Support & Education For people, not just companies The debunkings are the useful part

Your phone probably
isn’t listening.
The truth is worse.

Almost everyone has had the experience: you mention a thing out loud, and an ad for it appears. The conclusion feels obvious. It is also, on the best available evidence, probably wrong, and the reason it is wrong is more unsettling than the theory it replaces.

Nobody needs your microphone. What exists instead is an economy built on location, purchase history, app signals and inference, most of it legal, some of it recently fined, and almost none of it requiring anyone to hear a word you say.

This is an honest tour of it, with the folklore removed in both directions, and it ends with the four things that measurably work.

Jump to what works ↓
Two rules for this page:
no scary numbers we cannot source, and no lazy debunking either. Where the evidence has limits, we say so.

The business that
has your file.

↳ starting with a number nobody can actually support

You will see the data-broker industry described as worth two hundred billion dollars, or two hundred and fifty. Nobody credibly knows what it is worth. Those figures trace back to commercial market research rather than to any regulator, court or peer-reviewed source. The only government-audited figure is from a 2014 FTC study of nine brokers, and it should not be extrapolated either.

What can be counted is companies. California’s official data-broker registry listed 581 registered brokers as of June 2026, its highest count ever. That is a floor, since it only includes the ones that registered.

↳ what is actually in a file:

When the FTC studied nine data brokers in 2014, it found one holding 3,000 data segments on nearly every US consumer, and another adding three billion records a month. Published segment names included “Expectant Parent,” “Diabetes Interest,” “Financially Challenged,” and two, “Urban Scramble” and “Mobile Mixers,” that the FTC noted concentrated low-income Latino and Black consumers.

That report is old. The bridge to the present is the FTC’s 2024 complaint against InMarket Media, which described roughly 2,000 audience segments including “parents of preschoolers,” “Christian church goers,” and “wealthy and not healthy.” The categories did not get less intimate in the intervening decade.

↳ and enforcement is real, and did not stop:

X-Mode Social and Outlogic, finalized April 2024, was the first-ever ban on selling sensitive location data. The order’s definition of sensitive locations expressly includes religious organizations, LGBTQ+ venues and protest sites. The company’s SDK had been in more than 300 apps, with no sensitive-location policies at all until May 2023. InMarket Media followed in May 2024 with the first outright ban on selling precise location.

Mobilewalla, December 2024, is the most quotable: it collected bid-request data even when it did not have a winning bid, pairing more than 500 million advertising IDs with precise location. Gravy Analytics and Venntel were finalized in January 2025. On Kochava, the FTC announced a proposed order in May 2026 that would bar selling sensitive location without express consent and require telling consumers who their location data was sold to. We will update this line with the final order and its entry date once that document is linkable; until then, treat the case as announced rather than concluded.

None of these carried a monetary penalty, which is worth knowing. But the enforcement did not stop with a change of administration: Mobilewalla and Gravy in January 2025, GM and OnStar in January 2026, Match and OkCupid in March 2026, Kochava through mid-2026.

↳ the one genuinely new tool:

California built a single delete button.

The Delete Request and Opt-Out Platform has been live since 1 January 2026, and more than 300,000 Californians signed up in its first five months. You verify identity through Login.gov or the state’s identity gateway, and the minimum you supply is name, date of birth and ZIP. Since 1 August 2026, registered brokers have been required to check it and process deletion requests at least every 45 days.

Enforcement against brokers who ignore it has begun. We have seen specific fine amounts reported for individual brokers in August 2026, but as of 16 August 2026 we could not locate the underlying CPPA orders, so we are not printing the figures here.

Two limits, both important. It is for California residents only. And it reaches registered brokers, which is to say not the ones being fined for never registering. Vermont also maintains a registry; Texas and Oregon have registry laws whose public portals we could not verify, so we are not linking them.

Your email address is
the primary key.

↳ here is where it already leaked from

A file like the ones above is not assembled from one source. It is stitched together, record by record, from purchases, app SDKs, public records and breach dumps, and the stitching only works if there is a field two records have in common. That field is usually your email address.

Which makes the breach index an unusually honest mirror. It does not show you your broker file, because nobody will show you that. It shows you the raw material: which companies lost your address, and what they lost alongside it.

Read the results as inputs, not as an incident.

Each card below carries a line naming what that particular leak makes joinable. None of it means a broker holds a file on you specifically. It means the field exists, in public, attached to your address, and the entire industry above is built on exactly that.

Breach lookup

Check an address

The one you have used longest is the one worth checking. Ten years of an address is ten years of joins.

