Stop Killing Social Media Accounts! A case against harsh inactive account policies

PPI recently signed on to the Stop Killing the Internet initiative: https://www.stopkillingtheinternet.com/
As part of our support for this movement to preserve and promote digital rights we present the following discussion that was drafted collaboratively by members of our community about our concern over the forced removal of social media accounts and content.
Why can’t our social media accounts be online forever?
When we die our friends and family are still there. They want to remember us, and our social media accounts are one important way for them to look back and remember us. However, a recent article by Koa DeMarzo called “A Case Against Forever,” <https://www.techpolicy.press/a-case-against-forever-why-cloud-and-social-media-need-inactivitybased-deletions/> frames indefinite data retention as a looming crisis. The article claims that failure to erase social media accounts represents a danger to privacy, security, and a threat of environmental waste. He argues that Big Tech platforms, especially social media sites, should purge dormant accounts after 1-2 years, with limited exceptions.
The need to erase social media accounts overstates risks, underestimates user needs, and proposes a paternalistic solution that prioritizes corporate risk aversion and regulatory ideals over individual autonomy and real-world utility. Permanence has been the internet’s default, especially on social media websites, for good reasons. Users upload photos, documents, posts, and memories on social media sites expecting control. We do not want or need an invisible timer that could erase parts of our lives. Mandating automatic blanket deletions on social media flips the burden from user choice to platform decree. The recent case of Dutch streamer Joshua Khane having his hacked Microsoft account deleted instead of getting handed back to him is one example of that. <https://www.gadgetreview.com/microsoft-wiped-a-hacked-xbox-account-25-years-of-digital-games-gone-including-baby-photos> And as the recent Sony controversy on physical discs and inactive accounts have hinted, users are not going to take it kindly.
User Control and the Myth of “Forgotten” Data
Users already face challenges with security issues (password resets, account dormancy warnings, and 2FA requirements), but automatic deletion creates a further level of emergency that is real. They will delete our accounts whether we want them to or not. Many people intentionally maintain low-activity accounts: accounts that host bank contacts, family archives, long-term research pages, creative portfolios, backups for future generations. These accounts are important to us, and there is no reason for them to be erased. A soldier deployed overseas, a researcher on sabbatical, an elderly person with sporadic internet use, a person living in areas under internet blackouts such as Iran, human trafficking victims who’re trapped in Southeast Asian scam factories, or someone simply taking a deliberate break from social media could lose irreplaceable data.
“Inactivity” is a crude excuse, and these channels often fail to properly contact their owners. Paid storage already incentivizes retention for active user. Social media services cannot be turned into rental models where you pay or lose access. In the case of email services, many web platforms including essential services like banking rely on emails as two factor authentication methods and zealotic blanket deletions of inactive accounts on that type of services will result in massive user inconvenience as their linked accounts get de facto locked out. Some like Proton had even recently incorporated crypto wallet functions in their services; harsh inactive account deletions will mean that users will be locked out of their funds too <https://proton.me/support/wallet-getting-started>.
Users already have tools like the “right to be forgotten” (erasure requests under GDPR and similar laws) and manual deletion options. Strengthening opt-out mechanisms, data control mechanisms, data export tools, and clear notifications serves autonomy better than forced sunsetting. Platforms can (and do) notify users before any deletion; making this robust addresses most concerns without blanket policies.
Security and Privacy: Deletion Is No Panacea
Dormant accounts pose risks. They can have outdated security. Nefarious actors can hijack them for scams. However, the “one size fits all” approach of automatic deletion after 1-2 years is a blunt instrument. Stronger, uniform security, including mandatory modern password hashing methods, can mitigate threats more effectively than hoping inactivity timers catch everything.
Quantum computing threats or evolving encryption are legitimate long-term issues, but they argue for better cryptography and key management, not preemptively destroying user data. Backups and distributed systems mean “deletion” is rarely total anyway as regulators acknowledge technical feasibility limits. Focusing on “duty to delete” creates compliance theater while ignoring that determined actors (or platforms themselves) retain data in other forms. Data minimization is a valid GDPR principle, but it should balance against legitimate interests, including user-requested storage. Indefinite retention isn’t inherently unlawful if tied to user consent or service provision. In the context of social media sites, many users want their data for memories or evidence for disputes. Painting all retention as corporate hoarding ignores this demand. AI training on dormant data raises consent issues, but solutions like opt-outs, anonymization, or licensing frameworks address this without mass deletion. The answer is better platform defenses and user education, not erasing history by default.
