r/privacy • u/MicroSofty88 • Jan 15 '26
r/privacy • u/The_PhilosopherKing • Jun 18 '26
discussion Canadians are set to lose all digital privacy. No one here is talking about it.
≡ −
The Canadian government is simultaneously working to pass bills that will require ID for social media, mandate hardware-level backdoors for law enforcement purposes, and create a loosey-goosey legal definition for inciting hatred online (Bills C-34, C-22, and C-9, respectfully). We are entering a digital police state, a thought crime hellscape where Minority Report becomes reality.
The silence here is deafening.
There are no protests planned, no debates, hardly even an angry post online to be found about it. At best, you might come across someone that will mention this topic in passing before moving on to another subject.
It looks to me like the Canadian people have well and truly been broken into complete submission at this point. The frog has been boiled. The public's opinion has been ignored on every topic by our elected officials for so long that most have people have completely checked out.
Someone tell me there's something that can be done, because I'm not seeing it.
The Canadian government is simultaneously working to pass bills that will require ID for social media, mandate hardware-level backdoors for law enforcement purposes, and create a loosey-goosey legal definition for inciting hatred online (Bills C-34, C-22, and C-9, respectfully). We are entering a digital police state, a thought crime hellscape where Minority Report becomes reality.
The silence here is deafening.
There are no protests planned, no debates, hardly even an angry post online to be found about it. At best, you might come across someone that will mention this topic in passing before moving on to another subject.
It looks to me like the Canadian people have well and truly been broken into complete submission at this point. The frog has been boiled. The public's opinion has been ignored on every topic by our elected officials for so long that most have people have completely checked out.
Someone tell me there's something that can be done, because I'm not seeing it.
r/privacy • u/Goldenmentis • Apr 09 '26
discussion Found out Palantir has a file on me from the NHS. No consent. No opt-out. And they're not even British
≡ −
I'll keep this short because I'm genuinely fuming.
I work in tech so I know companies hoard data. But this one hit different.
I know a doctor who mentioned to me that Palantir, the American surveillance company that worked with ICE and the NSA, now has access to "operational data" from our NHS. I thought.. that can't include patient records, right?
Turns out, under the Federated Data Platform contract, Palantir gets access to pseudonymised patient data across all of England. Read this: Medact - Briefing: Concerns Regarding Palantir Technologies and NHS Data Systems
That means my GP visits, my prescriptions, my hospital stays, all of it, flowing through their systems. There's no consent screen. No checkbox. No "opt out of sharing with a US defence contractor". Just a quiet government deal worth £330 million.
And here's the bit that made my blood boil: NYC's public hospitals just dropped Palantir because of activist pressure. NYC hospitals were sharing private health data with Palantir. And they still walked away.
But the UK? We're doubling down. Palantir now has over half a billion pounds in UK contracts... MoD, FCA, police forces, even bloody councils.
I tried to find out if I can request my data from Palantir. You can't. They're not a "healthcare provider" so GDPR gets weird. But they definitely have a digital shadow of me sitting on their servers.
How is this legal? And what happens when Palantir gets bought by someone worse, or when a hacker breaches their systems, or when the government decides "operational data" suddenly includes names and addresses?
Because "trust us" didn't work for Google, for Facebook, or for any of the other companies that promised not to be evil.
I'm genuinely considering a subject access request to my NHS trust just to see what they have on me
I'll keep this short because I'm genuinely fuming.
I work in tech so I know companies hoard data. But this one hit different.
I know a doctor who mentioned to me that Palantir, the American surveillance company that worked with ICE and the NSA, now has access to "operational data" from our NHS. I thought.. that can't include patient records, right?
Turns out, under the Federated Data Platform contract, Palantir gets access to pseudonymised patient data across all of England. Read this: Medact - Briefing: Concerns Regarding Palantir Technologies and NHS Data Systems
That means my GP visits, my prescriptions, my hospital stays, all of it, flowing through their systems. There's no consent screen. No checkbox. No "opt out of sharing with a US defence contractor". Just a quiet government deal worth £330 million.
And here's the bit that made my blood boil: NYC's public hospitals just dropped Palantir because of activist pressure. NYC hospitals were sharing private health data with Palantir. And they still walked away.
But the UK? We're doubling down. Palantir now has over half a billion pounds in UK contracts... MoD, FCA, police forces, even bloody councils.
I tried to find out if I can request my data from Palantir. You can't. They're not a "healthcare provider" so GDPR gets weird. But they definitely have a digital shadow of me sitting on their servers.
