free to read
The internet remembers too much
The first time you search your own phone number and see it sitting on a website you have never heard of, the internet stops feeling abstract.
There is your old address.
There is a relative’s name.
There is a city you lived in for six months.
There is a profile from a service you joined for a free trial, forgot about, and quietly donated to the data pile.
Treating this as a background radiation?
Well, yk:
Spam calls happen.
Weird emails happen.
Old usernames float around.
Data brokers sell “people search” reports.
and I know
None of it feels urgent enough to spend a weekend on, so it keeps getting worse.
But, trust me you need it.
And our AI is unusually useful here because the work is not glamorous.
It is searching, sorting, drafting, comparing, writing polite but firm requests, finding privacy pages, and turning messy evidence into a sequence of small jobs and bro that is exactly the kind of admin work most people avoid until something breaks.
Btw,
The goal is not to become invisible online.
That is usually impossible, and for many people, not even desirable.
The goal is narrower and more useful:
reduce the amount of casual information about you that a stranger, scammer, recruiter, angry customer, bored classmate, or automated system can grab in five minutes.
You still have to make decisions.
You still have to submit forms.
You still have to verify your identity in a few places.
But an AI assistant can turn a foggy privacy chore into a checklist you can actually finish.
Dude, can you cut the crap and actually tell me how to?
Yes, sirrrr.
Start with a private search audit
Do not begin by deleting things. Begin by looking.
Open a private or incognito window and search the obvious versions of yourself: your full name, your name plus city, your email address in quotation marks, your phone number in quotation marks, and your home address if you are comfortable checking it. If you use a professional handle, search that too.
Keep a simple note as you go. You do not need a spreadsheet with sixteen columns unless spreadsheets soothe you. A plain list is fine. Capture the URL, what it exposes, and whether the result seems removable. If a page bothers you, screenshot it before you touch anything.
Then give the pile to your AI tool of choice and ask it to organize the mess. A prompt like this works:
I searched my name, email, phone number, and address. Here are the results I found. Group them into data broker pages, old accounts, social profiles, public records, media mentions, and unknown results. For each item, estimate the likely privacy risk, explain why, and suggest the first action I should take.
This is where AI earns its keep. Search results are emotionally noisy. Your brain sees one creepy listing and wants to either fix everything immediately or close the laptop. The model can sort the results into buckets and help you handle the boring cases first.
Be careful with what you paste. You do not need to hand an AI assistant your full Social Security number, passport scan, bank details, or the inside of your password manager. For a privacy cleanup, URLs and short descriptions are usually enough. If you include personal details to draft a request, remove anything the company does not need.
Data brokers are the easiest win, but the least fun
People search sites are often the most annoying part of this whole exercise.
They collect fragments from public records, social profiles, and other data sources, then package those fragments into profiles that anyone can find or buy.
The FTC describes people search sites as a type of data broker and explains that they may compile reports from public records, social media, and other brokers.
That explains why the information feels uncanny. No single item may be secret, but the assembled profile can feel much more invasive than the source records ever did.
Your first pass should be mechanical. For each broker result, ask your AI assistant to find the opt-out or deletion path. Then ask it to draft a short request you can paste into the form.
Try this:
Draft a concise deletion request for this data broker. I want my personal information removed from public search results and from sale or sharing where applicable. Include my name, the profile URL, and a request for written confirmation. Keep the tone calm and firm.
If you live in California, your rights may be stronger. California’s privacy guidance says businesses must respond to delete, correct, or know requests within 45 calendar days, with a possible 45-day extension if they notify you.
California has also rolled out DROP, a deletion request and opt-out platform for California residents that lets eligible users send one request to hundreds of registered data brokers.
If you are in the EU, the GDPR gives people a right to erasure in certain circumstances.
The European Commission says organizations generally need to reply to data protection rights requests within one month, and they may ask for information needed to confirm identity. That makes the request sound less like “please be nice” and more like what it is: an exercise of a legal right.
Avoid spraying your full identity documents across shady forms. Some companies need enough information to match you to a record. That does not mean every site deserves a driver’s license scan. If a broker asks for too much, use the company’s official privacy contact, document what happened, and consider filing a complaint with the relevant regulator.
Old accounts are quiet liabilities
Your old accounts are probably less searchable than broker listings, but they can be more dangerous.
A forgotten shopping account may have an address and partial card history. A forum account may connect an old username to your current email. A delivery app may still know where you lived.
A random productivity tool may have imported contacts in 2017 and kept them. Nothing dramatic has to happen for that to be a problem.
The account only has to sit there long enough to be breached, scraped, sold, or reused by someone who guesses an old password.
Start with your inbox. Search for phrases like “welcome to,” “verify your email,” “your account,” “password reset,” and “subscription.” Do not try to solve every result. Pick the ones you recognize and the ones that still look sensitive.
For each service, ask:
Find the account deletion process for this service. Tell me whether deletion is available in settings, whether I need to contact support, and how I can confirm the account was actually deleted rather than only deactivated.
The last part matters. Deactivation often means the account is hidden or paused. Deletion should mean the company removes personal data unless it has a legal or operational reason to keep some of it. Many companies blur that distinction because “deactivate” is safer for their retention metrics and easier for support.
JustDeleteMe is useful for this step because it tracks how hard various services make account deletion.
Use it as a starting point, then verify on the company’s own site before sending anything sensitive.
This part can get tedious fast. Set a timer for 45 minutes and do a batch. If you finish five accounts, that counts.
Privacy cleanup works better as repeated maintenance than as one heroic purge followed by two years of avoidance.
Use AI for legal letters, not legal fantasies
AI can write a decent privacy request.
It can also hallucinate statutes, invent deadlines, and make you sound like someone threatening a lawsuit in a comments section.