Environmental Claims and Practical Trade-offs
Environmental benefits of deletion are mentioned but thin. Storage efficiency has improved dramatically as new methods like DNA digital data storage and 5D optical data storage have appeared. The marginal energy of “dormant” data is negligible compared to training frontier AI models or video streaming. Mandating deletions incurs its own costs: notification systems, user support for recoveries, legal exceptions processing, and potential data loss leading to recreation (more emissions). Besides that, to address environmental costs of data centers, there are already proposals to place them in space, including on the Moon, instead of on Earth, although the constraint in the form of the universal speed limit, which is the speed of light, necessitates the creation and development of delay-tolerant networking (DTN) and associated infrastructure. True sustainability comes from efficient infrastructure, not purging user content.
Cultural and Historical Loss
Social media and to an extent, email services have become digital archives of personal and collective life which can include family histories, social movements, cultural moments. Automatic deletion risks sanitizing or erasing this record, especially for marginalized voices or long-tail content. Memorialized accounts and “historical interest” exceptions are acknowledged but would be bureaucratically nightmarish to administer fairly. Who decides what qualifies? Platforms? Governments? This opens doors to selective memory curation. We already see tensions with “the right to be forgotten” clashing with free expression, journalism, and historical accountability. Even more so, deletionism had been a major factor for many intractable editorial conflicts on Wikipedia. Expanding this via inactivity defaults amplifies conflicts rather than resolving them.
Harsh and blanket deletion policies on inactive accounts and contents at social media websites, and possibly, to an extent, email services, will enable AI-powered “historic context attacks” in the near future. A 2020 FastCompany article (https://www.fastcompany.com/90549441/how-to-prevent-deepfakes) had posited scenarios about such types of attacks, including a hypothetical situation where forgers were able to construct a convincing false narrative that in 2001 then-President George W. Bush met with Osama bin Laden. Without reliable digital primary source content, future generations will be fooled into thinking that the meeting did happen after all. Forgers might be able to convince the public that a massive cover-up by Big Tech platforms happened during the decade by showing how so much content from the period was deleted. Thus it will appear plausible that some of the news articles regarding the supposed bogus meeting may have actually existed.
How historic context attacks could work
Consider a hypothetical scenario set in 2040. A controversial politician is accused of corruption, and supporters release a “newly discovered” video from 2018 showing the politician rejecting a bribe and behaving ethically during a private meeting. To make the video appear authentic, they also generate:
- Fake news articles dated to 2018 and attributed to defunct or poorly archived websites, supposedly reporting on the video’s original “leak.”
- Screenshots of old Twitter threads in which users appear to discuss the footage.
- AI-generated emails and internal memoranda, supposedly written at the time, that refer to the meeting.
The forgers could point to gaps in the Wayback Machine, deleted social media accounts, or missing personal archives as supposed evidence of a cover-up. Historians would face a difficult task because similar meetings may genuinely have taken place, while the fabricated material could closely imitate the language, design, and technical conventions of the period.
When authentic records disappear, fabricated context becomes easier to present as forgotten history.
A similar attack could target a major protest in 2019 that later turned violent. One side might circulate altered body-camera or smartphone footage portraying protesters as the clear aggressors. The footage could be supported by fabricated eyewitness posts, geolocated images, AI-written blog posts and opinion articles dated to 2019 or 2020, and bylines matching those of real but relatively unknown journalists. The attackers might even produce a false “official report” from a think tank that supposedly investigated the event at the time.
This flood of synthetic corroboration could influence public memory and leave court records, historical accounts, and political debates contested for decades. The danger would not come from one convincing forgery alone, but from a coordinated collection of materials that appear to confirm one another.
Another example could involve a deepfake home video from the 1990s showing a deceased and widely admired celebrity in a compromising situation or expressing views that contradict their public image. The supposed context might include:
- Fake diary entries presented as recently digitized documents.
- Generated interviews with friends who claim that they “always knew.”