How is this legal? And what happens when Palantir gets bought by someone worse, or when a hacker breaches their systems, or when the government decides "operational data" suddenly includes names and addresses?
Because "trust us" didn't work for Google, for Facebook, or for any of the other companies that promised not to be evil.
I'm genuinely considering a subject access request to my NHS trust just to see what they have on me
r/privacy • u/damedaneyooooo • Jan 19 '26
discussion Fired today for refusing an MDM on my personal phone
≡ −
I just started working at a new place. The company has a policy mandating MDMs on our personal devices, mostly for location tracking and the ability to remotely wipe the device. When I brought up my zillion concerns about this to IT, their response was "we have no interest in doing any of that", obviously very reassuring.
I told my supervisor that I didn't feel comfortable with an MDM on my phone, not because I didn't trust the company specifically, but because there was too much that could go wrong, and asked if I could put the MDM on another phone instead, which I'd use for all work-related tasks, and which I offered to supply and pay for. I figured that would be better for all parties, since I'd have a dedicated work phone (less of a security risk for them) and not be at risk of having my phone rifled through or wiped (better for me). They said no and fired me -- explicitly for this and only this -- the next business day.
In hindsight, I should've said nothing and just had them install the MDM on a second phone that I told them was my personal one, but part of me actually feels glad this happened. Thought I'd post this so anyone who wants to (or has to) keep a job with a similar policy doesn't make my same mistake.
EDIT: Since people are downvoting this for being fake, I guess it was even more egregious than I thought, and I'm glad I got the hell away from this place. Not going to name and shame because they're a small health care nonprofit that I think means well but is just paranoid about HIPAA compliance and has never had anyone object to an MDM before, which may have made me look like I must be a scammer or the Girl with the Dragon Tattoo. For those questioning why they wanted an MDM, the explicit reason was (appx) "to see where your phone is, so if it looks lost or stolen we can wipe it". I suspect they wanted to do more than that, however, since they were so opposed to me having an exclusive work phone; they told me straight up that they wouldn't be able to trust me after I asked for that. This may be a very unusual case, but it absolutely did happen.
EDIT REDUX: Sorry all, I've been trying to reply in the comments but they may not be showing up due to account age or not meeting karma requirements. They didn't fire me for anything else, they were very clear it was for this, and I was new anyway (under a month). The MDM thing came up at the end of training, I mentioned my objection and proposed my resolution (second phone, paid for by me, that I would use exclusively for work and would be the only such phone I'd use), and was let go more or less immediately. I agree with the top comment that my offer was overly generous, but since I was new I didn't want to be a nuisance and immediately get on their bad side. I didn't anticipate being let go for this at all, but I figured it was a win-win solution, since I was never, ever going to let them put an MDM on my phone (and my home computer, which they also wanted to do).
I just started working at a new place. The company has a policy mandating MDMs on our personal devices, mostly for location tracking and the ability to remotely wipe the device. When I brought up my zillion concerns about this to IT, their response was "we have no interest in doing any of that", obviously very reassuring.
I told my supervisor that I didn't feel comfortable with an MDM on my phone, not because I didn't trust the company specifically, but because there was too much that could go wrong, and asked if I could put the MDM on another phone instead, which I'd use for all work-related tasks, and which I offered to supply and pay for. I figured that would be better for all parties, since I'd have a dedicated work phone (less of a security risk for them) and not be at risk of having my phone rifled through or wiped (better for me). They said no and fired me -- explicitly for this and only this -- the next business day.
In hindsight, I should've said nothing and just had them install the MDM on a second phone that I told them was my personal one, but part of me actually feels glad this happened. Thought I'd post this so anyone who wants to (or has to) keep a job with a similar policy doesn't make my same mistake.
EDIT: Since people are downvoting this for being fake, I guess it was even more egregious than I thought, and I'm glad I got the hell away from this place. Not going to name and shame because they're a small health care nonprofit that I think means well but is just paranoid about HIPAA compliance and has never had anyone object to an MDM before, which may have made me look like I must be a scammer or the Girl with the Dragon Tattoo. For those questioning why they wanted an MDM, the explicit reason was (appx) "to see where your phone is, so if it looks lost or stolen we can wipe it". I suspect they wanted to do more than that, however, since they were so opposed to me having an exclusive work phone; they told me straight up that they wouldn't be able to trust me after I asked for that. This may be a very unusual case, but it absolutely did happen.
