What is Your Personal Privacy Policy?

Neomailbox
Cover for What is Your Personal Privacy Policy?

At the bottom of most websites there’s a little link labelled “Privacy”. Clicking that link leads to the site’s privacy policy, which is often a long, dense document full of euphemistically phrased admissions of how the site collects, shares and processes your data.

While most websites have an explicit privacy policy, most people don’t.

Indeed, not only do most people not have a privacy policy, they almost always agree to the terms of use and privacy policy of any site they visit or any app they use, usually without even reading them.

This works out great for all the websites, apps, data brokers and surveillance agencies hoovering up, monetizing, and creeping out with individuals’ personal data, but not so great for the individuals whose personal data is being collected, traded, and creeped over.

If you value your privacy and intend to effectively protect it online, you must set your own parameters for what terms of service you will and will not accept from providers.

In other words, you must develop and implement a personal privacy policy.

When you have your own personal privacy policy, you can check the privacy policies of products and services that you’re considering using for compatibility with your personal privacy policy.

This compatibility check could also be automated, performed by a Large Language Model (LLM).

Let’s consider some of the main issues that should be addressed by a personal privacy policy.

Personal data collection

In general, as a first line of defense, a strong personal privacy policy will disallow disclosure of personal data to services unless they legitimately require the data to provide the service.

Does the provider or service require personal data? Does it need the personal data to provide the service? If not, why does it want it?

A notable example of unnecessary data collection for many years was the instant messaging app Signal, which, ironically, is marketed as a privacy-oriented app. But the first thing it did was require access to your entire contact list on your phone. It doesn’t need this information. You will likely use Signal to communicate with only a subset of your contacts. So why did Signal insist on accessing the entire contact list, without which it refused to function? That’s not privacy-oriented at all.

In 2018, Signal finally made it possible to opt out of providing access to all contacts. However, the app’s historic lack of respect for user privacy should make one highly skeptical of its privacy claims. It still defaults to requiring your full contact list, and most people accept the default.

Data security

How is the personal data entrusted to the service secured? Which legal jurisdictions is it stored in or subject to? How long is it held? Often, services do not disclose any of this information, which is a red flag that should itself be a disqualifying condition in a personal privacy policy.

Increasingly, one encounters privacy violating devices in the physical world, such as surveillance cameras, and biometric scanners for access control to buildings. The data security problem exists with these devices as well, and a strong personal privacy policy would require opting out of using or interacting with such devices whenever possible.

If your HoA or office building uses surveillance cameras, you might want to look into which ones they use, and whether the data is processed by third parties in the cloud.

Content scanning

For email and file storage services, does the service scan the contents of your emails or files? Is the content used to train AI models? Is it shared with surveillance agencies? Is it visible to employees of the service? What safeguards protect customer content from unauthorized access?

Device manufacturers such as Apple have also been toying with content scanning for a while. Some of these attempts had to be abandoned because of massive public pushback, but they are continuing with it in other sneakier ways. For example, if you allow Siri to search within content on your phone, which is enabled by default, that means Apple’s processes are scanning your content. And quite likely sharing it with Apple.

Cookies

How many cookies does the website want to store? How many third-party and tracking cookies? Is there a one-click opt-out available for non-essential cookies, or does the cookie consent banner make it difficult to opt out of non-essential cookies? Your privacy policy might require you to prefer sites that make non-essential cookie opt-out easy, and to avoid those that make it difficult.

Third party content

Does the site include content from third parties? Third parties whose content is included on a webpage will also receive your IP address and browser details when you access that content. Very often, websites include third party content from notorious privacy violators such as Facebook, Goolag, etc.

One of the special problems with third party content is that websites never ask your permission to include third party content, unlike with cookies. There is a strong case to be made that they should. After all, when I visit xyz.com, I don’t intend to communicate that to Goolag, and if xyz.com intends to leak my information to Goolag, they should first ask my permission.

You might wonder if we practice what we preach at Neomailbox. We do. This site has zero third party content. And browsing the site attracts zero tracking cookies or cookies of any kind. We only use cookies in the Control Panel and the Cart, where they are functionally required.

Analytics

This is a subcategory of third party content. Many sites use Goolag Analytics, which sends your IP address and browser details to Goolag. A related subcategory is DDoS mitigation / bot detection, for which many sites use CloudFlare. Any site that does that is sending your IP address and browser details to CloudFlare.

As with other third party content, sites don’t ask for permission to use third party analytics software on their website. And as this content is usually invisible on the page, you don’t even notice it when you view the site, as you do with other third party content such as advertisements.

Sharing of data

Besides data shared directly and instantly through cookies and loading third party content, most websites also mention in their privacy policy that they share data with various third party services. However, the specific third parties are almost never listed, so there is no way of checking the privacy policies of those services.

Consequently, any such unspecified sharing should be considered a strong red flag and should probably be prohibited by a personal privacy policy.

