
GhostSweep
Reclaim your digital footprint before someone else does.
I just ran my own handle through the 3,000-site scan I built (based on the Maigret engine).
It’s a massive reality check. I found stuff I haven’t touched since 2021, old dev forums, gaming profiles, and niche review sites I forgot existed.
The "Maigret" logic is wild because it shows how a single username can map out your entire digital history across the web. Most of us are walking around with a "zombie" footprint that's way bigger than we think.
If you’ve used the same alias for a decade, the results are honestly pretty surprising.
Last year, a fake clothing site called Wreio got my credit card info. It sucked, but the scary part was what happened next. I started getting login alerts for random accounts I hadn't touched in 5+ years.
It hit me: I had hundreds of "unlocked doors" from my past just sitting there for hackers.
I looked for a tool to find all these ghost accounts and realized nothing actually worked the way I wanted. So I spent the last few months building GhostSweep. It uses the Gmail API and OSINT to map your digital footprint so you can actually delete the stuff you don't use.
If you’ve ever felt like your data is out of your control, I’d love for you to try it out.
1 Like
3 Comments
3 Comments
-
1
That story hits 👍🏻. The “unlocked doors” analogy is real. Old accounts are one of the most underestimated risk surfaces.
The concept makes sense, especially if it helps people move from awareness to actual deletion.
One security question though.
Since you’re using the Gmail API to map someone’s digital footprint, how are you scoping and protecting access to mailbox data? Are you requesting read-only permissions, limiting token lifetime, and preventing long-term storage of email content?
If you’re positioning this as a security tool, tight OAuth scopes, short-lived tokens, and clear data handling boundaries will be critical for user trust.
-
1
Appreciate the nudge. Trust is the only way this works.
I’m using read-only scopes to scan the content for those sign-up confirmations, but I don't store any of it. Once the scan maps the accounts, the email data is wiped. I'm also keeping the tokens short-lived so I don't have long-term access.
Still refining the flow to keep it as lean as possible, but privacy is the whole point of the tool.
-
1
That’s the right mindset. Read-only scopes, no long-term storage of email content, and short-lived tokens are exactly what users expect from a tool positioned around security.
One thing worth considering as you refine it: transparent session visibility. For example, showing users when the last scan happened and offering a clear “revoke access” button inside the app builds extra confidence.
Old accounts and forgotten OAuth connections are common entry points. Tools that map exposure need to be even stricter than the platforms they analyze.
We’re the Nautillo Pro team. We build security tooling focused on helping founders and small teams uncover real attack paths before issues scale. If you ever want to test your own platform from an external perspective, our web attack simulator has a free version founders can run monthly, especially useful after adding new integrations.
Good direction overall! Privacy-first positioning is a strong differentiator if executed tightly.
-
-
About
In 2023, a scam site stole my credit card. The real wake-up call was the wave of login alerts for forgotten accounts that followed. My digital past was full of unlocked doors. I built GhostSweep to find and lock them.


Comment