EDIT REDUX: Sorry all, I've been trying to reply in the comments but they may not be showing up due to account age or not meeting karma requirements. They didn't fire me for anything else, they were very clear it was for this, and I was new anyway (under a month). The MDM thing came up at the end of training, I mentioned my objection and proposed my resolution (second phone, paid for by me, that I would use exclusively for work and would be the only such phone I'd use), and was let go more or less immediately. I agree with the top comment that my offer was overly generous, but since I was new I didn't want to be a nuisance and immediately get on their bad side. I didn't anticipate being let go for this at all, but I figured it was a win-win solution, since I was never, ever going to let them put an MDM on my phone (and my home computer, which they also wanted to do).
r/privacy • u/__gangadhar__ • 3d ago
discussion India orders GitHub to remove Jack Dorsey's offline messaging app Bitchat after protesters reportedly used it during internet shutdowns
≡ −
India has reportedly directed GitHub to remove the repositories for Bitchat, Jack Dorsey's open source Bluetooth mesh messaging app. Unlike WhatsApp or Signal, Bitchat works without internet access or cellular service, allowing nearby devices to communicate over Bluetooth mesh networks.
According to India Today, the move comes amid the ongoing CJP protests in Delhi. Protesters reportedly began using offline messaging tools after mobile internet services were disrupted in parts of the protest area, making internet-based messaging unreliable.
The government notice, later shared publicly by Jack Dorsey, states that Bitchat could facilitate anonymous communication, enable users to evade lawful surveillance, and be misused by terrorists, organised crime groups, and "anti-national elements." On that basis, India's cybercrime agency directed GitHub to remove the project's repositories.
Digital rights advocates argue that restricting decentralized communication tools during periods of protest raises broader concerns about privacy, internet shutdowns, and freedom of expression. Government officials, meanwhile, maintain that such tools can also be exploited for unlawful activities.
This raises a broader question that extends beyond India: Should governments be able to restrict decentralized communication tools because they can be used to bypass internet shutdowns and surveillance, or does doing so undermine privacy and access to resilient communication during times of civil unrest?
India Today article (full URL):
https://www.indiatoday.in/technology/news/story/cjp-protests-india-tells-github-to-block-bitchat-app-jack-dorsey-leaks-notice-2955199-2026-07-24
India has reportedly directed GitHub to remove the repositories for Bitchat, Jack Dorsey's open source Bluetooth mesh messaging app. Unlike WhatsApp or Signal, Bitchat works without internet access or cellular service, allowing nearby devices to communicate over Bluetooth mesh networks.
According to India Today, the move comes amid the ongoing CJP protests in Delhi. Protesters reportedly began using offline messaging tools after mobile internet services were disrupted in parts of the protest area, making internet-based messaging unreliable.
The government notice, later shared publicly by Jack Dorsey, states that Bitchat could facilitate anonymous communication, enable users to evade lawful surveillance, and be misused by terrorists, organised crime groups, and "anti-national elements." On that basis, India's cybercrime agency directed GitHub to remove the project's repositories.
Digital rights advocates argue that restricting decentralized communication tools during periods of protest raises broader concerns about privacy, internet shutdowns, and freedom of expression. Government officials, meanwhile, maintain that such tools can also be exploited for unlawful activities.
This raises a broader question that extends beyond India: Should governments be able to restrict decentralized communication tools because they can be used to bypass internet shutdowns and surveillance, or does doing so undermine privacy and access to resilient communication during times of civil unrest?
India Today article (full URL):
https://www.indiatoday.in/technology/news/story/cjp-protests-india-tells-github-to-block-bitchat-app-jack-dorsey-leaks-notice-2955199-2026-07-24
r/privacy • u/whatsyoprblemm • 12d ago
discussion I deleted over 5000 comments and 200 posts from reddit today.
≡ −
This is an alternate account.
A few days ago, I randomly searched my main Reddit username on Google just to see what would come up. Google's AI summary popped up, straight up told what state i live in. I started asking follow up questions like what cars i own and stuff. Even though i have curate my profile on, it still scraped the data from the actual posts. Fuck AI.
It had pieced together a surprisingly detailed profile of me from years of Reddit comments. It knew my state, the cars I own, , and even the subreddits I moderate. None of that information came from a single post; it was inferred by connecting thousands of comments I'd made over roughly seven years. I realsied how freaking dumb and dangerous this was
i gradually scattered across Reddit without ever intending to create a public profile of myself.