Privacy: the address is checked against Have I Been Pwned through our own server. We do not save it in application storage or analytics, and we do not add it to any list. Being straight with you about the limit: it does travel through our server to HIBP, and transient operational logs may exist somewhere in that delivery chain, which is not something we can promise away. If you would rather avoid that entirely, look the address up on their own site instead. Full detail in our privacy policy.

Breach data powered by Have I Been Pwned.

The trail your phone
leaves anyway.

↳ the carriers stopped; the market did not

Between 2018 and 2019, all four major US carriers shut down the programs that sold customer location data to third-party aggregators, after reporting revealed that a sheriff’s deputy had obtained location data by uploading his own car-insurance policy as the “legal authorization,” and that bounty hunters had bought access. In April 2024 the FCC fined the four carriers nearly $196.5 million in total: $80,080,000 for T-Mobile, $57,265,625 for AT&T, $46,901,250 for Verizon and $12,240,000 for Sprint.

The carriers challenged the fines and the appeals split. In June 2026 the Supreme Court ruled 8 to 1 for the FCC, holding that because a forfeiture order does not itself compel payment and the government must win a jury trial before collecting, issuing one without a jury does not violate the Seventh Amendment. The fines against Verizon, T-Mobile and Sprint are final. AT&T’s is not: its case was reversed and remanded, and the Fifth Circuit expressly did not reach its other arguments, with no new opinion as of 15 August 2026.

The consumer-facing win that survived untouched: two circuits held that device-location data is statutorily protected customer information under Section 222.

“all of the participating carriers ended their LBS programs. So our decision today does not address any ongoing practice… They have simply shifted to obtaining this same type of location information from other types of entities.”
Brendan Carr, dissenting from the AT&T order, before becoming FCC Chairman in January 2025 · FCC enforcement documents

That is the honest bottom line, and it comes from the agency’s own current chairman. The carriers got out of the business. The business did not need them.

↳ where it moved to: the advertising bid stream

Every time an app loads an ad, a request goes out describing the device and often its location, and it goes to many potential bidders at once. Companies collect from that stream whether or not they ever win a bid, which is exactly what the FTC described Mobilewalla doing.

The best current investigation is Databroker Files: Targeting the EU, published November 2025 by netzpolitik.org with BR, Le Monde, L’Echo and BNR. It is empirical rather than modelled: cumulatively more than 13 billion location points, obtained as free samples. The Belgian slice alone exposed devices at the European Commission headquarters, the European Parliament, NATO headquarters, and the home addresses of five officials. The series was still running as of 11 August 2026.

Two cautions about the numbers you will see quoted elsewhere. The widely-repeated claim that your phone broadcasts your location a specific number of times per day comes from an aggregate industry broadcast count divided by an assumed online population, drawn from a confidential unpublished source, and the organization that produced it called it a low estimate. We are not going to repeat it as a per-person figure. And the claim that one surveillance vendor profiled five billion people is that vendor’s own marketing claim, not a measurement.

On enforcement: no EU or German regulatory outcome resulted from the Databroker Files through August 2026, and the long-running challenge to the ad industry’s consent framework has gone the industry’s way on appeal twice. The fair summary is that it remains unresolved after more than four years of appeals.

↳ the leak that showed the plumbing:

In January 2025, a hacker who had contacted the company obtained data from Gravy Analytics using a stolen cloud key, and posted a sample. Not the database: a sample, containing more than 30 million location points, including devices at the White House, the Kremlin, the Vatican and military bases. Its parent filed with Norway’s data-protection authority and the UK ICO confirmed receiving a report.

The load-bearing finding is the one that reads backwards from the headlines. The files listed source app names, including dating apps, games, fitness trackers, period trackers, prayer apps and VPNs. But researchers who examined them concluded the data came from the advertising bid stream, not from code embedded in those apps. The named apps denied any relationship with the broker. As one researcher put it, the evidence suggested the broker was acquiring data from the bid stream “rather than code embedded into the apps themselves.”

So the correct lesson is not “delete that app.” It is that an app you trust can leak your location through an ad request it did not choose the recipients of. And the company was not shut down: it now redirects to its parent, which raised $28 million in December 2025 and is still marketing location data.

↳ three famous stories, told accurately:

Muslim Pro. Reporting established two parallel things: that the app sent data to the broker X-Mode, and that X-Mode sold to defense contractors. It never established that the US military received Muslim Pro users’ data specifically, and the reporters said so themselves. The FTC’s X-Mode complaint names neither the app nor the military.

