Fair warning before the disclaimers even start: this one's a little long, a little uncomfortable, and not really written for someone who's going to bounce after the first two paragraphs. If you're still here by the end, you'll know things about your own phone that most people never bother to check.
A disclaimer before we start, because apparently that's how it works now: this is one person's opinion, built on public facts and the collective paranoia of people who still bother reading terms of service. I'm not trying to cancel Google — please, Google, I'm a competent engineer, hire me, I'm kidding, I'm not kidding. I just think somebody should say the quiet part out loud before saying it becomes a compliance violation.
A bigger, more boring disclaimer, because this one actually matters: everything below is built on real, checkable sources — court verdicts, regulator fines, academic research, and independent audit tools like Exodus Privacy. Where a specific claim couldn't be independently verified, I've labeled it explicitly as a theory or an unverified report, not a fact, and I'd rather under-claim than dress up a rumor as a courtroom finding. I also touch on identity-verification laws and proposals from a few different countries — Vietnam, the EU, Russia — purely as a technical and factual comparison of what each is doing and when. That's not a scorecard, and it's not me passing judgment on any government, political system, or policy choice. I'm not qualified to rule on sovereign lawmaking and I'm not trying to. This is a breakdown of mechanisms, not a verdict on the people who built them.
The myth everyone gets wrong (so let's kill it properly)
Let's start with the thing you think you know: "my phone is listening to me." You said "air fryer" out loud once and an ad for an air fryer showed up. Spooky, right?
It's not spooky. It's worse.
Every major platform — Meta, Google, Apple — has said on record, repeatedly, under oath in Meta's case, that they don't use your microphone to target ads. Independent security researchers have tested this claim for years, tearing apart thousands of apps looking for secret always-on listening, and they keep finding basically nothing. No hidden audio pipeline running in the background of TikTok. No microphone spyware baked into Instagram.
Why? Because they don't need it. They already know you searched for kitchen gadgets three times last week, follow four cooking accounts, paused two seconds longer on a fryer ad last month, and that your friend with identical shopping habits just bought one. That's not surveillance through a microphone. That's a statistical ghost of you, built from years of clicks and dwell time, predicting your next move before you've made it. Ad tech doesn't need your voice. It has something better.
That said — the myth isn't entirely fantasy. A marketing outfit branded "Active Listening" got dragged in front of the FTC for claiming it could target ads via smart-device microphones in real time; the "service" turned out to be repackaged data-broker email lists sold at a markup, but the pitch decks named Google as a partner. Apple paid $95 million in a class-action settlement over Siri recordings potentially reaching third parties. Amazon is currently defending a federal class action in Seattle over Alexa recordings allegedly retained and used to train its AI models.
So no, your phone probably isn't listening to your dinner plans. The industry built entirely around not needing to listen is more unsettling, because there's no toggle for "please stop knowing me."
The receipts, because "trust me" isn't a source
If this sounds like tinfoil-hat energy, here's what regulators and juries have actually done about it in the last few years — not allegations, verdicts and settled fact:
- Meta / Cambridge Analytica. A UK firm harvested the data of roughly 87 million Facebook users through a single quiz app, built psychological profiles from it, and sold political targeting off the back of it. The FTC fined Meta $5 billion — still one of the largest privacy penalties ever issued against a single company.
- Meta / Flo period-tracking app. In August 2025, a federal jury found Meta liable under a 1967 California wiretapping law for secretly collecting menstrual and pregnancy data from the Flo app — cycle dates, whether users were trying to conceive — through an embedded software kit, then using it for ad targeting. The jury needed three hours to decide Meta had eavesdropped without consent. Damages could run into the billions once the full class is counted.
- Google / "Web & App Activity." In September 2025, a San Francisco jury ordered Google to pay $425.7 million after finding it kept collecting data from about 98 million users across an eight-year stretch — even after those users had explicitly flipped the privacy switch meant to stop it.
- Amazon / Alexa Voice ID. A federal judge in Chicago certified a class of roughly 1.18 million Illinois Alexa users in November 2025, over allegations that Amazon built biometric "voiceprints" from their voices without the written consent Illinois law requires.
