Why privacy matters

You have nothing to hide. You still have everything to protect.

Privacy isn't secrecy. It's the space to be a person — to read, ask, wander, and change your mind without being catalogued and sold. This is a calm, sourced look at how modern tracking actually works, what it costs you, and the concrete moves that put some of it back in your hands.

  • Evidence, not fear
  • Every claim is sourced
  • Ends with what to do
Illustration: fragments of everyday life — where you sleep, what you search, love, and buy — drift into an assembled profile card marked 'consent: never requested' and 'for sale'.

The mechanics

How you're actually tracked.

Tracking isn't one thing watching you. It's a mesh of small, ordinary-looking features — on the web and inside your phone — each collecting a sliver, all of it flowing to the same handful of companies.

On the web

Most pages you open quietly load code from other companies. The classic tools are familiar; the newer ones are the problem.

  • Cookies & tracking pixels — tiny, invisible images and stored IDs that report back which pages you loaded and when.
  • Browser fingerprinting — your fonts, screen, and settings combine into a near-unique signature that survives clearing your cookies. Deleting cookies doesn't delete you.
  • One dominant watcher — Google's trackers alone reach roughly 80% of web traffic, appearing on about 86% of the top 50,000 sites. Ghostery / WhoTracks.me

On your phone

Apps are the bigger story. Most of the tracking happens inside software development kits (SDKs) bundled into apps you already trust.

  • An advertising ID follows you across apps. You can reset it — but few people know it exists, and a reset only helps until the next profile is stitched together.
  • In one study of 24,000 apps, the median app carried three third-party trackers, and Google's tracking code sat inside 87.3% of Android apps. Kollnig et al., 2022
  • The trackers rarely announce themselves. To an ordinary user, a flashlight app and a spyware-adjacent SDK look identical.
Six labelled cards for categories of device monitoring: spyware, stalkerware, trackerware, mobile-device-management profiles, root or jailbreak traces, and cloud-account abuse, each with a signal-radar motif.
The many shapes of monitoring. Commercial tracking and outright surveillance sit on a spectrum — from ad trackerware bundled into everyday apps, to management profiles and cloud-account access. The techniques differ; the pattern is the same: quiet collection you never agreed to in any meaningful way.

The market

There's an economy that trades in you.

All those slivers have a destination. Data brokers — companies like Acxiom, Oracle, LiveRamp, Epsilon, and Experian — buy, merge, and resell information about people who have mostly never heard their names.

700 billion data elements held by a single broker, drawn from 1.4 billion consumer transactions, as the FTC found back in 2014. FTC, 2014
3 billion new data points another broker was adding every month — a decade ago, before the industry's modern expansion. FTC, 2014
3,000 distinct data segments some brokers hold on nearly every U.S. consumer — interests, habits, life events, inferred traits. FTC, 2014

This isn't a fringe grievance. In 2024, after studying the largest platforms, the FTC described the result plainly as “vast surveillance” — collecting on users and non-users alike — and concluded that industry “self-regulation has been a failure.” FTC, 2024 The brokers profiling you are legal, ordinary businesses. That's exactly why it's hard to see.

The profile

The shadow profile: a stand-in for you.

Every time a page loads an ad, an auction fires. Details about what you're doing are broadcast to bidders in milliseconds. In the U.S. this happens for the average person about 747 times a day — roughly 178 trillion times a year across the U.S. and Europe, to as many as 4,698 companies. ICCL, 2022

People sometimes call this a “digital twin.” It's a useful metaphor with one caveat: it isn't a copy of you. It's an inferred profile — a stand-in assembled from fragments, often wrong in the specifics, yet accurate enough to decide which ads, prices, and messages you see.

How your shadow profile is assembled Scattered signals on the left — an app opened, a store visited, a search typed, a post liked, and a location ping — flow into a central identity-resolution and data-broker hub, which merges them into one composite profile. That profile is then sold to a fan of advertisers and real-time bidders on the right. SCATTERED SIGNALS IDENTITY RESOLUTION SOLD TO BIDDERS App opened a fitness tracker Store visited a location ping Search typed a symptom, a name Post liked an interest inferred Card swiped a purchase pattern Merge & match brokers stitch fragments One profile a stand-in for you Advertisers & real-time bidders up to 4,698 companies (US)
How a shadow profile is assembled. Individually harmless signals — an app, a store visit, a search, a like, a purchase — are merged and matched by brokers into one composite profile, then sold to advertisers and bidders. “Digital twin” is a metaphor: this is an inference about you, not a copy of you.

“Anonymous” is weaker than it sounds

Companies reassure you that the data is anonymized. But uniqueness betrays us. Just four location points are enough to single out 95% of people in a mobility dataset de Montjoye et al., 2013, and four credit-card transactions re-identify 90% of shoppers. de Montjoye et al., 2015

These studies prove uniqueness — that a stripped-of-name record can often be tied back to one person — not that everyone is being re-identified all the time. The honest takeaway is narrower, and still damning: “anonymized” data is far weaker protection than marketers claim.

