Privacy Is a Dial, Not a Switch
A Practical Guide to Managing Your Personal Exposure
Farsight Intelligence · Brett Maternowski
A Word Before We Start
Turn the dial down too far and you don’t just disappear. You break.
I’ll be straight with you. I’m a privacy advocate who professionally dismantles privacy for a living. I hold a Florida PI license (#3500261), and that license is the very thin line between what I do and what the federal government calls espionage. I locate people, trace assets, profile exposure, and build intelligence packages on individuals and businesses, all legally, all within scope, all documented. The irony isn’t lost on me.
That background is exactly why this guide exists. I know what’s visible about you. I know how fast someone with the right tools can pull it together. I work with deep data sets from commercial brokers and aggregators that most people don’t know exist. I use open-source intelligence, what the intelligence community calls OSINT, pulling together publicly available information from court records, social media, business filings, domain registrations, property records, news archives, forum posts, and dozens of other sources to build a complete picture of a person or organization. And when the data I need isn’t available through standard channels, I have a professional network of specialists who can access legal data sources that simply aren’t available to the general public. Licensed financial data. Proprietary records networks. Sources that take years of relationship-building to access. Legal. Documented. Thorough.
I know what the people who want to know things about you are capable of. This guide is written from that side of the desk.
This isn’t about going dark. It’s about knowing where you are and making intentional choices.
The Anonymity Trap
Anonymity sounds appealing. It isn’t practical.
Automated underwriting for life insurance, property insurance, mortgage lending, and commercial banking runs on your public record. It cross-references your identity, address history, credit profile, and public data footprint. If your record is too thin, too inconsistent, or doesn’t resolve cleanly, you don’t look private. You look like a liability or a fraud. The system doesn’t reward invisibility.
The goal is managed exposure, not zero exposure. You want to be visible where it helps you and quiet where it doesn’t.
Section 1: The Machine Is Already Watching. Here’s What That Actually Means.
Before we get to the checklist, you need to understand what you’re up against. Not in a theoretical way. In a this-already-happened-to-real-people way.
The data ecosystem around you is not a collection of separate systems. It is one system.
Your phone knows where you are. Your apps know what you’re doing. The cameras on the roads know where your car has been. The weather app knows you weren’t home. The retail loyalty card knows what you bought. The credit card knows when you bought it. And all of that data is being cross-referenced, scored, and sold, continuously, in real time, without your awareness and usually without meaningful consent.
Here’s what that looks like in practice.
The Surveillance Infrastructure You Drive Through Every Day
Most people think of surveillance cameras as isolated devices. A ring doorbell. A bank ATM. A traffic light. What they don’t understand is that those devices are increasingly nodes in a connected network that logs, retains, and shares data across agencies and platforms.
Flock Safety is one of the most visible examples. Flock sells license plate reader cameras to homeowners associations, local police departments, and private communities. As of 2024, they had partnerships with over 5,000 law enforcement agencies and hardware deployed across millions of locations nationwide. But Flock is one piece of a much larger picture.
Alongside Flock, cities and private operators run fixed LPR systems on arterial roads, highway on-ramps, and bridge checkpoints. Private parking operators run their own plate readers. Some retailers log every plate that enters their lot. Insurance companies have started deploying LPR infrastructure and acquiring the resulting data.
Then there are ShotSpotter and similar acoustic gunshot detection systems. Originally marketed for detecting gunfire, these devices contain microphones that continuously record ambient audio in the areas they cover, which in some cities means entire residential neighborhoods. The recordings are retained. Law enforcement has accessed them in investigations unrelated to gunfire.
Private camera networks, Ring doorbells, Nest cameras, Arlo systems, and commercial CCTV, feed into platforms like Amazon’s Neighbors app and local police department partnerships that allow voluntary, and sometimes not entirely voluntary, data sharing. A detective looking for a vehicle doesn’t need a warrant to ask Ring users if they captured footage. Ring has a portal that facilitates exactly that request at scale.
Put it together and here’s what exists: every time your car moves, there is a reasonable probability that its location is being logged. Not by one system. By several, simultaneously, cross-referencing each other.
Every time your plate passes a reader, the time, date, location, direction of travel, and a photo of your vehicle are logged. That data is retained and searchable. Law enforcement can query most of it without a warrant.
But here’s what most people miss. Flock isn’t just a camera company. It’s a subscription intelligence platform. The business model is recurring revenue built on data retention and cross-agency sharing. Your movement history isn’t stored to help find a stolen car. It’s stored because stored data is a product. The same is true of every private camera network that feeds into a shared platform. The hardware is the entry cost. The data is the business.
The Phone Data Market
Your phone’s advertising ID, a unique string your device broadcasts to apps, is being sold thousands of times per day. Every app that has location permissions is potentially selling your location data to a data broker. That broker sells it to advertisers. And in a growing number of cases, to lawyers and law enforcement.
