CYBER WELFARE

Protect your Digital Privacy

Consequences of forgotten apps: what happens when an app you no longer use is breached

The risks of abandoned apps describe what can happen to your data and your phone when an app stays installed without being used or updated. The consequences describe what happens to people: a charge that keeps coming back month after month, a client asking for an explanation, an afternoon spent working out which services you signed up to years ago.

A forgotten app is rarely just an icon at the end of your last home screen. It almost always comes with a linked account — the profile you created the first time you opened it, often with your own email address and a password chosen in a hurry — along with permissions you granted once and never looked at again, and sometimes a saved payment method. When you stop opening the app, all of that carries on existing: on your phone and, above all, on the servers of whoever built it. This post tries to describe what happens when one of those services is breached, honestly, without dramatising and without downplaying.

It expands on the recommendation about removing apps you no longer use.

A realistic scenario

John runs a small heating and plumbing business: himself, one employee and a van. His phone is his office: quotes, appointments, photos of boilers and pipework, messages with customers.

Three years ago he tried out an app for managing quotes and jobs. He used it for a few months and uploaded his customer list — names, addresses, phone numbers, a few notes about each job — then went back to his usual way of working. The app stayed on his phone, in a folder called “Other”, alongside a card game downloaded on holiday, the app for a trade fair, the app of a supermarket in a town he no longer lives in, and a fitness app with an annual subscription started during a spell of good intentions.

In the meantime, the developer of the quotes app stopped updating it and later sold the service to another company. One day that service’s servers suffer a data breach: unauthorised access that takes information out of the service when it should have stayed private. John does not notice: the warning goes to an old email address he rarely checks.

A month later, a customer rings him. She has received a message, signed with the name of his business, asking her to settle an invoice using new bank details. The message knew her address, the job done in the spring, even the model of her boiler.

From this point on, the consequences spread across five planes.

1. Operational consequences: when you have to rebuild what you had forgotten

A practical example

John cannot even remember the exact name of the app. He finds it again in the “Other” folder, but it no longer opens: it asks for an update that does not exist in the official app stores, because the app has been withdrawn. To ask for his data to be deleted, he has to track down a contact at the new owner. Meanwhile he discovers that the password for that account was the same as the one for his old work email address, which is now reporting suspicious sign-in attempts.

Possible effects

  • half-days of work spent working out what data was there and where;
  • no way of getting into the app to export or delete the data;
  • linked accounts to secure: the email address used to sign up, other services with the same password, and any you signed in to with the “Sign in with” option using an account you already had;
  • jobs and appointments postponed.

Why it matters

Uninstalling an app removes it from your phone, not from the world. The operational consequence is not the breach itself but the reconstruction: the longer it has been since you last opened an app, the less you remember about what it holds, which email address you used to sign up and what you allowed it to reach.

2. Financial consequences: when small amounts add up

A practical example

Going through his bank statement, John finds two charges he had forgotten about: the fitness app’s annual subscription, renewed automatically for the third year in a row, and a small monthly charge for the “full” version of the quotes app, which the new owner is still collecting. Meanwhile an older customer, unlike the first, has actually made the transfer to the new bank details.

Possible effects

  • subscriptions that renew themselves even though the app is no longer on your phone;
  • small recurring charges that go unnoticed for months or years;
  • customer payments diverted by messages built with genuine data;
  • cards saved in forgotten apps that need to be blocked or replaced;
  • refunds that are not guaranteed and depend on the service’s terms and on how soon the problem is spotted.

Why it matters

Uninstalling an app does not cancel the subscription. Automatic renewal is tied to the account and the payment method, not to the icon on your phone: it only stops when you cancel it in the app store’s subscription settings or in the service’s own settings. It is a detail that many people miss. Noticing early matters: the more time passes, the harder it is to get anything back.

3. Legal and regulatory consequences: when the app held customer data

A practical example

The app held the details of around a hundred customers. As the owner of the business, John is the data controller: the person or organisation that decides why and how personal data is used, and who is answerable for it. The fact that the app had been forgotten does not change who has to deal with the breach.

Possible effects

  • a duty to assess, together with the service provider, what was exposed and, where the conditions apply, to notify the relevant authority and the people affected;
  • checks on who is now responsible for the data, after the app was sold to another company;
  • formal steps to handle within tight deadlines, while day-to-day work carries on;
  • possible complaints from the customers involved.

Why it matters

When an app holds other people’s data, keeping it or removing it is no longer a purely personal choice. A work app that was tried and then abandoned is still, to all intents and purposes, a place where that data is kept. This section describes the general picture and is not a substitute for legal advice: if a breach involves other people’s personal data, it is worth speaking to a professional or to your data protection contact.

4. Reputational consequences: when your name signs a fake message

A practical example

The first customer did not pay, but she told her neighbours and mentioned it in her street’s group chat. Over the next few days, two customers ring to ask whether the business “has been hacked”. One is more direct: “How did they get my address and the model of my boiler?”

Possible effects

  • customers wary of later invoices and messages, even genuine ones;
  • the need to explain what happened, several times and to different people;
  • a perception of carelessness with the data people entrusted to you, even when it is unfair;
  • the business name linked to a scam in local word of mouth.

Why it matters

For a small business, reputation lives on word of mouth, and word of mouth travels faster than any clarification. Letting customers know promptly and openly — what happened, what you will never ask for by message, how to check a payment request — is part of the response, not a detail.

