The Practical Guide to Taking Back Your Data (Without Moving to a Cabin in Montana)
You made it.
You've read about how the government buys your location data without a warrant. How Meta makes $16 billion from scam ads. How your TV makes more money watching you than you paid for it. How your car sold you out for 26 cents. How your period app told Facebook you're pregnant. How 23andMe's bankruptcy put 15 million people's DNA up for auction.
If you're feeling overwhelmed, paralyzed, or like you want to throw your phone into the ocean—that's a reasonable response.
But you're not powerless. You're just under-informed. That changes now.
This is the comprehensive guide to taking back your data. Not everything. You can't undo what's already been collected. But you can close the spigots. You can stop the bleeding. You can make informed choices about what you're willing to trade and what you're not.
Let's get to work.
SECTION 1: YOUR PHONE
Your phone is ground zero. It's with you everywhere. It knows everything. Start here.
Disable Your Advertising ID
Every phone has a unique identifier used to track you across apps and websites. Disable it.
iPhone: Settings → Privacy & Security → Tracking → Toggle OFF "Allow Apps to Request to Track"
Then: Settings → Privacy & Security → Apple Advertising → Toggle OFF "Personalized Ads"
Android: Settings → Privacy → Ads → Delete advertising ID (and confirm)
On older Android: Settings → Google → Ads → Reset advertising ID / Opt out of ads personalization
Audit App Permissions
Go through every app and ask: does this app actually need this permission?
Key permissions to scrutinize:
- Location: Does your flashlight app need to know where you are? No.
- Microphone: Is this app recording audio? Why?
- Camera: When is this app using your camera?
- Contacts: Why does a game need your contact list?
- Health data: Is this app accessing health information?
iPhone: Settings → Privacy & Security → [Permission type] → Review each app
Android: Settings → Apps → [App name] → Permissions
Rule of thumb: If you can't explain why an app needs a permission, revoke it. If the app breaks, you'll find out. If it doesn't break, the permission was unnecessary.
Remove Apps You Don't Use
Every app is a potential data leak. If you haven't opened it in 3 months, delete it.
Check your app library. Be ruthless. That game you played once in 2021? Gone. That shopping app you downloaded for one purchase? Gone.
Fewer apps = fewer attack surfaces = less data collection.
Use Privacy-Focused Alternatives
| Instead of | Use |
|---|---|
| Google Search | DuckDuckGo, Brave Search |
| Chrome | Firefox, Brave, Safari (with privacy settings) |
| Gmail | ProtonMail, Tutanota |
| Google Maps | Apple Maps, OSMand (offline maps) |
| Signal | |
| Standard keyboard | Don't use third-party keyboards (they log everything) |
SECTION 2: SOCIAL MEDIA
Social media is surveillance infrastructure. Here's how to limit the damage.
Download Your Data
Before changing anything, download what these companies have on you. You might be surprised.
- Facebook/Instagram: Settings → Your information → Download your information
- Twitter/X: Settings → Your Account → Download an archive of your data
- TikTok: Settings → Privacy → Personalization and Data → Download your data
- Google: takeout.google.com
- LinkedIn: Settings → Data privacy → Get a copy of your data
Tighten Privacy Settings
Facebook:
- Settings → Privacy → Review all settings
- Limit past posts visibility
- Turn off face recognition
- Disable off-Facebook activity tracking (Settings → Your Facebook Information → Off-Facebook Activity)
Instagram:
- Settings → Privacy → Activity Status → OFF
- Settings → Privacy → Accounts Center → Ad preferences → Limit ad data usage
TikTok:
- Settings → Privacy → Personalization and Data → Turn off as many as possible
- Settings → Privacy → Download your data → Review what they have
Twitter/X:
- Settings → Privacy and Safety → Review all toggles
- Settings → Security and account access → Apps and sessions → Review connected apps
Consider Deletion
If you don't actively use a platform, delete the account entirely. Dormant accounts are still data sources.
Important: Download your data first if you want to keep anything.
Most platforms have a "deactivate" option that isn't deletion. Look for permanent deletion. It's usually harder to find.
If You Must Stay
- Don't use "Login with Facebook/Google" on other sites
- Don't connect your accounts to each other
- Use separate email addresses for each platform
- Review connected apps regularly and revoke access
- Assume everything you post is permanent and public
SECTION 3: YOUR TV
Your smart TV is a surveillance device. Here's how to limit it.
