Week 1 of rm -rf
YOUR DATA NEVER DIES
Open your phone right now. Go to Settings. Then App Permissions. Look at the list of apps that have access to your microphone. Count them. Then check camera. Then contacts.
Chances are, there are apps in that list you haven't opened in months. A game that asks for your location. A QR scanner that wants your camera even when you are not scanning anything. A "beauty camera" app from 2020 that still has access to your photos, contacts, and microphone.
Every single one of those permissions is a pipeline. Your data flows through it to servers you don't control, stored alongside your name, your phone number, your email, your address — all of which you willingly typed into some form years ago.
This week is about finding all those pipelines. Every account, every profile, every exposed piece of data. Don't panic when you find things — that's what Week 2 is for. But you need to see the full picture first.
Task 1: Google Yourself (The Right Way)
You've probably googled your own name before. That's not enough. You need to search like someone who wants to find you.
Open a private/incognito window (so your search history doesn't influence results) and run these queries:
-
"Your Full Name"— quotes force exact match. Try with and without middle name. -
"Your Full Name" phone— finds pages that mention both your name and any phone number. -
"Your Full Name" email— same for email addresses. -
"Your Full Name" address— see if your physical location is listed. -
"Your Email Address"— quotes around your email (replace@with@). -
site:facebook.com "Your Full Name"— restrict search to specific platforms. -
site:linkedin.com/in "Your Full Name"— LinkedIn profiles. -
inurl:"YourUsername"— find pages containing your username in the URL. -
filetype:pdf "Your Full Name"— find PDFs with your name (directories, newsletters, reports).
Pro tip: Search for your old usernames, handles, and gamertags too. People often abandon accounts without deleting them, leaving a trail of personal information.
Take screenshots of everything you find. You'll need them for Week 2.
Advanced: Google Dorking Yourself
These queries are more powerful but also more likely to return noise. Experiment with them:
-
intitle:"Your Full Name"— pages with your name in the title. -
intext:"Your Email"— pages containing your email in the body text. -
"Your Phone Number"— with and without country code. -
"Your Street Address"— partial address, just the street name and number. -
cache:yoursite.com— Google's cached version of your own site, if you have one.
If you find your Aadhaar number, PAN card, passport details, or other government ID exposed in any search result, that is a critical finding. Document the URL and proceed to Week 2 immediately for that specific item.
⚠ Warning: Stick to Google and DuckDuckGo for these searches. Other search engines (Bing, Yahoo, Yandex, Baidu) may log your queries and associate them with your IP. You are literally searching for your own PII — do not hand it to another data broker disguised as a search engine.
Task 2: Check People Search Sites
People search sites (also called "data aggregators" or "people finders") scrape public records — voter registrations, property records, court documents, social media — and compile them into searchable profiles. They then charge money to access the full details, but the preview alone often shows enough to be concerning.
Visit each of these sites, search for yourself, and note what you find in the free preview:
- Spokeo — spokeo.com — Shows name, age, relatives, address history, and sometimes email/phone in preview.
- Whitepages — whitepages.com — Landline and address lookup, often shows relatives.
- TruePeopleSearch — truepeoplesearch.com — Phone, name, and address lookup. Free preview is generous.
- FastPeopleSearch — fastpeoplesearch.com — Similar to the above.
- Radaris — radaris.com — Background check aggregator with free name search.
- PeekYou — peekyou.com — Social media focused people search.
- ZabaSearch — zabasearch.com — Basic people search.
Note: Do NOT pay for any "full report" or "premium lookup." The free preview is enough to assess your exposure. If a site demands payment to see anything, skip it — you can target it in Week 2's opt-out phase.
Create a list of every site where you find a profile. You'll be using this list extensively next week.
What About India?
India-specific people search and data aggregation sites to check:
- JustDial — justdial.com — Business and personal listings often include phone numbers without consent.
- IndiaMart — indiamart.com — Supplier directory, but individual profiles sometimes appear.
- SearchMob — searchmob.co — Indian people search with phone and email lookups.
- Myspace / BharatMatrimony / Shaadi.com — Old profiles on matrimonial and social sites often linger for years.
Note on government data: If your information is on a government portal (electoral rolls, Aadhaar, PAN, property records), there is usually no way to remove it. These are public records by law. The most you can do is correct inaccuracies through official channels. Do not waste time trying to "opt out" of government databases — focus on the commercial sites where removal is actually possible.
Task 3: Find Your Breach Exposure
Data breaches happen constantly. Your email, password, phone number, and even physical address may be circulating in breach dumps that are publicly accessible.
