81% of Americans say they're concerned about how companies use their data. And then they open the app. Privacy isn't about guilt. It's about power: who has it, and who doesn't.
This isn't apathy. Researchers call it hyperbolic discounting, the tendency to choose immediate convenience over future protection, every single time. Your brain isn't broken. It's being exploited.
Tech companies don't just collect your data. They spend billions engineering the psychological conditions under which you willingly hand it over and then rationalize it afterward.
There's a name for the gap between how much you say you care about privacy and what you actually do about it: the privacy paradox. Understanding it is the first step to escaping it.
These aren't stupid arguments. They're sophisticated psychological defenses against a threat that feels abstract. Hover each one to see what's actually going on underneath.
Privacy isn't about hiding wrongdoing. Cardinal Richelieu said "give me six lines written by the hand of the most honest man, and I'll find enough to hang him." Your data doesn't need to be incriminating. It just needs to exist.
This is learned hopelessness, not logic. You lock your door even though thieves exist. Minimizing new exposure still matters: every piece of data you protect is one they can't use, sell, or lose in a breach.
The same data that serves you ads determines your insurance rates, whether you get a loan, how you're targeted politically, and what job opportunities reach you. The pipeline is invisible. The consequences are not.
Mass surveillance isn't targeted. It's structural. Julian Assange said it plainly: "when society goes bad, it takes you with it, even if you're the blandest person on earth." You don't need to be special to be affected.
Your browsing, location, purchases, apps, connected devices, and even your friends' behavior all create a detailed profile of you, without you ever posting a single thing. Absence from platforms ≠ absence from surveillance.
Governments change. Laws change. The EU recognized this. They made privacy a fundamental right specifically because they'd lived through what happens when surveillance infrastructure meets a regime that decides to use it.
Here's what the pipeline from your data to your daily life actually looks like.
Your location data, purchase history, and browsing habits are used by insurers and employers to infer health conditions. No diagnosis required. Pattern recognition does it for them.
Cambridge Analytica illegally harvested data from 87 million Facebook users to build psychological profiles used to influence elections. This is not a hypothetical.
Zip code, browsing behavior, and social connections influence loan approvals, credit limits, and interest rates, often without any legal disclosure that this data was used at all.
Shoshana Zuboff calls it surveillance capitalism: your behavioral data isn't just observed, it's used to predict and modify your future behavior, for profit, by people you'll never meet.
In 2023, US data compromises hit a record 3,205, a 78% jump from the prior year, affecting 353 million people. When companies collect your data, they also hold your risk. And they keep getting breached.
Once your data is out, it doesn't expire. It's bought, sold, aggregated, and refined across data brokers you've never heard of. You can't un-leak yourself, but you can stop the bleeding.
Privacy is the infrastructure of autonomy. Without it, you cannot freely form opinions, organize with others, dissent, or simply exist outside someone else's definition of who you are.
The European Union enshrined data protection as a fundamental human right, not because Europeans are more paranoid, but because they're more historically informed. They've seen what happens when surveillance infrastructure meets a government that decides to use it.
Focus-group research on surveillance found that the "nothing to hide" response breaks down as soon as identity enters the picture: what makes being watched threatening is not guilt, but who you are and how you expect to be seen.
Stuart & Levine, European Journal of Social Psychology, 2017Privacy isn't about hiding. It's about having a self that isn't permanently legible to power. That's not a radical idea. It's the reason we have doors.
The GDPR went into effect in 2018. It didn't just create rules. It shifted the entire cultural baseline for what privacy means as a right, not a preference.
The results are measurable, and they are measurable in enforcement rather than in opinion polls. Regulators have issued billions in fines against companies that treated the rules as optional, and the law has been copied far beyond Europe. When a law says your data belongs to you, and an agency is funded to mean it, behaviour changes.
The US has no equivalent federal law. Instead: a fragmented patchwork of state regulations that leaves your rights dependent on your postcode, and an industry that spent decades lobbying against any change.
Nothing on this page solves the problem. Every item on it reduces one specific harm by some specific amount and leaves the rest untouched. That is the most any tool currently does. Pretending otherwise is how the privacy industry sells subscriptions.