You were never asked. There is no single file with your name on it — and that's the point. A profile assembled from a thousand fragments needs no consent, because no one step ever looked like surveillance.

The persuasion question

Sorting people into segments.

The same profiling that sells you shoes can be used to sort communities for political persuasion. The Cambridge Analytica scandal is the famous example — and a case study in how easy this story is to get wrong.

What's well documented: Cambridge Analytica improperly obtained Facebook data on up to 87 million people through a personality-quiz app that also scraped the quiz-takers' friends. In 2019 the FTC formally charged the firm, its CEO, and the app developer over the deception. FTC v. Cambridge Analytica, 2019

Two things to keep straight. First, the widely cited $5 billion FTC penalty was levied on Facebook, not Cambridge Analytica — the broker itself went bankrupt and paid no such fine. FTC, 2019

Second, the “psychographic mind-control that swung an election” framing is disputed and most likely overstated. Independent research finds microtargeting's persuasive edge is modest and highly context-dependent — sometimes beating a naive approach, but often no better than simply showing everyone the single most persuasive message. Tappin et al., 2023 The real, provable harm was the misuse of data taken without meaningful consent.

Strip away the hype and a genuine concern remains: audience segments are built and sold to sort and target communities for persuasion, and you can be placed in one without ever knowing. The mechanism is real even where the mythology isn't. Privacy is what keeps you from being quietly filed into a category and messaged accordingly.

The stakes

Some data you can never reset.

You can change a leaked password. You cannot change a diagnosis, a pregnancy, or a genome — and a genome implicates your relatives, who never opted in at all. That permanence is why health data deserves a different standard.

What already happened

Flo, a period-tracking app, shared users' pregnancy status with Facebook and Google; the 2021 FTC settlement carried no monetary penalty. FTC, 2021

GoodRx was fined $1.5M in 2023 — the FTC's first action under its Health Breach Notification Rule. FTC, 2023 BetterHelp paid $7.8M the same year for handing mental-health intake data to advertisers. FTC, 2023

Kochava's location feeds could trace 61 million-plus devices — including trips to reproductive-health clinics. FTC, 2022 And the 23andMe breach began with reused passwords on ~14,000 accounts, but a “DNA Relatives” feature let that spread to 6.9 million profiles. 2023

Where the line actually is

Modeling health data isn't the villain. A medical digital twin — a computational model of a patient, an organ, or a tumor, built to personalize your own treatment — is a legitimate and genuinely promising clinical and research tool.

The problem is narrower and sharper: the unconsented sale and ad-targeting of health inferences about you. Modeling your health to help you, under your consent, is good medicine. Selling “likely depressed” to whoever pays is something else.

How much else? One study bought mental-health lists where records went for as little as $0.06 each. Duke, 2023

Notice how careful the record actually is: Flo paid no fine; GoodRx and BetterHelp did. The point isn't that every company is evil — it's that the rules are thin, the enforcement is uneven, and the data, once sold, doesn't come back.

Consent by exhaustion

“I Agree” is the biggest lie online.

The entire system leans on a fiction: that you read the terms and freely consented. Almost nobody does — and the design counts on it.

The real cost of reading the terms Reading every privacy policy you encounter would take roughly 40 minutes a day, adding up to about 200 to 250 hours a year, an estimated national opportunity cost of about 781 billion dollars. Meanwhile 74 percent of people skip the policy and about 98 percent miss deliberately planted gotcha clauses. ~40 min / day just to read the policies you meet 200–250 hours every year $781B est. U.S. opportunity cost What people actually do skip the privacy policy 74% miss the “gotcha” clauses 98% Consent isn't given here so much as extracted by exhaustion and design.
The cost of reading the terms. Reading the privacy policy of every service you use would run to roughly 200–250 hours a year (about 40 minutes a day) — an estimated $781 billion national opportunity cost. McDonald & Cranor, 2008 No wonder 74% skip it, and about 98% miss planted “gotcha” clauses. Obar & Oeldorf-Hirsch

To be precise about that 98%: it comes from a research experiment. Volunteers joined a fake social network, “NameDrop,” whose terms demanded your data be shared with the NSA and your employer — and a firstborn child as payment. Almost everyone agreed without noticing. It wasn't a real company's terms; it was a controlled demonstration of how thoroughly nobody reads. Obar & Oeldorf-Hirsch

That's the quiet trick. Consent is manufactured by exhaustion and design — walls of text no human could reasonably read, a bright “Accept” button, and a friction-filled path to “decline.” You clicked “I Agree.” You never actually agreed.

The consequences

Where it lands, in real life.