Life360. The family-safety app was one of the largest sources of raw location data, earning $16 million from it in 2020. It is often said to have stopped in 2022. It did not: it exited the broker market with exceptions, and its own FY2025 annual report shows data revenue of $32.7 million in 2025, up from $26.6 million and $21.6 million in the two prior years, with risk factors conceding precise geolocation is a core component of its products.

The priest. In 2021 a publication bought commercially available app signal data from an unnamed vendor and used movement patterns to identify a US church official, who resigned. The data carried no name; the attribution was inference. It was never established that any particular app sold or leaked his data. Separately and unrelatedly, Norway fined Grindr NOK 65 million in December 2021 over conduct that ended in April 2020, upheld on appeal three times through October 2025. Those are two different stories and they get merged constantly.

And what a subscription buys. In October 2024, a private investigator hired by a privacy company obtained a free two-week trial of a location-tracking tool sold to government, and was told that merely contemplating future government work was “good enough” and that “they don’t actually check.” The demonstration showed devices at a mosque, a synagogue, and a juror parking lot. Read that as a capability demonstration by a company building a lawsuit, which is what it was, rather than as evidence that particular people were surveilled.

And in the
physical world.

↳ cameras, stores, and one opt-out that genuinely works

Licence-plate camerasScale is company-claimed

Flock Safety says its cameras operate in thousands of US communities and scan billions of vehicles each month. Those figures come from the company and have not been independently audited.

What is documented is a 2025 sworn affidavit describing a Texas detective querying roughly 83,000 cameras nationwide, including in states where the conduct under investigation is legal. The sheriff characterised it as a welfare check and the company called it a missing-person case; the affidavit contradicts both. A Fourth Amendment challenge to a municipal camera network is on appeal, with no ruling as of August 2026.

DoorbellsReversed, then re-reversed

Ring ended its police video-request tool in January 2024, announced a partnership in October 2025 that would have let agencies request footage again, then cancelled it in February 2026 after public backlash, saying it had never been implemented.

Its exact current mechanism is unconfirmed, so check Ring’s own policy page rather than trusting any article, including this one, on what police can request today.

StoresThe clearest order on record

In December 2023 the FTC banned Rite Aid from using facial recognition for surveillance for five years. It had been deployed from 2012 to 2020 across hundreds of stores, and the FTC found the system “generated thousands of false-positive matches,” and was more likely to generate them in plurality-Black and Asian communities than in plurality-White ones.

The order also required deleting the images, notifying consumers when biometric information is enrolled, and independent security assessments. Rite Aid liquidated its stores by October 2025, so the practical effect is limited, but the findings stand.

↳ the most actionable thing on this page:

You can decline the airport face scan.

From TSA’s own page, verbatim: “Facial comparison technology is voluntary. Tell a TSA officer if you do not wish to participate.” And: “Tell the officer if you do not want your photo taken. You will not lose your place in line.

TSA also states that your photo and personal data are deleted after your identity is verified, and that images are not used for law enforcement or surveillance and are not shared with other entities. Digital IDs are accepted at more than 250 airports, though a physical compliant ID is still required.

Two related notes. TSA ConfirmID is a $45 optional service for travellers without acceptable ID, and TSA says that if you choose not to use it and lack acceptable ID you may not be allowed through security. And a DHS final rule from October 2025 expands biometric collection for aliens entering and departing; it does not require photographing US citizens, whatever you may have read.

So is your phone
listening?

↳ the honest answer, in both directions

This is the question everyone actually came for, so it deserves a careful answer rather than a confident one.

A large field study

No app was caught sending audio

Researchers at Northeastern University analysed 17,260 Android apps across four app stores. Their finding, verbatim: “We did not find any true positive audio files in our extracted dataset, i.e., no apps appeared to exfiltrate audio in our tests.”

What they found instead was arguably worse. Third-party analytics libraries were uploading screen recordings and screenshots with no permission requested and no notification. One conference app sent 45 screenshots, including contacts and messages.

State the limits, as the authors did: automated interaction could miss audio transcribed or transformed on the device, the study was Android-only, and it was published in 2018. No newer replication was found. “No evidence found, with known blind spots” is the honest summary. Not “proven impossible,” and not “repeatedly debunked.”

The famous proof

It was false advertising

In 2024 a media company’s leaked pitch deck advertised an “Active Listening” product and named major platforms as partners. It circulated everywhere as proof that phones listen, and Google dropped the company from its partner programme.

Then in May 2026 the FTC charged the company and two others with falsely representing that the product worked. The FTC’s position: it never listened to anyone and used no voice data. It was resold data-broker email lists at inflated prices with inaccurate geo-targeting. The settlement totalled $930,000.