Disable ACR (Automatic Content Recognition)
Samsung: Settings → Privacy Choices → Terms & Policies → Viewing Information Services → Disable
LG: Settings → All Settings → General → System → Additional Settings → Live Plus → Turn Off
AND: Settings → All Settings → Support → Privacy & Terms → Viewing Information → Disable
Vizio: Menu → Admin & Privacy → Viewing Data → Turn Off
Sony: Settings → Device Preferences → Samba Interactive TV → Disable
Roku (built-in or streaming):
- Settings → Privacy → Smart TV Experience → Disable
- Settings → Privacy → Advertising → Limit ad tracking
Fire TV: Settings → Preferences → Privacy Settings → Toggle off data collection options
The Nuclear Option
Don't connect your TV to the internet at all.
Use a separate streaming device (Roku, Apple TV, Fire Stick) that you've configured with privacy settings. Keep the TV itself offline. It becomes a dumb display, which is what you paid for anyway.
Check After Updates
TV manufacturers have been caught re-enabling tracking after software updates. After any update, re-check your privacy settings.
SECTION 4: YOUR CAR
Your car is collecting driving data and potentially sharing it with insurance companies. Here's what to do.
Check What's Been Collected
- Request your LexisNexis report: consumer.risk.lexisnexis.com/request
- Request your Verisk report: personalreports.verisk.com
These are free (thanks to the Fair Credit Reporting Act). What you receive may include driving data you never knew was being collected.
Opt Out of Telematics
This varies dramatically by manufacturer. Generally:
- Check your car's infotainment settings for "Connected Services" or "Data Sharing"
- Check the manufacturer's mobile app (OnStar, FordPass, etc.)
- Check your online account on the manufacturer's website
- Call customer service directly and request opt-out
Warning: Opting out may disable features like remote start, vehicle location, and crash notification. The manufacturers bundle surveillance with useful features deliberately.
GM owners: Given the FTC action, GM must now provide clearer opt-out. Check your OnStar settings and request data deletion.
For New Car Purchases
- Ask about data collection policies before buying
- Read the connected services agreement before signing
- Consider whether you actually need connected features
- Some manufacturers are better than others—research before buying
SECTION 5: MENTAL HEALTH & HEALTH APPS
Health apps may not be covered by HIPAA. Treat them with extreme caution.
Apps to Avoid
Based on FTC enforcement and documented data sharing:
- BetterHelp (shared with Facebook)
- Cerebral (shared with Google, TikTok, Meta)
- Most free mental health apps with advertising
Safer Alternatives
- PTSD Coach — Free, made by VA, no data sharing
- Wysa — AI chatbot with strong privacy protections
- Traditional therapy — Licensed providers are HIPAA-covered
- Employee Assistance Programs — HIPAA-protected
If You've Used Compromised Apps
- Request data deletion through the app's privacy settings
- Submit formal CCPA/state privacy law deletion requests
- Opt out of research sharing
- Delete your account entirely
General Health App Rules
- Read privacy policies before answering sensitive questions
- Look for "marketing partners" or "advertising networks" mentions
- Prefer apps that store data locally, not in the cloud
- Never connect health apps to social media accounts
SECTION 6: PERIOD TRACKERS & REPRODUCTIVE HEALTH
Post-Roe, this data is potentially dangerous. Take it seriously.
Apps to Avoid
Documented data sharing:
- Flo (FTC settlement)
- Clue (third-party sharing)
- Period Tracker by GP Apps
- Glow
- Ovia (shares with employers)
Safe Alternatives
Local-storage-only apps:
- Drip — Open source, no cloud
- Euki — Built by reproductive rights org
- Periodical — Open source, local only
The safest option: Paper calendar or journal
If You've Used Risky Apps
- Delete the app AND your account
- Request data deletion in writing
- Clear your search history related to reproductive health
- Consider the data already out there cannot be recalled
Additional Precautions
- Use a VPN when searching for reproductive health information
- Consider using cash for sensitive purchases
- Be aware that data brokers may already have inferences about your reproductive status based on other behavior
SECTION 7: DNA SERVICES
Your DNA is permanent. If you haven't submitted it, don't. If you have, here's what to do.
If You've Used 23andMe
Given the bankruptcy situation:
- Log in now
- Download your raw data (if you want to keep it locally)
- Go to Settings → 23andMe Data → Delete Data
- Request deletion of genetic information, personal info, and account
- Opt out of research if you previously consented
- Disconnect from DNA Relatives
Do this immediately. Before the auction.
If You've Used Other DNA Services
The same logic applies to Ancestry, MyHeritage, etc.:
- Download what you want to keep
- Delete your account and data
- Opt out of research sharing
If You're Considering DNA Testing
Don't. The privacy risks are not worth learning you're 4% Scandinavian.