- Meta and Yandex / the localhost trick. In 2025, researchers caught Meta's Facebook and Instagram apps — and Yandex's apps, reportedly since 2017 — quietly listening on local network ports on Android phones. Any website with a Meta Pixel or Yandex Metrica tracker could use this to silently hand your anonymous browsing session to the app sitting on your phone and stitch it to your actual identity. It worked straight through incognito mode, cookie clearing, and ad-ID resets — the three things privacy-conscious people are told will protect them. Meta paused it within days of the research going public, calling it a "miscommunication" about Google's policies.
- GDPR, cumulatively. European regulators have now handed out more than €7 billion in fines since 2018, including a €1.2 billion penalty against Meta for unlawful US data transfers and €530 million against TikTok for sending EU user data to China. Enforcement isn't slowing down — more fines have hit small and mid-sized companies in the last three years than in GDPR's entire first five.
None of this required a conspiracy theory. It required a courtroom, a jury, and people willing to read the fine print out loud.
VK: the eastern giant nobody in the West is watching
Everything above is Western Big Tech getting dragged into courtrooms, mostly because Western courtrooms exist for that purpose and Western journalists chase that beat. But swap hemispheres and you find a mirror image: VKontakte (VK), the dominant social network across Russia and much of the CIS, running the same playbook with a different flag on it.
Independent app-auditing tools like Exodus Privacy — which do static analysis on Android APKs to catalogue embedded tracking SDKs and requested permissions rather than take a developer's word for it — put VK's official Android app at 16 separate tracker SDKs and 99 requested permissions in its most recent scanned build (full report here — go look yourself, don't take my word for it). The tracker list alone reads like a cross-section of the entire ad industry: Google AdMob and Firebase Analytics, Yandex Ad, Huawei's HMS Core (which bundles location, advertising, and analytics in one package), plus ad-mediation networks like ironSource, Mintegral, and Unity3d Ads, alongside VK's own first-party identification SDK. The permissions list goes well past what a messaging-and-newsfeed app needs to function: precise GPS location, reading your call log, reading and writing your contacts and calendar (including a permission that explicitly lets the app "send email to guests without owners' knowledge" when it modifies calendar events), reading your phone number and device identity, recording audio, using the camera, and reading fitness data like step count and calories burned. Not all 99 are sinister on their own — plenty are mundane plumbing every app needs — but stacked together with 16 separate third-party trackers quietly reporting home, it's a genuinely large surface area for a platform whose stated job is "let people message their friends." Worth being precise about what VK actually is here, because it matters for how you read the rest of this: VK isn't just a private company that happens to be popular in Russia, it's a platform with formal ties to the Russian state and legal obligations to cooperate with its authorities on request, and unlike Meta or WhatsApp, VK's messages carry no end-to-end encryption at all — meaning that data, once collected, isn't just sitting in a corporate server somewhere abstract, it's structurally reachable by a government. That's a documented, publicly reported fact about how the platform is built and regulated, not a political opinion about Russia, and I'd say the exact same thing about any platform, in any country, built the same way. So if you're weighing which regional giant to worry about, the honest answer is: don't pick a side. East and West both built the same machine — they just answer to different governments when the machine gets audited.
A theory worth reading, not a verified fact
While we're here — a claim that's been floating around tech circles that I want to flag as a claim, not smuggle in as fact: reports have circulated alleging that in 2026, Meta ran an internal program collecting employee activity — keystrokes, screen content, even messages — from company laptops, ostensibly to train AI systems, and that some of those records ended up visible to a far larger internal audience than intended, triggering an employee petition. I haven't been able to independently verify the specifics — the numbers attached to it move depending on which forum you read — so take it exactly as advertised: an interesting, plausible-sounding story making the rounds, not a courtroom fact like the ones above. If true, it's the same surveillance logic Big Tech applies to its users, just pointed inward at the people building the tools. If it's exaggerated, it's still a useful thought experiment: what happens when the company that profiles you for a living starts applying the same instincts to its own staff?
