- Digital Minimalism
What Actually Happens When You Delete an Online Account? (2026)
Quick answer. Four different outcomes travel under the word "delete," and the button in your settings usually gives you the weakest one. Deactivation suspends your login and keeps the record whole. Account deletion removes the login and leaves behind whatever a retention policy allows. Anonymisation strips your name off a record that stays in the database. A formal deletion request under a privacy law is the only version with a legal deadline attached to it. Most services never tell you which one you got. Last updated September 2026. Current as of 18 September 2026.

In this article
- A delete button and a deletion request are different instruments, and only one of them comes with a deadline and somewhere to complain
- Deactivation is a retention feature, and the grace period is doing two jobs at once
- Ten major services on what they promise, and the exact point at which each one goes quiet
- Backups are the reason "immediately" is never the honest answer, and regulators have already conceded the point in writing
- Anonymized is a real category, it is not the same as deleted, and European regulators found companies using it as a substitute
- The data can be gone while what was learned from it stays
What actually happens when you delete an online account?
Somewhere in the settings there is a button. You click it, and after a confirmation screen the account disappears from view. That last part is precise in a way most people miss. It disappeared from view.
Here is what is actually happening underneath, and there are four versions of it.
Deactivation. Your login is suspended and the record stays intact. You can undo it whenever you like. You decide, from a settings menu.
Account deletion. Your login is removed. Part of the record stays, under a retention policy you agreed to at signup. Reversible only inside the grace period, and the company's own policy decides what survives.
Anonymization. Your login is removed and the record stays, with the identifiers stripped out of it. Not reversible. The company decides, usually without telling you.
Verified deletion request. Your login is removed and the record is deleted, minus a named list of legal exceptions. Not reversible. The law decides, and it comes with a deadline.
The gap between the second of those and the fourth is the whole subject of this page. Account deletion is a product feature that a company designs and revises at will. A verified deletion request is a legal instrument with a clock on it and an obligation to answer you, plus a requirement in California to explain itself if the answer is no.
Most people have only ever used row two.
What is the difference between deactivating and deleting?
Deactivation hides you. Deletion is supposed to remove you. That much is widely understood, and it is also where most explanations stop, which is a shame, because the interesting part is what deactivation is for.
Facebook's own help page lays out the deactivated state plainly: "People won't be able to see or go to your Facebook profile," and "Your photos, posts and videos won't be deleted." You keep Messenger. Your profile picture stays visible in conversations. People can still search for you by name to send you a message.
So a deactivated account is a live account that other people cannot see. Nothing has left the building.
On X, deactivation is not an alternative to deletion at all. It is the mechanism: "Deactivation begins the process to permanently delete your X account. This step initiates a 30-day window that gives you space to decide if you'd like to reactivate your account." Two services, one word, opposite meanings.
Discord splits them cleanly. Disabling puts the account "on-hold for when you return" and is described as temporary. Deleting is permanent, and "Once deleted, your account cannot be restored."
Now look at the grace period, because it is doing two jobs. The first is genuine and useful: people delete things by accident, and an undo window is good engineering. The second is that a delete request with a 30-day pause attached is also a 30-day window in which a company gets to show you what you are giving up. Facebook's is thirty days. Discord's retention policy says fifteen to thirty. Microsoft lets you choose thirty or sixty. LinkedIn will reopen a closed account "in most cases if it's been closed less than 14 days."
None of that is sinister. It is worth knowing that the countdown is not neutral.
How long do companies keep your data after you delete?
This is the question people actually have, and it is the one the help pages answer least well. Here is what ten services say in their own documentation, checked on 18 September 2026. The first figure in each is the recovery window. The second is when they claim the data is actually gone.
Google. Up to a month of recovery inside the deletion process. Says the whole thing takes "around 2 months," with encrypted backups holding data "up to 6 months." Keeps data longer where it is needed for "security, fraud and abuse prevention, or financial record-keeping."
Facebook. Thirty days to cancel the deletion. Says it may take "up to 90 days" to delete the things you posted. "Copies of your information may remain after the 90 days in backup storage," and messages you sent sit in other people's inboxes.
