Privacy Cyber Security India Digital Footprint Account Safety

Old Apps, Forgotten Accounts and Your Exposed Phone Number: A Practical Privacy Guide for India

Scan My ShadowAugust 21, 202612 min read
Old Apps, Forgotten Accounts and Your Exposed Phone Number: A Practical Privacy Guide for India

Photo by William Hook on Unsplash

TL;DR

👉 See if your data's already leaked — free 30-second check →

Think about the last time you downloaded a food-delivery app for a single order, registered on a job portal for one application, or signed up on an e-commerce site for a one-off sale. You filled in your name, mobile number and email — and then never opened the app again. That account is almost certainly still active, still holding your personal information, and still sitting in a database that could be breached, sold or scraped at any point.

Most Indians have dozens of such accounts scattered across apps and websites they have long since forgotten. Together, these dormant sign-ups quietly build a digital footprint that is much larger — and more exposed — than most people realise. This guide explains why these old accounts are a genuine privacy risk, what makes the Indian context particularly sharp, and what practical steps you can take to shrink your exposure.

Why Old and Unused Accounts Are a Real Privacy Risk

It is tempting to think that an account you no longer use is harmless. In practice, the opposite is often true.

They are less protected by design

Old accounts are typically less protected than current ones. Many were created before stronger security measures such as multi-factor authentication became standard, and they often carry weak or reused passwords that have never been updated. When a data breach occurs at any of the services where you hold an old account, attackers can use the leaked credentials to attempt logins on your active accounts elsewhere — a technique known as credential stuffing.

You will not notice when something goes wrong

Because you no longer log in, you are unlikely to see warning signs such as login alerts, password-change notifications or unusual activity. By the time you find out, the damage may already be done.

Apps continue collecting data even after you stop using them

Unused apps installed on your phone may continue to run background processes and collect data long after you last opened them. Outdated apps that are no longer receiving security patches from developers present additional vulnerabilities that attackers can exploit.

One weak account can compromise stronger ones

Some services allow password resets through a linked email address or mobile number. A forgotten account that shares your email or phone with a more important account can become a back door into your banking, UPI or social media logins.

Why the Risk Is Especially Sharp in India

Your phone number is the master key to your digital life

In India, your mobile number is linked to almost everything: your Aadhaar, UPI handles, bank accounts, income-tax e-filing, EPFO UAN, insurance policies, demat accounts and social-media logins. Every time you signed up for a new app using your primary number, you gave that service a key that unlocks far more than just the app itself.

As one observer has noted, your phone number has effectively become a commercial asset handled by a large and not always well-regulated ecosystem of marketers, data brokers and, in the worst cases, outright scammers. Sharing it indiscriminately — even with legitimate-seeming apps — adds to a cumulative exposure that is difficult to walk back.

The recycled mobile number problem

There is an additional risk that is specific to India. Under TRAI norms, a mobile number that remains unused or unpaid for roughly 90 days can be deactivated by your telecom operator and, after a short quarantine period, reassigned to an entirely new subscriber. If your old number is still linked to your bank, Aadhaar, UPI, email, DigiLocker or EPFO account, whoever receives that number next could receive your OTPs and reset your logins without any technical trickery on their part.

Social media accounts are particularly vulnerable here. Platforms such as WhatsApp allow account recovery based purely on the SIM. If you have not enabled two-step verification, a new holder of your old number can simply install WhatsApp and inherit your account.

India's new data protection law gives you new rights

India's Digital Personal Data Protection Act, 2023, operationalised through the DPDP Rules notified by MeitY on 13 November 2025, now gives Indian residents formal rights over their personal data. Under these rules, consent must be specific, informed and easy to withdraw, and collection of data beyond what is necessary for a declared purpose is no longer permitted. Importantly, certain categories of platforms — including e-commerce sites, online gaming intermediaries and social-media services with significant Indian user bases — are now required to delete personal data within a set period if a user does not actively maintain their account.

This means you now have a legal basis to request deletion of your data from platforms you no longer use. Exercising that right, however, requires knowing which platforms hold your information in the first place.

How Your Phone Number and Email End Up Exposed

Personal data does not simply stay inside the app you gave it to. Here are the most common routes by which your phone number and email address travel beyond your control:

How to Audit and Clean Up Your Old Accounts

A practical account audit does not need to be complicated. Work through the following steps methodically.

Step 1: Check where your email address has been used

Your email address is the registration anchor for most online accounts. Search your inbox for phrases such as "welcome to", "confirm your account", "you have registered" and "your account has been created". Make a list of every service that appears. Pay particular attention to services you no longer recognise or no longer use.

