The LinkedIn account I deleted came back: why closing an account isn't closing it, and the four steps that are

A deleted account reappeared because the sign-in grant behind it had never been revoked \u2014 and it had no password, so I couldn't close it again. The mechanism, the four-step playbook, and the same failure pointing the other way inside your own product.

The LinkedIn account I deleted came back: why closing an account isn't closing it, and the four steps that are

I deleted my LinkedIn account a while ago. Last week I found it live again, with my name on it, my photo, and a profile I had not written.

I went to close it a second time and the flow asked for my password. There wasn't one. There had never been one. The account existed because at some point I had clicked "Sign in with Google", and an account created that way doesn't need a password — until the day you try to close it, at which point the absence of a password is the thing standing between you and the exit.

That is a small, stupid problem with a general shape, and the general shape is worth writing down, because most of us are going to do this several more times.

Deleting an account does not close the door you came in through

Here is the mechanism, and once you see it you will notice it everywhere. When you sign in to a service with Google or Apple or Microsoft, two things are created. One is the account on that service. The other is a standing grant at your identity provider — a permission that says this application may identify you, and in many cases sign you in automatically.

Deleting the account removes the first. It does not touch the second. Google's own Sign-In documentation is clear that the flow covers both sign-in and sign-up, and that is exactly the design: an application receiving a valid token for someone with no account will, quite reasonably, make them one. So any single tap on a "continue with Google" button — yours, or an app you installed, or a link in an email you opened on a phone — quietly recreates the thing you deleted, often with a profile reconstructed from whatever fragments the service kept.

Closing an account is a product action. Erasing your data is a legal one. Revoking the way back in is a third, separate thing, and it is the one everybody skips.

The four steps, in this order

Order matters here, which I did not appreciate until I got it wrong.

First, look before you close. Every serious platform has a page listing active sessions and devices. Open it and read it before you delete anything, because the moment the account is gone so is the evidence. In my case it showed two sessions, both from my own home connection, which was reassuring — but "was anyone else in here" is a question you only get one chance to answer, and it is worth ninety seconds.

Second, close the account properly. If it was created via a social sign-in, expect the password obstacle and set one first. Note that the working URLs for these flows are frequently not the ones the help centre gives you; I hit two 404s on documented paths before finding the live ones by hand.

Third, revoke the grant at the identity provider. This is the step that actually stops the resurrection, and it lives in a place nobody visits: the third-party connections section of your Google Account, or the equivalent under Apple or Microsoft. Mine showed a grant issued more than a year earlier, with automatic sign-in enabled. Removing it took one click. While I was there I went through the rest of the list and removed twenty-one grants to services I no longer use, which is a genuinely uncomfortable afternoon and I recommend it to everyone.

Fourth, ask for erasure in writing. Closing your account tells the company to stop showing your profile. It does not oblige them to delete what they hold. That obligation comes from Article 17 of the GDPR, the right to erasure, and you have to invoke it — normally through the privacy or data-protection form rather than the self-service delete button, because the self-service route is scoped to the product, not to the records. The UK regulator's guidance is the clearest plain-English explanation of what is and isn't covered. A controller has a month to respond. Put the date in your calendar when you send it, because a month is exactly long enough to forget.

Then, optionally but sensibly: set a filter or label on your inbox for mail from that domain. Not to read it. To notice, on the day it happens, if the account comes back a third time.

Why I'm writing this as a business post

Because the same shape sits inside every company I work with, pointing the other way.

When a customer asks you to delete their account, does your system delete the record, or does it flag the profile as inactive and leave the identity mapping intact so that the next OAuth login restores everything? Both are common. Only one of them matches what the customer thinks they asked for. If your product offers social sign-in and your deletion routine doesn't also invalidate the identity link, you have built exactly the mechanism that put my profile back on the internet — and you will find that out from a complaint, not from a test.

The related question is the one I'd ask in any audit: when a customer's record is deleted, what happens in the CRM, the email platform, the analytics store, the support tool and the backups? "Deleted from the app" is one system. Erasure is a list. I've written about systems that return a cheerful 200 while doing nothing at all, and deletion routines are a favourite habitat for that failure, because almost nobody tests the negative case.

The uncomfortable part

The reason I was even looking is that I had been going through what the internet currently says about me — an exercise I'd put off for years and that I'd now put in the same category as checking your own site's mobile checkout: you assume it's fine because you built it, and you are the last person who should be trusted on that.

Old profiles on services I'd forgotten. Data brokers with a working phone number. Directory mirrors of a company register entry that is a decade out of date. Each one individually harmless; together, a version of me assembled by nobody, maintained by no one, and increasingly the version that automated systems read first. Most of it is now requested for removal and a few requests will be ignored, which I expected.

The bit that changed how I think was smaller than any of that. It was discovering that a thing I had deliberately deleted had been silently rebuilt, and that the door I'd left open was one I didn't know existed.

Check your connections page. You will not like what's on it.

Sources & further reading

External: GDPR Article 17 — right to erasure · ICO — guidance on the right to erasure · Google Account Help — manage links between your account and third-party apps · Google Identity — Sign in with Google overview

Related posts: Everything returned 200 · I wrote about my own website · The work was deciding what not to index

Subscribe to Remco Livain

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe
Work with me →×