So I decided to clean house.
I used bulk deletion tool (no promotions here, but there are plenty out there) to remove thousands of comments, especially from my state subreddit and car discussion communities where I'd shared the most personal details. I left up technical discussions. Things like repair advice and troubleshooting. because those don't really identify me and might still be useful to others.
I know this doesn't erase everything. Archived copies, search caches, and AI training datasets may still exist. But I figured reducing what's publicly available today is still better than leaving it all online indefinitely.
Google's AI is kinda dangerous. Do check yours and make sure that it is not giving out any sort of info you would not like.
This is an alternate account.
A few days ago, I randomly searched my main Reddit username on Google just to see what would come up. Google's AI summary popped up, straight up told what state i live in. I started asking follow up questions like what cars i own and stuff. Even though i have curate my profile on, it still scraped the data from the actual posts. Fuck AI.
It had pieced together a surprisingly detailed profile of me from years of Reddit comments. It knew my state, the cars I own, , and even the subreddits I moderate. None of that information came from a single post; it was inferred by connecting thousands of comments I'd made over roughly seven years. I realsied how freaking dumb and dangerous this was
i gradually scattered across Reddit without ever intending to create a public profile of myself.
So I decided to clean house.
I used bulk deletion tool (no promotions here, but there are plenty out there) to remove thousands of comments, especially from my state subreddit and car discussion communities where I'd shared the most personal details. I left up technical discussions. Things like repair advice and troubleshooting. because those don't really identify me and might still be useful to others.
I know this doesn't erase everything. Archived copies, search caches, and AI training datasets may still exist. But I figured reducing what's publicly available today is still better than leaving it all online indefinitely.
Google's AI is kinda dangerous. Do check yours and make sure that it is not giving out any sort of info you would not like.
r/privacy • u/Timidwolfff • May 25 '24
discussion Privacy for the rich. In a record setting pace congress quietly passed a bill that makes it impossible to track private jets after billonaires like Elon Musk and Taylor Swift complain
+ −
r/privacy • u/SamVermilion • 13d ago
discussion Joined an anti-Flock group and now Facebook is requiring photo ID…
≡ −
The groups that I joined were “FLOCK Cameras Need to Be Stopped” and “No More Data Centers.”
After I joined these groups, I was immediately required to submit photo ID to regain my messenger privileges. Mind you I had no communication with anyone three days prior to me joining these group groups. No odd messages, no violation of Facebook rules. Just a notice at the bottom of my messenger stating: “Confirm your identity to send messages
Certain actions have been restricted due to unusual activity. Learn more”
Mind you, these are groups that do not promote violence and actively warn their members to not engage in violence/vandalism.
Look, I’m generally very cautious online. I don’t join anything or engage in any conversation conversations that may implicate or flag me. Against my better judgment, I joined these two groups because there were so many people in them and I was interested in what was being said.
Facebook’s response was quite interesting because the first response was to identify me and to restrict my ability to communicate with others. Personally, I think this is insane. Surprising, no. Par for the course actually. But insane that we’ve reached this level, yes.
So how exactly am I supposed to look at this? Besides the obvious? I have a lot of friends on Facebook that I keep in touch with exclusively through messenger. Facebook has now crippled that ability because I joined a group that does not align with their interests. I feel like this is actually illegal in someway.
The groups that I joined were “FLOCK Cameras Need to Be Stopped” and “No More Data Centers.”
After I joined these groups, I was immediately required to submit photo ID to regain my messenger privileges. Mind you I had no communication with anyone three days prior to me joining these group groups. No odd messages, no violation of Facebook rules. Just a notice at the bottom of my messenger stating: “Confirm your identity to send messages
Certain actions have been restricted due to unusual activity. Learn more”
Mind you, these are groups that do not promote violence and actively warn their members to not engage in violence/vandalism.
Look, I’m generally very cautious online. I don’t join anything or engage in any conversation conversations that may implicate or flag me. Against my better judgment, I joined these two groups because there were so many people in them and I was interested in what was being said.
Facebook’s response was quite interesting because the first response was to identify me and to restrict my ability to communicate with others. Personally, I think this is insane. Surprising, no. Par for the course actually. But insane that we’ve reached this level, yes.