The data doesn't have to be sold to end up in the wrong hands
Right now, while you're reading this sentence, a screenshot of somebody's desktop is sitting on a server they never explicitly agreed to. Somewhere, a password nobody's changed in five years is sitting in a database that already leaked once. Statistically, given how many billions of records are already circulating, the odds that none of it is yours are getting worse every year, not better.
Here's the part that ties everything above together, and it's arguably the most important one: none of this requires a company to be evil on purpose. Every dataset described in this post — location history, voiceprints, screenshots, browsing profiles, passport scans — sits somewhere on a server. And servers get breached. Constantly. At a scale that's honestly hard to hold in your head.
2025 alone produced the largest credential leak ever recorded: roughly 16 billion login records — usernames, passwords, session tokens — pulled together from infostealer malware infections across services including Apple, Google, Facebook, and Telegram, surfacing on criminal marketplaces in June 2025. Separately, a data broker called National Public Data lost roughly 2.9 billion records covering an estimated 170 million people — full names, Social Security numbers, decades of address history (IBM's writeup of the incident is worth a read) — and that dataset kept circulating on dark web markets throughout 2025, more than a year after the original breach. Qantas got hit in 2025 too: attackers social-engineered their way into a third-party customer service platform in June, and after the airline refused to pay a ransom, dumped roughly 5.7 million customer records — names, emails, birth dates, frequent-flyer numbers — onto the dark web that October (Qantas's own public breach timeline confirms it). None of these companies wanted this to happen. It happened anyway, because a large enough pile of valuable data is, by definition, a target worth attacking.
And this isn't hypothetical for the platform we just spent a whole section on. VK has been breached, leaked, or scraped repeatedly across more than a decade: around 100 million account credentials — plaintext passwords included — were stolen and put up for sale on the dark web for the price of a fast-food meal back in 2016 (Have I Been Pwned has the full record); over 32 million scraped and API-pulled records, including data from supposedly private and closed profiles, surfaced in a 2022 leak; more than 390 million user records were dumped on a hacking forum in September 2024 (Cybernews covered it in detail); and as recently as February 2026, researchers found malicious Chrome extensions had hijacked over half a million VK accounts to spread malware and manipulate security tokens. Whatever VK collects doesn't just sit in a vault under VK's control forever — history shows it eventually ends up copy-pasted onto a forum where anyone with a few dollars in cryptocurrency can buy it. And once your name, phone number, location history, or password is sitting in a criminal marketplace, it isn't used to sell you sneakers anymore. It's used for account takeovers, SIM-swap fraud, blackmail, and identity theft — by people with considerably worse intentions than an ad network.
This is the actual argument for minimizing what gets collected in the first place, and it has nothing to do with distrusting any single company's intentions. It's just math: the less data exists about you in any one place, the less there is to steal when — not if — that place eventually gets broken into.
Windows would like to remember everything you've ever looked at
Microsoft shipped a feature that screenshots your desktop every few seconds and uses on-device AI to let you search your own life like a browser history. It's called Recall. The first version stored everything in a folder, unencrypted, extractable by a two-minute script researchers named — I am not making this up — "TotalRecall." After the backlash, Microsoft rebuilt it: encrypted, tied to Windows Hello, wrapped in a hardware-isolated enclave, off by default.
Great. Except security researchers have gone back in more than once and found new ways to reach the stored data anyway — most recently in early 2026. The pattern repeats: Microsoft hardens it, someone breaks it again, Microsoft patches it. The core problem was never really the encryption implementation. A running photographic log of everything you've ever typed or clicked is an extraordinarily attractive target no matter how good the lock is. A vault is still a vault worth robbing.
Quick detour, because you're probably thinking "fine, I'll just get a VPN." Good instinct. Bad ending, sometimes.
I actually did this — emailed a mid-market paid VPN provider (Russian-jurisdiction, "no-logs" is literally in their marketing) with one clean question: do you store IP addresses and connection timestamps, and can you confirm no-logs in writing?
Their first reply: "We don't store or share client data with third parties." Clean. Confident. Case closed, right?