The most-cited proof that phones listen is now on the record as a company being penalised for claiming a capability it did not have.

↳ where the microphone genuinely is the story:

Wake words. Apple settled the Siri litigation for $95 million, with final approval in November 2025 and payments distributed from January 2026, averaging about $8 per device. Apple denied that Siri data was used for advertising. Amazon paid $25 million in May 2023 over retaining children’s voice recordings indefinitely, ignoring parental deletion requests, and using that audio to train speech models.

And your television. Automatic content recognition is the quieter version of this. In 2017 Vizio paid $2.2 million after capturing second-by-second viewing from roughly 11 million televisions, surfaced to owners only as a feature called “Smart Interactivity,” then appending age, income, marital status, education and home value and selling it.

A 2024 academic audit of current Samsung and LG sets found ACR running even when the television was used as a plain HDMI monitor. Here is the encouraging half, and it is the reason to bother: opting out actually stops the traffic. The researchers measured it. Menu names drift between firmware versions, so find the setting in your own set’s current support article rather than trusting a name from an article.

Your car, too. In January 2026 the FTC finalized an order against GM and OnStar over collecting and selling precise geolocation and driving-behaviour data from millions of vehicles without adequate notice or consent, including to consumer reporting agencies. It carries a five-year ban on that sharing and a twenty-year express-consent requirement. California settled separately for $12.75 million in May 2026, and several state attorneys general have their own suits running.

When it is
someone you know.

↳ read the safety note before the how-to
Please read this first

If you think someone is monitoring your phone, do not start by removing it.

From the Coalition Against Stalkerware, verbatim:

“Removing stalkerware or other monitoring detection and/or making significant changes may be detected by the abuser and could increase the abuse and harassment.”
“Deleting stalkerware means also deleting evidence related to this. If you wish to report the incident, you may need to seek help from law enforcement, as this evidence could be helpful.”

Their guidance is to build a safety plan with the assistance of a trusted survivor assistance program, and to attempt removal only if you believe it is safe to do so. That ordering is deliberate and it matters more than anything else in this section.

National Domestic Violence Hotline: 1-800-799-7233, available 24 hours a day and confidential. Technical safety guidance is available from stopstalkerware.org and techsafety.org.

↳ how common, honestly:

The most recent industry count comes from one security vendor’s 2023 to 2024 report: 31,031 unique affected users in 2023, up from 29,312 the year before, with the largest counts in Russia, Brazil and India. No 2025 or 2026 edition exists.

The vendor’s own caveat is the important part: “The statistics reflect only mobile users of Kaspersky’s security solutions.” These counts undercount badly. Treat them as a floor, not a prevalence rate.

The same report’s survey found 12% of respondents admitting they had installed monitoring software or altered settings on a partner’s phone, 13% reporting a partner had done so to them, and 23% encountering online stalking from someone they had recently started dating.

↳ trackers, and what actually shipped:

In May 2024 Apple and Google jointly shipped a detection specification, so that an unknown tracker moving with you produces an alert regardless of the platform the device is paired with. It is in iOS 17.5 and Android 6.0 and later, and Chipolo, eufy, Jio, Motorola and Pebblebee committed to compatibility. Call it an industry specification rather than a standard: the underlying draft has expired.

Two limits worth stating. It detects trackers, not a phone running monitoring software, which is the more common interpersonal case. And the AirTag litigation against Apple is still live: a docket entry showing it terminated in July 2026 reflects a transfer to a different district, not a dismissal or settlement.

If you are checking a device and it is safe to do so, the places to look are app permissions and Safety Check on iOS, and on Android the device-admin app list and, above all, accessibility services, which is the mechanism most monitoring software relies on. Verify the exact menu paths on the device itself, since they move between versions.

And at work.

↳ one Puerto Rico line that is genuinely unusual

In the United States generally, private-sector monitoring of company systems is largely lawful. Federal wiretap law’s business-use and consent exceptions do most of the work, and employers are commonly advised to eliminate any reasonable expectation of privacy on company systems. State wiretap laws, particularly in two-party-consent states, constrain the recording of conversations more than they constrain monitoring generally.

Some states require notice. New York has required prior written notice of email, internet and phone monitoring since 7 May 2022, and Connecticut and Delaware have comparable notice laws.

↳ a correction, because this one is widely repeated:

A 2022 National Labor Relations Board memo would have treated pervasive worker surveillance as presumptively unlawful where it chills organizing. That memo was rescinded on 14 February 2025, so it no longer reflects agency enforcement policy. Any guide describing it as current is out of date.

