"How to delete yourself from the internet" is a search that deserves an honest opening: you can't erase yourself completely. Your data survives in web archives, in breach dumps that already spread across torrents, and in data-broker databases that resell it to each other. Any guide promising you'll "disappear in five steps" is either misreading the mechanics or selling you a service.

The useful news is different: the visible footprint — the one attackers, stalkers, and casual "look-ups" actually use — shrinks dramatically, and mostly for free. Below I'll break down what genuinely gets deleted, what only gets hidden, and what never leaves at all — and the order to work through it so you don't drown in a list of two hundred sites.

I write this from a defensive angle: the goal is to see your own footprint before someone uses it against you, not to build a dossier on anyone else. It's the flip side of operational security — first you understand how people are found, then you make yourself harder to find.

Start with your threat model#

The central mistake in every "complete guide" is a flat, two-hundred-item checklist that's impossible to finish and quietly kills your motivation. Removal is pointless without answering one question: who are you protecting yourself from? That decides what to clean first — and what you can safely ignore.

  • Scammers and social engineering. Priority: phone, email, and any government IDs sitting in breaches, plus the way those identifiers are linked in people-search results. That's the raw material for a convincing "fraud department" call.
  • A stalker or personal adversary. Priority: home address (property records, delivery traces), geotags on photos, reverse image search.
  • A competitor or hostile due-diligence check. Priority: business registries and aggregators, court records, old publications.
  • Targeting of the people around you — relevant for public figures and executives. Priority: family data, shared addresses, tags in other people's accounts. That's its own discipline, covered in OPSEC for executives.

The practical point: delete what raises your targeting risk, not every mention of your name. A five-year-old marketplace review and your home address in a public record are different risk classes, and they don't deserve equal effort.

Self-audit: find everything that's out there#

Before you delete, you have to see. "Google your name" is correct but shallow — that finds the top layer. A proper self-check works by identifier, not by name.

  • By name — with search operators. Not just "John Smith" but precise constructs:
    • "John Smith" (phone OR address OR email) — mentions next to contact details;
    • "John Smith" site:linkedin.com (or facebook.com, reddit.com) — a specific platform;
    • filetype:pdf "John Smith" — documents: résumés, member lists, minutes where the name sits inside a file.
  • By username. One handle links accounts across dozens of sites — exactly how deanonymization works, as I show in how someone is found by their username. Run yourself through the same username-enumeration tools: Maigret covers several thousand sites and pulls profile metadata, Sherlock is faster across several hundred, and WhatsMyName runs in the browser with no install on a hand-maintained list of 700+ platforms. The main trap is false positives on common handles — verify each hit by hand before you treat a profile as yours.
  • By phone and email. Put them in quotes in search — classifieds, résumés, and leaked databases surface. What actually accumulates around a number is covered in how someone is found by their phone number.
  • By face. Upload your photo to reverse image search (see the face section below).
  • Old accounts. Sweep your inbox for "welcome," "confirm your email," "your new account," "reset password" — that surfaces dozens of forgotten sign-ups. A tool like deseat.me (Google sign-in) collects linked accounts into a list. Delete them through the JustDeleteMe directory — it shows how hard each site is to leave and links straight to the form.

Flag your shadow profiles too — data collected without any account of yours: tags in other people's posts, your number in someone's address book (see the caller-ID section), mentions on employer sites and in cached pages. You can't "delete these in settings" — they go through the site owner or through search de-indexing.

The output of this step is a source list sorted by your threat model. From here you work that list, not the abstract "internet."

Data brokers and people-search: the core cleanup#

For a US or EU audience this is the heart of the problem. Data brokers and people-search sites (Spokeo, Whitepages, BeenVerified, Radaris, Intelius, plus wholesalers like Acxiom and LexisNexis) are where your address, relatives, and phone quietly live and get resold.

The biggest 2026 change: California's DROP. Under the state's DELETE Act, the California Privacy Protection Agency launched the Delete Request and Opt-out Platform (DROP) on January 1, 2026. A California resident submits one authenticated request and it applies to every registered data broker — more than 600 are registered. From August 1, 2026, brokers must check DROP at least every 45 days and report the status of each deletion request within 45 days of retrieving it. Uptake was immediate: hundreds of thousands of residents signed up in the first days. This is genuinely new leverage, but it's California-only — everyone else still opts out broker by broker.