Discord. A 15 to 30 day hold, then "up to 45 days to delete identifying information from backups." Content you posted in servers stays up, "no longer tied to your account."
LinkedIn. Reopens a closed account in most cases within 14 days. Removed from the production system "within 24 hours." Logs and backup information are "de-identified" within 30 days rather than deleted.
X. A 30-day window, and no timeline for anything after it. "Deactivating your account does not remove data from X systems."
Microsoft. Thirty or sixty days, whichever you pick. No timeline given for what happens once the window closes.
Spotify. Seven days to reactivate. After that, "the process to delete your data will be initiated." No backup timeline.
Apple. You can cancel with an access code while the request is processing, but no deletion timeline is published on the support page or in the privacy policy. Keeps past transaction information for financial reporting, plus "a one-way hash of the email address of the deleted account."
Reddit. No recovery window at all, and no timeline. "Any posts or comments you made from your deleted account stay on Reddit, but people can't see who they came from."
Amazon. Five days to verify the request by reply. No deletion timeline given. "Amazon is legally required to retain some types of data, such as order history."
Read the recovery windows, then read what each company says comes after them. Seven of these ten put a number on the window that protects them from your regret. Four put a number on when the data itself goes. Only two, Google and Discord, commit to a date by which it leaves their backups, and LinkedIn's thirty-day backup promise is to de-identify rather than to delete, which is a different thing for reasons the next section gets to.
Google is unusually specific here, and its answer is worth quoting at length because it describes the real sequence: "First, we aim to immediately remove it from view and the data may no longer be used to personalize your Google experience." Then: "This process generally takes around 2 months from the time of deletion." And then the part nobody expects: "Our services also use encrypted backup storage as another layer of protection to help recover from potential disasters. Data can remain on these systems for up to 6 months."
Removed from view, then removed from active systems, then aged out of backups. Half a year, at the company that documents this better than anyone.
Why is my data still in a backup?
Because backups are built to resist exactly the thing you are asking for.
A backup is a snapshot taken on a rotation, usually encrypted, often immutable on purpose, and valuable precisely because nobody can reach into it and change what it says. Surgically removing one person's rows from a two-month-old snapshot is not a supported operation at most companies, and restoring, editing and rewriting every snapshot would break the integrity guarantee that makes the backup worth having.
Regulators know this, and both of the big ones have written the compromise into their guidance.
The UK's Information Commissioner's Office puts it like this: "It may be that the erasure request can be instantly fulfilled in respect of live systems, but that the data will remain within the backup environment for a certain period of time until it is overwritten." And then the operative sentence: "The key issue is to put the backup data 'beyond use', even if it cannot be immediately overwritten."
California goes further and writes the carve-out into the definition of compliance. Under the CCPA regulations, a business complies with a deletion request by "Permanently and completely erasing the personal information from its existing systems except archived or backup systems, deidentifying the personal information, or aggregating the consumer information." A business "may delay compliance with the consumer's request to delete, with respect to data stored on the archived or backup system, until the archived or backup system relating to that data is restored to an active system."
So when a company tells you your data is deleted while a copy sits in a backup, it is not necessarily lying, and it is not necessarily breaking the law. It is describing a state that the law has already agreed to call deletion.
There is a second reason, and it is more technical. Distributed databases often cannot delete a row at all. Apache Cassandra, which runs underneath a great many large services, "treats a deletion as an insertion": the delete is written as a new marker called a tombstone, stored next to the data it supersedes, and kept for a default of ten days. It has to be. If a server was offline when you deleted your account and the row had simply vanished, that server would helpfully replicate your data back into the cluster when it reconnected. Cassandra's own documentation describes what happens when the window is missed: "If a node remains down or disconnected for longer than gc_grace_seconds, its deleted data will be repaired back to the other nodes and reappear in the cluster."
Deleted data coming back is not a conspiracy theory. It is a named, documented failure mode with a configuration setting attached to it.