“So what if they show me ads?” is a fair question. The honest answer is that the same machinery reaches well past advertising.

Price steering

Personalized pricing is mostly suspected and under FTC investigation. What's proven is steering: Orbitz once steered Mac users toward pricier hotels — showing costlier options first, not overtly charging more — and Staples varied prices by neighborhood. Hannak et al., 2014

Stalking & safety

Brokers can arm an abuser. Amy Boyer was murdered in 1999 by a stalker who bought her data — including her workplace — from an information broker. New Hampshire's Supreme Court later held such brokers can owe a duty of care. EPIC

A chilling effect

Being watched changes behavior. After the 2013 surveillance revelations, evidence suggests visits to privacy-sensitive Wikipedia articles fell by around a fifth — people quietly avoiding topics they had every right to read. Penney, 2016

None of this requires a villain with a master plan. It's the ordinary output of a system that treats your life as inventory — mental-health lists sold cheaply, movements mapped, categories assigned — with you as the one party never in the room.

The hopeful part

You gave a lot away. You can take some back.

Every “I Agree” handed something over — but this isn't hopeless, and it isn't all-or-nothing. Privacy is a practice, built from small, winnable moves. Here's where to start.

Stylized illustration of an evidence table listing signals such as an unknown management profile, accessibility abuse, a suspicious cloud-account grant, and root or jailbreak traces, each with a risk bar.
Monitoring leaves signals. The quiet stuff shows up as configurations — management profiles, accessibility grants, cloud access, leftover traces. Nameable signals are checkable signals, and checkable means you're not stuck guessing.
Stylized illustration of a DeSpy report screen with a confidence dial, a list of flagged artifacts, and recommended next actions.
Knowledge you can act on. DeSpy turns those signals into a plain report — what was found, why it matters, and what to do next — kept entirely on your machine. Privacy tools should hand you the answers, not collect a new profile in the process.

Privacy is freedom. Start reclaiming yours.

You don't have to fix all of it today. Read one app's data practices, file one opt-out, learn one new move — then, if you want to know what's on your own phone, scan it privately with DeSpy.

Stylized illustration of a secure vault flanked by device silhouettes, representing personal data kept private on your own computer.

Sources

Every figure on this page is drawn from the references below — regulators, peer-reviewed research, and civil-liberties reporting. Links open in a new tab.

  1. Are iPhones Really Better for Privacy? A Comparative Study of iOS and Android Apps — Kollnig, Shuba, Binns, Van Kleek & Shadbolt · PoPETs · 2022
  2. WhoTracks.me — tracker prevalence across the web — Ghostery · ongoing
  3. Data Brokers: A Call for Transparency and Accountability — U.S. Federal Trade Commission · 2014
  4. A Look Behind the Screens (“vast surveillance”) — U.S. Federal Trade Commission · 2024
  5. Unique in the Crowd: The privacy bounds of human mobility — de Montjoye et al. · Nature Scientific Reports · 2013
  6. Unique in the shopping mall: reidentifiability of credit-card metadata — de Montjoye et al. · Science · 2015
  7. The Biggest Data Breach: the scale of Real-Time Bidding — Irish Council for Civil Liberties · 2022
  8. In the Matter of Cambridge Analytica, LLC — U.S. Federal Trade Commission · 2019
  9. FTC Imposes $5 Billion Penalty on Facebook — U.S. Federal Trade Commission · 2019
  10. Quantifying the potential persuasive returns to political microtargeting — Tappin, Wittenberg, Hewitt, Berinsky & Rand · PNAS · 2023
  11. Flo fertility-app settlement (no monetary penalty) — U.S. Federal Trade Commission · 2021
  12. GoodRx — $1.5M, first Health Breach Notification Rule action — U.S. Federal Trade Commission · 2023
  13. BetterHelp — $7.8M for sharing mental-health data — U.S. Federal Trade Commission · 2023
  14. FTC v. Kochava — location data tracing sensitive visits — U.S. Federal Trade Commission · 2022
  15. 23andMe breach — 6.9 million profiles via DNA Relatives — reporting on the 2023 credential-stuffing incident
  16. The Biggest Lie on the Internet (the “NameDrop” experiment) — Obar & Oeldorf-Hirsch · 2016 / 2020
  17. The Cost of Reading Privacy Policies — McDonald & Cranor · I/S: A Journal of Law and Policy · 2008
  18. Measuring Price Discrimination and Steering on E-commerce Web Sites — Hannak et al. · ACM IMC · 2014
  19. The Amy Boyer Case (Remsburg v. Docusearch) — Electronic Privacy Information Center (EPIC)
  20. Data Brokers and the Sale of Americans' Mental Health Data — Duke Sanford / Tech Policy Lab · 2023
  21. Chilling Effects: Online Surveillance and Wikipedia Use — Penney · Berkeley Technology Law Journal · 2016