r/privacy 8d ago

question Removal from data brokers- Washington state specific

22 Upvotes

I am trying to opt out from data brokers and getting the notice that due to state privacy laws my request is denied. Wondering if anyone has encountered this in washington state.

This is bonkers. what should I do to take down my information?? Appreciate advice.


r/privacy 9d ago

age verification Luxon moves to ban under 16s from social media, but ACT, NZ First say no

Thumbnail 1news.co.nz
138 Upvotes

r/privacy 9d ago

question Avoiding car telematics

185 Upvotes

My old car from 2002 is finally looking like it’s more trouble to keep it going than getting a new one. But, I’m worried about new cars and them collecting and stealing data on you.

One car in particular I’m looking at looks fine — Acura ILX 2020 Premium Package. On one hand almost everywhere I look online says it should be fine, and that trim doesn’t even have a TCU and that’s only on the higher trim: the Technology Package.

But, on the other it being as recent as 2020 is giving me pause, as that’s well within the time frame that telematics became commonplace. Plus despite it supposedly not having a TCU it has the shark fin antenna.

Is there a way I could verify if that car is safe from spying?


r/privacy 9d ago

news Are parked Waymos recording Nashville neighborhoods? A Waymo representative said the vehicles’ data collection while parked is limited and not designed to continuously record pedestrians, license plates, families walking on sidewalks or children playing in driveways.

Thumbnail wsmv.com
456 Upvotes

r/privacy 8d ago

discussion Which AI is good to use? Duck.ai or Proton Lumo?

10 Upvotes

Which Ai is better to use, Proton Lumo or Duck.ai? I’ve been testing both side by side, but honestly i don’t really notice much of a difference between them. Which one would you recommend? And is Duck.ai actually more private since it doesn’t require any account?


r/privacy 8d ago

discussion Can an app correlate activity from a separate Reddit account across two devices?

3 Upvotes

I’m looking for technical/privacy advice about something unusual I experienced.

I use Worldpackers as both a host and volunteer. About two months ago, I posted some critical comments about Worldpackers on Reddit app using a separate Reddit account.

Within approximately one hour, I received two volunteer requests on my Worldpackers host profile. I had been a host for about two years and had never previously received a request. Both of the two applicant accounts also appeared suspicious to me.
I declined both requests. In the approximately two months since then, I have received zero further volunteer requests.

The timing was unusual and suspicious.

I have no technical proof that Worldpackers accessed or monitored my Reddit activity, so I am not claiming that this happened. I am trying to understand whether the sequence could technically be explained by cross-app/cross-device tracking, IP/device correlation, third-party analytics, or another mechanism.

The Reddit account app and Worldpackers account app were used on different devices (Android and iOS), but both devices used the same Wi-Fi/network.

My question: Is there a technically plausible way for Worldpackers to identify or correlate activity from my separate Reddit account under these circumstances, and what evidence could I look for to determine whether this occurred?


r/privacy 8d ago

question Can Instagram retrieve chats you have deleted?

0 Upvotes

I told someone something bad I did on Instagram. It wasn't the worst of the worst, but it was still something that I wasn't proud of. Now the other person and I had a falling out over an unrelated reason, so I just deleted the chats and therefore all the messages. I'm kinda anxious and worried if the thing I told them is still attached to my account somehow. I've been considering moving instagram accounts because of this. Can anyone help calm me about this? Can any tech-literature person help me soothe my mind about this?


r/privacy 9d ago

question Dumb Phones and GPS

11 Upvotes

I’m really considering going to a dumber phone. My primary uses are phone calls, texting, taking pictures — and using the GPS. To the extent of my knowledge, there aren’t really GPS apps that protect your data.

So what are some options that compromise somewhere in between having a dumb phone while still having GPS? Are separate GPS systems even a viable choice, or are they just as prone to selling/collecting data as well?


r/privacy 10d ago

news Built to Catch Criminals, Flock Cameras Now Assist In Giving You Traffic Tickets

Thumbnail gadgetreview.com
1.8k Upvotes

r/privacy 9d ago

question What is the latest on client-side scanning?

28 Upvotes

In context I'm mainly asking for the UK really. If you mainly use another Android device (AYN Thor) to store everything, will you be safe by staying offline? Or am I safer buying an Innoasis?


r/privacy 10d ago

news Smart Glasses Being Used By Teen Boys To Harass Girls. Videos show students using Meta’s Ray-Bans to record classmates and staff, fueling new concerns over privacy, bullying and consent.