And even at companies with real engineering resources, knowing which rows are yours is the hard part. Meta published a paper on this at USENIX Security in 2020 describing the system it built to handle deletion at scale. The framing sentence is unusually candid: "The architecture of modern distributed data stores makes it challenging for developers to implement deletion." The stores offer a way to delete a given row, the paper notes, but "offload to applications the work of figuring out when to invoke that API and with which arguments." The database can delete anything. It has no idea which pieces of it are you.
What is anonymization, and does it count as deletion?
It is a real legal category, and it is not deletion.
Under European law the distinction is sharp. Recital 26 of the GDPR takes anonymous information out of the regulation entirely: "This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes." But the bar is high, and the same recital closes the obvious loophole: "Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person."
European regulators said it more bluntly back in 2014, and the line has never needed improving: "Pseudonymisation is not a method of anonymisation. It merely reduces the linkability of a dataset with the original identity of a data subject."
You can watch this happen in the wild. LinkedIn says it will "de-identify any logs or other backup information within 30 days of account closure." Reddit says your posts stay up but "people can't see who they came from." Discord says it continues to retain and display what you shared, "but that content is no longer tied to your account." In each case the record survives your account by design, with your name unhooked from it.
Whether that unhooking is durable is a separate question, and it is one European regulators have now examined directly. In February 2026 the European Data Protection Board published the results of a coordinated action across 32 supervisory authorities, with 764 controllers responding to a questionnaire about how they actually handle erasure requests. Two of the recurring problems it identified: difficulties with deletion in backup contexts, flagged by half the responding authorities, and companies "relying upon anonymisation as a substitute for permanent deletion of personal data." On overall performance, "According to almost two thirds of the participating SAs, the level of compliance can be assessed as 'average'."
That is a regulator, across an entire continent, confirming the two things this article is about.
What can a company legally keep after you ask them to delete you?
More than you would guess, and less than a refusal usually implies.
Both major frameworks work the same way. There is a right to erasure, and then a short list of purposes that override it.
Under GDPR Article 17(3), the right does not apply "to the extent that processing is necessary" for freedom of expression and information, for compliance with a legal obligation, for public interest in public health, for archiving and research purposes, or "for the establishment, exercise or defence of legal claims."
Under California law, the CCPA lists eight exceptions at Civil Code 1798.105(d). A business may keep your information where it is reasonably necessary to complete the transaction you started, to help ensure security and integrity, to debug errors, to exercise free speech rights, to comply with the California Electronic Communications Privacy Act, to conduct public or peer-reviewed research, to enable internal uses "reasonably aligned with the expectations of the consumer," or to comply with a legal obligation.
Note the phrasing in both. GDPR says "to the extent that." California says "reasonably necessary." An exception is a scalpel rather than a shield, and California's regulations spell out what that means when a business says no. It must "Provide to the consumer a detailed explanation of the basis for the denial," it must "Delete the consumer's personal information that is not subject to the exception," and it must "Not use the consumer's personal information retained for any other purpose than provided for by that exception."
"We can't delete your account" with no explanation attached is not a lawful answer in California.
Some of those legal obligations are real and boring, and worth naming so you can recognize them. Amazon states it directly: "Be advised that Amazon is legally required to retain some types of data, such as order history. We retain this data in line with applicable laws including for tax and accounting and fraud prevention purposes." In the United States, financial institutions must keep Bank Secrecy Act records for five years under 31 CFR 1010.430(d). In the European Union, invoice storage periods are set by each member state under Article 247 of the VAT Directive, and ten years is common.
Delete your account at a German retailer and the invoice outlives the account by a decade. That is not the retailer being difficult. That is tax law, and it is one of the few places where "we have to keep it" is simply true.
What is a formal deletion request, and how is it different from the button?
The button is a product feature. The request is a legal instrument, and the difference shows up as a deadline with a duty to answer you attached to it. The deadline depends on where you are.
