← all articles

Untangling shared accounts after a relationship ends

Why this cleanup is different

Most account cleanup guides assume a stranger is trying to break in. This one is different, because the person who has the most access to your digital life right now is someone you used to trust completely, and trust doesn’t reset itself just because the relationship did.

That’s an important distinction for setting expectations. Your ex probably isn’t a sophisticated attacker. They don’t need to be. They already know your dog’s name, your mother’s maiden name, the PIN you use for everything, and the answer to “what street did you grow up on.” Security questions and password patterns that are designed to stop strangers do nothing against someone who was in the room when you set them up. The work here isn’t about outsmarting a hacker. It’s about closing the specific gaps that come from years of convenience: shared logins, linked accounts, and devices that still remember things you’d rather they forgot.

Start with the phone in your hand

Before touching any account, check what your phone is currently sharing, because a lot of this happens invisibly in the background.

On iPhone, go to Settings, tap your name, and look at Family Sharing. If you’re in a shared group, anyone in it can see your location (if you’ve enabled Find My sharing), your purchased apps and subscriptions, and in some setups, your screen time. Leaving a Family Sharing group is straightforward from that same menu, but note that it can affect subscriptions purchased through the group, so check what you’d lose before you leave.

On Android, the equivalent is a Google Family group, managed through the Family Link or Google One settings. Same idea: check who’s in it, check what’s shared, and leave if you no longer want that link.

This step matters first because everything else you do (changing passwords, moving photos) is undermined if your location and device activity are still visible to someone else through a sharing group you forgot existed.

Location sharing is often the biggest blind spot

Location sharing tends to outlive the reason it was turned on. Couples enable it for logistics, “let me know when you’re close,” and then never turn it off.

Apple’s Find My lets you share your location with specific people indefinitely, and it shows up as a simple toggle per contact under Find My > People. Google Maps has its own separate location sharing feature, independent of a Family group, found under your profile icon in Maps. Both are worth checking, because a person can be removed from one and still visible in the other.

Apps like Life360 work differently: they use “circles,” and anyone who set up the circle has admin rights over it, including the ability to see members’ locations and, depending on the plan, driving history. If you didn’t create the circle, you may not be able to fully remove yourself from visibility just by leaving; the safer move is deleting your account from the app entirely and creating a fresh one if you want to keep using it.

Smart home devices have an admin, and it might not be you

If you lived together with a smart speaker, video doorbell, or connected thermostat, one of you is the “owner” or “household admin” on that platform, and the other is a guest. Ownership isn’t symmetric. The owner can usually see device history, camera footage, and sometimes even live audio, while a guest account can be removed from the household with a few taps by the owner, no notification required.

If you’re the one moving out, check who owns the Google Home, Amazon Alexa, or Ring account tied to any device you’re keeping. If it’s registered to your ex’s account, factory reset it before you leave, and set it up fresh under your own account afterward, because a factory reset severs the pairing but a login handoff can leave old permissions intact.

If you’re staying in the home and your ex had admin access, the equivalent move is resetting router-connected devices and re-adding them under an account they can’t access, particularly for anything with a camera or microphone.

Shared photo albums are one of the easiest things to overlook because they don’t feel like an “account.” If you had a shared album on iCloud or Google Photos, check whether it’s still syncing. Shared albums keep adding new photos both people take unless someone actively stops sharing or leaves the album.

Family subscription plans (iCloud+, Google One, streaming services billed through a family group) are worth an inventory pass too, not because they’re a security risk exactly, but because they’re a control point. Whoever owns the family plan can usually see storage usage and, in some cases, remove other members’ access unilaterally. If your photo backups, files, or email storage sit inside a plan your ex owns, that’s worth migrating off before the relationship dynamics make that harder.

Passwords, autofill, and the memory of shared devices

If you ever logged into anything on a shared laptop or your ex’s phone, that device’s browser may still have your saved password in its autofill. Chrome, Safari, and Edge all store credentials locally and will happily fill them in for whoever is sitting at the keyboard.

The direct fix is going through your important accounts (email, banking apps, social media) and changing the passwords, which invalidates whatever was saved anywhere else. Do this even for accounts you don’t think were compromised, because the goal isn’t proving something happened, it’s removing the possibility.

If you and your ex ever shared a password manager vault, that’s a bigger one to unwind. Shared vaults in tools like 1Password or Bitwarden give both people access to every saved credential in that vault, not just the ones you meant to share. Leaving the shared vault removes your access going forward, but it doesn’t retroactively change any passwords your ex already saw, so anything in that vault needs a manual password change, not just an exit from the vault.

Two-factor authentication needs a second look

Two-factor authentication is supposed to be a second lock, but it’s only as separate as the thing it’s tied to. If your 2FA codes come by SMS to a phone number on a shared family plan, or through an authenticator app installed on a device your ex still has access to, that “second factor” isn’t really independent of them.

Check each important account’s 2FA settings and move away from SMS where you can, toward an authenticator app on a device only you control. If you used an authenticator app that backs up codes to a cloud account (some do this by default), confirm that backup is tied to your own login, not a shared one.

Email is the master key

Your email account is usually the recovery path for everything else, which makes it the highest-priority account to lock down first, not last. Check the recovery email and recovery phone number listed on your primary email account. It’s common, especially in long relationships, for partners to have listed each other as the recovery contact for convenience. Update it before you touch anything downstream, because a lot of “forgot password” flows route through whatever recovery contact is on file.

A working checklist

  • Check Family Sharing (Apple) or Family group (Google) and leave or restructure it
  • Turn off location sharing in Find My, Google Maps, and any circle-based app, and delete rather than just leave circle-based apps if you didn’t create the circle
  • Identify who owns smart home devices and factory reset or re-register anything you’re keeping
  • Stop sharing or leave any shared photo albums
  • Move files and photos off a family storage plan you don’t own
  • Change passwords on email, banking, and social accounts, even ones you don’t suspect were accessed
  • Leave any shared password manager vault and manually change every password that lived in it
  • Switch 2FA from SMS to an authenticator app on a device only you control
  • Update the recovery email and phone number on your primary email account first

When the stakes are higher

Some breakups involve real fear for your physical safety, not just a wish for digital tidiness. If that’s your situation, this checklist is still useful, but it’s not a complete answer, and the order of operations matters more than usual, particularly around location sharing and device access, since acting too visibly too fast can sometimes escalate risk before it reduces it. Local domestic violence advocacy organizations often have staff specifically trained in safety planning around technology, and they’re a better resource for sequencing than any general guide.

For everyone else, none of these steps alone makes you secure. It’s the combination, closing the location leaks, resetting the smart home admin, changing the passwords, and moving your 2FA off a shared line, that actually removes the access your relationship left behind.

If you want more explainers like this on the everyday privacy gaps most people never think to check, take a look around The Privacy Wire.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →