Back to Blog
Check and Score2026-09-16·Digital Footprint Health Team

When Your Footprint Report Flags Something Innocent

footprint reportfalse positivesrisk triageflag review

Two reactions are almost universal on a first footprint report. Alarm at the number of flagged items, then the assumption that everything flagged has to go.

The second reaction deserves a pause. Scanning works by pattern matching. It recognises shapes, not intent. A string that looks like a phone number may be an order reference, a place name may sit inside a news post you reshared, an email address may be the work contact you publish on purpose.

A false positive costs you nothing directly, but it carries two costs: deleting things that should stay, and slowing the real cleanup behind a pile of noise. Here are the five kinds you will see most.

Why a check flags content that is not a risk

Risk scanning is rule matching plus weighted scoring. The question it answers is whether a piece of content resembles sensitive information, not whether it actually caused exposure.

That design is deliberate. A miss is far more dangerous than a false alarm. If a post containing your home address is not flagged, you never learn about it. So the threshold leans permissive and collects anything suspicious, leaving the final call to you.

That reframes what the report is for. It is a list to review, not a list of instructions. The scoring side is described in how the health score is calculated.

The five kinds of false positive

Ordered by how often they appear, these five account for the large majority:

  1. Order references, tracking numbers and event codes. These digit strings are close to phone numbers in length and format, particularly eleven-digit ones. The giveaway is the context word in front, usually order, parcel or booking.
  2. Reshared news and other people's content. Place names, organisations and personal names inside a retweet are not yours. The scan cannot tell whose information it is reading.
  3. Public business contact details. A work email, office address or support line that is meant to be public is not a leak. Deleting it can break the contact route you rely on.
  4. Someone else's details inside a conversation. An address you included while replying to another person, or something a commenter left under your post, does not belong to you.
  5. Generic geographic phrasing. Street names, districts and building names turn up in figures of speech and jokes with no locating value at all.

How to triage a single flag quickly

Three tests, applied in order:

TestSigns of a false positiveSigns of a real risk
ContextSits next to order, shipping, event wordsSits next to address, delivery, contact me
OwnershipInside a retweet or someone's replyPublished by you directly
CurrencyPoints to information no longer validPoints to information still in use

If all three point to a false positive, skip it. If one points to a real risk, treat the item as a risk and stop deliberating. The goal is not triage accuracy for its own sake, it is not letting a real problem slip through.

Do false positives drag my score down

Slightly, and it does not matter much. Scoring weights categories and totals them, so a handful of false positives put the number a point or three below reality.

Structure matters more than the total. If most of your deductions sit in the email category and most of those emails are public work addresses, your real exposure is low and the score is simply being read through a strict lens. The category breakdown can be expanded item by item in the report.

The reverse also holds. A comfortable-looking score is not safety. Two records pointing at the address you live at now carry more risk than twenty historical order numbers scattered across old years. The score is the entrance, the item level is where the judgement happens.

Cutting the review workload

Three habits shorten triage noticeably.

Work by category first. False positives in one category usually share a signature, such as a cluster of order numbers from the same year or reshared from the same topic. Spot the signature and skip the category in bulk.

Handle high-risk categories first. Items with current contact details, addresses or identity documents come before everything else. If you do not finish, the important part is already done. The ordering logic is in cleaning by risk tier.

Record your calls. Mark which items you judged harmless and why. On a cleanup that spans days, that note saves you from re-deciding the same items, and it is the step that saves the most time in using an audit checklist.

About digital-footprint-health.shop

digital-footprint-health.shop lists findings by category with surrounding context, precisely so false positives can be spotted quickly. Each item shows the full sentence it came from, its publication date and its risk category, which lets you clear whole categories at once instead of reopening posts one by one. Parsing runs entirely on your own device and nothing is uploaded. Start with a free footprint check, read how the health score works, and check what each risk label means.

Frequently Asked Questions

Do I have to delete everything the report flags?

No. The scan matches patterns and flags anything that resembles sensitive content, leaving the judgement to you. Order numbers, reshared third-party details and public business emails are all common false positives.

What is the fastest way to tell a false positive?

Check three things: the adjacent context word (order or address), ownership (published by you or reshared), and currency (dead information or something still in use). If all three say harmless, skip it.

Do false positives lower my health score?

Slightly, usually by one to three points. Read the category breakdown rather than the total. If deductions cluster in public work emails, your real exposure is low.

Does a high score mean I am safe?

Not necessarily. The score does not weigh how current the information is. Two records pointing at your present address carry more risk than twenty historical order numbers. Judgement belongs at the item level.

Check your own X/Twitter footprint

Free on-device scan. Your archive never leaves your computer.

Start Free Check

Related Reads

Published on 2026-09-16. Last updated 2026-09-16.