Privacy and Tracking: What Your Devices and Browsers Reveal
Cookies, cross-site tracking, app permissions, location settings, browser extensions, file metadata, and smart home devices, explained with the settings that genuinely change what is collected.
The difference between what you give and what you leak
Digital privacy discussions tend to blur two very different things. There is information you deliberately provide, such as a name at sign-up or a photograph you post, and there is information generated as a by-product of using a device at all: which app was open, from which network, on which model of handset, at what time. The second category is larger, less visible, and harder to withdraw, because you never consciously handed it over in the first place.
This distinction matters because it determines which controls are useful. Deleting a post removes something you gave. It does nothing about the by-product data, which is governed instead by permissions, browser settings, and the design of the services you use. Effective privacy work therefore focuses less on what you publish and more on which components of your device are permitted to observe you and which parties receive the resulting records.
What app permissions actually control
Most mobile operating systems group permissions by category, and each category corresponds to a specific hardware sensor or data store rather than to a general notion of privacy. Camera, microphone, location, contacts, calendar, photographs, and nearby device scanning are typically separate grants. The system enforces them at the point the app tries to use the resource, which is why a denied permission produces a broken feature rather than silent failure of the whole app.
The useful mental model is purpose. A navigation app plainly needs location while you are navigating. A torch app has no legitimate use for your contact list. When a request does not match the visible function, denying it is usually safe, and the app will either work with reduced capability or prompt you again at the moment the feature is genuinely needed, which is a much better time to make the decision.
Modern systems also offer intermediate options that are more useful than a straight yes or no. Location is usually separated into precise and approximate, and access can often be limited to while the app is in use rather than always. Photograph access can frequently be narrowed to selected items instead of the entire library. Where an app asks for continuous background access to something, ask what it would do with that access when you are not looking.
Cookies do less than people assume, and more
A cookie is a small piece of text a website asks your browser to store and send back on subsequent requests. It cannot read your files, run programs, or see what you do on other sites by itself. Its function is memory: it is how a site recognises that this browser is the one that logged in a moment ago, or chose a language, or has three items in a basket. Without something of this kind, the web would forget you between clicks.
The privacy problem is not the mechanism but who sets it. A cookie set by the site you are visiting is a first-party cookie and is generally unremarkable. A cookie set by a different domain whose content is embedded in the page, typically an advertising or analytics provider, is a third-party cookie, and that provider sees the same identifier on every unrelated site where its code appears. Clearing cookies logs you out of things and resets some tracking, which is why it feels both useful and annoying.
How cross-site tracking is assembled
Cross-site tracking works by having a common third party present on many sites. Each embedded advertisement, share button, analytics script, or invisible pixel is a request to that third party, and each request carries the page you were on. Repeated across a browsing session, this produces a list of visited pages associated with a single identifier, which is then used for advertising profiles, measurement, or resale depending on the arrangement.
Browsers have been restricting the classic third-party cookie for some years, and the industry response has been to find other stable signals. Fingerprinting combines characteristics your browser reveals in normal operation, such as screen dimensions, installed fonts, time zone, language, and graphics rendering quirks, into a value distinctive enough to recognise on return. Server-side matching by hashed email address is another route, which is why so many sites now push hard for you to log in.
There is a limit worth being honest about. No browser setting makes you unidentifiable, and tools promising complete anonymity are overpromising. What settings do achieve is a meaningful reduction in the number of parties holding a coherent record of your browsing. Blocking third-party cookies, using a tracker-blocking browser or extension, and separating logged-in activity into a different browser profile all reduce linkage without pretending to eliminate it.
Location: precise, approximate, and inferred
Devices establish position from several sources. Satellite positioning is the most accurate outdoors, but indoors and in dense urban areas devices rely more on the identifiers of nearby Wi-Fi networks and mobile towers, matched against databases of where those transmitters are known to be. This is why location can be surprisingly good with satellite reception disabled, and why turning Wi-Fi scanning off changes accuracy even when you are not connected to any network.
Even with every location permission denied, an approximate position is inferable from the network address your traffic arrives from, which typically resolves to a city or region. Photographs are a separate channel, since cameras can embed coordinates in the image file itself, so a picture shared privately may carry a precise location even when the app has no location permission. Treat the approximate option as the default and reserve precise access for apps that navigate or map.