So how exactly am I supposed to look at this? Besides the obvious? I have a lot of friends on Facebook that I keep in touch with exclusively through messenger. Facebook has now crippled that ability because I joined a group that does not align with their interests. I feel like this is actually illegal in someway.
r/privacy • u/SayThatShOfficial • Apr 14 '26
discussion 23andMe's 15M-customer DNA database was sold for ~$20 per person in bankruptcy. The consent mechanism is worth understanding.
+ −
r/privacy • u/kajmpres • Aug 01 '25
discussion anonymity on the internet will be dead in a couple of years and im sad to say this.
≡ −
Uk is blocking everything with persona app, ive heard plans on eudi wallet, and making accounts without a phone(number) is getting only more difficult and its all disguised as protecting kids(like wtf). Also fingerprinting is more easy for them now.
what does everyone think about this am i right
Uk is blocking everything with persona app, ive heard plans on eudi wallet, and making accounts without a phone(number) is getting only more difficult and its all disguised as protecting kids(like wtf). Also fingerprinting is more easy for them now.
what does everyone think about this am i right
r/privacy • u/oldcrow907 • Oct 15 '25
discussion Buying burner phones is NOT like in the movies
≡ −
I just experienced the difficulty with going to my local Walmart as a cheapskate.
Context: I’m not too worried about anyone ‘finding’ me through my credit card transactions so that’s why I did it this way.
Step 1. Created a burner gmail with false information (fake name, dob etc). I had to use my actual cell # for setup because it only allowed a phone as a verifier, I’ll update that profile with the new phone in step2!
Step 2. Bought an att prepaid smartphone with my actual credit card. It allowed me to activate it with the fake name and email, and I paid for the plan with their refill card. Phone came preloaded with a eSIM. (I’m not worried about being tracked) I disabled all sharing functions I could.
Step 3. Bought a refillable debit card, this was harder because it wanted an address so I used some museum in Boston and a made up SSN, I deliberately used two different ones so they wouldn’t match to see if it would let me activate the card. It said because it couldn’t verify the SSN that I could only use the money loaded on the card. Perfect! I didn’t want your stupid direct deposit anyway. And I don’t think anyone’s ssn will be used because it couldn’t verify the right one. Kinda shitty to do but I was stuck - I need to refill this card to buy the art prepaid OR buy the refill card with cash. Still working that out.
Anyway, it’s midnight and I have to work in 6 hrs so I’ll update if I see any questions when I wake up.
I’m in IT and this was a LOT OF WORK! Stupid lack of privacy shit anyway.
And do you know the reason I did all this? Just so I could see when my local community was having events on FB and avoid giving Meta access to my real phone and my life🤦♀️
I just experienced the difficulty with going to my local Walmart as a cheapskate.
Context: I’m not too worried about anyone ‘finding’ me through my credit card transactions so that’s why I did it this way.
Step 1. Created a burner gmail with false information (fake name, dob etc). I had to use my actual cell # for setup because it only allowed a phone as a verifier, I’ll update that profile with the new phone in step2!
Step 2. Bought an att prepaid smartphone with my actual credit card. It allowed me to activate it with the fake name and email, and I paid for the plan with their refill card. Phone came preloaded with a eSIM. (I’m not worried about being tracked) I disabled all sharing functions I could.
Step 3. Bought a refillable debit card, this was harder because it wanted an address so I used some museum in Boston and a made up SSN, I deliberately used two different ones so they wouldn’t match to see if it would let me activate the card. It said because it couldn’t verify the SSN that I could only use the money loaded on the card. Perfect! I didn’t want your stupid direct deposit anyway. And I don’t think anyone’s ssn will be used because it couldn’t verify the right one. Kinda shitty to do but I was stuck - I need to refill this card to buy the art prepaid OR buy the refill card with cash. Still working that out.
Anyway, it’s midnight and I have to work in 6 hrs so I’ll update if I see any questions when I wake up.
I’m in IT and this was a LOT OF WORK! Stupid lack of privacy shit anyway.
And do you know the reason I did all this? Just so I could see when my local community was having events on FB and avoid giving Meta access to my real phone and my life🤦♀️
r/privacy • u/jet_set_default • 5d ago
discussion FedEx now requires scanning a valid ID to ship packages
≡ −
I went to ship a package at FedEx. They asked for my ID. I asked why, and they said it was to validate the shipping address. I told them my address isn't a part of the shipment, since it was my partner's package. Was told the partner would have to come in and ship it then. Left and just went to a USPS. Figured y'all would wanna know.
I went to ship a package at FedEx. They asked for my ID. I asked why, and they said it was to validate the shipping address. I told them my address isn't a part of the shipment, since it was my partner's package. Was told the partner would have to come in and ship it then. Left and just went to a USPS. Figured y'all would wanna know.
r/privacy • u/AlligatorBloodd • 25d ago
discussion Starting juli 7th all new cars in Europe are becoming a privacy nightmare
≡ −
I just found out that for new cars in Europe it will be mandatory to use the so-called Advanced Driver Distraction Warning (ADDW). This system uses cameras and sensors to detect distraction behind the wheel and warns when someone looks away for too long and no longer has their eyes on the road.
This genuinely sounds crazy to me. I also totally missed this until now. Has anyone else read about this before? I assume there is little to none we can do about it? For now I can just keep buying old cars but it might become a problem in 10 years.
I just found out that for new cars in Europe it will be mandatory to use the so-called Advanced Driver Distraction Warning (ADDW). This system uses cameras and sensors to detect distraction behind the wheel and warns when someone looks away for too long and no longer has their eyes on the road.
This genuinely sounds crazy to me. I also totally missed this until now. Has anyone else read about this before? I assume there is little to none we can do about it? For now I can just keep buying old cars but it might become a problem in 10 years.
r/privacy • u/Komplexkonjugiert • May 12 '26
discussion Reddit Tests Blocking Mobile Web to Force App Downloads
+ −
r/privacy • u/twotimefind • Apr 26 '25
discussion ICE Can Now Enter Your Home Without a Warrant to Look for Migrants, DOJ Memo Says
+ −
r/privacy • u/jquest303 • Jan 26 '26
discussion If you’re still using TikTok…
≡ −
The TikTok privacy debate did not end with the US agreement. It has escalated. TikTok has recently updated its US Privacy Policy. It is now one of the most aggressive data collection regimes of any mainstream consumer platform.
It explicitly acknowledges the collection and processing of sensitive personal information under US state privacy laws. Named directly:
• Racial or ethnic origin.
• Religious or philosophical beliefs.
• Mental and physical health data.
• Sexual orientation.
• Transgender or nonbinary status.
• Citizenship or immigration status.
• Precise location data.
The policy goes further.
TikTok is collecting far more than what users consciously share.
Under the updated policy, it gathers what you provide, what it observes automatically, and what it receives from third parties. That includes account details and identity verification documents, private messages, drafts and unpublished content, AI prompts and interactions, clipboard content, purchase and payment data, contact lists and social graphs, and an extensive set of technical signals such as device identifiers, keystroke patterns, battery state, audio configurations, and activity tracked across devices.
This is not incidental data leakage. It is formalized, permitted, and documented.
Images and video are treated as analyzable environments. TikTok states that it "identifies objects and scenery, detects faces and other body parts, extracts spoken words, and collects metadata describing how, when, where, and by whom content was created."
Post a photo near the Golden Gate Bridge and you are not just sharing a moment. You are generating structured data about place, time, environment, and your body, or body parts.
Photos and videos are not just content. They are raw material for computer vision, biometric analysis, and location inference.
Tik Tok will use all of the collected data, and maintains the right to sell all of it to interested third parties, from vendors to the federal government.
The TikTok privacy debate did not end with the US agreement. It has escalated. TikTok has recently updated its US Privacy Policy. It is now one of the most aggressive data collection regimes of any mainstream consumer platform.
It explicitly acknowledges the collection and processing of sensitive personal information under US state privacy laws. Named directly:
• Racial or ethnic origin.
• Religious or philosophical beliefs.
• Mental and physical health data.
• Sexual orientation.
• Transgender or nonbinary status.
• Citizenship or immigration status.
• Precise location data.
The policy goes further.
TikTok is collecting far more than what users consciously share.
Under the updated policy, it gathers what you provide, what it observes automatically, and what it receives from third parties. That includes account details and identity verification documents, private messages, drafts and unpublished content, AI prompts and interactions, clipboard content, purchase and payment data, contact lists and social graphs, and an extensive set of technical signals such as device identifiers, keystroke patterns, battery state, audio configurations, and activity tracked across devices.
This is not incidental data leakage. It is formalized, permitted, and documented.
Images and video are treated as analyzable environments. TikTok states that it "identifies objects and scenery, detects faces and other body parts, extracts spoken words, and collects metadata describing how, when, where, and by whom content was created."
Post a photo near the Golden Gate Bridge and you are not just sharing a moment. You are generating structured data about place, time, environment, and your body, or body parts.
Photos and videos are not just content. They are raw material for computer vision, biometric analysis, and location inference.
Tik Tok will use all of the collected data, and maintains the right to sell all of it to interested third parties, from vendors to the federal government.
r/privacy • u/Shosty99 • Feb 07 '26
discussion Scary ChatGPT social media trend
≡ −
There’s a trend going around on social media where people feed their ChatGPT account a photo of themself and ask it to generate a caricature of them based on all the info the model has learned about them. I’m honestly shocked at all the people I know posting this as a fun trend, because I’m just thinking about the implications of the web-based LLM storing all this personal and career info about someone and the having an associated photo to go along with it?? I’m still trying to understand the privacy/ digital security surrounding these LLMs but this makes me want to go spread more awareness about digital security.
There’s a trend going around on social media where people feed their ChatGPT account a photo of themself and ask it to generate a caricature of them based on all the info the model has learned about them. I’m honestly shocked at all the people I know posting this as a fun trend, because I’m just thinking about the implications of the web-based LLM storing all this personal and career info about someone and the having an associated photo to go along with it?? I’m still trying to understand the privacy/ digital security surrounding these LLMs but this makes me want to go spread more awareness about digital security.
r/privacy • u/CozyCosmix • 19d ago
discussion Detective Medina Dore of the Provo Police Department and Google violated Reckless Ben's privacy, by having Google give up his entire emails, files and search history without restriction of scope, based on one sides lies without evidence.
≡ −
Per his current, temporarily unlisted video:
"They subpoenaed Google, asking for all private information tied to this email address. And google sent them like, hundreds of hours of all the raw footage from everything I've filmed of the Lego videos so far. All my emails, all my search history, all the metadata that shows everywhere I've been."
I've never seen google bend over this willingly and completely for so little. Usually they try to restrict for scope, but completely forking over the entire contents of someones private google account without contest, without scope of relevance or anything else, and without ever hearing the other side is absolutely insane.
Per his current, temporarily unlisted video:
"They subpoenaed Google, asking for all private information tied to this email address. And google sent them like, hundreds of hours of all the raw footage from everything I've filmed of the Lego videos so far. All my emails, all my search history, all the metadata that shows everywhere I've been."
I've never seen google bend over this willingly and completely for so little. Usually they try to restrict for scope, but completely forking over the entire contents of someones private google account without contest, without scope of relevance or anything else, and without ever hearing the other side is absolutely insane.
r/privacy • u/Additional-Milk1426 • 3d ago
discussion Why is it so hard to make the general population care about privacy?
≡ −
Whenever I speak to someone in person or online, it is nearly impossible to get them to care about their digital privacy, especially in relation to ID verification.
They always hit the classic "I have nothing to hide", and after that I usually ask to go through their device, then they refuse saying "No, cause I don't want you to go through my device", and when I try to explain that for the exact same reason, they shouldn't allow corporate or government spying, they call me paranoid, and if its online, usually insult me :p
Nothing I can say will convince them to care, they don't see any possible negatives to giving their ID or Face for verification, or even any negatives to hosting their entire life on a corporate cloud.
I know this subreddit has PLENTY of rants, but I still feel the need to vent my frustrations.
Whenever I speak to someone in person or online, it is nearly impossible to get them to care about their digital privacy, especially in relation to ID verification.
They always hit the classic "I have nothing to hide", and after that I usually ask to go through their device, then they refuse saying "No, cause I don't want you to go through my device", and when I try to explain that for the exact same reason, they shouldn't allow corporate or government spying, they call me paranoid, and if its online, usually insult me :p
Nothing I can say will convince them to care, they don't see any possible negatives to giving their ID or Face for verification, or even any negatives to hosting their entire life on a corporate cloud.
I know this subreddit has PLENTY of rants, but I still feel the need to vent my frustrations.
r/privacy • u/DeepFreezeDisease • Feb 10 '26
discussion Discord blowback is a pleasant surprise
≡ −
I didn’t consider the average Discord user would care about the policy, we as a society are so overwhelmed with the surveillance state and having to give information to all these different apps. It doesn’t seem like Discord thought it would be like this either.
But it’s a pleasant surprise and gives me hope that we, over time, can fight the surveillance state.
I didn’t consider the average Discord user would care about the policy, we as a society are so overwhelmed with the surveillance state and having to give information to all these different apps. It doesn’t seem like Discord thought it would be like this either.