- Photoshopped or AI-generated group photographs inserted into old digital albums hosted on personal or family websites.
Tabloid media already promotes sensational and poorly supported narratives. AI could make such campaigns substantially more convincing, while lost personal archives, crashed hard drives, and deleted accounts would provide a convenient explanation for the absence of authentic corroborating material.
Historic context attacks could also have serious geopolitical consequences. A state might claim that an international agreement signed in 2005 granted it rights over disputed territory. To support the claim, it could release:
- Scanned PDFs with forged metadata designed to match the period.
- Fabricated diplomatic cables and meeting minutes.
- Generated news footage produced in the style of contemporary state-media broadcasts.
- Supposed social media messages from diplomats’ private accounts, allegedly obtained through a hack and leaked years later.
Without authentic content from the era made by powerful figures and regular citizens alike which can challenge the forged narratives, the nation could justify aggressive actions, with the volume of “evidence” making international bodies hesitant.
Better methods or alternatives
Instead of the default, blanket deletion of inactive accounts and their associated contents, we advocate the following more balanced and sensible approaches.
- User-empowering defaults: Provide easy, one-click bulk export and deletion tools, as well as configurable retention settings (e.g., “keep forever” flags for premium users or explicit opt-ins).
- Tiered storage: Automatically move inactive data to cold, encrypted archives with reduced visibility and access.
- Targeted security measures: Automatically upgrade security on dormant accounts, monitor for anomalous access, and allow users to “freeze” accounts.
- Exceptions and granularity: Preserve purchased media, shared public content with value, or accounts with legal or educational ties. Support user-defined policies. For email services, and especially those with crypto wallet functions embedded within them like Proton Wallet, they should opt for the approach of preserving the account while clearing out its email contents instead of harsh total inactive account deletions.
- Third-level domains: To address some arguments by email services about username exhaustions caused by inactive accounts, they should consider implementing third-level domains to expand username pools, like test@a.proton.me in the case of Proton.
- Transparency mandates: Require companies to disclose data usage for AI, explain their retention practices, and report breach statistics differentiated by account activity.
- Shift in governance paradigms: As mentioned in prior PPI reports (https://pp-international.net/2026/02/digitallegacies/, https://pp-international.net/2026/05/stopageverificationenforcement/), ultimately, to address the main corporate arguments that it’s costly to maintain access and preserve user data, a shift in governance regulations is required. Some major or large scale email services and social media platforms (e.g. Apple, AOL, Bluesky, Discord, Facebook, Github, Google (including YouTube), Mastodon.social, Microsoft, Instagram, LinkedIn, Proton, Pinterest, Reddit, Roblox, Steam, Threads, TikTok, Twitch, WordPress, X, and Yahoo) must be treated as effective utilities, similar to healthcare and other emergency services. This means that the financial costs required for the services to maintain access to user data would become a government expense, an essential service akin to a military defense budget.
- Thanatosensivistic features: For the above aforementioned platforms, we also call for implementation of thanatosensitivistic features where users will have a say on what to do with their accounts if they die. They can choose for the accounts to be archived/memorialized upon the receipt of a valid legal will and/or when the account has been inactive for five years, deleted, or if technically possible, have them transferred to other parties such as their family members.
The digital realm should expand human freedom, memory, and creativity. Forced blanket inactivity deletions, however well-meaning, impose a regulator’s or corporation’s timeline on personal data. They treat users as liabilities rather than sovereign individuals. Pirate Parties must advocate for true digital rights: the freedom to create, store, access, and control one’s own information permanently, if the user so chooses.
The right to be remembered, just like the right to be forgotten and other digital rights such as privacy, empowers individuals in an age where digital lives matter. True privacy and responsibility come from informed user choice, strong defaults for security, and tools that respect memory— not timers that decide when your data no longer matters. Policymakers should prioritize empowerment over erasure.
————————————————————————————————–
The following message was prepared by members of the PPI Discord community and PPI Board. It does not necessarily reflect the views of all PPI members, but we hope it does. If any of our members have competing ideas about this issue or any other issue that they would like us to broadcast, please share them with us. We are happy to broadcast a variety of ideological opinions and diverse issues. Our goal is to create positive communication to solve problems.