If you are in the United States. California gives a business 45 days to respond to a verifiable deletion request, extendable once by another 45 days with notice. Roughly twenty states now have comprehensive privacy laws on the books, with nineteen in force as of early 2026, and Indiana, Kentucky and Rhode Island joining on 1 January 2026. The 45-day pattern is the common one. What you can demand still depends on your zip code, so a Californian and an Ohioan are not asking for the same thing.
If you are in the EU. The controller must act "without undue delay and in any event within one month of receipt of the request," extendable by two further months where the request is complex. Your rights do not depend on where the company is. Article 3(2) of the GDPR reaches a controller outside the Union processing the data of people who are in it, where the activity relates to "the offering of goods or services, irrespective of whether a payment of the data subject is required" or to "the monitoring of their behaviour as far as their behaviour takes place within the Union." Nearly every American service named above is in scope for an EU resident, which is why several of them list an Irish entity as the data controller.
The practical difference is that a deletion request creates evidence. The button gives you a confirmation screen you will never see again. A written request gives you a timestamp and an obligation on the other side.
How do I know whether my data was actually deleted?
You mostly cannot, directly. What you can do is check the things that leak.
Ask for it in writing, and keep the reply. California's regulations require that "a business shall inform the consumer whether it has complied with the consumer's request." A confirmation email is the only artifact you will get, so keep it.
Send an access request sixty days later. If the company can still produce a file about you, deletion did not reach whatever system produced it. This is the single most useful test available to a consumer, and it costs one email.
Watch the mail. Marketing that keeps arriving after a deletion means your address is still in a live system somewhere, or in a list that was exported before you left.
Check a breach service in a year. If the account is deleted, your address should stop appearing in new breaches attributed to that company.
It is worth being clear about why this verification matters, because the failures are documented rather than theoretical.
In May 2023 the FTC and Department of Justice charged Amazon over Alexa, alleging that it "retained children's recordings indefinitely" and that even when parents requested deletion, Amazon "failed to delete transcripts of what kids said from all its databases." The company paid a $25 million civil penalty. Note the phrasing: not all its databases. The button worked. It did not work everywhere.
In January 2021 the FTC settled with Everalbum, which had promised to delete photos and videos when users deactivated their accounts. The Commission found that "until at least October 2019, Everalbum failed to delete the photos or videos of any users who had deactivated their accounts and instead retained them indefinitely."
In June 2023 the FTC charged 1Health.io, which sold DNA testing and promised to destroy saliva samples after analysis. The company "did not implement a policy to ensure that the lab that analyzed the DNA samples had a policy in place to destroy them." It had outsourced the analysis and never checked what happened to the samples afterwards. That is the supply chain problem in its purest form, and it applies to every company that uses a vendor, which is every company.
In July 2026 France's CNIL fined the recruitment firm EXTIA €300,000 for mishandling erasure requests. Of 265 requests received in 2024, more than three quarters were unaddressed or inadequately processed. Twelve went entirely unprocessed. A hundred and sixty-six people who asked for erasure never received confirmation.
And in July 2026 researchers at UC Irvine published the results of submitting deletion requests under the CCPA to every California-registered data broker they could reach, using synthetic identities. They report that "Among the 322 DBR-s contacted, only 97 responded with the result of the deletion requests." The detail that should stay with you: "Many DBR-s replied that data was deleted, even though the consumer was synthetic and the data obviously does not and did not exist."
Some of those companies confirmed deleting a person who had never existed.
What if the company ignores you?
Both systems give you somewhere to go, and neither of them is a courtroom.
In the EU, Article 77 of the GDPR gives every data subject "the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement." That is your national data protection authority. It costs nothing, and it is the mechanism that produced the CNIL fine described above. Those cases start with one person filing.
In the United States, enforcement is the state's job rather than yours. California's Attorney General is explicit that for most CCPA violations "only the Attorney General or the California Privacy Protection Agency may take legal action against non-compliant entities." You can file a consumer complaint with either one. Outside California, the route is your state attorney general, in the states that have a privacy law to enforce.
Neither path gets your data deleted this week. Both build the record that enforcement runs on, which is the only reason any of the penalties in the previous section exist.