Manual opt-out, done right. The catalog with direct links and priority flags is journalist Yael Grauer's Big Ass Data Broker Opt-Out List. Work it by "most impact for least effort" — start with the highest-reach sites (Spokeo, Radaris, Whitepages, Intelius, BeenVerified, TruePeopleSearch), not alphabetically. A sane pace is one or two sites a day, or you'll burn out halfway through a list of two hundred. Verify each removal after 1–2 weeks, and repeat the cycle every 3–4 months — the data comes back (why, in a later section).

If you also have a footprint outside the US, the same principle applies to that region's brokers; the mechanics are identical, only the sites change.

Paid removal services: what you're actually paying for#

The obvious question: why not pay a service to do all this? The only independent measurement — Consumer Reports with Tall Poppy (2024) — is sobering. Thirty-two volunteers, removal from 13 major people-search sites, seven services, measured at four months:

MethodRecords removed after 4 months
Manual opt-out by the user70%
Optery68%
EasyOptOuts (~$20/yr)65%
DeleteMe27%

Across all services, only about 35% of found records were removed. The takeaway: a paid service buys convenience and time, but not a guarantee, and manual work is objectively more effective. Privacy expert Michael Bazzell puts it bluntly — don't pay anyone to remove your data, including him; do it from the catalog yourself.

If your time is worth more than the money, the reasonable compromise is the cheapest of the effective ones: EasyOptOuts (about $20/year) matched pricier tools in testing, though even it skips some sites (Intelius, PeekYou, for example) that you'll still handle by hand. And a fully free layer for Google's results is the "Results about you" tool (goo.gle/resultsaboutyou): it monitors your contact details appearing in Search and lets you request removal — though it only cleans Google's results, not the source sites.

Search engines and the right to be forgotten#

De-indexing removes a link from search results; the material stays on the source site. What you can do depends heavily on where you are — and this is where US and EU users diverge.

  • EU/EEA — a real right to erasure. Under GDPR (Article 17) you can require both search engines and site operators to erase your personal data, subject to public-interest exceptions. Google's dedicated EU removal form handles the search-results side. This is a genuine legal lever, not a courtesy.
  • United States — no general right to be forgotten. There's no federal equivalent. What you do have is narrower: Google's "Results about you" for specific sensitive data. A February 2026 update extended it to government-issued IDs — Social Security number, driver's license, passport — appearing in results, and made requesting removal of non-consensual explicit images easier.
  • Everywhere — go to the source. De-indexing hides a link; it doesn't delete the page. For real removal, contact the site owner, and if they refuse, escalate (GDPR/CCPA request, state AG complaint, or legal counsel for defamation).

Face and phone: reverse search and caller-ID apps#

Two under-rated vectors that most guides skip.

  • Face — PimEyes. It searches the open web by face. The opt-out form is at pimeyes.com/en/opt-out-request-form: upload a clear face photo and a government ID with the name, address, and number redacted (face visible only). Results are blocked within 3–7 business days, free. Common rejection causes: an old or off-center photo, a fully redacted document, or rewriting the legal justification in your own words — don't.
  • Face — social networks. Services that index social profiles by face draw mostly from open profiles, and their exclusion requests run through whatever contact form the site currently lists. Prevention works better than requests here: set your profile to private and remove the avatar — if it isn't indexed yet, it won't enter the database.
  • Phone — Truecaller. Caller-ID apps show how you're saved in other people's address books. Truecaller has an unlisting form (truecaller.com/unlisting) plus a separate profile deactivation. The catch: tags are crowdsourced from users' contact lists, so your number resurfaces when a new user uploads a contact list you're in. What protects you is the standing unlisted status, not a one-time removal.

Your data in a breach: you can't delete it — contain it#

If your data is already in a breach, you can't delete it from the dump — it's copied across torrents, forums, and bots. Legally important: an operator must erase your data from its live database, but not from a leaked dump it no longer controls. So the strategy here is damage minimization, not deletion.

The full self-check-and-response protocol (how to check email, phone, and passwords, how to spot stealer logs, what to do in the first 24 hours) is a separate deep-dive — how to check if your data was breached. Here, three anchor actions:

  • Rotate compromised secrets: passwords via a manager, turn on two-factor (an app or key beats SMS). The fundamentals are in 10 digital hygiene mistakes.
  • Swap identifiers going forward: email aliases (+ in Gmail, SimpleLogin/addy.io) and virtual numbers for sign-ups, so one breach doesn't link all your accounts.
  • Close the financial risk: in the US, place a credit freeze with all three bureaus (Equifax, Experian, TransUnion). Federal law has made freezing, lifting, and removing it free since 2018, and a freeze requested online must be placed within one business day and lifted within an hour. The catch people miss: a freeze at one bureau does not carry to the other two — you file three times.