This isn’t hypothetical.
In 2023, the Wall Street Journal and multiple subsequent investigations confirmed that lawyers in civil litigation were purchasing location data from commercial brokers to track the movements of opposing parties. No subpoena. No warrant. No court order. Just a credit card and a data broker account. If your phone was near the scene of an accident, near a competitor’s facility, or somewhere your spouse’s attorney finds interesting, that data may already be in someone’s hands.
Law enforcement has done the same. The practice of purchasing commercially available location data to avoid the warrant requirement has been documented in federal cases. The argument is straightforward: if the data is for sale to the public, acquiring it isn’t a search. Courts are still working through the implications. In the meantime, it’s happening.
When the Machine Gets It Wrong
The scariest part of a surveillance system isn’t malicious use. It’s confident error.
In January 2023, Randal Reid was arrested in Georgia and jailed for six days for a theft he did not commit, in a city he had never visited. The arrest was based on a facial recognition match from a surveillance camera. The algorithm was wrong. He was Black. Studies have consistently shown facial recognition systems have significantly higher error rates for darker-skinned individuals. He lost his job during the six days he spent in jail waiting for someone to look at the actual evidence.
Robert Williams in Detroit. Michael Oliver in New Orleans. Nijeer Parks in New Jersey. All arrested on the basis of facial recognition matches. All innocent. All spent days or weeks in jail while the error was sorted out.
These are not fringe cases from experimental technology. These are documented wrongful arrests from systems actively deployed by police departments in American cities right now. The AI doesn’t know it’s wrong. It produces a match score and moves on. The humans downstream treat the score as evidence.
The App Economy Is a Surveillance Economy
Here’s a question worth sitting with: why would someone spend months building an app, pay for servers, maintain it, update it, and offer it to you completely free?
The answer is never charity. Free apps are data businesses with a utility interface. The product isn’t the app. The product is you, your location, your behavior, your contacts, your patterns, and your attention, packaged and sold to brokers, advertisers, and data platforms.
The weather app is the most cited example because it’s so obvious once you see it. A weather app needs your location to function. It’s one of the first permissions requested. And once you grant it, most weather apps ping your GPS on a regular interval regardless of whether the app is open. That data is sold. It has been used in criminal cases, civil litigation, and insurance investigations.
But it’s not just weather.
The free flashlight app you downloaded in 2019 and forgot about. The app your utility company pushed you to download to track your energy use. The app your doctor’s office rolled out for appointment scheduling. The movie theater app with the loyalty rewards. The grocery store app with the digital coupons. The free game you played for two weeks and haven’t touched since. Every one of those apps requested permissions. Most of them got location. Many got contacts. Some got access to your photos. All of that access, unless explicitly revoked, is still active.
Your doctor’s app knows when you’re home and when you’re not, based on location history. Your grocery app knows what you eat, what you drink, whether you buy medications, and how often you entertain. Your utility app knows your daily schedule better than most of your friends because it can infer when you wake up, when you leave, and when you go to bed based on consumption patterns.
None of that data stays inside the app. It flows to data brokers, analytics platforms, and in some cases directly to insurers and financial institutions. That’s not speculation. It’s the disclosed, legal business model of the data broker industry, which generates over $200 billion in annual revenue in the United States.
The Weather App Scenario
Here’s a scenario that requires no speculation. It’s drawn directly from documented legal cases and data practices.
You tell your spouse you’re working late. Your weather app pings your GPS every 15 minutes. Your grocery app logged your last three purchases, including wine for two on a Tuesday. Your phone connected to a WiFi network at a restaurant three miles from the office. The Flock camera at the intersection logged your plate at 7:14 PM heading away from the office, not toward it.
A divorce attorney purchases a location history report for $300. They purchase a retail behavior summary for another $150. They don’t need a subpoena. They don’t need a judge. They need a broker account and a credit card.
You didn’t do anything wrong. The data doesn’t know that. The exhibit doesn’t say that.
The Retail Behavior Loop
You walk into a store. Your phone, with Bluetooth and WiFi scanning enabled, connects to the store’s passive sensor network. That network logs your device ID, your dwell time in each section, and your path through the store. You pay with a loyalty card. The purchase is matched to your device ID. The purchase history is sold to a consumer behavior platform.
That platform already has your location history from an app, your purchase patterns from a grocery loyalty card, and your browsing behavior from a free game installed two years ago. The profile that results knows your income bracket, your household composition, your health concerns based on what you buy, your relationship status based on your location patterns, and your weekly routine down to which gas station you stop at on Monday mornings.
That profile is for sale. To insurers. To employers. To whoever is willing to pay. And none of it required a warrant.
