Online privacy: what is actually collected, and what you can change
Online privacy is not about having something to hide. It is about who holds a record of your behaviour, how precisely you can be identified without cookies, and which of those things you can practically change.
The short answer
- Online privacy is about who holds a record of your behaviour and how precisely you can be re-identified, not about secrecy.
- Blocking cookies is no longer sufficient - browser fingerprinting identifies a device from its configuration alone, with no stored identifier.
- Data brokers assemble profiles from purchases, public records, app data and loyalty schemes, and sell them to buyers you never interact with.
- Location is the most sensitive category, because a movement history reveals home, work, health and relationships without any content at all.
- A small number of changes - browser choice, app permission review, and location settings - remove most routine exposure.
Online privacy is usually framed as secrecy, which is why the debate stalls at "I have nothing to hide". A more useful framing: privacy is about who holds a durable record of your behaviour, and what they are permitted to do with it later.
That reframing matters because the risk is rarely embarrassment. It is that a profile assembled for advertising gets reused for something with consequences — a price, a decision, a scam that knows enough about you to be convincing.
What is actually collected
Three distinct mechanisms, often confused with one another, and they need different defences.
Stored identifiers
Cookies and their relatives: a small file placed on your device so a site can recognise it later. These are the mechanism most people know about, largely because they are the only one with a consent banner attached.
They are also the easiest to defeat. You can clear them, block third-party ones, or use a browser that partitions them per site.
Fingerprinting
This is the one that matters more, and almost nobody has heard of it.
Your browser reveals a large amount of incidental configuration to every site you visit: screen dimensions, installed fonts, time zone, language, graphics hardware behaviour, audio processing quirks. Individually, none identifies you. Combined, the set is frequently unique — and it requires storing nothing at all, so clearing cookies changes nothing.
→ How browser fingerprinting works
Aggregation
The third mechanism is not technical at all. Data brokers buy, merge and resell information from public records, purchase histories, loyalty schemes, app SDKs and each other. The resulting profile can include your address history, household composition, estimated income, health interests and daily movement patterns — assembled by a company you have never contacted.
Why it connects to scams
Privacy and fraud are usually treated as separate subjects. They are not.
Every detail in a profile is raw material for a more convincing approach. The FTC's own guidance on avoiding social media scams leads with limiting who can see your posts and contacts — because scammers "exploit what a user posts to figure out how to target them", and buy ads targeted by age, interests and shopping habits using the same tools any business uses.
A spear phishing message that names your employer, your recent purchase and your colleague is not the product of sophisticated hacking. It is the product of information that was available for purchase.
What actually helps
Ordered by effect per unit of effort. The first three are worth doing this week; the rest are refinements.
1. Review app location permissions
The highest-value change available to most people. Open your phone's privacy settings, look at every app with location access, and downgrade anything that does not need it to "while using" or "never". Turn off precise location for apps that only need a general area.
A movement history is the most revealing dataset most people generate. It identifies home, workplace, place of worship, medical appointments and personal relationships — without containing a single word of content.
→ Location privacy in practice
2. Audit the rest of your app permissions
Contacts, microphone, camera, photo library. Many apps request these speculatively at install and never need them again. Access granted in 2022 is still access today.
→ How to review app permissions
3. Use a browser that resists fingerprinting
Browser choice does more than any individual setting. Firefox, Safari and Brave all ship meaningful anti-tracking and anti-fingerprinting protection by default; enabling the stricter modes costs very little in practice.
4. Decline non-essential cookies
The banner is tedious and mostly theatre, but "reject all" genuinely reduces third-party collection. It takes one extra click.
5. Reduce what is publicly posted
Birth dates, employers, pet names, children's schools, holiday dates. Each is a security question answer, a password guess, or the specific detail that makes a pretext land.
6. Opt out of data brokers
Slow, repetitive, and partially effective — profiles regenerate as new data flows in. Worth doing for the largest brokers, and worth knowing that some jurisdictions now provide a single deletion mechanism.
What does not help as much as people think
- Incognito mode prevents local history being saved. It does not hide you from the sites you visit, your network, or fingerprinting.
- A VPN hides your traffic from your network provider and moves trust to the VPN operator. It does nothing about cookies, fingerprinting, or the account you then log into.
- Deleting one social media account while the same information remains across three others and several brokers.
Where to go next
- Browser fingerprinting — how a device is identified with no stored data
- How online tracking works — the machinery behind following you between sites
- Data brokers — who assembles the profiles, and how to remove yourself
- App permissions — a practical review you can do in ten minutes
- Location privacy — the most sensitive category, and what to change
See your own exposure
Our privacy walkthrough shows what a site can determine about your device before you have typed anything, and which settings actually change it.
Try it freeFrequently asked questions
- Why does online privacy matter if I have nothing to hide?
- Privacy is not about hidden wrongdoing, it is about control over a record. The same profile that targets advertising can influence an insurance quote, a loan decision, or what a stranger can learn about your daily movements. The question is not whether the data is incriminating but who holds it and what they may do with it later.
- Does blocking cookies stop tracking?
- Only partly. Cookies are a stored identifier that you can delete, but browser fingerprinting derives an identifier from your device's configuration — screen size, fonts, graphics behaviour, time zone — which persists whether or not you clear anything. A browser with fingerprinting protection matters more than cookie settings alone.
- What is a data broker?
- A company that collects personal information about people it has no relationship with, assembles it into profiles, and sells access. Sources include public records, purchase histories, loyalty programmes, app data and other brokers. Most people have never heard of the companies holding the most detailed profiles of them.
- Is private or incognito mode actually private?
- No, not in the way most people assume. It prevents your browsing being saved to that device's local history. It does not hide activity from the websites you visit, your internet provider, your employer's network, or trackers that fingerprint your device rather than storing a cookie.
- What is the single most effective privacy change I can make?
- Review app location permissions and switch anything that does not need continuous access to "while using" or "never". Location history is the most revealing data most people leak, because a movement record exposes where you live, work, worship and seek medical care without containing a single message.
Sources
- NIST SP 800-63B: Digital Identity Guidelines — National Institute of Standards and Technology, 2025
- New FTC Data Show People Have Lost Billions to Social Media Scams — Federal Trade Commission, 2026
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Social Engineering
What is social engineering? The techniques behind every scam
Social engineering is manipulating a person into doing something against their own interest. It is the common ancestor of phishing, impersonation, romance scams and fraud calls, and it works on a small number of predictable psychological levers.
- Password Security
Password security: what actually matters in 2026
Most password advice is a decade out of date. The current guidance from NIST and the NCSC is shorter, simpler, and contradicts almost everything you were taught about symbols, capitals and changing your password every ninety days.
- Online Scams
Online scams: the main types and how each one works
Americans reported losing about $16 billion to fraud in 2025, the highest figure on record. The categories that account for most of it are surprisingly few, and each has a recognisable structure.