Method A: Manual Search (Recommended)
The most trustworthy way to check for breaches is to not give your data to anyone. Instead:
-
Search for
"your.email@example.com" leakor"your.email@example.com" breachon Google and DuckDuckGo. -
Search for your email on Pastebin (pastebin.com) —
breaches are frequently dumped there. Use
site:pastebin.com "your.email@example.com". - Check Telegram channels that publish breach data (search for "leaked database" or "breach dump" channels). ⚠ Warning: Most of these channels are scams or honeypots. They will try to sell you data, infect you with malware, or log your IP and telegram ID. Do not download any files. Do not click any links. Just search for your email in the channel's message history and leave.
-
Search for your username on GitHub gists —
site:gist.github.com "yourusername". - Check 9ghz.com — A breach data aggregator. Search for your email or username. Shows which services your data appears in. Caveat: you are trusting their server with your query.
Method B: Third-Party Breach Checkers (Use with Caution)
These services can tell you if your email appears in known breaches, but they require you to submit your email to their server. Decide for yourself whether the trade-off is worth it.
- HaveIBeenPwned — haveibeenpwned.com — The most well-known breach checker. They have a good track record and don't store search queries. However, you are trusting Troy Hunt's server with your email address.
- Firefox Monitor — monitor.firefox.com — Uses HIBP's API, same caveat.
- Dehashed — dehashed.com — Shows more detailed breach data but requires payment for full results. Free preview is limited.
- IntelX — intelx.io — Darknet intelligence search. Free tier is very limited.
Our advice: Start with Method A (manual search). Use Method B only after you've exhausted manual options, and understand that you are trusting a third party with your email address.
Task 4: App Permission Audit (The One Everyone Skips)
Here is a number you won't like: the average phone has 15-20 apps with active permissions that the user forgot about. Camera access for apps that have never taken a photo. Microphone access for apps that have no business listening. Location tracking for apps that work fine without it.
Go through your phone right now and audit every permission:
- iPhone: Settings → Privacy & Security → Review each section (Camera, Microphone, Location, Contacts, Photos, etc.). For every app that doesn't need that permission to function, turn it off.
- Android: Settings → Privacy → Permission Manager. Same process. Android also shows you which apps have been given access to "Phone" and "SMS" — revoke anything suspicious.
Note: Modern Android and iOS automatically revoke permissions for apps you haven't opened in a while. This is good, but don't rely on it — some apps request permissions again on launch, and you might blindly tap "Allow."
For advanced users (Android only): Some apps hide from your
app drawer — system bloatware, spyware, or apps with hidden launcher
icons. Go to Settings → Apps → See all X apps (show system
apps) to see everything installed. Look for apps with generic
names like "System Update," "Settings Storage," or "Device Health"
that don't belong to your phone manufacturer. If you find something
suspicious, check its package name and search online. You can also
use adb shell pm list packages from a computer to dump
every package installed on your device.
While you're at it, check your installed apps list. How many of those do you actually use? Anything you haven't opened in 3 months? Uninstall it. But remember: uninstalling does not delete your account data — it just removes the icon. You'll handle the actual account deletion in Week 2. For now, just remove unused apps to cut off ongoing data collection.
The most dangerous apps:
- Flashlight apps that ask for contacts, location, and camera (your phone already has a built-in flashlight — these are pure data harvesters)
- "Beauty camera" and photo editor apps with microphone access
- Free VPN apps (if the service is free, you are the product being sold)
- Antivirus apps for Android (most are scams that collect more data than they protect)
- QR scanner apps with permission to read your photos and contacts (your phone's camera can scan QR codes without a separate app)
Task 5: Social Media Audit
Social media platforms are data goldmines — not just for what you post, but for what your settings expose to the world.
For each platform you use (Facebook, Instagram, Twitter/X, LinkedIn, Reddit, Telegram, Discord, etc.):
- Open your profile in a private/incognito window — this shows exactly what a stranger sees. Screenshot it.
- Check your tagged photos — you might not have posted something, but someone else tagged you in it.
- Review connected apps — third-party apps with access to your account often have broad data permissions.
- Download your data — Facebook and Instagram let you download a complete archive of everything the platform knows about you. Request it and look through it. You will likely find things you forgot existed.
India note: If you use ShareChat, MX Player, or other India-first platforms, include them in this audit. These platforms have different data retention policies and may expose different information than Western platforms.