Most privacy advice is abstinence-only. Delete everything. Go off-grid. Trust nobody. It sets a standard almost nobody meets, and when you inevitably fall short of it, the lesson you take away is that none of it works. So you stop. That reaction is rational, and it is exactly what the advice was built to produce.
Harm reduction starts from the assumption that you will keep using the internet like a normal person. It asks what actually reduces damage, by how much, and at what ongoing cost. Everything below tells you what a tool stops, what it doesn't, and whether you ever have to think about it again.
Assume you will do three things, ever, and never revisit them. These are the three, ranked by harm prevented per minute spent. The list is short on purpose. A longer one would be more complete, and you would do none of it.
Use Bitwarden: free, open source, no upsell required. 1Password is also fine if you would rather pay. So is the manager already built into your browser or phone, which is weaker, but a manager you actually use beats a better one you don't.
Do email and bank first and stop there if you run out of patience. Your email is the master key: whoever controls it can reset everything else you own. Two-factor authentication (2FA) means a second step after your password, usually a six-digit code. Use an authenticator app rather than text messages where you are given the choice, because text messages can be redirected to someone else's phone.
Then freeze your credit. A password manager protects the accounts you already have. It does nothing about someone opening a new account in your name, which is the more common problem: of the roughly 449,000 credit card identity theft reports the FTC received in 2024, about 90 percent involved new accounts rather than existing ones. A credit freeze blocks new accounts from being opened against your credit file. It is free by law, you do it once at each of the three bureaus, and you can lift it temporarily when you actually need credit.
An alias is a disposable address that forwards to your real inbox. A different one for each service means a leak or a sale from one does not connect to the rest of your life. It also tells you exactly who sold you out, because you can see which address the spam arrived at.
DuckDuckGo Email Protection is the simplest free place to start: unlimited aliases, no payment. Firefox Relay, addy.io, SimpleLogin, and Apple's Hide My Email all do the same core thing. We are not picking a winner because there isn't one. They differ on price, polish, and how many aliases you get free, not on mechanism. Any of them beats using your real address.
A content blocker that removes most advertising and most third-party tracking. "Third-party" means companies other than the site you are actually looking at. It is free, it is not funded by an ad company, and it does not have a paid tier to push you toward.
uBlock Origin is going away on Chrome. It is not going away on Firefox.
Google removed the extension technology the full version depends on. It stopped working on Chrome in July 2025, and on 31 August 2026 it is removed from the Chrome Web Store entirely.
On Firefox: install uBlock Origin. Full version, unaffected, two minutes.
On Chrome: you can install uBlock Origin Lite, which is meaningfully weaker because Google's rules cap what it is permitted to block, or you can switch to Firefox, which takes about twenty minutes including moving your bookmarks and passwords.
We are not going to pretend those two options are equivalent. The tool did not get worse. The browser did.
The last column is the one to read. A permanent fix and a subscription you must re-run every two months are not the same product, and most privacy writing quietly refuses to tell you which one you are buying.
| Tool | What it stops | What it doesn't | One-time or ongoing |
|---|---|---|---|
| VPN | Your internet provider, and whoever runs the wifi you are on, from seeing which sites you visit. Genuinely useful on a network you do not control. | Anything Google, Meta, or any account you are logged into does. A VPN moves your trust to the VPN company. It does not remove trust from the equation. If you are going to hand a company that trust anyway, Proton VPN and Mullvad are the usual defensible answers. | Ongoing A subscription, indefinitely. |
| Tor | Unlinks you from a destination for a single session, more thoroughly than a VPN can. | Daily life. It is slow, it breaks a lot of sites, and logging into your real accounts over it defeats the entire point. | Situational The wrong tool for everyday browsing. |
| Data removal servicesDeleteMe, Optery, and similar | Some of your footprint on people-search sites, the ones publishing your address, phone number, and relatives. Less of it than the marketing implies. | Ad tech, entirely. And most of what you are paying them to remove. In Consumer Reports' 2024 test of seven services, only 35 percent of profiles were gone after four months. Opting out by hand, for free, removed 70 percent. | Ongoing A subscription that mostly does not finish the job. |
| Password manager + 2FA | Account takeover: someone getting into the accounts you already have. | New accounts opened in your name, which is the more common fraud and needs a credit freeze instead. Collection continues exactly as before. | One-time Setup only. |
| Credit freeze | New accounts being opened against your credit file. This is the most-reported form of identity theft, and the freeze is free by law. | Anything about accounts you already have, and nothing whatsoever about collection. It is a lock on your credit file, not on your data. | One-time Stays until you lift it. |
| uBlock Origin | Most third-party tracking and ads. | First-party tracking by the site itself. Anything inside a phone app. | One-time But see the Chrome notice above. |
| Email aliases | Future accumulation, permanently. | Everything collected about you already. | One-time Setup, then a small habit. |
Everything above assumes your problem is ambient: companies collecting data because it is profitable, not because it is you. If a specific person is trying to find you, that is a different problem and this page is not sufficient for it.
