Personal audit

How to audit your own public footprint by username

Answer first: make an inventory of handles you control, search each one only across public sources, verify every useful lead at the original URL, and record the minimum needed to close or correct unwanted exposure. Do not infer identity or account control from a username match.

Use this checklist for your own accounts. It is designed to produce a small remediation list—not a permanent dossier about yourself.

Maigret 3.0 is available now. App workflow examples on this site preview 3.1, which is in development. The research method and its limitations apply independently of those upcoming features.

Define the outcome

Start with a question you can finish

A useful self-audit answers a bounded question such as “Which public profiles still expose my retired creator handle?” or “Which profiles using my current handle need a privacy-setting review?” “Find everything about me” is not a workable objective: it encourages excessive collection and makes it hard to decide when the audit is done.

Write the purpose and a deletion date at the top of your notes. Your deliverable should be a short list of actions—keep, update, make private, close, or investigate—not a copied archive of every page you find.

A good audit output

Handle checked, original public URL, observed status and date, why the page is likely yours, the remediation action, and whether that action is complete.

Step 1

Build a handle inventory from memory first

List only usernames you created, used, or are authorized to manage. Begin before searching so that a result does not quietly expand the scope. Include spelling variants you knowingly used, but do not generate guesses about other people.

FieldWhat to recordWhat to leave out
HandleThe exact public usernamePasswords, recovery answers, tokens
ContextPersonal, work, gaming, forum, creatorUnrelated people who use the same name
Known periodApproximate years you used itSpeculation presented as fact
Desired stateKeep, review, close, or remove detailA copy of every page or post

Separate current public handles from retired handles. A retired handle often produces the most actionable findings because old forums, portfolio pages, and abandoned accounts may still carry profile text or links you no longer want public.

Step 2

Search in tiers, not all at once

  1. Start with the exact current handle. Run a focused public username scan and keep Confirmed, Not Found, Blocked, Unknown, and conflicting results separate.
  2. Review high-context services first. Prioritize sites you remember using or where a public bio, location, link, or image could reveal more than intended.
  3. Open original URLs. A result card is a pointer. Confirm the current page state in the public source and do not log in through links you do not trust.
  4. Repeat for one retired variant at a time. Keeping runs separate prevents evidence from two handles from being merged into an identity claim.
  5. Stop when the scope is answered. Do not broaden the search to contacts, followers, family members, or coworkers unless each person has separately authorized that work.

If a site blocks the check, record that the status is unresolved. Do not attempt to bypass a login, CAPTCHA, rate limit, or technical access control. A later manual visit to the ordinary public page may resolve the question without escalating collection.

Step 3

Distinguish a page match from your account

A username match answers a narrow technical question: a public endpoint behaved like the site’s “profile exists” pattern. It does not establish who created the account or who controls it now. Before labeling a page as yours, look for context you independently recognize, such as your own linked domain, an avatar you published, an account-creation email in your records, or successful access through the platform’s official recovery flow.

Use the least invasive evidence that resolves ownership. Do not copy another user’s posts or personal details merely to prove that a same-name page is unrelated. Mark the page “same handle, ownership unresolved” and move on.

For a status-by-status decision table, read How to interpret OSINT username results.

Step 4

Turn findings into low-risk remediation

Current account, excess detail

Use the platform’s official settings to reduce public fields, remove stale outbound links, review discoverability, and enable appropriate account security. Recheck the public view while signed out.

Old account you control

Export anything you need through the platform’s official tools, then update or close the account. Keep the platform’s closure confirmation rather than a full copy of the profile.

Same handle, unrelated account

Do not contact, report, or attribute it without another valid reason. Record “unrelated or unresolved” and exclude it from your remediation list.

Possible impersonation

Compare the public presentation with the platform’s impersonation policy. Preserve only the evidence required by the official reporting form and avoid public confrontation.

Search-engine removal and source removal are different actions. Where possible, correct or remove the information at the source first. A search engine may continue to show a stale snippet until it recrawls the page; use its official outdated-content process when eligible.

Step 5

Close the audit and delete excess evidence

After each action, revisit the ordinary public URL and record whether the desired public state is visible. Some closures take time, so set one follow-up date instead of repeatedly polling. If you cannot resolve a page, note the platform support path and stop.

  • Keep the action ledger; delete screenshots that are no longer needed.
  • Do not retain cookies, page source, private messages, or unrelated profile content.
  • Store the ledger somewhere appropriate for the sensitivity of the findings.
  • Schedule the next review only if your exposure or risk warrants it.

The audit is complete when every in-scope finding has an action or a documented reason to leave it alone—not when every site on the internet has produced a binary answer.

Guide FAQ

Questions to settle before you act

Should I search my email address, phone number, or password too?

No. This workflow is for public username and handle checks. Do not enter passwords, authentication codes, private contact details, or session data into a username-search tool. Review email and phone exposure through services designed for those data types and with their own privacy boundaries.

Does a Confirmed result prove I still control the profile?

No. It means the public page matched the site rule at the time of the check. The profile may be old, reassigned, copied, or unrelated. Open the original URL and use account recovery or a signed-in view—not the shared username alone—to establish control.

Does Not Found mean the username is safe or available?

No. The site may use a different URL, hide profiles, reserve the name, or change its response. Treat Not Found as one observed check, not a guarantee about registration, privacy, or future availability.

How often should I repeat a self-audit?

Use a cadence proportionate to your exposure. A quarterly check and an extra check after a public name change, account closure, breach notice, or impersonation report is a practical starting point. Avoid continuous monitoring when it creates more sensitive records than it resolves.