Your Data Is the Product: A Practical Guide to Digital Privacy
How personal data collection actually works, where most of it leaks from, and the short list of protections that give you the most benefit for the least effort.
Open the settings on your phone and look at which apps have location permission set to Always. Not While Using. Always. For most people it is between four and nine apps, and at least two of them have no plausible reason to know where you are at 3 a.m. A weather app. A shopping app. A game you downloaded in 2022 and opened twice. Digital privacy is decided in settings screens like that one, not in a policy document nobody reads.
That list is a small window into a very large business. Understanding how it works is what makes the difference between privacy advice that feels like paranoia and privacy advice you will actually follow.
How the money actually flows
The phrase you are the product is repeated so often it has stopped meaning anything. Here is the concrete version.
Advertisers do not want to show ads to everyone. They want to show ads to people likely to buy. To do that they need to know things about you: roughly your age, income bracket, where you live, what you shop for, whether you recently started looking at cars or baby products or gym memberships. That information is worth money because it makes advertising more efficient.
Several kinds of companies collect it. Platforms you use directly know what you do on their services. App developers collect data through code embedded in their apps, often software development kits provided by advertising companies, which means the app maker may not fully know what is being transmitted either. Data brokers aggregate information from many sources, including public records, loyalty programs, warranty registrations, and purchased app data, then sell profiles or audience segments.
The critical mechanism is linkage. Individually, the fact that a device was at a particular grocery store is meaningless. Combined with the same device being at a specific residential address every night, a specific office every weekday, and a medical building once a month, it stops being anonymous in any meaningful sense. Researchers have repeatedly demonstrated that supposedly anonymized location data can be re-identified with a small number of data points, because human movement patterns are close to unique.
The three places most of it leaks
Your phone
Apps are the highest-volume source for most people. Every permission you grant is a tap that opens a channel. Location, contacts, photos, microphone, and the ability to see other installed apps are the ones that matter most.
There is also an advertising identifier on your device, a random string that ad companies use to link your activity across different apps. It is designed to be resettable, and most people never reset it or turn it off.
Your browser
Third party cookies are the well known mechanism, and they are gradually being restricted. The less known one is fingerprinting: a site collects your screen resolution, installed fonts, time zone, graphics hardware behavior, and browser version, and the combination is frequently distinctive enough to recognize you again without any cookie at all. This works even in private browsing mode.
Everything you sign up for
Every account you create is a copy of your email address, often your phone number, sometimes your home address and date of birth, sitting on a server you will never see. Loyalty cards trade your purchase history for discounts. That is a straightforward transaction, and sometimes worth it, but people rarely think of it as a data sale.
Digital privacy steps that actually work, in priority order
Most privacy guides give you thirty steps and you do none of them. Here are the ones with the best return on effort, roughly in order.
Use a password manager and stop reusing passwords. This is first because it protects you from the largest real harm, which is account takeover. When a company gets breached and your password leaks, attackers try that same email and password combination everywhere else. Reused passwords turn one breach into ten. A password manager generates a different long random password for every site and remembers them. The built-in ones in your browser or phone are decent. Dedicated apps are better. Either is enormously better than reuse.
Turn on two factor authentication on email, banking, and anything financial. Start with email, because email is the master key: whoever controls it can reset the password on everything else. An authenticator app is more secure than text message codes, since SMS can be intercepted through phone number takeover. Physical security keys are stronger still if you want that level. Any second factor beats none.
Audit app permissions once, properly. Go through the list on your phone. Set location to While Using for almost everything, and Never for things that clearly do not need it. Revoke contacts access from anything that is not a messaging or calendar app. Delete apps you have not opened in six months, since an unused app still transmits. This takes about twenty minutes and you may not need to do it again for a year.
Reset or disable your advertising identifier. On both major mobile platforms this lives in the privacy or ads section of settings. Disabling it meaningfully reduces cross-app tracking, and it costs nothing.
Use a browser with tracking protection, plus a content blocker. Browsers that block third party trackers by default do most of the work automatically. A reputable content blocker extension handles more. This also makes pages load faster, which is a nice side effect.
Stop using one email address for everything. Keep one for financial and government accounts, one for personal contacts, and a third for shopping, newsletters, and anything requiring a signup. Some providers offer email aliasing, which lets you generate a unique forwarding address per service. If an alias starts getting spam, you know exactly who sold or lost it.
The credit freeze, and why almost nobody does it
This one deserves its own section because it is the single most effective protection against the most damaging outcome, and it is underused.
A credit freeze blocks new credit accounts from being opened in your name. Someone with your full personal details cannot take out a loan or open a card against your credit file while it is frozen, because the lender cannot pull your report to approve it. In many countries, including the United States, placing and lifting a freeze is free by law.
You place it separately with each major credit bureau. It takes maybe fifteen minutes total. When you legitimately need credit, you temporarily lift it, which is usually instant online. Freeze the credit files of any children in your household too, since child identity theft often goes undetected for years.
Credit monitoring services tell you after something bad happened. A freeze prevents it. If you do one thing from this article, do this one.
Choosing what you are willing to trade
Total privacy is not on the menu, and pretending otherwise is how people give up entirely. If you carry a phone, you are producing data. The realistic goal is to decide deliberately what you trade rather than having it taken by default.
Some trades are genuinely fine. A maps app needs your location, and getting directions is worth it. A grocery loyalty card that saves you real money in exchange for knowing what you buy is a defensible deal if you have thought about it. The problem is not exchange. The problem is exchange you never agreed to and cannot see.
A useful test before granting any permission or creating any account: what would this look like if the company holding it got breached tomorrow, and what would it look like in five years when this data has been merged with everything else about me? A shopping app knowing your purchase history is annoying. A period tracking app, a mental health app, or a dating app leaking is a different category of harm entirely, and those deserve much more scrutiny about where the data is stored and whether it is sold.
The uncomfortable truth is that no individual setting saves you, because the system is designed to collect by default and the defaults favor collection. What genuinely helps is a small number of structural choices made once: unique passwords, a second factor on the accounts that matter, a frozen credit file, and a phone that is not broadcasting your location to nine companies. That is a weekend afternoon of work, and it puts you ahead of nearly everyone.
Related reading
More on what happens to your data once it leaves your phone: