Protect yourself

Reduce your data exhaust

Practical steps that reduce how much is collected about you by default, how long it is kept, and how easily it can be handed to someone else.

The framing matters, so we will state it plainly. This page is about reducing unnecessary data exhaust, exercising rights you already have, and understanding what you are actually consenting to.

It is not about evading lawful investigation, and nothing here is offered for that purpose. If a court authorizes a search of a specific person on individualized suspicion, that is the system working as designed — it is the version of policing this organization explicitly supports.

Your phone

The largest single source of location data about you, and the one you have the most control over.

  • Audit location permissions

    Go through every app that has location access and ask whether it needs it. Most do not. Where an app genuinely needs location, "while using" is almost always sufficient — "always" is what produces a continuous history.

  • Turn off advertising identifiers

    iOS and Android both assign a resettable advertising ID that ties activity across apps to one profile. Both let you disable or reset it. This is the identifier that makes commercially available location data commercially valuable.

  • Review location history settings

    Platform accounts often keep a timeline of everywhere your phone has been, sometimes for years. It can usually be turned off and existing history deleted. Do both — turning it off does not delete what already exists.

  • Consider a privacy-focused mobile OS

    GrapheneOS is a well-regarded hardened Android distribution with strong sandboxing and granular permission controls. It runs on a limited set of devices and takes real effort to set up, so it is a considered choice rather than a casual one — but for people with elevated risk it is a meaningful step.

Your car

The least understood surveillance surface most people own, and the one this organization spends most of its time on.

  • Understand what a connected car collects

    Modern vehicles routinely record location, speed, braking, seatbelt use, and in-cabin data, and many transmit it to the manufacturer. Some manufacturers have shared or sold driving data onward. Check your vehicle brand's privacy settings and connected-services account.

  • Opt out of connected services where you can

    Many manufacturers let you disable data sharing, or the connected service entirely, though the option is often buried. Some have separate opt-outs for the manufacturer, the app, and any insurance or telematics program.

  • Know what ALPRs do and do not capture

    An ALPR reads your plate and records where and when it saw it. It does not need your phone, your account, or your consent, and nothing you do in the car changes what it records. That is precisely why this one is a policy problem rather than a personal-settings problem.

Data brokers

The commercial pipeline that lets agencies buy what they might otherwise need a warrant to compel.

  • Submit opt-out and deletion requests

    Major data brokers accept deletion requests, and residents of states with comprehensive privacy laws — California, Colorado, Connecticut, Virginia, Texas, and others — have enforceable rights to demand it. Requests generally have to be repeated periodically, since data flows back in.

  • Use your state law by name

    A request that cites the specific statute gets a materially better response than a polite email. Your state attorney general's office usually publishes a plain-language guide to what you are entitled to.

  • Understand why this matters here

    Government purchase of commercially available location data is one of the clearest end-runs around warrant requirements. Reducing what brokers hold about you is worth doing — and it is not a substitute for the legal rule that should govern the purchase.

Browser and accounts

Cheap changes with a large effect on how much of your behaviour is recorded by default.

  • Use a browser that blocks third-party tracking by default

    Firefox and Safari both do out of the box. So does a hardened Chromium build with a reputable content blocker. The default configuration is the one that matters, because it is the one you will actually keep.

  • Turn off ad personalization on platform accounts

    Every major platform account has a privacy or ad-settings page controlling how much activity is retained and cross-referenced. These are usually several clicks deep and worth the twenty minutes.

  • Prefer end-to-end encrypted messaging

    For ordinary conversations with friends and family. This is not about hiding anything; it is about the sensible default that the contents of your private conversations are not stored in a form somebody else can hand over.

Your home

Devices you installed for convenience that also produce records about your household.

  • Know which devices share footage with police

    Several consumer camera and doorbell platforms have offered law-enforcement request or sharing programs, and the terms have changed repeatedly. Check the current setting in your own account rather than relying on what was true when you bought it.

  • Separate smart devices onto a guest network

    A guest network or dedicated VLAN limits what a compromised device can see. Most consumer routers support this in about five minutes.

  • Prefer local storage where the option exists

    Cameras that record to local storage rather than a vendor cloud produce far fewer records held by a third party — and therefore far fewer records available on request.

What none of this fixes

Every step on this page reduces what is collected with your participation — through an app you installed, an account you opened, a service you connected, a device you bought.

Automated license plate readers do not require your participation. You cannot opt out of a camera on a public road. There is no setting, no permission prompt, no account, and no deletion request. It photographs the car, reads the plate, and writes a timestamped record whether or not you have ever heard of it.

That is the whole reason this organization exists and the reason most of this site is about policy rather than settings. Individual privacy practices are worth adopting and they are not a substitute for rules about what government may build, keep, share, and search.

Privacy practices can reduce your exposure. They cannot guarantee anonymity, and they cannot substitute for a legal limit on indiscriminate collection.

If you have gone through this page and want the part that actually changes the ALPR problem, it is on the action page: find out what your city operates, and be there when the contract comes up.

General information, not legal or security advice. Settings, product names, and available rights change frequently, and this page will not always be current. If you are at elevated risk — because of your work, your immigration status, an abusive ex-partner, or a specific threat — please consult a specialist organization with expertise in your situation rather than relying on a general guide.