Task 6: Check Third-Party Connections (OAuth Leaks)
You know the "Sign in with Google" or "Login with Facebook" buttons? Every time you use them, you create a connection between your main account and a third-party service. That third-party service now has access to the data that your Google or Facebook allows — which is often your name, email, profile photo, and friend list.
The problem: people accumulate dozens of these connections over the years and forget about them. A random forum you signed into with Google in 2016 still has a token. If that forum gets breached, the attacker now has your Google-linked identity — and possibly the ability to re-request permissions.
Go through your connected apps on every major platform:
- Google: myaccount.google.com/connected-apps — Revoke access for anything you don't recognize or no longer use. Pay special attention to apps that have access to your Gmail, Drive, or Calendar — those can read your emails and files.
- Facebook: Settings → Apps and Websites → Logged in with Facebook — Remove everything you don't actively use.
- Apple ID: Settings → Apple ID → Sign in with Apple — Review and revoke.
- Twitter/X: Settings → Security and Account Access → Connected Apps.
- GitHub: Settings → Applications → Authorized OAuth Apps.
- Discord: User Settings → Authorized Apps.
For each app you revoke, ask yourself: did I also have an account on that service using a different login method? If so, that account still exists with your email — add it to your Week 2 deletion list.
One more thing: Check your Google Third-Party Access specifically at myaccount.google.com/security-checkup. Google highlights apps with "full account access" — these can read your email, see your location, and access your Drive. Revoke any that you don't absolutely trust.
🌍 Region-Specific Discovery
India (🇮🇳)
- Telecom data leaks: India has seen massive telecom data breaches (Jio, Airtel, etc.). Search for your phone number on breach forums and paste sites. If you find your number in a breach dump, that data is being actively traded.
- PAN Card: Search for your PAN number. If it's exposed, it can be used for financial fraud.
- COEP / University data: If you attended college in India, search for your college name + "student data" + "leak". University databases are frequently breached.
European Union (🇪🇺)
- GDPR Right of Access: Under Article 15 of GDPR, you have the right to request every piece of data any company holds about you. Send a GDPR access request to major platforms, data brokers, and even your bank. They must respond within 30 days.
- Sample template: "Under Article 15 of the GDPR, I request confirmation as to whether you process my personal data, and if so, access to all data you hold about me, including the purposes of processing and any third parties with whom it has been shared."
-
Use
yourdigitalrights.orgfor pre-written requests (caveat: you're giving your data to a third-party site, but the templates are useful reference).
United States (🇺🇸)
- CCPA Right to Know: Under California Consumer Privacy Act, California residents can request what data businesses have collected about them. Some companies extend this to all US residents.
- OptOutPrescreen.com: Check if your credit header data is being sold to marketing companies. This is separate from people search sites and comes from the credit bureaus themselves.
- County property records: Many US counties publish property records online with owner names and addresses. Search your county + "property search" to see if your home address is public.
Asia-Pacific (🌏)
- Singapore: Check the PDPC (Personal Data Protection Commission) for breach notifications.
- Australia: Under the Privacy Act 1988, you can request access to personal data held by Australian agencies. The OAIC (Office of the Australian Information Commissioner) handles complaints.
- Japan: The Act on Protection of Personal Information (APPI) gives you the right to request disclosure of retained personal data.
What to Do With What You Find
By the end of this week, you should have:
- A list of people search sites where your profile exists
- A list of data brokers that have your information
- A list of breached accounts (email + service)
- A list of old/abandoned accounts you forgot about
- A cleaned-up app permissions list (unnecessary permissions revoked)
- Third-party OAuth connections audited and unnecessary ones revoked
- Unused apps uninstalled (accounts pending deletion in Week 2)
- Screenshots of any exposed personal data
- Notes on region-specific exposure (telecom leaks, PAN exposure, property records, etc.)
Do not attempt to remove anything yet. That's the entire purpose of Week 2. For now, just document. The more thorough your discovery, the more effective your removal will be.
⚠ SELF-CHECK: Be Honest, No One Is Watching (Except the Data Brokers)
☐ Did you search for yourself using at least 5 different queries?
☐ Did you check at least 5 people search sites?
☐ Did you search for your email on Pastebin?
☐ Did you audit every app permission on your phone?
☐ Did you uninstall apps you haven't used in 3+ months?
☐ Did you audit third-party OAuth connections (Google Sign-In etc.)?
☐ Did you do the India-specific checks (if applicable)?
☐ Did you do the region-specific checks for your country?
☐ Did you take screenshots of everything?
☐ Did you download your social media data?
If you ticked fewer than 5 boxes, you're not done. The data brokers are more persistent than your procrastination. Try again.