Protect yourself
Reduce your data exhaust
Practical steps that reduce how much is collected about you by default, how long it is kept, and how easily it can be handed to someone else.
The framing matters, so we will state it plainly. This page is about reducing unnecessary data exhaust, exercising rights you already have, and understanding what you are actually consenting to.
It is not about evading lawful investigation, and nothing here is offered for that purpose. If a court authorizes a search of a specific person on individualized suspicion, that is the system working as designed — it is the version of policing this organization explicitly supports.
Your phone
The largest single source of location data about you, and the one you have the most control over.
-
Audit location permissions
Go through every app that has location access and ask whether it needs it. Most do not. Where an app genuinely needs location, "while using" is almost always sufficient — "always" is what produces a continuous history.
-
Turn off advertising identifiers
iOS and Android both assign a resettable advertising ID that ties activity across apps to one profile. Both let you disable or reset it. This is the identifier that makes commercially available location data commercially valuable.
-
Review location history settings
Platform accounts often keep a timeline of everywhere your phone has been, sometimes for years. It can usually be turned off and existing history deleted. Do both — turning it off does not delete what already exists.
-
Consider a privacy-focused mobile OS
GrapheneOS is a well-regarded hardened Android distribution with strong sandboxing and granular permission controls. It runs on a limited set of devices and takes real effort to set up, so it is a considered choice rather than a casual one — but for people with elevated risk it is a meaningful step.
Your car
The least understood surveillance surface most people own, and the one this organization spends most of its time on.
-
Understand what a connected car collects
Modern vehicles routinely record location, speed, braking, seatbelt use, and in-cabin data, and many transmit it to the manufacturer. Some manufacturers have shared or sold driving data onward. Check your vehicle brand's privacy settings and connected-services account.
-
Opt out of connected services where you can
Many manufacturers let you disable data sharing, or the connected service entirely, though the option is often buried. Some have separate opt-outs for the manufacturer, the app, and any insurance or telematics program.
-
Know what ALPRs do and do not capture
An ALPR reads your plate and records where and when it saw it. It does not need your phone, your account, or your consent, and nothing you do in the car changes what it records. That is precisely why this one is a policy problem rather than a personal-settings problem.
Data brokers
The commercial pipeline that lets agencies buy what they might otherwise need a warrant to compel.
-
Submit opt-out and deletion requests
Major data brokers accept deletion requests, and residents of states with comprehensive privacy laws — California, Colorado, Connecticut, Virginia, Texas, and others — have enforceable rights to demand it. Requests generally have to be repeated periodically, since data flows back in.
-
Use your state law by name
A request that cites the specific statute gets a materially better response than a polite email. Your state attorney general's office usually publishes a plain-language guide to what you are entitled to.
-
Understand why this matters here
Government purchase of commercially available location data is one of the clearest end-runs around warrant requirements. Reducing what brokers hold about you is worth doing — and it is not a substitute for the legal rule that should govern the purchase.
Browser and accounts
Cheap changes with a large effect on how much of your behaviour is recorded by default.
-
Use a browser that blocks third-party tracking by default
Firefox and Safari both do out of the box. So does a hardened Chromium build with a reputable content blocker. The default configuration is the one that matters, because it is the one you will actually keep.
-
Turn off ad personalization on platform accounts
Every major platform account has a privacy or ad-settings page controlling how much activity is retained and cross-referenced. These are usually several clicks deep and worth the twenty minutes.
-
Prefer end-to-end encrypted messaging
For ordinary conversations with friends and family. This is not about hiding anything; it is about the sensible default that the contents of your private conversations are not stored in a form somebody else can hand over.
Your home
Devices you installed for convenience that also produce records about your household.
-
Know which devices share footage with police
Several consumer camera and doorbell platforms have offered law-enforcement request or sharing programs, and the terms have changed repeatedly. Check the current setting in your own account rather than relying on what was true when you bought it.
-
Separate smart devices onto a guest network
A guest network or dedicated VLAN limits what a compromised device can see. Most consumer routers support this in about five minutes.
-
Prefer local storage where the option exists
Cameras that record to local storage rather than a vendor cloud produce far fewer records held by a third party — and therefore far fewer records available on request.
What none of this fixes
Every step on this page reduces what is collected with your participation — through an app you installed, an account you opened, a service you connected, a device you bought.
Automated license plate readers do not require your participation. You cannot opt out of a camera on a public road. There is no setting, no permission prompt, no account, and no deletion request. It photographs the car, reads the plate, and writes a timestamped record whether or not you have ever heard of it.
That is the whole reason this organization exists and the reason most of this site is about policy rather than settings. Individual privacy practices are worth adopting and they are not a substitute for rules about what government may build, keep, share, and search.
Privacy practices can reduce your exposure. They cannot guarantee anonymity, and they cannot substitute for a legal limit on indiscriminate collection.
If you have gone through this page and want the part that actually changes the ALPR problem, it is on the action page: find out what your city operates, and be there when the contract comes up.
General information, not legal or security advice. Settings, product names, and available rights change frequently, and this page will not always be current. If you are at elevated risk — because of your work, your immigration status, an abusive ex-partner, or a specific threat — please consult a specialist organization with expertise in your situation rather than relying on a general guide.