Browser extensions have the widest access of anything you install
An extension that can read and change data on all websites is, in effect, sitting inside every page you load, including your banking and email. It can see what is displayed, what you type, and the session state that keeps you logged in. Extensions are genuinely useful, and content blockers require broad access to do their job, but the permission being granted is far larger than the interface suggests and deserves proportionate scrutiny.
Two failure modes recur. The first is an extension that was honest and is later sold or transferred to a new owner who monetises the installed base, since updates arrive automatically and the access carries over. The second is an extension whose stated purpose has nothing to do with the access it requests. Practical hygiene is to keep the list short, remove anything unused, prefer extensions with an identifiable maintainer, and check whether narrower site-specific access is available.
Metadata travels with your files
Files carry descriptive data alongside their visible content. Photographs commonly record the camera or phone model, exposure settings, the date and time, and sometimes coordinates. Documents and spreadsheets often retain author names, the organisation the software was registered to, revision history, and comments that were never meant for outside readers. None of this is visible when you look at the file, which is exactly why it gets shared by accident.
Behaviour differs by route. Some platforms strip metadata from uploads as a matter of course, while sending the same file as an email attachment or through a file-sharing link usually preserves it intact. If you are publishing a photograph from home or sharing a document outside your organisation, check the file properties first, or export a fresh copy through a route you know removes extra fields. Screenshots of documents are a crude but effective way to discard everything except pixels.
Reading a privacy policy without reading all of it
Privacy policies are written for regulators and litigation, not for readers, but they are still the only authoritative statement of what a service claims to do. Rather than reading start to finish, search the document for a few specific things: the categories of data collected, whether data is shared with or sold to third parties, how long it is retained, whether it is transferred to other countries, and how you can request export or deletion. Those sections carry nearly all the meaningful content.
Certain phrasings deserve attention. Language about sharing with partners or affiliates for business purposes is doing significant work with very little specificity. A retention clause stating that data is kept as long as necessary sets no limit at all. Conversely, a clear statement that a defined category is deleted after a stated period is a real commitment. Where local rules grant rights to export or erase data, exercising them when you leave a service is the most concrete privacy action available.
Smart home devices turn a household into a data source
Connected speakers, cameras, televisions, and appliances generate records about a shared space rather than an individual. Occupancy patterns, sleeping hours, viewing habits, and the timing of arrivals and departures can be inferred from routine device telemetry without any single sensor being obviously invasive. The people affected include family members, domestic staff, and visitors who never agreed to anything, which makes these decisions different in kind from choices about your own phone.
Voice assistants illustrate a common misconception. Devices generally listen locally for a wake word and transmit audio only after it is detected, so continuous streaming of everything said in a room is not the usual design. The real issues are false activations, which do send unintended audio, and the retention of recordings afterwards. Most platforms offer a history view where past interactions can be reviewed and deleted, and settings governing whether recordings are used for product improvement.
Televisions are worth singling out because content recognition features may report what is displayed on screen, including from devices plugged into it. This is usually presented at setup as a personalisation or recommendations feature rather than as data collection. It can generally be declined without losing the ability to watch anything. Where a device offers a local-only mode or works without an account, that is often the simplest privacy improvement available.
Deciding what to change, and in what order
Privacy effort should be proportionate, and the highest-value changes are few. Reviewing which apps hold location, microphone, and camera access takes minutes and reduces continuous collection. Trimming browser extensions to the ones you actually use removes the broadest access on your machine. Turning off advertising personalisation and content recognition where offered stops specific collection at source. These are one-time actions with lasting effect, which is what makes them worth prioritising.
It is more sustainable to accept that some tracking will occur and to decide what you are protecting against. If the concern is advertising profiles, blocking third-party cookies and trackers addresses most of it. If it is the exposure of your home address, photograph metadata and location permissions matter far more. If it is other members of your household, device-level accounts and screen locks are the relevant controls. Naming the concern makes the choice of setting obvious rather than arbitrary.
Sources & References
Editorial Team
Editorial
In-house writers and editors producing original explainers, guides, and analysis. Articles cite authoritative public sources where helpful.