So I sent back their own privacy policy. Turns out their own terms define "processing" — using the exact wording from Russia's data protection law — as including collection, storage, and retention. And their own clauses say IP addresses and login timestamps get "processed." And a separate clause says processing happens on Russian territory. And another says data gets handed over if Russian law requires it.
Their second reply, paraphrased because their actual answer ran three defensive paragraphs: "technically it's only in RAM, only for the session, destroyed after you disconnect, and we're legally required to use that wording from the law, we can't change it."
Here's the part that matters and takes five seconds to understand: RAM is still storage. If your IP and timestamp exist anywhere a system can read them — disk or memory, doesn't matter — while your session is active, and that system sits inside a jurisdiction that can legally compel a live extraction, then "no-logs" was never really a technical guarantee. It was a marketing sentence sitting on top of a legal document that says the opposite in its own words.
I'm not naming the company, and I'm not telling you every VPN does this — plenty of providers publish real, independently audited no-logs reports and mean it. I'm telling you to do exactly what I did: ask the pointed question, then actually read the policy they hand you afterward, especially the definitions section. If "processing" quietly includes "storage" and the company sits under a jurisdiction with broad data-access laws, you haven't bought anonymity. You've bought a very polite waiting room.
Your phone is a rental, and you're the tenant who can't change the locks
You paid full price — sometimes over a thousand dollars — for a device you don't fully control. Bootloaders are locked. Bloatware is preinstalled and often can't be removed without voiding a warranty or tripping hardware checks that quietly break your banking app. The manufacturer decides what OS you're allowed to run, which repair shops count as "authorized," and how long the device gets security updates before it's engineered into obsolescence. You're the owner on paper and the guest in practice. The device is the hook; your data and your next upgrade purchase are the actual product.
The passport paradox
Here's where it gets genuinely interesting, and where I want to be careful, because this isn't a story with a villain — it's a story with a trade-off, and different countries are answering it completely differently at the same time.
Vietnam just did something almost nobody expected: starting January 1, 2026, its new Law on Personal Data Protection bans social platforms operating there — local or foreign — from requiring users to upload a photo of their ID card or passport just to verify an account. It also bans platforms from reading private messages or recording calls without consent. That's a real, enforceable ban with serious financial penalties attached. At the same time, Vietnam is separately rolling out rules requiring accounts to be linked to a verified local phone number or national ID number for anti-fraud purposes. So the picture isn't "more privacy" or "less privacy" — it's "no more handing platforms a photo of your actual passport," while identity still gets tied to you through a different, arguably less exploitable channel. Genuinely nuanced, genuinely worth watching.
Europe took the opposite visual approach for an entirely different reason. In early 2026, a new EU-based platform called W Social launched as a deliberate alternative to X, built specifically to be bot-resistant: to post, you verify your identity by scanning a passport or national ID card and a selfie through a separate companion app. The pitch is that the scan and match happen on your own device, and the company says it doesn't store the document itself centrally — you can also browse anonymously with reduced functionality if you skip verification entirely. Whether "we process it locally and don't store it" survives contact with millions of users and a few years of pressure is exactly the kind of promise worth revisiting in twelve months. It's the same core question as always — how much of "prove you're human" ends up as "here's your permanent identity record" — just answered by a private company instead of a government this time.
Russia's telecom regulator, Roskomnadzor, put forward a proposal back in 2021 that would have required new social media and messenger users to submit passport details, home address, and contact information, cross-checked against the state's Gosuslugi portal, as part of consent-management infrastructure for personal data. To be clear about where this actually stands: it was a draft proposal, not a law that took effect, and it hasn't been implemented as originally floated. I'm not going to pretend to have a verdict on whether that specific idea was good policy or bad policy — plenty of countries debate identity requirements for online services, for all kinds of legitimate and illegitimate reasons, and that's a conversation about tradeoffs, not a referendum on any one government. What's actually worth sitting with is the pattern above it: state ID portals, private "trust and safety" platforms, and social networks are all reaching for the same solution — link your face and your legal identity to your online activity — at almost exactly the same moment, for reasons ranging from fighting bots to fighting fraud to fighting disinformation. Some of those reasons are good. The output is still the same: your passport, your biometrics, and your posting history increasingly living in the same place.