If you absolutely must:
- Use a pseudonym
- Use a burner email
- Pay with a prepaid card
- Never opt into research sharing
- Delete as soon as you have results
The Family Conversation
Even if you haven't tested, your relatives' tests affect your privacy. Talk to your family about genetic privacy. This is a collective issue.
SECTION 8: VOICE ASSISTANTS & SMART HOME
Always-listening devices are surveillance devices. Treat them accordingly.
Voice Assistant Settings
Alexa:
- Alexa app → Settings → Alexa Privacy
- Review Voice History → Delete all
- Manage Your Alexa Data → Enable auto-delete (3 months or less)
- Don't Save Recordings → Enable
- Use of Voice Recordings → Disable "Help improve Alexa"
Google Assistant:
- myactivity.google.com
- Delete voice & audio activity
- Set auto-delete to 3 months
- Disable "Help improve speech recognition"
Siri:
- Settings → Siri & Search → Siri & Dictation History → Delete
- Settings → Privacy & Security → Analytics & Improvements → Disable Siri improvement
General Smart Home Rules
- Keep voice assistants out of bedrooms and private spaces
- Use the physical mute button when not giving commands
- Don't connect smart home devices unnecessarily
- Review what data each device collects before buying
- Consider whether you actually need the "smart" features
Ring and Security Cameras
If you use Ring or similar:
- Enable two-factor authentication
- Review who has access to your videos
- Check for linked accounts you don't recognize
- Consider local-storage cameras instead of cloud-connected
SECTION 9: LOYALTY PROGRAMS & RETAIL
Your grocery store knows more than you think. Here's how to limit exposure.
Minimize Loyalty Program Data
If you want to keep using programs:
- Use a dedicated email address (not your primary)
- Provide minimal information (fake birthday, non-primary phone)
- Opt out of third-party data sharing in account settings
- Don't install the retailer's app (use physical cards)
- Turn off Bluetooth when shopping to avoid beacon tracking
The CVS Warning
Never sign the HIPAA waiver for prescription rewards. $5 is not worth your medical privacy.
The Opt-Out Option
Pay cash without a loyalty card. Old-fashioned but effective.
Request your data under CCPA (California) or similar state laws, then request deletion.
Understand the Trade-Off
Calculate how much you actually save versus the value of your data. For most people, the savings are minimal and the surveillance is extensive.
SECTION 10: DATA BROKER OPT-OUTS
This is tedious but important. Data brokers are the pipes that carry your information everywhere.
Major Data Brokers to Opt Out Of
| Broker | Opt-Out Link |
|---|---|
| Acxiom | isapps.acxiom.com/optout |
| Oracle/Datalogix | datacloudoptout.oracle.com |
| Epsilon | epsilon.com/privacy-policy |
| LexisNexis | consumer.risk.lexisnexis.com/request |
| Experian | experian.com/privacy/opting_out |
| Equifax | myprivacy.equifax.com |
| TransUnion | transunion.com/privacy |
| Spokeo | spokeo.com/optout |
| Whitepages | whitepages.com/suppression-requests |
| Intelius | intelius.com/opt-out |
| BeenVerified | beenverified.com/opt-out |
| PeopleFinder | peoplefinder.com/opt-out |
The Process
- Visit each site
- Search for yourself
- Submit opt-out/removal request
- Verify by email if required
- Check back in 30 days to confirm removal
- Repeat periodically (some re-add you)
Consider a Removal Service
This is tedious work. Services like DeleteMe, Privacy Duck, and Kanary will do it for you for a fee. Evaluate whether the time savings are worth the cost.
SECTION 11: FOR PARENTS — PROTECTING YOUR KIDS
Children are the most vulnerable and most valuable demographic. Protect them aggressively.
Device-Level Controls
iPhone: Settings → Screen Time → Content & Privacy Restrictions
- Limit app installations
- Restrict explicit content
- Prevent privacy setting changes
Android: Set up Family Link
- Approve app installations
- Set screen time limits
- Review app activity
App-Specific Actions
- Don't let kids under 13 use social media (COPPA exists for a reason)
- If teens use social media, review privacy settings together
- Disable in-app purchases on all devices
- Check what data has been collected via parental data requests
Voice Assistants and Kids
- Keep Alexa/Google out of kids' rooms
- Review and delete voice history regularly
- Enable parental controls in assistant apps
- Consider whether your family actually needs these devices
The Conversation
Talk to your kids about data privacy. Age-appropriate conversations about:
- Why apps want their data
- What happens when they share information
- How to recognize when something feels wrong
- Why some things should stay private
SECTION 12: FOR ADULT CHILDREN — PROTECTING YOUR PARENTS
Elders are heavily targeted by scammers using data broker information. Help them.