The part that survives deletion entirely
Even a perfect deletion leaves something behind, and this is the least discussed answer to "is my data really gone."
Your records can be removed while what was learned from them stays in production. Regulators noticed, and built a remedy for it. When the FTC settled with Everalbum, the order required deletion of the photos, of the face embeddings derived from them, and of "any facial recognition models or algorithms developed with Ever users' photos or videos." When it settled with Avast in February 2024 over browsing data sold through its Jumpshot subsidiary, the order required Avast to "delete the web browsing information transferred to Jumpshot and any products or algorithms Jumpshot derived from that data." The X-Mode order in January 2024 required destruction of location data "and any products produced from this data." The Amazon order barred using unlawfully retained data "for the creation or improvement of any data product."
Those remedies exist because deleting the source records leaves the value extracted from them untouched. It has a name in enforcement practice now, and almost no consumer-facing page on this topic mentions it.
So what should you actually do
Deletion is slow and only partly verifiable. It is also the only action on this list that reduces anything.
A deactivated account is a live record with a hidden profile. An account you left open because deleting felt pointless is a complete record, holding your address, your saved card, your order history and whatever you typed into a form in 2017, sitting in a database that gets breached or quietly repurposed on a timeline you do not control. A deleted account is a shrinking record with a legal clock on it.
The delete button gets you most of the way there at most companies, most of the time. A written deletion request gets you a deadline and an answer you can keep. Use the button for the long tail, and use the request for the accounts that actually hold something.
And do it in the order that matters: the retailer with your card on file before the newsletter you never open.
Where Yorba fits
Yorba scans inbox metadata to find the accounts you have forgotten you created, which is usually the hard part, because you cannot delete an account you cannot name. Deletion instructions for more than 10,000 services are free through Delete Desk. On Premium, at $60 a year, Yorba sends the deletion request on your behalf rather than handing you a link.
The honest limits. Yorba connects Google and Microsoft mailboxes, so Yahoo and iCloud are not supported. And Yorba cannot verify what happens inside a company's backups any more than you can, because nobody outside the company can. Yorba's own 2025 State of Clutter report puts the success rate of member requests at roughly 48% for account and data removal, a figure that includes the half that fails. [FLAG: 48% figure requires Chris's approval before use in SEO contexts]
Yorba is a Public Benefit Corporation and takes no outside funding.
Frequently asked questions
Does deleting an account delete my data? Usually not all of it, and rarely straight away. A delete button typically removes your login and starts a process that takes weeks to months, leaves copies in backups, and preserves whatever a retention policy or a legal obligation covers. Google says the process takes around two months and that data can stay on backup systems for up to six.
What is the difference between deactivating and deleting an account? Deactivation hides your profile and keeps everything intact so you can come back. Deletion removes the login and begins removing the record. On Facebook, deactivation keeps your photos and posts and leaves you on Messenger. On X, deactivation is the deletion process, with a 30-day window before it completes.
How long can a company keep my data after I delete my account? As long as a stated retention purpose or a law allows. GDPR Article 17(3) and California Civil Code 1798.105(d) both list exceptions covering legal obligations, security, research and legal claims. Financial records are the common one: US financial institutions keep Bank Secrecy Act records for five years, and EU invoice retention runs up to ten years in several member states.
Is anonymized data the same as deleted data? No. Anonymous data falls outside the GDPR entirely, but only if re-identification is genuinely not possible. If the company can still link the record back to you using information it holds, that is pseudonymization, and European regulators have stated plainly that "pseudonymisation is not a method of anonymisation." An anonymized record still exists. It just no longer has your name on it.
Can I get my account back after deleting it? Only inside the grace period, and only where one exists. Facebook gives 30 days, Microsoft 30 or 60, Discord 15 to 30, Spotify 7, and LinkedIn will reopen in most cases within 14 days. Reddit gives none: "our administrators won't be able to bring it back for you."
Do companies have to confirm that they deleted my data? In California, yes. The CCPA regulations require that a business inform you whether it has complied, and if it refuses in whole or in part it must give "a detailed explanation of the basis for the denial" and delete everything the exception does not cover. Under GDPR, the controller must respond within one month, extendable to three for complex requests.
