All articles

What personal data are you giving away?

Kent — founder, former banking CTO/CIO · July 9, 2026

Think about what you handed over this week without thinking: an email address for a discount code, a phone number “to verify your account,” a birth date for a form that didn’t really need it. None of it felt like a decision. That’s the point — giving away personal data is designed to feel like nothing.

This isn’t an argument for paranoia. Most of these trades are harmless, some are genuinely useful, and you can’t opt out of modern life. But the pile compounds quietly, it never expires, and you never see who’s holding it. Here’s what’s actually being collected, what it’s used for — and a realistic, twenty-minute way to take some of it back. No particular app required.

Where your data leaks out

There's no single faucet — it drips from four places at once:
Every form you fill
Sign-ups, checkouts, intake forms, warranties — each one asks for a little more than it needs, and keeps it longer than you'd guess.
Apps and trackers
Location, contacts, browsing habits, device IDs — collected in the background and shared with partners you've never heard of.
Breaches you never hear about
Companies you forgot exist still hold your details — and when they're breached, your data leaks without you doing anything at all.
Data brokers
A quiet industry that assembles those pieces into a profile — home, family, income, habits — and sells it to whoever's buying.
Each piece alone is small. It's the combination that turns into a profile of your life — assembled by people you've never met, held forever, and never shown to you.

What it’s used for

Mostly money, in ways that range from benign to corrosive. Profiles power the ads that follow you around, the prices you’re quoted, and risk scores you never see. Spammers and scammers buy from the same ecosystem the marketers do — that’s how the calls know your name. And when breached data joins the pile, it stops being about ads: recycled passwords plus rich personal profiles are exactly what identity theft is made of.

Here’s the uncomfortable math: you can’t take all of it back, and chasing every scrap would eat your life. What you can do — in about twenty minutes — is cut off the master keys, shrink what’s already out there, and stop feeding the pile.

A hand feeding a blank sheet into a small home paper shredder — taking back what's yours, one piece at a time.

How to take it back — the 20-minute pass

Five moves, biggest levers first. You don't need to finish in one sitting — each one stands on its own.
1
Change the locks on your master keys. Your email and phone number unlock everything else. Give every account its own password — a password generator makes that painless — and turn on two-factor authentication for email and banking first.
2
Audit what your apps can reach. Ten minutes in your phone's privacy settings: revoke location and contacts from apps that don't need them, and remove third-party apps you no longer use from your Google, Apple, and Facebook accounts — each one is an open tap.
3
Delete the accounts you've abandoned. Every dormant account is a future breach with your name in it. Search your inbox for "welcome to" and "verify your email" to rediscover them, then close what you don't use.
4
Opt out where it counts. Run the opt-out pages of the big people-search and broker sites, and use the "do not sell / delete my data" links the law now requires many companies to offer. One pass removes most of what a casual search surfaces.
5
Give less, going forward. Many fields are optional even when they look required — the dentist doesn't need your SSN, and the newsletter doesn't need your birthday. When something matters enough to keep at all, keep it somewhere only you can open.

Your rights, in one paragraph

Depending on where you live, the law is increasingly on your side. Europe’s GDPR and California’s CCPA/CPRA — echoed by a growing list of states and countries — give you the right to see what a company holds about you, correct it, delete it, and refuse its sale. Exercising those rights is usually one footer link away: look for “privacy choices,” “do not sell,” or “privacy request.” It isn’t instant and it isn’t universal, but it’s real leverage that didn’t exist a decade ago. (Details vary by place; this isn’t legal advice.)

Where Simply Once fits

Every step above follows one pattern: scatter less, control more. That's the entire idea behind Simply Once. Your identity, documents, and details live in one encrypted place instead of a hundred forms and inboxes — you share exactly the field that's needed and nothing more, you can always see who has what, and zero-knowledge encryption means nobody, including us, can read what you keep. The less of you that's scattered, the less there ever is to take back.

Get the monthly note

One useful, jargon-free email a month on keeping your digital life organized and protected — no spam, unsubscribe anytime.

No spam, ever. Unsubscribe anytime.