Use it as a drafting assistant, then check the parts that matter.
A better prompt is specific about jurisdiction and modest about tone:
Write a privacy deletion request for this company. I am a resident of [state or country]. Ask for deletion of personal information associated with my email address and profile URL. Include a short identity verification paragraph, request written confirmation, and cite the relevant privacy right only if you are confident it applies. Do not threaten litigation.
Then read it. Remove anything that sounds inflated. Add the exact URL of the profile or account.
Make sure the deadline matches your jurisdiction. California guidance currently says 45 calendar days for deletion requests.
EU guidance says organizations should generally reply within one month. Other places differ.
Also remember that deletion rights have exceptions. Companies may need to keep invoices, fraud records, safety logs, tax records, or data required by law.
Your request can still be worth sending, but a serious company may respond with partial deletion rather than a clean wipe.
That is not failure. If the public profile disappears, the marketing use stops, the account is closed, and unnecessary data gets removed, you have reduced your exposure.
The point is not to win a legal theory. The point is to leave less lying around.
For things you cannot delete, change what ranks
Some results will not move. A news mention. A court record. A quote in an old blog post. A cached page controlled by someone who vanished. A public directory that mirrors another public source.
When deletion is unrealistic, your next option is suppression. That sounds dramatic, but the ordinary version is simple: publish better, fresher, more relevant pages that match your name and the context people are likely to search.
Ask AI to help you plan the content, not to flood the web with sludge.
I want newer search results for my name to reflect my current work. Here are the search terms where an old result appears. Suggest five useful article or profile ideas I could publish under my real name. Keep them relevant to my actual profession and avoid fake biography details.
Then write something worth existing. Update your LinkedIn. Create a simple personal site. Publish a few practical posts on Medium or your own domain. Add a short bio to sites you already use professionally. Use the same name format you want people to search.
This does not erase the old result. It gives Google and other search engines newer pages that better answer the query. It takes time, and nobody should promise exact rankings. But for many people, the goal is not to delete every trace. It is to make the first page less weird.
Check breach exposure without spiraling
After search results and account cleanup, check breach exposure. Have I Been Pwned lets you search whether an email address appears in known data breaches.
Its FAQ explains that it aggregates breach data so people can assess where their personal data has been exposed, and it also notes that absence from the database does not prove an address has never been compromised.
That last caveat is important. This is not a magic truth machine. It is a very useful indicator.
If your email appears in breaches, paste the breach names into your AI assistant and ask for a response plan:
Here are the breaches associated with my email address. Rank them by likely current risk. For each one, tell me whether I should change the password, enable two-factor authentication, delete the account, watch for phishing, or take another action. Assume I may have reused passwords years ago.
Do not paste real passwords into a chatbot. Ever. If you need to check whether a password has appeared in breaches, use a reputable password manager’s built in checker or Have I Been Pwned’s password search, which is designed around privacy preserving range checks.
The breach step is where many people feel embarrassed. They see a list of old leaks and read it as proof that they were careless. That is not useful. Breaches are a condition of using the modern internet. Your job now is to stop one old leak from becoming a current account takeover.
Stop refilling the bucket
Cleaning your footprint once helps. Changing your habits helps more.
Use email aliases for new signups. Apple’s Hide My Email, SimpleLogin, Firefox Relay, and similar tools let you give each service a different forwarding address. When one company starts spamming or gets breached, you can disable that alias instead of changing your real email everywhere.
Use a password manager. Unique passwords are boring until the day one breached account does not unlock ten others. Turn on two-factor authentication for email, banking, cloud storage, social accounts, and anything that can reset other accounts.
Use a browser that gives you decent tracking controls. Firefox documents Enhanced Tracking Protection and Total Cookie Protection as features that block known trackers and isolate cookies across sites. Brave and Safari also give many users stronger defaults than the old habit of accepting every tracker everywhere. The exact browser matters less than the behavior: stop handing the same identifiers to every site you visit.
Separate public and private identities where it makes sense. Your professional email does not need to sign up for every coupon. Your personal phone number does not need to sit in every delivery app forever. Your real birthday does not need to be volunteered unless the service has a real reason to ask.
Finally, repeat the audit. Put a 30-minute privacy check on the calendar every quarter. Search your name again. Check your broker listings. Review old accounts. Run your email through breach monitoring. Data brokers refresh their records, services change deletion flows, and old profiles sometimes crawl back into search.
Privacy is not a one-time cleanse. It is closer to laundry. Annoying, recurring, and much worse when ignored for too long.
The best AI use case is the one you would never do manually
There is a funny thing about this workflow: none of it requires genius. It requires patience.
You search. You sort. You write requests. You submit forms. You close accounts. You check breaches. You change passwords. You make better defaults for next time.
Before AI assistants, that process felt like a pile of unrelated chores. You needed legal phrasing for deletion requests, security judgment for breach triage, search patience for broker opt-outs, and enough emotional stamina to look at creepy results without rage-quitting.
Now the machine can do the least human parts. It can turn the mess into categories. It can draft the letter. It can compare policies. It can remind you that “deactivated” is not the same as “deleted.” It can help you write new pages that describe who you are now, instead of letting stale fragments do the talking.
That does not make AI your privacy savior. It makes it a competent clerk. For this job, a competent clerk is exactly what you need.
Give it a Saturday afternoon. Start with search. Remove the obvious broker pages. Kill five accounts you no longer use. Check one email for breaches. Set up aliases before the next signup.
You will not disappear from the internet. But you can make yourself harder to casually profile, harder to scam, and harder to reduce to whatever data trail you forgot to sweep up.
In case we are meeting for the first time, come over here, it’ll be worth the roller coaster of articles that are gonna come up in the next few weeks.
If you’re an established writer, here are the brands paying for sponsored articles.