Person surrounded by tracking threads from screens, illustrating online privacy
Geeky

Online Privacy Isn’t Dead, But Total Privacy Is

Hey everyone, Eyad here. Is online privacy still a real thing, or did we lose it somewhere between the first cookie banner and the fortieth? People ask me this a lot, usually right after they search for a blender once and then see blender ads in three different apps for a week.

My answer: total privacy is gone, but meaningful online privacy isn’t. Nobody is going to make you invisible, yet you can shrink what’s collected about you by a lot. First, it helps to know who is doing the watching, because it isn’t one machine. It’s several, each with a different weak spot.

Why online privacy feels like a lost cause

You’re not imagining the helplessness. In Pew Research Center’s 2023 survey, 73% of US adults said they have very little or no control over the data companies collect about them. And 67% said they understand little to nothing about what companies do with that data, up from 59% in 2019.

Feeling powerless isn’t the same as being powerless. Much of that gap is confusion, and confusion is fixable.

Who is actually tracking you

WhoWhat they can seeCan you do anything?
Websites and ad networksCookies, your browser’s fingerprintYes, quite a lot
Apps on your phoneLocation, advertising ID, sometimes contactsYes, through permissions
Data brokersThey buy and combine data from the rows abovePartly
Your internet providerWhich sites you connect to, not what you do on themPartly
Platforms you’re logged intoEverything you do inside themOnly by using them less

Cookies: the famous tracker, and the least interesting one

A cookie is a small file a site stores in your browser. A third-party cookie is one placed by an advertiser embedded in the page, which lets the same ad network recognize you across unrelated sites. That’s the “blender ads follow me around” mechanism.

Firefox and Safari block these by default. Chrome doesn’t. Google spent years planning to phase them out, then backed off in 2024 and 2025 and retired its cookie-replacement project. If Chrome is your daily browser, third-party cookies are on unless you switch them off yourself.

Fingerprinting: tracking without storing anything

Browser fingerprint made of device signals, a hidden way online privacy is tracked

Delete your cookies and a fingerprinting tracker just shrugs. A script asks your browser dozens of small questions: screen size, installed fonts, time zone, how your graphics chip draws a hidden shape. Each answer is boring. Together they’re often unique enough to recognize you next time, with nothing saved on your device.

You can see how identifiable your browser is with EFF’s free Cover Your Tracks test. Browsers fight fingerprinting in different ways: Brave scrambles the signals slightly for each site, while Tor Browser and Mullvad Browser try to make every user look identical. Neither is perfect, and both beat doing nothing.

Your phone leaks more than your browser

Smartphone location trail showing how apps can erode online privacy

Websites guess. Apps know. An app with “always” location access can reveal where you sleep, where you work, and which buildings you visit, and that data is often linked to the advertising ID your phone hands to apps. Data brokers collect that stream, combine it with other sources, and resell it.

This isn’t hypothetical. In May 2026, the FTC announced an order banning the data broker Kochava and its subsidiary from selling sensitive location data without consumers’ consent. The agency alleged the companies sold location data from hundreds of millions of mobile devices that could be used to trace individuals’ movements.

Regulators are acting, which is good news. But the FTC sued in 2022, the settlement landed in 2026, and Kochava is one broker in a large industry. Enforcement is real, and slow.

Your ISP and the VPN question

HTTPS encrypts what you do on a site, but your internet provider can generally still see which sites you connect to. A VPN moves that visibility from your ISP to the VPN company. That’s a trade of who you trust, not a cure.

A VPN helps on public Wi-Fi and keeps your browsing away from your provider. It does nothing against cookies, fingerprinting, or an app that already knows who you are.

Why logging in undoes most of it

My own setup is a VPN whenever I’m online, with Brave or Firefox as my main browser. It works, right up until I have to log into one of the big platforms for work or for social reasons. Then the targeted ads show up anyway, even with ad personalization switched off for that platform.

That’s less mysterious than it feels. A VPN and a tracker-blocking browser stop third parties from following you around. They do nothing about the platform you’re signed into, because it knows exactly who you are. And the toggle doesn’t mean what it sounds like. Google’s own help page says that with personalization off you still see ads, based on things like the time of day, the topic of the page, and your location.

I can’t see inside any platform’s systems, so I won’t claim to know why a given ad appeared. The lesson is that an account login is the one place your privacy tools can’t reach.

What still works for online privacy

You don’t need a tinfoil setup. A few changes remove the easy, default tracking:

  • Use a browser that blocks trackers by default. Brave, Firefox, or Safari. On Chrome, turn off third-party cookies in settings and add a content blocker.
  • Audit location permissions. Set anything that doesn’t need your location to “while using” or “ask every time.” Most apps don’t need it.
  • Limit your advertising ID. Both iPhone and Android let you restrict or reset it, which weakens the link between apps and the profiles built on you.
  • Use email aliases for sign-ups. When a list gets sold or breached, it can’t be stitched together with your real address.
  • Keep logins contained. Give the big platforms their own browser profile, so your signed-in activity stays away from your everyday browsing, and sign out when you don’t need the account.

Pro Tip: Don’t change everything in one evening. Start with the two that cost nothing, the location permission audit and a tracker-blocking browser, and live with them for a week before adding more.

So, is online privacy dead?

Total anonymity is dead for most people. Meaningful online privacy is alive, because most tracking runs on defaults: Chrome’s cookie setting, always-on location, a default advertising ID. Defaults are something you can change in an afternoon.

You won’t disappear, and you don’t need to. The goal is to stop being the easy target.

Which of these do you think leaks the most about you, your browser or your phone? I’d love to hear your answer in the comments.

Frequently Asked Questions

Is online privacy really dead?

No. Complete anonymity is unrealistic, but you can cut a large share of tracking by changing browser settings, app permissions, and a few habits.

Does incognito mode make me private?

Not really. It stops your browser from saving history and cookies locally. The sites you visit, your ISP, and your network can still see your activity, and fingerprinting still works.

Does a VPN protect my online privacy?

Partly. It hides your browsing from your ISP and protects you on public Wi-Fi, but it doesn’t stop cookies, fingerprinting, or tracking by apps and sites you’re logged into.

Can I stop data brokers from selling my data?

Only in part. Some brokers honor opt-out requests, and California keeps a public registry of registered data brokers. Opting out is tedious and the data can reappear, so limiting what you hand over in the first place works better.

Related

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.