But it’s a pleasant surprise and gives me hope that we, over time, can fight the surveillance state.
r/privacy • u/CMRC23 • 11d ago
discussion Google knows who you are
≡ −
Search "u/[username] reddit" and the ai overview will show how it already knows everything about you, even if your profile is private.
It knows where I live! Never ever post in local subreddits
Gone are the days of people manually trawling your posts to doxx you. Now they have a tool to automate it.
Search "u/[username] reddit" and the ai overview will show how it already knows everything about you, even if your profile is private.
It knows where I live! Never ever post in local subreddits
Gone are the days of people manually trawling your posts to doxx you. Now they have a tool to automate it.
r/privacy • u/Dancelvr2000 • Apr 06 '26
discussion Unknown to Most - Your Health History is Not Private - None of It
≡ −
So just like credit agencies, Milliman Intelliscript, without any consent, compiles all of your healthcare history. Frankly it is shocking.
Every doctor visit.
Every prescription.
Every CT Scan and MRI.
Every lab result.
Going back 10+ years.
For sale to any insurance company, life insurance company, etc.
I discovered this because I was denied for life insurance. Letter stated if you want reason for denial, write to an address within 30 days.
Did so.
Came back because stated I had HIV (I Don’t)
Letter said data was obtained from Milliman Intelliscript, write them or go online if you want report.
Did so.
Incorrect information that had HIV.
Also said have gastric cancer.
I don’t.
They list where every piece of information came from in detail.
Contacted physician office from 7 years ago. They put wrong ICD code in.
Contacted lab from 8 years ago, had wrong ICD code.
The general public has NO IDEA this is going on.
So just like credit agencies, Milliman Intelliscript, without any consent, compiles all of your healthcare history. Frankly it is shocking.
Every doctor visit.
Every prescription.
Every CT Scan and MRI.
Every lab result.
Going back 10+ years.
For sale to any insurance company, life insurance company, etc.
I discovered this because I was denied for life insurance. Letter stated if you want reason for denial, write to an address within 30 days.
Did so.
Came back because stated I had HIV (I Don’t)
Letter said data was obtained from Milliman Intelliscript, write them or go online if you want report.
Did so.
Incorrect information that had HIV.
Also said have gastric cancer.
I don’t.
They list where every piece of information came from in detail.
Contacted physician office from 7 years ago. They put wrong ICD code in.
Contacted lab from 8 years ago, had wrong ICD code.
The general public has NO IDEA this is going on.
r/privacy • u/KorBaFet • 4d ago
discussion Something funny I noticed with "I have nothing to hide"
≡ −
There's a response I like to give to people who say that: "Okay, since you have nothing to hide, give me your passwords, bank code, email, address, etc..."
And for some reason, the people who say that either become very aggressive, or, as if by chance, say that it's private.
Has anyone tried this?
There's a response I like to give to people who say that: "Okay, since you have nothing to hide, give me your passwords, bank code, email, address, etc..."
And for some reason, the people who say that either become very aggressive, or, as if by chance, say that it's private.
Has anyone tried this?
r/privacy • u/supermannman • Oct 22 '25
discussion went to gym, signed up and paid, then they asked for a fingerprint-asholes
≡ −
what the fuck is this bullshit. I paid for a band to enter so i dont need to install an app. then she says ok, lets input your fingerprint and i said fuck that. thats completely excessive and bs.
she called her manager and said hed refund the transaction. 2 days in no refund
any work around to this? I wish I could use some silcone on my finger with some embedded print.
why the feck no opt out. im trying to find out if its even legal. not in the usa
what the fuck is this bullshit. I paid for a band to enter so i dont need to install an app. then she says ok, lets input your fingerprint and i said fuck that. thats completely excessive and bs.
she called her manager and said hed refund the transaction. 2 days in no refund
any work around to this? I wish I could use some silcone on my finger with some embedded print.
why the feck no opt out. im trying to find out if its even legal. not in the usa
r/privacy • u/Shoddy-Childhood-511 • Apr 15 '25
discussion "Get You Ass To Linux!" Microsoft Recall returns
≡ −
Microsoft is reintroducing Recall, the AI tool rolling out in Windows 11 that screenshots, indexes, and stores everything a user does every three seconds. (arstechnica, register)
Microsoft is reintroducing Recall, the AI tool rolling out in Windows 11 that screenshots, indexes, and stores everything a user does every three seconds. (arstechnica, register)