You can also check whether your email address has appeared in known data breaches. Scan My Shadow scans your email address across more than 1,500 sources and produces a report of where it has been found, helping you understand your current level of exposure before you begin cleaning up.

Step 2: Check where your phone number has been used

Your Indian mobile number has likely been given to even more services than your email, because many apps require it for OTP-based registration. Search your SMS inbox for OTPs and verification messages from services you may have forgotten. Note every sender name.

You can also run a check on your phone number at Scan My Shadow to see which sources currently return results for your number across the open web and data-aggregation platforms.

Step 3: Review app permissions on your phone

Step 4: Delete or deactivate old accounts

For each service you identified in Steps 1 and 2, decide whether you still need the account. If you do not, log in and look for a Delete Account or Close Account option. If no such option is visible, email the company's support or privacy team requesting account deletion and erasure of your personal data. Under India's DPDP Act, certain categories of services are now obligated to respond to such requests.

Step 5: Delink your old mobile number

If you have changed your number or are using a number you no longer actively pay for, delink it from your bank accounts, UPI handles, Aadhaar-linked services, EPFO UAN, income-tax portal and DigiLocker before it is reassigned. This single step can prevent a stranger from receiving your OTPs after a number is recycled.

Step 6: Enable two-factor authentication on accounts you keep

For every account you decide to retain, enable multi-factor authentication. Use an authenticator app rather than SMS wherever possible, since SIM-based OTPs can be intercepted if your number is recycled or if you are targeted by a SIM-swap attempt. If you notice that your phone has suddenly lost network connectivity without explanation, contact your telecom operator immediately, as fraudsters sometimes obtain duplicate SIM cards to intercept OTPs.

Practical Habits That Reduce Long-Term Exposure

Frequently Asked Questions

1. If I stopped using an app, is my data still stored there?

Yes, in most cases. Simply stopping use of an app does not delete your account or the personal information tied to it. The data remains stored on the company's servers until you formally request deletion or the company's data-retention policy requires it to be removed. Under India's DPDP Rules 2025, certain platforms are required to delete data after a defined period of inactivity, but this applies to specific categories of services and the timelines vary. For other platforms, you need to actively request deletion.

2. Can someone misuse my phone number even if I no longer use a particular app?

Yes. Your phone number stored in an old account can be exposed if that service suffers a data breach. Once in a leaked database, your number may be used for spam calls, phishing attempts, or social-engineering attacks that rely on knowing your number to appear credible. Additionally, if your number appears in public-facing directories or scraped listings, it can be found by anyone searching for it.

3. What happens to my WhatsApp account if my old number gets reassigned in India?

Under TRAI norms, a mobile number that is unused or unpaid for roughly 90 days can be deactivated and eventually reassigned to a new subscriber. If your WhatsApp is still linked to that number and you have not enabled two-step verification, the new holder of the number can register WhatsApp on their device and gain access to your account. To prevent this, delink any old number from your WhatsApp and other social-media accounts before you let it lapse, and always enable two-step verification.

4. Does India's new data protection law help me get my data deleted from old apps?

The Digital Personal Data Protection Act, 2023 and the DPDP Rules 2025 do give Indian residents the right to request erasure of their personal data from certain services. Specific categories of platforms are also required to delete data after a defined period of user inactivity. However, the law is being implemented in phases, and not all provisions apply to all types of services immediately. The right of erasure is a useful tool, but exercising it requires you to identify which services hold your data, contact them, and follow up if needed.

5. How do I find out where my phone number or email address currently appears online?

A useful first step is to run your phone number and email address through a digital exposure check. Scan My Shadow scans your details across more than 1,500 sources — including data-aggregation platforms, breach databases and public directories — and returns a report of where your information has been found. This gives you a starting point for your account audit and helps you prioritise which exposures to address first. You can start a check at www.scanmyshadow.com.

Find Out Where Your Phone Number and Email Are Exposed

Your personal data has been collected by dozens of apps and websites over the years. Some of those services have suffered breaches. Others share your information with third parties. And some of your old details may now appear in public directories you never consented to.

Scan My Shadow checks your phone number and email address across more than 1,500 sources and gives you a clear, plain-language report of where your personal information has been found. No guesswork. No generic advice. Just a factual picture of your current digital exposure so you can decide what to do next.

Check your digital exposure at Scan My Shadow →

Curious what's publicly visible about you right now? Try the free Digital Footprint Checker — it takes under a minute.

Phone + email scan · 1,500+ data sources worldwide · Full report
₹498one-time
Scan My Digital Footprint
Secure payment via Razorpay
  • Results within about 5 minutes
  • Clear, plain-English report
  • Delivered straight to your inbox
  • No login or passwords required
  • Scan data deleted after report is generated