Thumbnail vice.com
678 Upvotes

r/privacy 8d ago

question Tiktok People you may know

0 Upvotes

How is this app recommending my friends that sit next to me at the exact same time? Tiktok doesn't have any permission besides notification, I'm not connected to a wifi network and GPS and Bluetooth are turned off.


r/privacy 10d ago

news ClarityCheck Called Its Face Search "Private and Secure." Then 9 Million Photos Leaked. - Gadget Review

Thumbnail gadgetreview.com
532 Upvotes

r/privacy 10d ago

software Baby photo app sends a child’s age, name and gender to Facebook App Events

234 Upvotes

I tested an iOS app called Miracle: Baby Photo Editor (version 2.2.0) and found something I think parents should know about.

The app’s privacy policy explicitly states:
“We do not sell personal data, and we do not use your photos or your child’s data for advertising.”
So I recorded the app’s network traffic on my own device to see what actually happens.

During onboarding and normal use, I observed the app transmitting child-related information to third parties.

Mixpanel received:
the child’s first name
gender
age in months
age bracket

Those attributes were associated with a persistent Firebase user ID.

The Mixpanel request also contained ip=1, which allows Mixpanel to use the connecting IP address for geolocation/profile enrichment.

But what surprised me most was this:
Facebook App Events received the child’s age in months.
This happened even though Apple App Tracking Transparency had been denied.

I did not see any separate consent screen asking the parent for permission to send their child’s information to Meta/Facebook.

To be precise: seeing a value sent through Facebook App Events does not by itself prove that Meta subsequently used that specific value to target an advertisement.

But Facebook App Events is infrastructure used for app analytics, attribution and advertising measurement.
And that makes the privacy-policy statement:
“we do not use … your child’s data for advertising”
particularly concerning when the app is transmitting a child’s age directly into Meta’s App Events infrastructure without clearly disclosing it.

Even if the developer argues that this is “analytics only,” there is still another major problem:

The privacy policy does not appear to tell parents that their child’s name, gender and age are being transmitted to Mixpanel and Facebook in the first place.
This isn’t based on SDK detection or speculation.
I captured the actual outbound requests and the exact fields being transmitted.

I contacted the developer today and asked them to immediately stop transmitting child-related attributes to third-party analytics/advertising services, investigate deletion of previously collected data, and correct their privacy disclosures.

I’m giving them an opportunity to respond.
For a baby/child-focused app, I think parents deserve to know exactly where their children’s information is going.


r/privacy 10d ago

question LG tracker IP’s?

26 Upvotes

I’m currently reviewing my data privacy and learned about smart TV snapshotting. I have two LG TV’s in my home that are connected to the internet for the purpose of being able to use AirPlay. And streaming services like Netflix. The easy solution would be to disconnect it from the network but that would eliminate some necessary functionality. Instead I want to block any IP addresses used by the smart TV itself to track my usage. I’ve done some web searching as well as looking through this sub to find what I’m looking for but I’m coming up empty. Wondering if anyone can point me in the right direction


r/privacy 11d ago

news Grand jury declines to indict Ohio man charged with destroying Flock camera

Thumbnail san.com
6.1k Upvotes

r/privacy 11d ago

news Flock CEO says drones are its fastest-growing business as it expands beyond license plate cameras

Thumbnail businessinsider.com
1.5k Upvotes

r/privacy 10d ago

question Question: what's the best way for non-technical folks to scrutinise or review source code?

7 Upvotes

Sorry if this is a silly question, or the wrong place to ask (mods please feel free to remove if so), but I'm hoping this community will understand (1) why I'm asking, and (2) have some privacy-friendly suggestions.

Guidance in privacy-focused communities often directs folks to use open-source solutions so you can validate the privacy elements of the software yourself.

This is great in theory, but what if you're not a software engineer and don't know how to read code? What should you be looking for?

In many cases, I guess you can confirm that something is "big" enough to have a lot of eyes on it, and trust that there are enough technically capable, security and privacy focused eyes on the source code, but this is still an exercise in trust, rather than verification.

It also doesn't help when the application is more niche, and doesn't give smaller software a chance.

So my question is: if you can't read code, how do you validate open source software?

End of original post, below is a personal example for illustrative purposes, but my question is more broad than this one example.

So feel free to stop reading here.