Many services have data-sharing arrangements with nation states, including in some cases with tryannical, authoritarian governments such as the CCP. For example, the widely-used video-conferencing app Zoom has a history of lying about security features including encryption, routing meetings through China, and various other nefarious acts. Its terms of service state that it can collect all content from your messaging and meetings, and that it may share data with governments.

Apple and SpaceX are two major companies that have banned the use of Zoom, and it deserves a ban in anyone’s personal privacy policy.

Even Apple, which presents itself as a privacy-focussed brand, makes the data of Chinese users easily available to the CCP, by storing all Chinese iCloud data in data centers in China, and also keeping in its possession, also in China, the decryption keys for all user data.

Some apps share data with your own contacts without your explicit consent. The Signal messaging app, which is marketed as a privacy-oriented app, was an example of this for many years. When you signed up to Signal, every other Signal user who had your phone number stored in their contact list would receive a notification that you had joined Signal, regardless of whether you wanted them to or not. Signal finally started allowing users to opt out of this in 2018.

Privacy compromise by your contacts

There’s also the issue of your data being shared by your friends and acquaintances without your permission. You may be privacy-aware enough not to give WhatsApp access to your full contacts list, but most of your contacts probably aren’t. And when they give WhatsApp access to their contact list, your name and number gets shared with WhatsApp.

There’s little you can do about this, other than perhaps requesting your contacts to save your contact information under a nickname rather than your real name.

Another aspect of this is when you email someone at a free or big tech email service. You may be using a secure email service such as Neomailbox, but when you email people at most big tech email services, the content and metadata of your email will be sucked up into their surveillance systems and most likely used to train Large Language Models (LLMs) which can then instantly recall all that information when asked.

One way to address this is to request your frequent contacts for a non-big-tech, privacy-oriented email address you can correspond with them at. Let them know you have privacy concerns about their big tech email address and don’t feel comfortable communicating via a medium where everything you say is being surveilled and recorded.

Biometric data

Some sites and services require biometric data. In almost all cases, this is not technically necessary to provide the service, and exposes this highly private data to the risk of theft and abuse. Many governments are implementing biometric data collection as part of immigration controls and other systems. Some countries don’t allow visitors to opt out of biometric data collection.

A personal privacy policy should require opting out of biometric data collection whenever possible, and avoiding private services that don’t provide the ability to opt out.

Reputation of provider

Almost all online services claim to care about privacy, but what’s the real track record? The history of many services shows clearly their utter lack of respect for user privacy. Most of the big tech companies fall in this category.

Another aspect of provider reputation includes their marketing and promotional messaging. Do they use misleading messaging and make false promises, as many VPN vendors do? Do they use technical jargon to confuse buyers and advertise illusory benefits?

Another aspect is financial. What are the financial ties of the provider? Do they have financial backing from, or contracts with, nation states, big tech, NGOs, or surveillance agencies?

Reading the Terms and Privacy Policy

Most people usually click OK on the Terms of Service of websites and apps without actually reading them. Your personal privacy policy should require you to read, or at least scan, terms of service and privacy policies before using any product or service. Yes, these are usually full of boring legalese, but at least scanning quickly over them with an awareness of the above factors will go a long way in helping to detect and avoid significant privacy threats.

Alternatively, as suggested above, you could write out your personal privacy policy, and then you can feed that as well as a website or app’s privacy policy to a Large Language Model (LLM) and ask it to analyze whether their privacy policy is compatible with your personal privacy policy, and to highlight where it isn’t.

Supporting Privacy-Respecting Services

Privacy-respecting service providers can only flourish and thrive if users try them and support them. So if you value the availability of high-quality independent privacy-respecting services, it’s important to prioritize searching for such services, trying them out, and supporting them if they meet your needs.

Discernment is important in which services you choose to use and support. As we’ve seen above, there are many providers who claim to be privacy-oriented, but are really just using privacy as a marketing point, and don’t really understand or care about privacy.

Avoiding Privacy Posturing

Some tell-tale signs of insincere privacy-posturing (also known as privacywashing) include:

  • third party tracking cookies, analytics or content on a “privacy-oriented” website

  • the use of Windows servers or cloud services on the back-end

  • free accounts (if the service is free you’re not the customer, you’re the product)

  • absolute claims such as “your data is totally secure. nobody can access it, not even us.” (In reality, there are only degrees of security, and only from specific threats. Absolute security doesn’t exist, and it’s misleading to imply that it does).

  • financial or historical ties to governments, NGOs, big tech, surveillance agencies, or companies or services with a poor reputation for privacy.

Privacy posturing reveals that a company’s true motivations don’t align with its users’ privacy. This is usually a deep systemic and cultural issue and can rarely be fixed by official proclamations to improve privacy.

It makes sense to avoid services and companies that have been known to disregard customer privacy in the past, or to engage in privacy posturing, even if they claim to have a renewed and genuine respect for privacy now.

Towards a Society of Privacy

As Ayn Rand wrote, “Civilization is the progress towards a society of privacy.” While the current trend in our world seems to be towards ever-increasing surveillance and diminishing privacy, we all have the power to dramatically increase our own privacy by creating and implementing a personal privacy policy.