And that's the actual tension, stripped of any single country's politics: identity verification is a genuinely reasonable answer to bots, fraud, and disinformation. It is also, structurally, a new centralized target. So next time something asks you to prove you're human, the interesting question isn't whether they have a good reason today. It's what happens to that proof on the day their reason stops mattering. You don't need me to answer that one for you — but here's a hint: databases don't retire. They just wait.
So what do we actually do about it?
Here's the part where I disappoint anyone expecting a manifesto: I'm not telling you to throw your phone in a lake and move to a cabin. I use the apps too. I like fast information and dumb memes as much as anyone. This isn't a call to abandon convenience — it's a call to stop pretending the convenience is free.
You can also do nothing. Close the tab, keep scrolling, change nothing — that's a real option and nobody's coming to stop you. Or you can spend the next two minutes doing this, right now, before you close this tab:
- Open your phone's settings.
- Pick one app you use daily — VK, Instagram, whatever's already open in another tab.
- Turn off its access to your microphone, contacts, and location if the app doesn't strictly need them to function.
Done. That's it. You just did more for your own privacy in two minutes than most people will do all year. Not a revolution. Not a lake cabin. Just one small door you closed that used to be wide open.
A few more things that cost five minutes each and nothing beyond that:
- Turn off ad personalization in your Google, Meta, and TikTok settings. It doesn't stop collection, but it shrinks the targeting surface.
- Use a real password manager and 2FA. Most "hacks" are just reused passwords from a breach nobody rotated.
- Read one privacy policy this year. Just one. You'll never look at "free" the same way again.
- If you're a developer, push back inside your own stack. You decide what telemetry ships in the product you build. That's more power than most people in this conversation will ever have.
Here's the uncomfortable part, though. You probably think of yourself as a person — opinions, habits, a face. Every system described in this post thinks of you as a row. A data point with a name attached purely for convenience. You don't have to agree with that framing. But once you've actually sat with it for a second, it's a little harder to just close the tab and pretend you didn't read this.
Now, about why you actually read this whole thing
Since we're being honest with each other: this post used a specific structure on purpose, and it's worth naming, because recognizing the pattern here is the same skill that protects you from the next one.
- It opened with a myth I could confidently debunk — trust, earned fast.
- It escalated with dollar figures and jury verdicts — specificity that reads as credibility, whether or not you checked it yourself (you should).
- It made the threat feel like it's happening to you, right now, not to some abstract "user out there."
- It gave you a way out that felt like a choice, not an order — do nothing, or spend two minutes. Either way, you decided.
- It handed you one small, immediate action instead of a vague suggestion, because five minutes of resistance beats another lecture you'll forget by tomorrow.
- It pulled you into an unresolved debate — the passport paradox — with no clean villain, because open loops keep people reading.
- It's closing on a moment of "wait, is this article doing the thing it just described" — a little vertigo is what makes people screenshot something and send it to a friend.
None of that makes the verified parts above less true. The Flo verdict happened. The $425 million happened. The localhost tracking happened. I flagged the one item I couldn't fully verify as exactly that — a claim, not a fact — because the moment you stop distinguishing the two, you've become exactly the kind of unreliable narrator this whole post is warning you about. But the fact that true information can be arranged to hook you exactly like an ad can is, honestly, the whole point of this post. The mechanism doesn't care whether the payload is a sneaker ad or a privacy manifesto. Worth remembering the next time something online makes you feel like you have to keep scrolling — including this one.
One last note, plainly stated: everything in this piece is either a matter of public court record, a regulatory decision, published academic research, or the output of an open, independently verifiable auditing tool that anyone can run themselves — sources are linked or named where they exist specifically so you don't have to trust me. The one exception is flagged inline as an unverified claim, not presented as fact. This is a personal, informational write-up, not legal advice, not a security audit of any product named here, and not a statement about the character, intentions, or legitimacy of any company or government mentioned. Company names, product names, and country names appear because they're the ones with public data behind them — not because I'm accusing anyone of anything beyond what's already a matter of public record. If something here is factually wrong, I'd rather be corrected than be right — go check the sources, that's what they're there for.