5. Personal consequences: when the weight falls on the person

A practical example

John spends his evenings scrolling through his apps, searching for old sign-up emails and wondering what else might have been there. He remembers that his fitness app profile held his weight, the times of his runs and the route that started from his front door. He feels guilty towards his customers about something that, a week earlier, he did not even know he had.

Possible effects

  • prolonged stress and a feeling of having lost control;
  • personal and family time swallowed up by recovery;
  • private information unrelated to work exposed, such as habits and movements;
  • distrust even of new apps that would genuinely be useful;
  • a sense of guilt, often out of proportion to what actually happened.

Why it matters

This is the least visible consequence and the most lasting one. It is worth saying clearly: if this has happened to you, it is not because you were careless. Installing an app takes one tap; removing it is not part of any habit anyone ever taught us. That is exactly why it makes sense to turn clearing out your apps into a small routine, rather than leaving it to memory.

PlaneWhat changesHow long it lasts
OperationalAccounts, data and access to rebuild, work slowed downHours to days
FinancialSubscriptions never cancelled, recurring charges, diverted paymentsMonths, sometimes years before anyone notices
LegalDuties to assess and notify if the app held customer dataTight deadlines, formal steps
ReputationalCustomer trust to rebuild, name linked to a scamMonths
PersonalStress, guilt, private habits exposedVariable, often the longest

The cost no one budgets for: time

Financial consequences can be added up. Time is much harder — and it is almost always the heaviest item.

A realistic estimate, based on how these recoveries usually unfold:

ActivityIndicative time
Finding the app again and remembering which email address you used and what data it held1–2 hours
Asking the service to close the account and delete the data, if the app no longer opensA few days to several weeks, with no guarantee of a reply
Changing reused passwords and revoking linked access1–2 hours
Checking bank statements, active subscriptions and saved cards1–2 hours
Replying to customers and warning them about the fake messages2–4 hours
Formal steps if other people’s data is involvedDays, with deadlines to meet
Follow-up checks over the following weeksOngoing

These are hours taken away from work or family, at a time when you are already under pressure.

The comparison speaks for itself: clearing out your apps takes about twenty minutes, a few times a year.

The consequences that fall on other people

The consequences of a forgotten app rarely stop with the person who installed it.

  • Customers receive convincing messages in the name of the business, built with their real details. If someone pays, the loss is first and foremost theirs.
  • John’s employee, who used the same app with the same account for a while, finds himself caught up in an incident he did not cause.
  • Family members see charges on the household card and, if the children’s tablet had apps linked to the same account, those profiles need checking too.
  • The people in the address book: if the app had permission to read contacts, their numbers may have ended up on the service’s servers without anyone asking them.

This is why, in the Cyber Welfare Framework, looking after your phone is not treated as a purely private matter: every app you remove is one less place where other people’s data can be left exposed.

How this ties back to the recommendation

All of these consequences start from the same place: an app that is no longer used but still exists — with its account, its permissions, its subscription and the data that was entrusted to it.

Not a malicious app. Not a glaring mistake. An app that was useful at one point, then forgotten, and often no longer updated by its developer. Apps that stop receiving updates keep their known flaws, and many attacks focus on exactly those flaws: the post on vulnerabilities in outdated apps explains how, alongside the recommendation on keeping your software up to date.

That is why recommendation R22 is not about storage space: it decides how many doors stay open onto services you no longer keep an eye on.

How to reduce the risk

  1. Go through the full list of apps, not just your home screen: your phone’s settings also show the ones tucked away in folders.
  2. Use a simple rule of thumb. If you have not opened an app for three months and it has no emergency role, it is a candidate for removal. If you need it again one day, you can download the latest version.
  3. Before uninstalling, close the account and cancel the subscription. These steps are separate from uninstalling. The full sequence is in the post on how to clean up your apps.
  4. Revoke linked access: in your main accounts, check which apps have access through “Sign in with”, and remember checking what your apps can do for the ones you keep.
  5. Keep work data only in apps you use and update. With customer data, one simple rule applies: the fewer apps that hold it, the fewer places there are to protect.
  6. Make clearing out a habit. Once every three months is enough. The tools for managing apps already built into your phone’s operating system help you spot the ones you do not use, and the signs of unused apps still active on your phone tell you where to look first.

Quick checklist

  • ☐ I know which apps on my phone hold customer or work data
  • ☐ I have checked my active subscriptions in the app store’s subscription settings
  • ☐ When I remove an app, I close the linked account first
  • ☐ I have checked which apps can access my main accounts through “Sign in with”
  • ☐ I have no apps installed that have gone without updates for a long time
  • ☐ I clear out my apps at least every three months

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessRecognising that a forgotten app keeps accounts, data, permissions and payments active
SkillsTelling the five planes of consequence apart and knowing what to do beyond uninstalling
Secure BehaviourClearing out apps regularly, closing accounts and subscriptions before removing an app

Reference level: FL2 — Beginner. This is the level at which a simple act of tidying, such as removing an app, stops being about storage space and becomes a choice with a clear reason behind it.

Conclusion

A forgotten app does not produce “a cyber risk.” It produces charges nobody remembered, customers asking for explanations, formal steps to deal with in a hurry, and evenings spent piecing together a digital past you had lost track of.

The good news is that most of these consequences can be reduced with two habits within anyone’s reach: removing the apps you do not use, after closing their accounts and subscriptions, and keeping the ones you keep up to date. If you want to know where to start, the digital resilience self-assessment helps you see in a few minutes which areas are worth working on.

Something to think about. If a service you signed up to years ago wrote to you tomorrow to report a breach, could you say what data you had left there — and whose it was?

Related resources

Short explainers from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.