.MKITOS

Week 1 of rm -rf

YOUR DATA NEVER DIES

Open your phone right now. Go to Settings. Then App Permissions. Look at the list of apps that have access to your microphone. Count them. Then check camera. Then contacts.

Chances are, there are apps in that list you haven't opened in months. A game that asks for your location. A QR scanner that wants your camera even when you are not scanning anything. A "beauty camera" app from 2020 that still has access to your photos, contacts, and microphone.

Every single one of those permissions is a pipeline. Your data flows through it to servers you don't control, stored alongside your name, your phone number, your email, your address — all of which you willingly typed into some form years ago.

This week is about finding all those pipelines. Every account, every profile, every exposed piece of data. Don't panic when you find things — that's what Week 2 is for. But you need to see the full picture first.

Task 1: Google Yourself (The Right Way)

You've probably googled your own name before. That's not enough. You need to search like someone who wants to find you.

Open a private/incognito window (so your search history doesn't influence results) and run these queries:

Pro tip: Search for your old usernames, handles, and gamertags too. People often abandon accounts without deleting them, leaving a trail of personal information.

Take screenshots of everything you find. You'll need them for Week 2.

Advanced: Google Dorking Yourself

These queries are more powerful but also more likely to return noise. Experiment with them:

If you find your Aadhaar number, PAN card, passport details, or other government ID exposed in any search result, that is a critical finding. Document the URL and proceed to Week 2 immediately for that specific item.

⚠ Warning: Stick to Google and DuckDuckGo for these searches. Other search engines (Bing, Yahoo, Yandex, Baidu) may log your queries and associate them with your IP. You are literally searching for your own PII — do not hand it to another data broker disguised as a search engine.

Task 2: Check People Search Sites

People search sites (also called "data aggregators" or "people finders") scrape public records — voter registrations, property records, court documents, social media — and compile them into searchable profiles. They then charge money to access the full details, but the preview alone often shows enough to be concerning.

Visit each of these sites, search for yourself, and note what you find in the free preview:

Note: Do NOT pay for any "full report" or "premium lookup." The free preview is enough to assess your exposure. If a site demands payment to see anything, skip it — you can target it in Week 2's opt-out phase.

Create a list of every site where you find a profile. You'll be using this list extensively next week.

What About India?

India-specific people search and data aggregation sites to check:

Note on government data: If your information is on a government portal (electoral rolls, Aadhaar, PAN, property records), there is usually no way to remove it. These are public records by law. The most you can do is correct inaccuracies through official channels. Do not waste time trying to "opt out" of government databases — focus on the commercial sites where removal is actually possible.

Task 3: Find Your Breach Exposure

Data breaches happen constantly. Your email, password, phone number, and even physical address may be circulating in breach dumps that are publicly accessible.

Method A: Manual Search (Recommended)

The most trustworthy way to check for breaches is to not give your data to anyone. Instead:

Method B: Third-Party Breach Checkers (Use with Caution)

These services can tell you if your email appears in known breaches, but they require you to submit your email to their server. Decide for yourself whether the trade-off is worth it.

Our advice: Start with Method A (manual search). Use Method B only after you've exhausted manual options, and understand that you are trusting a third party with your email address.

Task 4: App Permission Audit (The One Everyone Skips)

Here is a number you won't like: the average phone has 15-20 apps with active permissions that the user forgot about. Camera access for apps that have never taken a photo. Microphone access for apps that have no business listening. Location tracking for apps that work fine without it.

Go through your phone right now and audit every permission:

  1. iPhone: Settings → Privacy & Security → Review each section (Camera, Microphone, Location, Contacts, Photos, etc.). For every app that doesn't need that permission to function, turn it off.
  2. Android: Settings → Privacy → Permission Manager. Same process. Android also shows you which apps have been given access to "Phone" and "SMS" — revoke anything suspicious.

Note: Modern Android and iOS automatically revoke permissions for apps you haven't opened in a while. This is good, but don't rely on it — some apps request permissions again on launch, and you might blindly tap "Allow."

For advanced users (Android only): Some apps hide from your app drawer — system bloatware, spyware, or apps with hidden launcher icons. Go to Settings → Apps → See all X apps (show system apps) to see everything installed. Look for apps with generic names like "System Update," "Settings Storage," or "Device Health" that don't belong to your phone manufacturer. If you find something suspicious, check its package name and search online. You can also use adb shell pm list packages from a computer to dump every package installed on your device.

While you're at it, check your installed apps list. How many of those do you actually use? Anything you haven't opened in 3 months? Uninstall it. But remember: uninstalling does not delete your account data — it just removes the icon. You'll handle the actual account deletion in Week 2. For now, just remove unused apps to cut off ongoing data collection.

The most dangerous apps:

Task 5: Social Media Audit

Social media platforms are data goldmines — not just for what you post, but for what your settings expose to the world.

For each platform you use (Facebook, Instagram, Twitter/X, LinkedIn, Reddit, Telegram, Discord, etc.):

India note: If you use ShareChat, MX Player, or other India-first platforms, include them in this audit. These platforms have different data retention policies and may expose different information than Western platforms.

Task 6: Check Third-Party Connections (OAuth Leaks)

You know the "Sign in with Google" or "Login with Facebook" buttons? Every time you use them, you create a connection between your main account and a third-party service. That third-party service now has access to the data that your Google or Facebook allows — which is often your name, email, profile photo, and friend list.

The problem: people accumulate dozens of these connections over the years and forget about them. A random forum you signed into with Google in 2016 still has a token. If that forum gets breached, the attacker now has your Google-linked identity — and possibly the ability to re-request permissions.

Go through your connected apps on every major platform:

For each app you revoke, ask yourself: did I also have an account on that service using a different login method? If so, that account still exists with your email — add it to your Week 2 deletion list.

One more thing: Check your Google Third-Party Access specifically at myaccount.google.com/security-checkup. Google highlights apps with "full account access" — these can read your email, see your location, and access your Drive. Revoke any that you don't absolutely trust.

🌍 Region-Specific Discovery

India (🇮🇳)

European Union (🇪🇺)

United States (🇺🇸)

Asia-Pacific (🌏)

What to Do With What You Find

By the end of this week, you should have:

Do not attempt to remove anything yet. That's the entire purpose of Week 2. For now, just document. The more thorough your discovery, the more effective your removal will be.

⚠ SELF-CHECK: Be Honest, No One Is Watching (Except the Data Brokers)

☐ Did you search for yourself using at least 5 different queries?

☐ Did you check at least 5 people search sites?

☐ Did you search for your email on Pastebin?

☐ Did you audit every app permission on your phone?

☐ Did you uninstall apps you haven't used in 3+ months?

☐ Did you audit third-party OAuth connections (Google Sign-In etc.)?

☐ Did you do the India-specific checks (if applicable)?

☐ Did you do the region-specific checks for your country?

☐ Did you take screenshots of everything?

☐ Did you download your social media data?

If you ticked fewer than 5 boxes, you're not done. The data brokers are more persistent than your procrastination. Try again.

Back to Module Home    Week 2: PULL THE PLUG →