You mention something out loud near your phone — a brand of running shoes, a place you’re thinking of visiting, a medical symptom — and within a day, an ad for exactly that shows up in your feed. Or you search for a product once, close the tab, and spend the next week seeing it follow you across every website you visit. It feels like surveillance, and in a loose sense, it is. But it’s rarely as dramatic as it feels. Nobody is listening to your microphone in most of these cases. What’s actually happening is quieter, more automated, and more thoroughly built into the ordinary infrastructure of the internet than most people realize.

That’s the useful reframe: online privacy isn’t primarily a story about bad actors breaking in. It’s a story about how much of your normal, unremarkable activity — searches, clicks, app use, purchases — gets collected, connected, and sold as a matter of routine business. Understanding how that works is what makes it possible to actually do something about it, instead of just running through a checklist and hoping.

Is online privacy the same thing as online security?

No, and conflating the two is where a lot of privacy advice goes wrong. Security is about someone gaining access they shouldn’t have — a stranger breaking into your email account, malware stealing your files, a scammer tricking you into handing over a password. Privacy is a different problem: it’s about how much of your legitimate, everyday activity is being observed, recorded, and monetized by companies you’re knowingly using.

This distinction matters practically because the tools people reach for tend to address one problem while leaving the other untouched. A VPN mostly hides your traffic from your internet provider and from networks you connect to — it does very little to stop a website from fingerprinting your browser or a data broker from selling your address. Antivirus software is about malicious code, not about the ordinary, fully legal tracking built into most of the web. People who install both and still feel constantly tracked aren’t imagining it. Those tools were never aimed at this problem, because it isn’t a security problem — it’s a data-collection problem, and it needs a different set of responses.

How does tracking actually work?

This is the part worth understanding properly, because the fixes only make sense once the mechanism is clear. There isn’t one kind of tracking — there are several distinct ones, and they call for different responses.

Cookies and cross-site tracking

A cookie is a small piece of data a website stores in your browser so it can recognize you on a return visit — useful for staying logged in or keeping items in a cart. The privacy issue is a specific variant: many pages embed small pieces of code from advertising and analytics companies, and those embedded trackers can set their own cookies too. Because the same tracking company’s code sits on thousands of unrelated websites, it can recognize your browser as it moves from one site to the next and stitch together a profile of where you’ve been — this is cross-site tracking. It’s why an item you looked at on one shopping site can show up as an ad on a completely unrelated news site days later.

Browser fingerprinting

Fingerprinting is subtler and doesn’t rely on cookies at all. Your browser and device have a combination of characteristics — screen size, installed fonts, timezone, browser version, graphics hardware, and dozens of smaller settings — that, taken together, is often unique or nearly unique to your specific device. A tracking script can read this combination and generate an identifier for you without ever storing anything on your machine. This is precisely why “I cleared my cookies” doesn’t fully solve tracking: clearing cookies removes the sticky note, but fingerprinting recognizes your handwriting.

Account-level tracking

The third mechanism is the most straightforward and, in some ways, the hardest to avoid: when you’re logged into a service and using it as intended, that service legitimately knows a great deal about you, because you’re handing it that information directly — what you search, what you watch, who you message, where you go if location is enabled. This isn’t a trick or a leak. It’s the product working as designed, funded by the data it collects about your use of it.

These three are genuinely different problems. Blocking cookies does nothing about fingerprinting. Avoiding fingerprinting does nothing about the fact that a service you’re logged into simply knows what you told it. A realistic privacy approach addresses each one differently rather than assuming one setting handles all three.

Does private or incognito browsing actually protect you?

It protects you from one specific thing: your own browser keeping a record. When you close a private browsing window, it doesn’t save that session to your local history, and it typically doesn’t retain cookies from that session afterward. That’s genuinely useful if you’re using a shared or borrowed device and don’t want the next person to see what you looked at.

What it does not do is hide your activity from your network, your employer or school (if you’re on their network or a managed device), your internet provider, or the websites you actually visit. A site you log into during a private session still knows it’s you. Your workplace’s network monitoring still sees the same traffic it always would. This is the single most common misconception in everyday privacy habits — people treat private browsing as a general anonymity tool when its real job is much narrower: keeping something out of your own device’s history, not out of anyone else’s view.