Have the Conversation
- Explain how scammers get their information
- Show them examples of scam ads
- Establish a "call me before you click" rule
- No judgment—scammers are sophisticated
Practical Steps
- Help them opt out of data brokers (especially those selling to marketers)
- Review their social media privacy settings
- Set up a family code word for verifying unexpected requests
- Enable two-factor authentication on their accounts
- Consider call-blocking apps like Nomorobo
Warning Signs
- Unexpected packages or subscriptions
- Withdrawals they can't explain
- New "friends" asking for money
- Reluctance to discuss finances
- Mail from sweepstakes or charities they don't recognize
Tools That Help
Apps like ZoraSafe are designed specifically to help protect vulnerable users by identifying data leaks, suspicious apps, and potential scam vectors. Set them up for your parents.
SECTION 13: TOOLS THAT HELP
You don't have to do all of this manually. Tools exist.
Privacy Tools
| Tool | What It Does |
|---|---|
| ZoraSafe | Shows where your data is going, identifies risky apps, protects vulnerable users |
| Privacy Badger | Browser extension that blocks invisible trackers |
| uBlock Origin | Ad and tracker blocker |
| Signal | Encrypted messaging |
| ProtonMail | Encrypted email |
| DuckDuckGo | Privacy-focused search |
| Bitwarden/1Password | Password managers |
| NordVPN/ProtonVPN | VPNs for hiding your IP address |
Automated Opt-Out Services
| Service | What It Does |
|---|---|
| DeleteMe | Removes you from data broker sites |
| Privacy Duck | Data broker removal |
| Kanary | Monitors and removes personal info |
| Incogni | Automated opt-out requests |
Browser Settings
Whatever browser you use:
- Enable "Do Not Track"
- Block third-party cookies
- Clear cookies regularly
- Use private/incognito mode for sensitive searches
SECTION 14: ADVOCACY — MAKING YOUR VOICE HEARD
Individual action matters. Collective action changes systems.
Support Better Laws
Federal level:
- The "Fourth Amendment Is Not For Sale Act" would close the warrant loophole
- Comprehensive federal privacy legislation is overdue
- FTC funding and enforcement authority needs expansion
State level:
- California (CCPA/CPRA), Virginia, Colorado, and others have privacy laws
- Push your state to pass strong privacy legislation
- Support expanding children's privacy protections
How to Advocate
- Contact your representatives (Congress.gov has contact info)
- Support organizations fighting for privacy (EFF, EPIC, Consumer Reports)
- Share this information with others
- Make privacy a voting issue
- Push back when companies overreach
Use Your Consumer Power
- Leave reviews calling out bad privacy practices
- Choose companies with better privacy policies
- Complain publicly on social media
- File FTC complaints when companies violate privacy
THE BOTTOM LINE
You've now seen behind the curtain.
The government buys your location data without a warrant. Social media conducts "vast surveillance." Your TV makes more money watching you than you paid for it. Your car sold you for pocket change. Your health apps betrayed your trust. Your DNA might be auctioned to the highest bidder.
The surveillance infrastructure is vast. The legal protections are weak. The companies are powerful.
But you're not powerless.
Every setting you change, every app you delete, every opt-out you submit chips away at the data economy. Every conversation you have with family spreads awareness. Every advocate who speaks up builds pressure for change.
This guide gives you the tools. What you do with them is up to you.
You can't undo what's already been collected. But you can stop feeding the machine. You can protect yourself and the people you love. You can make informed choices about what you're willing to trade.
The companies are counting on you being overwhelmed. They're counting on you giving up. They're counting on the problem being too big and too abstract to fight.
Don't give them that.
Start somewhere. Start anywhere. But start.
Your data is your life. It's time to take it back.
Quick Start Checklist
If you only do ten things, do these:
- Disable your phone's advertising ID
- Review and revoke unnecessary app permissions
- Enable auto-delete on voice assistant history
- Disable ACR on your smart TV
- Request your LexisNexis driving report
- Delete unused social media accounts
- Download and delete 23andMe data (if applicable)
- Delete risky period/health tracking apps
- Opt out of three major data brokers
- Talk to one family member about what you learned
You finished the series. Now share it with everyone who needs to see it.
The "Who Sold My Data?" series is free, public, and shareable. Send it to your parents. Send it to your kids. Send it to your friends who keep asking why they see such weird ads.
The more people who understand this system, the harder it becomes to sustain.
Thank you for reading. Now go protect yourself.
This guide is current as of January 2025. Privacy settings and opt-out processes change frequently. When in doubt, search for current instructions or contact the platform directly.