Stalking. Harassment campaigns. Doxxing. An abusive ex. A job that puts your name in public. Shrinking your people-search footprint is directly protective here, because the attack is literally someone typing your name into a search box. This is the one place on this page where removal work is worth serious effort.
It is also the place where the industry selling that work performs worst. Consumer Reports tested seven paid removal services against 13 people-search sites over four months in 2024. The services removed 35 percent of profiles. Opting out by hand, for free, removed 70 percent, and did it faster. Individual services ranged from 4 percent to 68 percent. Consumer Reports also found that some removal services advertise on or partner with the very people-search sites they promise to clear you from.
So do it yourself if you possibly can. It is slow and it is tedious, and it is also the most effective option anyone has measured. Pay for a service to buy back time, not to buy completeness, and know that you are buying a partial result either way.
It is also worth thinning your own history: old posts, old photos, old accounts tied to your real name. Redact bulk-deletes old social media posts, though it cannot touch anything already screenshotted, archived, or reposted by someone else.
Michael Bazzell's workbook is the thorough version. SimpleOptOut collects direct opt-out links for the major brokers. This is the option that scored highest in testing.
One request to every data broker registered in California, more than 500 of them. Brokers have been legally required to honour it since 1 August 2026. If you are a California resident, start here.
If you are paying anyway, Optery and EasyOptOuts scored highest in the Consumer Reports test, at 68 and 65 percent. EasyOptOuts was also the cheapest tested. DeleteMe, the best-known name, removed 27 percent.
If you are in immediate danger, a website is the wrong resource. Talk to someone who does this for a living.
Domestic violence and intimate partner abuse: the Safety Net Project at the National Network to End Domestic Violence covers stalkerware, location tracking, and building a technology safety plan. The National Domestic Violence Hotline is staffed around the clock.
Journalists, activists, and human rights defenders: the Access Now Digital Security Helpline gives free, direct technical help, 24 hours a day.
Online harassment and doxxing: the Games and Online Harassment Hotline maintains a practical digital safety guide, and PEN America's Online Harassment Field Manual is written for people whose work puts their name in public.
This is for a threat model most readers don't have. Most people reading this do not need what follows, and adopting it without a reason costs real convenience every day in exchange for protection against an adversary you do not have.
If you are a journalist protecting a source, an activist under surveillance, or someone with specific reason to believe a well-resourced adversary is interested in you, the tools change.
Each of these costs something every single day. That is the trade, and it is only worth making if you have a reason.
Data brokers exist because it is legal for them to exist. Every hour you spend opting out is an hour spent doing, unpaid and on your own time, what the law should have made unnecessary. "Protect yourself" concedes that quietly, then hands you the mop.
The evidence for that is sitting in the section above. A whole industry sells removal as a service, and independent testing found it removes about a third of what it promises, while doing it yourself for free works twice as well. The market did not solve this, because the market has no way to reach the upstream sources. A law can.
One already has. California's Delete Act built DROP, a single request that reaches every data broker registered in the state. It went live on 1 January 2026, and since 1 August 2026 brokers have been legally obliged to act on it. One form, more than 500 companies, no subscription. That is what the legislative version of this page looks like, and it exists in exactly one state.
The section above makes the political case. This is the part where you do something with it: ask your own state for a Delete Act, and support the organizations doing the legal work. The Electronic Frontier Foundation, the Electronic Privacy Information Center, Consumer Reports advocacy, and Privacy Rights Clearinghouse all work this specific issue.
You maintain your health. Your finances. Your relationships. Your data is the raw material other people use to build a model of you they can profit from. Start treating it accordingly.