Why "deleted" doesn't mean "gone": five comeback channels#

The most common complaint is "I deleted it and it's back in search." That's not failure — it's normal mechanics. Data returns through five independent channels, each with its own fix.

  1. Web archives (Wayback Machine). What you delete from a page survives at web.archive.org. The current removal path is an email to info@archive.org with the URL and the period you controlled the site or account (official instructions at help.archive.org). The old advice about a robots.txt User-agent: ia_archiver block no longer works — that was Alexa's crawler, not the Internet Archive. Proof of ownership is required.
  2. Search cache and re-indexing. After you remove the original, the cache lingers; speed it up via Google Search Console (removals/re-crawl).
  3. Address-book crowdsourcing. Truecaller and similar "return" your number when a new user uploads it. Unlisted status protects you, not a one-time delete.
  4. New breaches. Every fresh leak refeeds your data into people-search and bots — hence the cyclicality.
  5. Broker resellers. People-search sites buy data from each other, which is why opt-out has to be repeated every 3–4 months.

Public records: the hard tier#

The most under-appreciated source about business owners and executives isn't social media — it's public records that aggregators republish. Options here are narrow, and worth knowing.

  • Property and voter records. In much of the US these are public by design; brokers scrape them directly. Many states run an Address Confidentiality Program for survivors of stalking or domestic violence, which substitutes a proxy address on public records — availability and eligibility differ by state, so check your own before counting on it.
  • Court records. Generally public; some jurisdictions redact personal identifiers or allow sealing on specific grounds — otherwise, focus on de-indexing the aggregator copy rather than the primary record.
  • Business registries. Ownership and officer data is public in most registries; hiding it is rarely possible without a specific legal basis. The realistic move is removing the aggregator copies (many have a suppression form) rather than the source filing.

The pattern across this tier: you usually can't delete the primary public record, so you attack the copies — the aggregators and the search-results layer — and you use de-indexing where erasure isn't available.

Maintenance: audit cycle and prevention#

Deleting yourself from the internet isn't a one-time project — it's a process. Data returns through the five channels above, so your defense has to be recurring too.

  • Audit every six months. Put a calendar reminder: repeat the identifier-based self-audit, re-run broker opt-outs (or refresh your DROP request), check what came back.
  • Monitor instead of one-off checks. Subscribe to breach alerts; for public figures and their families this is a standing task, and it's where ongoing OPSEC consulting with continuous monitoring fits.
  • Prevention beats cleanup. A new footprint is cheaper not to create than to erase later: email aliases, virtual numbers for throwaway sign-ups, private profiles, minimal personal data in the open.

You can't completely delete yourself from the internet — but you can control what's visible and how easy you are to target. That's the real goal: not to disappear, but to stop being a convenient target. If the case is complex — defamation, extortion, coordinated harassment — that's work for dedicated removal and reputation management, not a $20 subscription.

FAQ#

Can you completely delete yourself from the internet?#

No. Your data persists in web archives, in breach dumps that have already spread, and in broker databases that resell it. The realistic goal isn't total erasure but minimizing your visible footprint against your threat model — removing what's used to find and target you.

How much does it cost to remove yourself, and do paid services work?#

Per independent Consumer Reports testing (2024), manual opt-out beat the paid services: 70% of records removed versus 68% for Optery and just 27% for DeleteMe. The cheapest effective option was EasyOptOuts (~$20/yr). Paying makes sense mainly for complex cases (defamation, press de-indexing), not routine broker removal.

What is California's DROP and can I use it?#

DROP is California's Delete Request and Opt-out Platform, live since January 1, 2026. One authenticated request applies to the 600+ registered data brokers, which from August 2026 must check the platform every 45 days and report each request's status. It's available to California residents only; everyone else opts out broker by broker.

Why does deleted information keep coming back?#

Five comeback channels: web archives, search cache, address-book crowdsourcing (Truecaller), new breaches, and brokers reselling to each other. That's why removal is a cycle, not a one-time act — broker opt-outs get repeated every 3–4 months.

How do I remove myself for free?#

Most of the working tools are free: Google's "Results about you" and (in the EU) GDPR erasure requests, the JustDeleteMe directory for old accounts, brokers' own opt-out forms, PimEyes opt-out, and California's DROP. Paying is only worth it for complex cases like press de-indexing or legal support.