run separate addresses for separate purposes: one for financial and government accounts that you give to almost nobody, one for real correspondence, and one disposable address for retail and newsletters. Aliasing services, including those in Apple’s ecosystem and some password managers, generate a unique forwarding address per site, which tells you who leaked or sold your address when the spam arrives.
Do the same with phone numbers. A secondary voice-over-IP number for forms, deliveries and loyalty programs keeps your real mobile number, the one tied to your bank and your two-factor codes, out of the data supply chain.
Then remove the published instances: your website and social bios, your email signature (often archived on public mailing lists), your domain WHOIS records, and the professional directories, alumni pages and speaker listings that publish contact details as a courtesy and usually remove them on request.
Images are harder than text: they are copied and reposted freely, they carry metadata, and facial recognition makes them searchable by face rather than by name.
Delete what you posted. Untag yourself from what others posted, and turn on tag review so future tags need your approval. Strip location metadata before uploading anywhere you are not certain the platform does it. Review shared albums and cloud folders left public years ago.
For a photo you took that someone else republished, copyright is your strongest lever, and a DMCA notice to the host or the search engine is a genuine removal route. For a photo of you that you did not take, you have no copyright claim and are relying on platform policy or on asking politely. Platform policies do specifically cover non-consensual intimate imagery, and every major platform and search engine has a reporting path for it, the one category where escalation is fast and usually successful.
Reverse image search your photos with Google Lens and at least one alternative to find where they have been reposted. Face search services are the newer problem: they index faces across the open web and let anyone find every photo of you from a single image. PimEyes, the best known, runs an opt-out form at pimeyes.com/en/opt-out that requires a photo of your face and an identification scan so it can locate and exclude your images. Weigh that trade honestly, since it means handing identification to the company you want to get away from, and recheck periodically.
Ordered by result per hour of effort. Do the first four rows and nothing else and you have addressed most of the realistic risk.
| Priority | Action | Rough time | Why it ranks here |
| 1 | Audit yourself: name matrix across two search engines, five pages deep, logged out | 1 to 2 hours | Everything else is guesswork without it |
| 2 | Lock down social settings: indexing, lookup by email and phone, connections, profile fields | 1 hour | Free, permanent, and breaks the cross-reference brokers rely on |
| 3 | Password manager, unique passwords, two-factor authentication everywhere important | 2 to 3 hours | Converts existing breach exposure from dangerous to inert |
| 4 | Opt out of the people search sites your audit found, highest ranking first | 3 to 6 hours | Directly changes what a stranger finds. Requires repetition |
| 5 | California residents: submit through the state DROP platform | Under 1 hour | One request reaching every registered broker, if eligible |
| 6 | Run Results about you and file removal requests for contact details | 1 hour | Fast and free, but suppresses results rather than deleting source pages |
| 7 | Check Have I Been Pwned for every address you have used, freeze credit if identifiers leaked | 1 hour | Freezes are free and block the worst use of leaked identifiers |
| 8 | Delete dormant accounts found via saved passwords and email archive | 3 to 8 hours | Shrinks your future breach surface permanently |
| 9 | Email and phone compartmentalization: aliases, secondary number, clean published instances | 2 hours plus habit | Prevents the next decade of accumulation |
| 10 | Bulk clean social history, prioritizing posts showing homes, plates, badges and documents | 2 to 5 hours | High volume, moderate risk reduction, copies may exist elsewhere |
| 11 | Contact source sites directly about specific pages you want removed | Variable | Deletes rather than hides, but outcomes depend on the publisher |
| 12 | Photos: untag, enable tag review, reverse image search, face search opt-outs | 2 to 4 hours | Hard to complete, and opt-outs require handing over identification |
| 13 | Long tail: public records exceptions, then suppression with accurate pages you control | Weeks to months | Slow, jurisdiction-specific and unguaranteed, but the last levers available |
Any guide that does not say this plainly is selling something. Several categories are not coming off the internet, and knowing which lets you stop wasting effort on them.
The right response is reframing, not despair. The goal was never a clean slate. It is that a casual searcher, an opportunistic scammer or an angry stranger finds an accurate, boring, unhelpful set of results instead of your home address, your routine and your children’s school. That is achievable, but it is a maintained state, not a finished project.
So set a calendar reminder every three months. Rerun the name searches. Check the brokers you opted out of, because some will have relisted you. Check Have I Been Pwned. Check whether a new job, house purchase or public filing has put something new into circulation. Thirty minutes a quarter holds the line that took you a weekend to establish.
Deleting your personal information from the internet is not one task. It is a stack of them, and they are not equally worth doing. The audit tells you what you are dealing with. Social settings and password hygiene cost almost nothing and neutralize a disproportionate share of the risk. Broker opt-outs change what a stranger sees, and they need repeating. Source removal beats search removal every time it is available. And a hard floor of public records, circulating breach data and legitimate reporting remains no matter how much effort you apply.
Work down the plan in order, accept that the last row may never be finished, and put the quarterly reminder in your calendar. The most common failure here is not doing it badly, it is doing it once and assuming it held.