A digital service can become unavailable without vanishing. Prices change. Features are removed. An account is suspended. A merger changes the product. An authentication method fails. The company still exists, but the version of the service your life depended on does not.

An exit plan does not require distrust of every provider or a retreat from the cloud. It requires one tested answer to a narrow question: if this service became unacceptable or inaccessible, could you recover the important material and continue the essential function?

Closed unbranded laptop beside blank folders and an external drive on a calm home-office desk
The laptop, folders and independent drive represent export, organization and custody. They are generic categories, not product endorsements. This is an original AI-assisted editorial photograph.
The exit testCan a trusted person, using your written instructions and an independent copy, locate the important records and open them without the original service? If not, you have an export option—not yet an exit.

Choose one service and one essential outcome

Do not begin with “leave the cloud.” Begin with one dependency: family photos, email, notes, password manager, financial records, calendar, website, domain registrar or smart-home account. Name the outcome that matters. “Preserve photos with dates and albums” is more useful than “download everything.” “Keep receiving mail at my domain” is different from “retain old messages.”

Rank the impact of losing access for one day, one week and permanently. High-impact services deserve a current export, documented recovery and an alternate route. Low-impact services may need only a list of subscriptions and a cancellation note.

Inventory data, relationships and authority

Data is only one layer. A service also contains relationships and authority: sharing permissions, collaborators, aliases, subscriptions, automations, domain records, API keys, recovery contacts and billing history. A file export may preserve content while losing the structure that made it useful.

Create a one-page dependency record:

  • Owner: whose account controls the service?
  • Essential material: which records cannot be recreated?
  • Structure: which folders, labels, albums or links matter?
  • Connections: which apps, people and domains depend on it?
  • Recovery: which device, email, phone or hardware key can restore access?
  • Exit destination: what can receive the material and perform the minimum function?

This is a threat-model exercise without drama. Use the same discipline as Personal Threat Modeling for Ordinary People: protect what matters against plausible failure, not every imaginable event.

Use the official export, then inspect what it means

Start with the provider's own export or portability tool. For Google accounts, Google Takeout lets users select products and create an archive; Google warns that downloading does not delete data from its servers. Apple's Data and Privacy guidance directs users to request a copy or transfer supported data through the official privacy portal. Capabilities vary by account, region and service, so check the current page before relying on a specific export.

Record the date, selected products, export format and destination. Do not send a sensitive archive to a shared or poorly protected location merely because the wizard offers it. Exports often contain more personal data than the daily interface shows.

Prefer usable, documented formats

A proprietary archive is valuable only if you have a working importer. When choices exist, prefer formats with multiple readers: common image and video files, PDF for fixed records, CSV for tables, JSON or XML for structured data, MBOX or EML for mail, ICS for calendars and VCF for contacts. No format is permanent, but documented and widely supported formats reduce dependence on one application.

Preserve original files when metadata matters. Converting every image to a new format may discard capture dates or quality. Keep the provider's manifest and metadata sidecars even when they are inconvenient; a future migration tool may need them.

Verify the archive before changing the account

Do not trust file count alone. Sample each important category. Open old and recent files. Check non-English characters, timestamps, attachments and large media. Confirm that a calendar import retains time zones and repeating events. Confirm that contacts keep more than names. Search the exported mail for a known message and open its attachment.

Then compare the export with the service. Write down what did not come across: shared albums, comments, link permissions, version history, app-specific fields or items owned by another account. This loss map is part of the plan.

Use checksums when practical for large archives. A checksum cannot prove the export is complete, but it can show whether the copy changed during transfer. Keep the export log beside the archive rather than inside the service being exited.

Make one copy independent

Independence means the same failure does not remove both the original and the recovery copy. A second folder in the same account is organization, not independence. A backup drive permanently connected to a compromised computer may be reachable by the same destructive process.

For irreplaceable material, use the familiar 3-2-1 pattern as a starting model: three copies, two types of storage, one off-site. It is a heuristic, not a certification. Encryption, recovery keys, maintenance and restoration still matter. The external SSD, hard drive and NAS guide explains the tradeoffs without treating any one device as a complete backup strategy.

Separate content recovery from account recovery

An archive restores content. It may not restore the identity, address or permissions attached to the account. Protect account recovery separately. Record the primary login identifier, recovery channels, second-factor method and location of backup codes. If a custom domain is involved, document the registrar, DNS provider, renewal method and the person authorized to make changes.

Password-manager exports need special care. Many export formats are unencrypted plain text. Follow the provider's current instructions, create the file only on a trusted device, import or protect it immediately and securely remove temporary copies when finished. Do not put a plain-text password export in an ordinary cloud folder.

Run a small migration before the deadline

Choose a representative slice and move it to the proposed destination. Import one calendar, one notes folder or a small photo album. Confirm search, dates, attachments, sharing and export from the new system. The ability to enter a platform is not enough; test the next exit too.

Keep the old service during the comparison period when possible. Point new activity to the new destination, but preserve a rollback window. For domains, email and shared work, migration can affect other people. Announce the change and define which system is authoritative during the transition.

The exit-readiness matrix

ConditionMeaningNext move
Export exists but is unopenedArchive availability is unverifiedOpen samples and document omissions
Files open, structure is missingContent survived; workflow may notRebuild the minimum useful structure
Copy uses the same accountProvider or identity failure remains sharedCreate an independent copy
Destination imports but cannot exportLock-in moved rather than disappearedTest the destination's exit path
Trusted person can follow the planRecovery no longer depends on private memorySchedule a refresh and sample restore

Use a refresh trigger, not vague good intentions

Schedule exports according to change rate and consequence. A yearly export may be enough for a stable archive; active business records may need automated daily protection. Also trigger a review when the owner, recovery phone, domain registrar, pricing model or export feature changes.

Put a review date in the plan and state who owns it. An exit plan without maintenance becomes a historical document about a system that no longer exists.

Who should skip a full migration today

Do not move a high-impact service during a deadline, health event or active account dispute unless continued use creates greater risk. Export first when permitted, stabilize recovery access and plan the change. If the service holds regulated, legal, medical or employer-controlled records, confirm retention and authorization requirements before copying or deleting anything.

The 45-minute exit drill

  1. Pick one service and define the minimum outcome.
  2. List essential data, structure, connections and recovery channels.
  3. Run the official export to a trusted destination.
  4. Open five representative items and one difficult edge case.
  5. Record missing structure or permissions.
  6. Create one independent copy.
  7. Import a small sample into the proposed replacement.
  8. Write the recovery steps for another trusted person.
  9. Set the next review date.

Pair the drill with data minimization. The easiest account to exit is the one that never accumulated unnecessary data and connections.

Official references and limits


END OF FIELD GUIDE 054

Keep the question. Test the model.

Choose the narrowest claim the evidence can carry, then leave room for revision.