Interlude: A Day in the Life, as Seen by the Data
The following is a fictional composite. The data sources are real. The capabilities described are real. The man is invented. The story is not.
6:47 AM. The device at 3214 Briarbrook Place powers on. Location confirmed via GPS. Home network handshake logged. A weather app pings coordinates: 28.1847° N, 82.4976° W. The advertising ID broadcasts to fourteen ad exchanges in the first ninety seconds of screen activity.
7:02 AM. The vehicle departs. A Flock LPR unit at the neighborhood entrance logs the plate, timestamp, direction of travel, and vehicle description. A second reader at the intersection of US-41 logs it again four minutes later. The data is uploaded to the shared regional law enforcement network. Retention: indefinite.
7:19 AM. The phone connects to the WiFi network at a coffee shop on Gunn Highway. The shop’s sensor network logs the device MAC address and dwell time. The loyalty app checks in automatically. Purchase logged: large coffee, breakfast sandwich. Payment via linked debit card. Card network logs the merchant, amount, and timestamp. The loyalty platform sells weekly purchase summaries to a consumer analytics firm.
8:04 AM. Arrival at an office building. Phone connects to guest WiFi. Badge swipe logs entry. The office building’s CCTV system captures facial image at lobby entry. The image is processed against a facial recognition database maintained by the building’s security contractor. No match flagged. Image retained for 90 days.
9:30 AM. Calendar app syncs. Meeting with an outside party detected by the calendar’s connected CRM integration. The integration exports contact metadata to a marketing data platform. The outside party’s LinkedIn profile is automatically scraped and appended.
12:14 PM. Lunch. Phone Bluetooth scans passively while walking through a retail corridor. Three proximity beacons log the device ID and physical path. A retail analytics company receives the movement data within the hour. The grocery store loyalty app activates when entering the attached supermarket. Items purchased: ibuprofen, antacids, energy drinks. The purchase is flagged by the health inference algorithm maintained by the store’s data partner. Inferred health profile updated: possible GI issue, stress indicators, fatigue markers. This data is sold to a health data broker. The health data broker’s clients include insurers.
3:45 PM. The phone enters a location not consistent with the registered home or work address. GPS coordinates logged by the weather app, the utility app running in the background, and a navigation app left open from the morning commute. Duration at location: 47 minutes. The address resolves to a residential property. The property record is public. The registered occupant is not a known associate on file.
4:33 PM. Departure. LPR at a cross street logs the plate heading back toward the highway. Travel pattern inconsistent with normal commute route flagged by the behavioral analytics layer of the vehicle tracking platform. Anomaly score updated.
6:02 PM. Home. Network handshake re-established. Smart TV powers on. Viewing data logged by the streaming platform. Ad ID linked to household profile. The streaming platform sells viewing behavior to a data cooperative. The cooperative’s members include financial services companies, insurance underwriters, and political consulting firms.
10:47 PM. Device plugged in. Final location ping logged. Day’s behavioral file complete.
Forty-three data points. Eleven separate platforms. Zero warrants. Zero notifications. Zero consent forms that a reasonable person would have read or understood.
This file is for sale. It was compiled today. It will be updated tomorrow.
Section 2: Know What’s Already Out There
Before you change anything, understand what you’re working with.
1. Google yourself. Use quotes around your full name. Try variations. Add your city. Check Images. Most people are surprised.
2. Search your home address. Property records are public. Your address, purchase price, assessed value, and square footage are one search away.
3. Check data broker sites. Spokeo, WhitePages, BeenVerified, Intelius, and about 200 others aggregate your name, address history, relatives, phone numbers, and more. Pull your own record on at least three of them.
4. Review your social media privacy settings. Default settings on Facebook, Instagram, and LinkedIn are almost always set to expose more than you realize. Go through each platform’s privacy settings manually.
5. Search your email address on HaveIBeenPwned.com. If it shows up in a breach, the credentials, and potentially much more, are likely for sale somewhere right now.
Section 3: Lock Down the Low-Hanging Fruit
These cost nothing and take under an hour.
6. Opt out of data brokers. Every major aggregator has an opt-out process. It’s tedious. It requires submitting your information to remove your information, yes. It works imperfectly and needs to be maintained. Start with the top ten: Spokeo, WhitePages, Intelius, BeenVerified, Radaris, PeopleFinder, FastPeopleSearch, TruthFinder, Instant Checkmate, and PeopleSmart.
7. Separate your email addresses. One for financial accounts. One for shopping and subscriptions. One for everything else. When a breach hits, it’s contained.
8. Use a password manager. Bitwarden is open-source and solid. 1Password works well. Either is better than reusing passwords. Reused passwords are how one breach becomes five.
9. Enable two-factor authentication. For every account that supports it. Authenticator apps are better than SMS. SMS is still better than nothing.