Does deleting my account remove my posts and comments? Often not. Reddit keeps them: "Any posts or comments you made from your deleted account stay on Reddit, but people can't see who they came from." Discord does the same for server messages. Facebook notes that copies of messages you sent are stored in other people's inboxes and may still be visible to them.
Does deleting an account stop the emails? It should, eventually, but not instantly and not always. Marketing lists are frequently exported to other systems, and a list that left the building before you did is not reached by your deletion request. If mail keeps arriving weeks later, that is evidence the deletion did not propagate everywhere.
Can a US company refuse to delete my data if I live in the EU? Not on the grounds that it is American. Article 3(2) of the GDPR applies to controllers outside the Union that process the data of people who are in it, where the activity relates to offering them goods or services or monitoring their behavior. A company can still refuse on one of the Article 17(3) exceptions. "We are not a European company" is not one of them.
What do I do if a company ignores my deletion request? In the EU, file a complaint with your national data protection authority under Article 77. It is free, and it is what regulators act on. In California, file with the Attorney General or the California Privacy Protection Agency, because for most CCPA violations only those two can take legal action. Elsewhere in the United States, your state attorney general, where your state has a privacy law.
How do I make a formal deletion request instead of just clicking delete? Email the privacy address in the company's privacy policy, state that you are exercising your right to deletion under the applicable law, and ask for written confirmation of what was deleted and what was retained under an exception. Diary it. California gives the business 45 days, extendable once. GDPR gives one month, extendable to three.
Sources
- GDPR Article 17, right to erasure, including the Article 17(3) exceptions
- GDPR Article 12(3), response deadlines
- GDPR Article 3, territorial scope
- GDPR Article 77, right to lodge a complaint with a supervisory authority
- GDPR Recital 26, anonymous information
- Article 29 Working Party, Opinion 05/2014 on Anonymisation Techniques, adopted 10 April 2014
- EDPB, Coordinated Enforcement Framework report on the right to erasure, adopted 10 February 2026
- ICO, Right to erasure guidance, including backups and "beyond use"
- California Civil Code 1798.105 and 1798.130
- 11 CCR 7022, requests to delete
- California Attorney General, CCPA enforcement and consumer complaints
- California Privacy Protection Agency, consumer complaint form
- Koley Jessen, state privacy laws effective 1 January 2026
- 31 CFR 1010.430, Bank Secrecy Act record retention
- European Commission, explanatory notes on VAT invoicing rules, Article 247 storage periods
- Google, how Google retains data we collect
- Google Privacy Policy, effective 26 May 2026
- Google Cloud, data deletion
- Facebook, permanently delete your Facebook profile, checked 18 September 2026
- Meta Privacy Policy, effective 23 July 2026
- Discord, data privacy controls and retention, last updated 17 September 2026
- Discord, how do I disable my account, last updated 19 September 2025
- LinkedIn, data retention and close and delete your account
- X, how to deactivate your X account
- Reddit, if I delete my account, what happens to my username, posts and comments, last updated 15 December 2025
- Apple, how to delete your Apple Account, published 28 August 2026
- Amazon, what happens when I close my account and request the closure of your account
- Microsoft, how to close your Microsoft account
- Spotify, close your account
- Apache Cassandra, tombstones documentation
- Cohn-Gordon et al., DELF: Safeguarding deletion correctness in online social networks, USENIX Security 2020
- FTC and DOJ charge Amazon with violating children's privacy law, 31 May 2023
- FTC settlement with Everalbum, 11 January 2021
- FTC action against 1Health.io, 16 June 2023
- FTC order against Avast, 22 February 2024
- FTC order against X-Mode Social and Outlogic, 9 January 2024
- CNIL fines EXTIA €300,000, 21 July 2026
- van Kempen, Tsudik, Jhunjhunwala and Raja, Let My Data Go: Data Brokers' Compliance with Opt-Out and Deletion Requests, 5 July 2026