What browser settings meaningfully reduce tracking?

Most modern browsers include privacy settings and tracker-blocking features that are worth turning on, and they do meaningfully cut down cross-site tracking — blocking known tracking scripts, limiting cross-site cookies, and in some cases resisting fingerprinting by making your browser’s configuration look more like everyone else’s. These settings are usually found under a privacy or tracker-protection section of the browser’s settings menu, and turning on the strictest reasonable option is a genuinely useful five-minute task.

The honest caveat: no browser setting eliminates tracking entirely. Fingerprinting techniques evolve, some sites break functionality if tracking protection is too aggressive, and account-level tracking happens regardless of browser settings because it’s based on you being logged in, not on cookies or scripts. Think of browser privacy settings as raising the cost and reducing the volume of tracking, not switching it off.

Why does search history reveal so much?

Of all the tracking surfaces in ordinary internet use, search history is one of the most revealing, simply because of what people search for. A browsing history shows where you went; a search history shows what you were thinking — health concerns, financial worries, relationship questions, things you’d never say out loud to anyone. Search engines that keep this history tied to your account are sitting on a genuinely intimate record, accumulated one ordinary query at a time.

Most search engines offer a way to view, pause, or delete stored search history, and some let you search without an account or in a way that isn’t tied to your identity at all. It’s worth knowing which mode you’re actually using, since the default is usually the one that retains the most.

What are data brokers, and why don’t more people know about them?

This is probably the least understood piece of the online privacy picture, mostly because data brokers don’t interact with you directly — you never sign up for them, never see their interface, and often don’t know they exist until something surfaces your information unexpectedly.

A data broker is a company whose business is aggregating personal information from many sources — public records (property records, court filings, voter registrations), purchase histories obtained from retailers and loyalty programs, and other companies that sell or share data — and compiling it into profiles that get sold on, often to marketers, background-check services, or anyone willing to pay. A single broker might hold your name, address history, phone number, relatives, estimated income bracket, and purchasing habits, all stitched together from sources you never directly gave that information to in combination.

Here’s the honest part that most privacy advice skips: opting out of data brokers is genuinely tedious. Where opt-out mechanisms exist, they’re often broker-by-broker, sometimes require mailing a written request or verifying your identity with the very documents you’re trying to keep private, and the data frequently reappears months later because brokers keep re-purchasing and re-aggregating from the same underlying sources. This isn’t a five-minute fix, and it’s fair to be skeptical of anyone who presents it as one. It’s still worth doing for the handful of brokers most relevant to you — often the ones connected to background-check or people-search sites — but go in expecting an afternoon of repetitive form-filling, not a single toggle.

Do app and account permissions matter?

Yes, more than most people revisit them. When you install an app or sign up for a service, you typically grant permissions once — location, contacts, microphone, camera, photo library — and then never think about it again. Those permissions don’t expire on their own, and an app that needed your location for one feature two years ago may still have standing access to it today, whether or not you use that feature anymore.

A periodic review — every few months is reasonable — of what apps and browser extensions actually have access to your location, contacts, and microphone is one of the more mechanically simple things you can do, and it directly limits ongoing collection rather than just cleaning up after the fact. Most phones and browsers have a single settings screen that lists every app and its granted permissions, which makes this faster than it sounds.

If a service is free, does that mean I’m the product?

It’s a cliché, but the underlying mechanism is real and worth understanding without either panic or cynicism. Running a large online service costs money — servers, staff, development — and free services need a way to pay for that. For many of them, the answer is collecting data about how you use the service and using it (directly or through advertising) to generate revenue. That’s not a hidden scam; it’s usually disclosed, if not always prominently, and it’s the actual business model of a large share of the free internet.

Framing this as a moral failing on your part for using free services isn’t accurate or useful — nearly everyone does, and the convenience is real. What’s useful is being conscious of the trade-off: a free service is, in a real sense, being paid for with your data and attention rather than your money, and it’s fair to occasionally ask whether that exchange still feels worth it for a given service, the same way you’d evaluate any other cost.