10. Audit app permissions on your phone. Go to Settings > Privacy on iOS or Android. Review which apps have location, microphone, camera, and contact access. Revoke anything that doesn’t need it. Most apps don’t.
Section 4: Your Phone Is the Biggest Hole
11. Disable ad tracking. iOS: Settings > Privacy & Security > Tracking. Android: Settings > Google > Ads > Opt out of ads personalization. This limits what can be tied to your advertising ID.
12. Set location permissions aggressively. Everything that doesn’t require location to function gets set to Never. Not “While Using.” Never.
13. Turn off WiFi and Bluetooth when not in use. Passive scanning is used to track your physical location inside retail stores, airports, and public spaces. If it’s broadcasting, it’s being logged.
14. Use a private DNS. In network settings, set to Cloudflare (1.1.1.1) or NextDNS. It stops your carrier from logging every domain you visit.
15. Be selective with free apps. If the app is free and the company has investors, you are the product. Read the privacy policy before installing. If there isn’t one, delete it.
Section 5: Your Computer Needs Attention Too
16. Audit browser extensions. Extensions have broad access to your browsing activity. Remove anything you don’t actively use.
17. Use a privacy-respecting browser. Firefox with uBlock Origin is a solid baseline. Brave works well for most users.
18. Change your router’s DNS. Your home router logs every domain every device visits. Cloudflare or Quad9 at the router level covers the whole household.
19. Review third-party app access on your Google or Apple account. Apps authorized years ago may still have access to your email, calendar, and contacts. Revoke anything you don’t recognize.
20. Use a VPN selectively, and choose carefully. A VPN shifts trust from your ISP to the VPN provider. Choose one with an independently audited no-log policy. Mullvad and ProtonVPN are the credible options. Free VPNs are almost always data businesses.
Section 6: Your Address and Identity
21. Use a P.O. box or mail forwarding service for subscriptions and low-trust relationships. Your home address does not need to be on every loyalty program and retailer account.
22. Opt out of pre-screened credit offers. OptOutPrescreen.com. Five years or permanent. Removes your name from lists sold to financial marketers.
23. Freeze your credit. Free at all three bureaus. Doesn’t affect your score. Blocks new credit inquiries without your active unfreeze. Single most effective identity theft prevention step available.
24. Place a fraud alert if you’ve been in a breach. Requires creditors to verify your identity before opening new credit.
Section 7: Behavior Is the Biggest Variable
25. Phishing, vishing, and smishing are responsible for more breaches than any technical exploit. Verify before you click. Verify before you give any information on an unsolicited call. No legitimate institution will pressure you into immediate action.
26. What you post is a map. Vacation photos tell people when you’re not home. Gym check-ins establish a routine. LinkedIn tells a social engineer your org structure. None of it is secret. All of it is useful to the wrong people.
27. Review your LinkedIn visibility settings manually. Your connections list, activity, and profile views default to public. Go through every setting.
These Steps Get You Most of the Way There
Twenty-seven items is a real list. Most people will do a few, feel better, and stop. That’s still better than nothing.
But doing this right, doing it once and maintaining it over time, takes technical familiarity, the right tools, and ongoing attention. Data broker opt-outs expire and need to be repeated. Breach monitoring needs to be continuous. Settings change after app updates. It doesn’t stay done.
And none of the steps above address what’s already been compiled about you. The profile that exists today, across brokers, aggregators, and data platforms, doesn’t disappear because you changed your phone settings. It has to be actively addressed.
What Farsight Intelligence Offers
If you want the work done rather than a checklist to manage, that’s what we do.
Personal Privacy and Security Audit We assess your current exposure across public records, data brokers, breach databases, OSINT sources, and your full digital footprint. You get a clear picture of what’s visible, what’s at risk, and what to prioritize.
Data Broker Removal Service We handle opt-outs across the major aggregators and monitor for reappearances. Ongoing, not one-time.
Phone and PC Audit (Remote) We walk through your device settings, app permissions, browser configuration, and account connections. Remote session, clear action items.
Hosted Photo and Memory Backup Private, encrypted, off the major platforms. Your personal files backed up to infrastructure you don’t share with an advertising company.
Self-Hosted Email Setup Move off Gmail. Your email isn’t a product when it lives on your own infrastructure.
Ongoing Monitoring Breach alerts, data broker re-listing notifications, and periodic check-ins.
The consultation is one session. No commitment. You’ll leave with a clear picture of your actual exposure and a prioritized plan. If you want us to execute it, we can do that too.
Schedule at FarsightIntelligence.com or reach us at [email protected]
Farsight Intelligence is a DBA of Florida Man Innovations Inc. PI services performed in partnership with Kalwary Investigations & Consulting, Agency License A3200132. FL PI Lic. #3500261.