The wake-up call wasn’t the money. It was a data breach notification from a service I didn’t even remember signing up for.
Somewhere in 2019 I had apparently created an account with a photo-storage app, attached a card, and forgotten about it. Seven years later that company got breached, my email and password hash ended up in a dump, and I got the standard “we take your security seriously” email. That’s when it hit me: every subscription I’d forgotten about wasn’t just a small monthly charge. It was an account. With my card, my email, sometimes my address — sitting on someone’s server, waiting to leak.
So I did a full audit. Not a budgeting exercise — a security one.
Step one: find the accounts, not the charges
Most subscription-cleanup guides tell you to read your bank statement. That finds the paid ones. It misses the dozens of free accounts that still hold your data.
I went through three sources:
- Bank and PayPal statements, 12 months back. This surfaced 14 recurring charges. Two I could not identify at first glance — always a bad sign.
- My password manager. 212 entries. That number should scare you more than any subscription total.
- Email search for “welcome to”, “your account has been created”, and “verify your email”. This dug up accounts that predated the password manager entirely.
The final count: 14 paid subscriptions and over 60 active accounts on services I hadn’t opened in more than a year.
Step two: rank by damage, not by price
A $3/month service holding scans of my passport is a bigger problem than a $30/month service that only knows my email. For every account I asked three questions:
- Does it store a payment method?
- Does it hold documents, photos, or personal identifiers?
- Does it use a password I’ve reused anywhere else?
Anything with two “yes” answers went on the kill list unless I was actively using it.
Step three: delete the account, not just the subscription
Here’s what most people get wrong: cancelling a subscription usually keeps the account — and the data — alive. I made myself do the full exit each time: export anything I needed, remove the payment method, then request account deletion under GDPR or CCPA where the “delete account” button was conveniently missing. About a third of services made deletion genuinely annoying. Those are exactly the companies you don’t want holding your data.
For the services I kept, I rotated every password to a unique generated one and turned on two-factor authentication everywhere it existed. Where a service only offered SMS 2FA, I noted it as a candidate for replacement — SMS codes are better than nothing, but they’re the weakest form of second factor.
The virtual card trick
The single best change I made: every subscription now runs on a virtual card with a hard limit. My bank lets me spawn disposable card numbers, and several fintech apps do the same. Each service gets its own number. If a service gets breached or tries a sneaky price hike, I kill that one card — nothing else is affected, and no merchant ever holds my real card number again.
As a bonus, “free trial that auto-converts” scams simply stopped working on me. The card has a $1 limit until I decide otherwise.
What it looks like six months later
- 8 paid subscriptions, each on its own virtual card
- 41 accounts permanently deleted, with confirmation emails saved
- One spreadsheet listing every remaining account, its 2FA status, and the date I last reviewed it
- A recurring calendar event every quarter to repeat the sweep in 20 minutes
The financial saving turned out to be around $40 a month, which is nice. But the real win is the shrinking of my attack surface. Every account you don’t have is an account that can’t be breached, phished, or credential-stuffed.
Your subscriptions aren’t a budgeting problem. They’re an inventory of places your identity can leak from. Treat the cleanup accordingly.