What privacy habits actually reduce tracking, and what’s mostly theatre?

Not all popular privacy advice carries equal weight, and it’s worth being honest about the difference.

Lower impact than commonly assumed:

  • Using private/incognito mode as a general privacy tool — it only affects your local browser history, not tracking by sites or networks.
  • Clearing cookies occasionally without also addressing fingerprinting or account-level tracking — it resets one mechanism while leaving two others fully intact.
  • Treating a single tool, like a VPN, as a complete privacy solution — worth having for its specific purpose, but it isn’t built for this problem, as covered above.

Genuinely higher impact:

  • Turning on your browser’s tracker-blocking and cross-site cookie protections.
  • Periodically reviewing app and service permissions and revoking what’s no longer needed.
  • Being deliberate about which services you log into for routine browsing versus browsing logged out where it doesn’t cost you functionality.
  • Reviewing and tightening privacy settings on the accounts and social platforms you actually use regularly.

What’s a realistic level of online privacy to aim for?

Complete privacy online isn’t realistically achievable for most people living a normal, connected life — using search engines, social platforms, mobile apps, and online shopping inherently generates data, and avoiding all of it would mean giving up most of the modern internet’s convenience. That’s not a failure of effort; it’s the nature of how these services are built and funded.

A more useful goal is proportionate: reduce unnecessary and easily avoidable tracking, be deliberate about the data trade-offs you’re making rather than accepting every default, and put real effort into the handful of areas where exposure is highest for you specifically — that might be data brokers if you’ve had privacy concerns before, or account permissions if you use a lot of apps, or social media settings if you’re a heavy user. Trying to eliminate every trace of your online presence usually isn’t worth the convenience it costs; a reasonable, sustained set of habits is.

Are the default privacy settings on social media good enough?

Generally not — default settings on most social platforms lean toward more visibility and more data sharing, not less, since broader sharing tends to support the platform’s own engagement and advertising goals. The privacy controls that let you limit who sees your posts, your friend or follower list, your location tagging, and your activity status typically exist, but they sit a few menus deep and aren’t the default state.

It’s worth reviewing these settings periodically rather than once — platforms redesign their settings pages and occasionally reset preferences during updates, and a setting you tightened a year ago may have quietly reverted or been superseded by a new option you haven’t looked at.

The FTC keeps consumer guidance on online privacy and security, and the Information Commissioner’s Office covers your rights over data held about you.

Frequently asked questions

Is someone actually listening to my phone’s microphone to serve me ads?

There’s no credible evidence of this happening at scale, and the mechanisms described above — cross-site tracking, fingerprinting, and account-level data — are more than sufficient to explain the “it heard me” feeling without needing microphone access at all. Search history, location data, purchase patterns, and who you’re connected to online can predict interests with startling accuracy on their own.

Do I need a VPN for privacy, not just security?

Whether you need a VPN at all is worth reading on its own, but for privacy specifically the short version is that a VPN hides your traffic from your network and provider — it doesn’t stop cookies, fingerprinting, or account-level tracking, so it isn’t a substitute for the habits covered in this article.

Will a password manager help with privacy?

Not directly — password managers are a security tool for keeping your accounts from being broken into, which is a different problem from how much your legitimate activity is tracked.

How do I know if something is a privacy risk versus a scam?

Tracking and data collection are typically disclosed, if buried, and operate through legitimate business relationships; a scam is designed to deceive you outright. Spotting scams is a distinct skill from managing privacy, and conflating the two tends to cause unnecessary alarm over ordinary advertising while under-preparing for actual deception.

Is deleting cookies enough to stop being tracked?

No. Cookies are one of at least three separate tracking mechanisms — deleting them addresses cross-site cookie tracking but leaves fingerprinting and account-level tracking untouched, which is why people who clear cookies regularly still see familiar patterns in what gets advertised to them.

Should I pay to opt out of every data broker?

Most data broker opt-outs are free but time-consuming rather than paid; some paid services exist to automate the process across many brokers at once, and they can be worth the cost if the manual effort isn’t realistic for you, but they don’t guarantee permanence since brokers can re-acquire your data from the same original sources over time.