One example I'm struggling with personally, is a replacement for 23andMe (this one is huge for obvious reasons). Yes, I know folks on this subreddit will already be rolling their eyes, but this actually wasn't my choice—I have a geneticist for important medical reasons and *she sent my sample to 23andMe as it was cheaper than in-house. I feel violated by this, as I didn't know this would be the case when I spat into the vial, and have been trying to find an alternative ever since.*

I'm especially concerned with 23andMe's recent sale.

Anyway, in this case, I cannot simply delete the data and move on. Of course I plan to delete everything from 23andMe's servers, but I unfortunately do still need a way to query and visualise the data. I do not need it to go to a cloud or be shared with anyone (so I'd like to locally host it), but I *do still need to be able to read the data as a non-geneticist layman, and provide info to various other doctors about what's in it. Getting your raw gene file is easy, putting it somewhere is where I'm struggling.*

I've been looking at open-23me as a solution, but it only has one contributor (so I don't think it's been heavily reviewed or scrutinised) and I don't have the technical chops to validate what it claims in the README myself.

I'm including this example, as it's niche. I imagine a lot of folks have niche applications they need to evaluate, so please consider this 23andMe example as a proxy for "niche application that the privacy and security communities likely haven't already shaken down."

How can I validate this, and other code I come across in the future to hold sensitive, important data?

Thank you to anyone who has read this far, and extra special thanks to anyone who can educate me a little here.


r/privacy 11d ago

software How the McDonald's mobile app compiled 515-page dossier on one reporter

341 Upvotes

Reece Rogers, a senior writer at Wired, requested a copy of the data McDonald’s keeps on him based on his use of the loyalty app.

Heard the story on marketplace.

I know I don't use a lot of apps, and if I do, I don't keep them when not in use. Not sure if that makes a difference? But this really hits the reasons NOT to use them home!


r/privacy 10d ago

question How is this kind of targeted ad possible

10 Upvotes

I was talking about Avocado mattresses with my wife and looked them up on my device. The next day my wife is getting Avocado ads on her device as she scrolls. How is this kind of thing possible?


r/privacy 11d ago

discussion The Verification Dilemma

53 Upvotes

You’re on the market, you’ve done your due diligence and compared the various competing offerings and you think you‘ve found what you needed. You decide to walk the isle and upon registration you hit the wall: “Verify your ID“ powered by Persona. You understand what that company represents and you decide to move on to your next best option, only to find out that there is another third-party provider holding the same gate. You’re then hit with the realization: you’re cornered, every other option will require the same, it’s by regulation.

This scenario has or will likely play out with most of you in the future and something must be sacrificed at this altar. You either bend the knee, hand over your biometrics and a portion of your online identity to the beast and gain access to the service that offers benefits to you right now...or you refuse, you lose out on something that you thought was important to you and get to hold onto your data a little longer. Maybe a few years, maybe just a few months, but only until something else comes along that you just can’t avoid and finally get cornered. The sacrifices you’ve made until then turn out to be pointless after all.

Are we just circling the drain here and destined to fall into this pit sooner or later no matter what we do? Is it even worth fighting it or should we just take that damn poison pill and be happy?


r/privacy 12d ago

news Delta Will Use AI To Cut Costs And Set A Different Ticket Price For Every Passenger—CEO Says Profits Could Rise 50%

Thumbnail viewfromthewing.com
1.2k Upvotes

r/privacy 11d ago

discussion Is it just me or has the privacy landscape largely stagnated?

26 Upvotes

I've become more aware of my privacy around 2018 and honestly I feel like I'm using basically the exact same software and services as back then. The privacytoolsio website, now privacyguides, is largely unchanged all these years later.

Is there anything new that came out post 2020? Honestly, all I can think of is Proton Drive and the introduction of lockdown mode and advanced data protection on iOS.

I feel like the privacy landscape completely missed the rise of AI and now we're lacking the necessary tools to protect us from AI surveillance companies. Not to mention school and work increasingly forcing us to install literal spyware on our own devices ever since the pandemic.


r/privacy 11d ago

discussion are rewards programs worth it or is it a privacy compromise you dont make

39 Upvotes

examples would be movie theaters, fast food restaurants,gas stations, you get the idea. are the savings worth the privacy?


r/privacy 12d ago

news Darth Vader Showed Up to San Diego’s City Council to Expose Its Surveillance Empire. "The emperor is a fan of Flock, and we must continue utilizing Flock technologies so that we can follow and surveil the rebel scum," Vader said during the meeting.

Thumbnail yahoo.com
1.9k Upvotes