All articles

What personal data are you giving away?

Kent — founder, former banking CTO/CIO · July 9, 2026

What you hand over

Think about what you handed over this week without thinking: an email address for a discount code, a phone number "to verify your account," a birth date for a form that didn't really need it. None of it felt like a decision. That's the point — giving away personal data is designed to feel like nothing.

This isn't an argument for paranoia. Most of these trades are harmless, some are genuinely useful, and you can't opt out of modern life. But the pile compounds quietly, it never expires, and you never see who's holding it. Here's what's actually being collected, what it's used for — and a realistic, twenty-minute way to take some of it back. No particular app required.

Where it leaks

Four taps, always running

There's no single faucet — your data drips from four places at once. Each leak is small; it's the combination, assembled by people you've never met and held forever, that becomes a profile of your life.

Every form you fill

Sign-ups, checkouts, warranties — each asks for a little more than it needs, and keeps it longer than you'd guess.

Apps and trackers

Location, contacts, browsing, device IDs — gathered in the background and shared with partners you've never heard of.

Breaches you never hear about

Companies you forgot exist still hold your details — and when they're breached, your data leaks while you do nothing at all.

Data brokers

A quiet industry assembles the pieces into a profile — home, family, income, habits — and sells it to whoever's buying.

What it's for

Mostly money. Some of it corrosive.

The same profile gets put to work in very different ways — from mildly annoying to genuinely dangerous.

Ads, prices, scores

Your profile sets the ads that follow you, the prices you're quoted, and risk scores you never see.

Spam and scams

Scammers shop the same market the advertisers do — that's how the calls already know your name.

Identity theft

Add breached passwords to a rich profile and it stops being about ads — that's what identity theft is made of.

A hand feeding a blank sheet into a small home paper shredder — taking back what's yours, one piece at a time.

Take it back

You can't get it all back. You don't need to.

Chasing every last scrap would eat your life. What actually moves the needle — in about twenty minutes — is cutting off the master keys, shrinking what's already out there, and refusing to feed the pile.

The 20-minute pass

Five moves, biggest levers first

You don't need to finish in one sitting — each one stands on its own.

1
Change the locks on your master keys. Your email and phone number unlock everything else. Give every account its own password — a password generator makes it painless — and turn on two-factor authentication for email and banking first.
2
Audit what your apps can reach. Ten minutes in your phone's privacy settings: revoke location and contacts from apps that don't need them, and remove third-party apps you no longer use from Google, Apple, and Facebook — each one is an open tap.
3
Delete the accounts you've abandoned. Every dormant account is a future breach with your name in it. Search your inbox for "welcome to" and "verify your email" to rediscover them, then close what you don't use.
4
Opt out where it counts. Run the opt-out pages of the big people-search and broker sites, and use the "do not sell / delete my data" links the law now requires many companies to offer. One pass removes most of what a casual search surfaces.
5
Give less, going forward. Many fields are optional even when they look required — the dentist doesn't need your SSN, and the newsletter doesn't need your birthday. When something matters enough to keep at all, keep it somewhere only you can open.

Your rights

The law is catching up

Depending on where you live, the law is increasingly on your side.

Europe's GDPR and California's CCPA/CPRA — echoed by a growing list of states and countries — give you the right to see what a company holds about you, correct it, delete it, and refuse its sale. Exercising those rights is usually one footer link away: look for "privacy choices," "do not sell," or "privacy request." It isn't instant and it isn't universal, but it's real leverage that didn't exist a decade ago. (Details vary by place; this isn't legal advice.)

Where Simply Once fits

Every step above follows one pattern: scatter less, control more. That's the whole idea behind Simply Once — your identity, documents, and details in one encrypted place instead of a hundred forms and inboxes. You share exactly the field that's needed, you can always see who has what, and zero-knowledge encryption means nobody, us included, can read what you keep. The less of you that's scattered, the less there ever is to take back.

Part of the guides to protecting your personal data online and organizing your family's important information →

Get the monthly note

One useful, jargon-free email a month on keeping your digital life organized and protected — no spam, unsubscribe anytime.

No spam, ever. Unsubscribe anytime.