On how common monitoring is: count the tools, not the adopters. Reliable figures on how many employers actually monitor are scarce, and most quoted percentages come from vendor marketing surveys with undisclosed methodology. The defensible datapoint is that Coworker.org’s database documents more than 550 labor-focused monitoring products developed since 2018.

↳ and the local exception:

Puerto Rico is unusual: its constitutional right to privacy under Article II, Section 8 has been applied directly against private parties, not just the government. In Arroyo v. Rattan Specialties (1986), the Supreme Court of Puerto Rico relied on it to limit a private employer’s polygraph testing of its own workers.

We are deliberately keeping that to one sentence and its case. The facts and the constitutional grounding are verified, but the further doctrinal reach is not something we will assert without counsel review. And we will not tell you Puerto Rico has no employee-monitoring statute, because we could not verify that negative either way. If this affects you, that is a question for a Puerto Rico employment lawyer, and it is a genuinely better question here than it would be on the mainland.

What actually
works.

↳ four things, and the free one wins

Consumer Reports ran the test almost nobody runs: it compared seven paid data-removal services against simply filling out the opt-out forms yourself, using 32 volunteers across 13 people-search sites, checked at one week, one month and four months.

Consumer Reports comparison of data-removal approaches, profiles removed at four months
ApproachAnnual costProfiles removed at 4 months
Doing it yourself$070%
Optery (Ultimate)$24968%
EasyOptOuts$19.9965%
IDX (Privacy Tier)$139.9240%
Kanary$179.8834%
DeleteMe$12927%
ReputationDefender (Privacy Pro)$996%
Confidently$1204%

Consumer Reports, Data Defense, August 2024. Of 332 profiles, 117 (35%) were removed within four months by the paid services. Doing it yourself was also faster: 70% gone within a week, against 26% for the services. CR states its own limits plainly, and so should we: a small non-random sample, explicitly not statistically significant or nationally representative, in which researchers supplied only name, current address and date of birth and never engaged with dashboards or follow-up requests. Real users who do engage may get better results.

↳ two things worth knowing about that industry:

Consumer Reports also found that some removal services advertise on, or partner with, the people-search sites they claim to fight. And Permission Slip, the free tool Consumer Reports itself built, is now owned by DeleteMe, a commercial removal service that CR’s own study ranked mid-tier at 27%. A free tier remains, alongside a paid upgrade. That is not an accusation, but it is a disclosure you should have before choosing a tool.

1. If you are in California, use DROP

One free request that reaches every registered broker at once, at consumer.drop.privacy.ca.gov. Since August 2026 brokers must process it at least every 45 days. Nothing else on this list has that reach.

2. Decline the airport face scan

It is voluntary, TSA says so on its own page, and you keep your place in line. The single lowest-effort item here.

3. Turn off ACR on your television

Independent researchers measured it and the traffic actually stops. Find the setting in your set’s current support article, since the menu names change between firmware versions.

4. Do the opt-outs yourself

Free, and it outperformed every paid service tested. If you would rather pay, the $19.99 service beat several costing six times more.

5. Reset your advertising ID

On iOS, Settings then Privacy & Security then Tracking. On Android, delete or reset the advertising ID under privacy settings. Check the current path on your own device; these menus move.

6. Expect to repeat it

Removal is maintenance, not a one-time fix. CR found profiles reappearing weeks or months later, which is the strongest argument for the free method: you can afford to do it again.

↳ and the limits, said plainly:

You cannot opt out of data breaches. You cannot opt out of government and court records. You cannot reach brokers who never registered anywhere, which is precisely the set being fined for not registering. DROP is California-only. And none of this is permanent.

One more piece of context for anyone who assumed the industry was fixing itself: in October 2025 Google retired most of Privacy Sandbox, the flagship replacement for third-party cookies, citing low levels of adoption, and stated that Chrome will maintain its current approach to third-party cookie choice. Third-party cookies did not go away. The privacy-preserving replacement mostly did.

a note on this page ↳

This is education, not legal advice. Everything above is as of 15 August 2026, and this is a fast-moving area where several of the cases described are still on appeal and several settings change between software versions. Where a menu path or a company’s current practice matters to you, check the vendor’s own page rather than trusting any article, including this one. If you are in danger from someone who knows you, start with the hotline above rather than with a settings menu.

↳ the organizational version of this question

What does your product collect?

Everything above describes being on the receiving end. If you build or run something that collects data about other people, the interesting question is what your own stack does by default, and who it hands data to.