Social Media

The industry files

What you type is a fraction of the profile. What you do on other sites reports back, and the platform works out the rest for itself. Deleting the profile closes the account, and there is no fixed end to any of it: a suspended account's email and phone number can be kept indefinitely.

The read at a glance

Tracking priority Recommended

They hold your network and a detailed read of what you engage with.

If it leaks High

A leak exposes your private messages, your network, and the inferences drawn about your politics and beliefs.

Expect it kept Indefinitely

Posts and "derived" profile data are commonly kept with no end date; deletion often means hidden, not gone.

Identity demanded Liveness or ID

Sign-up asks for little, but age-assurance and appeals increasingly demand a face scan or ID.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

What leaks is your private messages, your photo library and your contacts. None of it can be changed afterwards, and it exposes the people around you as much as it exposes you.

What repeats in the policies

What you hand over

Most of the profile never came from you

Advertisers and the platform's own tracking tag on other sites report back what you did away from the app. The platform then works out what you never told it: your age, your gender, your interests, sometimes a pay bracket, and an identity pinned to you even when you are signed out.

Where it goes

Shared by type, never by name

Policies name who receives your data by category, advertising, analytics and measurement partners, never one by one. Several also admit that these partners collect their own identifiers from you, a cookie or a device ID, and may use what they receive for their own purposes. UK and EU law lets you ask for the names behind a category. US law stops at the categories.

What stays

Open-ended by default

The default has no fixed end. Many policies say they hold your data as long as you keep the account, or as long as they judge it necessary. Where numbers do appear they are the company's own claim, and they run from about thirty days to two years and beyond, often only in the UK and EU version of the policy.

What to ask for

Deleting the profile closes the account

The profile is what the service runs on, so deleting it closes the account. The request that changes anything while you stay is a limit: stop the profiling, the targeting and the training, and leave the account standing. That is also the hardest one to refuse: a European regulator weighed all three grounds a platform gave for ad profiling and rejected every one.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileBrowsing & ActivityMessagesLocation Identity Documents · maybePhotos & Biometrics · maybeChildren's Data · maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Who matters to you Highly likely

Who you message and follow maps your whole network.

Political views Likely

What you engage with is used to infer your leanings.

Religion and community Likely

Follows and reactions imply faith and community.

Sexual orientation Possible

Engagement patterns have been shown to reveal orientation.

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

Safety and abuse records They set it as long as the ban holds

To enforce bans and stop blocked or abusive users coming back.

Online-safety and child-protection reports Law sets it 1 year for content, 5 for the report reference

A legal duty to preserve child-safety reports, which overrides an erasure request for that data.

Anonymised, aggregated, or AI-trained data They set it often kept indefinitely

They treat it as no longer being about you, though such data can sometimes be re-identified.

Tax and accounting records Law sets it about 6 years

Tax and company law makes them keep billing and payment records.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

A phone number you give only to secure the account does not stay there. US regulators penalised one platform after phone numbers and email addresses collected to secure accounts were used to target ads, affecting more than 140 million people. On some platforms your public posts now feed the company's own AI, and on at least one they flow to outside firms to train theirs unless you opt out.

Sold or shared Highly likely

Attention and inferred interests are the entire business model.

AI training High

Your posts, images, and messages train the platform's own models; opt-outs work only going forward.

Even anonymised, this can still be you

Language models infer who is behind pseudonymous posts from writing style alone, at scale (Staab et al., ICLR 2024), and network structure by itself re-identifies accounts (Narayanan and Shmatikov, 2009).

Name, date of birth, postcode Typical

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces Typical

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

How you write Typical

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

Face and voice Typical

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint Typical

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

Who you know Typical

The shape of who a person connects with re-identifies accounts across networks with no other data (Narayanan and Shmatikov, 2009).

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)·De-anonymizing Social Networks (IEEE Symposium on Security and Privacy, 2009)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“actions you have taken outside of our websites and apps”

“actions you have taken outside of our websites and apps”

Your ad profile grows from what you did on unrelated sites and apps, fed back by advertisers or picked up by the platform's own tag. It reaches well past anything you posted to the account.

The move A See request covers this off-site layer, not just your posts. What they pulled in, and from where, is theirs to lay out.

“we infer your attributes and interests based on the information we have about you”

“we infer your attributes and interests based on the information we have about you”

New data gets made about you that you never gave: age, gender, interests, and on some apps an identity while you are signed out. A request worded around the data you provided misses this layer, because you never provided it.

The move A See request reaches the data they made, not only the data you gave. What they infer is theirs to state.

“indefinitely to prevent repeat policy offenders from creating new accounts”

“indefinitely to prevent repeat policy offenders from creating new accounts”

The email or phone number you signed up with can be kept past every window they otherwise state, with no end, once the account is tied to a rule violation. You cannot see the trigger or the keeping.

The move A Delete request meets this carve-out where it applies. What they will hold, and for how long, is theirs to answer.

From the blog

ISSUE No. 01

Post 16 Jun 2026

You proved you were real. Where did the proof go?

To open an account, watch a video, or start a job, you hand your face and your ID to a company you never chose. Here is what they keep, why 'we delete it' is a claim you can't check, and what a regulator found when it looked.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.