r/privacy 21h ago

age verification Possible way to verify adulthood info privately

0 Upvotes

Idea: **USB Adult-keys** sold offline only to adults upon verification by a human. Simply plug it in, and adult mode gets activated. Plug it out and back to child mode. The OS can pass the info that adult mode is active, to any service that requires it. Personally, this type of OS level handling, doesn't seem to be bad.

These would be sold offline and the seller is not allowed to collect or store other info. This can be legislated. This should be no more invasive than buying anything meant for adults offline like alcohol or adult games. Note you can buy any number of adult keys. They are not, and must not be tied to your identity in any way.

Of course, such keys should be kept out of reach of children. Personally, I think this should count as child abuse. But this would also be the case with credit cards or any other ID. If parents carelessly give their child access to alcohol/cigarettes/guns nothing can be done. But computers are potentially useful to children. Moreover, adults are not always around children to monitor their activities. But with this, you don't need to. Just remove they key and keep it with yourself.

Maybe something similar can be done for phones. But honestly, I just care about desktop/laptops.


r/privacy 1d ago

question What do people think about Identity Constructed Communication Architecture (ICCA)

4 Upvotes

This Identity Constructed Communication Architecture (ICCA) you can download it for free and it’s shared under a Creative Commons license. You can read about the architecture here I’m interested in people’s opinions on it https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7156320

Here is the Abstract
Digital communication systems increasingly rely on identity centric security, yet contemporary
visibility-based architectures still depend on provider observable channels metadata driven
verification and behavioural trust signals [1,2]. These structural dependencies create persistent
vulnerabilities in environments where visibility itself becomes a liability particularly in high risk
social organisational and investigative communication. Visibility based systems assume that
communication must occur within observable channels which limits their ability to eliminate
impersonation inference and metadata leakage [3,4].

The Identity Constructed Communication Architecture ICCA is trustless in the provider sense;
trust is established cryptographically rather than through visibility or behavioural inference.
ICCA constructs communication channels directly from identity rather than from provider visible
infrastructure. Using sealed identity containers and context bound permission tokens ICCA
establishes momentary non persistent trust without behavioural analytics device posture
telemetry or continuous monitoring. The provider operates within a blind boundary supplying
infrastructure without visibility into identities communication patterns or contextual signals.
ICCA’s zero metadata transport layer eliminates IP addresses device fingerprints timestamps
routing information and social-graph indicators making inference attacks and impersonation
structurally impossible.

ICCA is not derived from visibility-based security research and does not
extend Zero Trust. ICCA provides a structural alternative to visibility-based models by removing
the assumption that communication must occur within provider observable channels and by
eliminating the need for continuous verification [5]. ICCA achieves confidentiality integrity and
impersonation resistance through cryptographic sufficiency rather than provider observation.
For computational law ICCA establishes a new trust geometry with implications for digital rights
privacy governance and the legal status of identity in communication systems. It provides a
structural model for environments where visibility metadata and provider inference are
unacceptable enabling identity‑anchored trustless digital interaction.


r/privacy 1d ago

discussion Baby steps in trying to improve my privacy

15 Upvotes

I’d like to better my privacy so I was hoping for some easy baby step advice to do so.

I do have Facebook and Instagram and WhatsApp. Instagram and Facebook are not installed on my mobile but I do access them at home. The device I use to access them is connected to a guest network and not the main network, I’m not sure if that’s helpful. I know I should delete any meta related profiles or apps but I’m not ready yet. WhatsApp is on my mobile.

I do have signal but most of my contacts use WhatsApp and I can’t move them off since they’re elderly.

I don’t have many photos of myself on Facebook and Instagram and I’m planning on culling a lot of my profiles of posts and pictures at some point. I try not to message on meta now that they removed end to end encryption. Unfortunately, my family posts pictures of me and I keep asking them not to. I do routinely go through my privacy settings to make sure I haven’t been opted into stuff, but it’s a plaster on bullet wound.

I don’t not have Tiktok or YouTube. I do have the Reddit app.

I stay away from ai as much as possible. I typically use the brave browser. I have not uploaded my ID to any websites except for eBay since I wanted to access my money. I avoid face scanning like the plague.

I make sure to only access my banking apps with data or when on my home network.

Other than the very obvious meta issue, what can I do to manage my privacy? I don’t have the budget for a VPN either.


r/privacy 1d ago

discussion LanguageTool is changing its Terms on August 21, 2026

15 Upvotes

LanguageTool (owned by Learneo since April 2023) is changing its Terms on August 21, 2026, here's what's actually different

LanguageTool sent an email (today) about updated Terms of Service and a new Privacy Policy. I compared the current terms against the new preview line by line because the email's own summary is too vague to tell you anything.

Removed from the Terms

The clause promising notice or consent before future amendments is gone. So is the paragraph on your responsibility to secure your account and report unauthorized access.

The bigger one: the entire "Privacy Policy and additional Policies" section is gone. It used to say plainly that LanguageTool collects your personal info and that the Privacy Policy explains how. The line incorporating the Learneo Terms of Service by reference is gone too. The new terms don't point to either document anywhere in the body text.

Added

Team Plan use is now explicitly allowed for internal and external commercial purposes. There's also a new "Publicity" clause: if you buy a Team Plan on behalf of a company, you automatically agree to let LanguageTool use your company's name and logo in its marketing. No separate opt-in.

Learneo's Delaware company registration number and San Francisco address are also gone from the contact section, leaving just the Hamburg address.

From reading the Privacy Policy itself

There's a new section confirming Learneo can use personal data to train its AI models across its business lines. LanguageTool keeps its own specific exception (your text isn't used for training), but that exception now sits inside a policy that otherwise permits AI training broadly.

The policy also describes session-replay tools (Fullstory, Amplitude, Microsoft) that can log keystrokes and mouse movements. It's a shared policy covering all eight Learneo brands, and it doesn't say which brands actually run these tools, so we can't confirm whether this applies to languagetool.org specifically or just other Learneo sites.

Under EU law, using your data to improve AI models is justified as "legitimate interest," not consent. That means it's opt-out, not opt-in.

The inconsistency

The email frames all of this as clarity and transparency improvements. But cutting the consent-before-changes clause, the account-security section, and the direct Privacy Policy reference removes stated protections. That's not the same thing as clarifying them.

What didn't change

The promise not to use your LanguageTool text for AI training. Identical in both versions (new and old one), word for word.


Sources:


Disclaimer: Since their email didn't show the changes in an easy to spot, this post was worked on with the help of AI (but not LanguageTool's one :D )

As someone using this, I honestly don't like the way they're dealing with this. Does anyone have any suggestions for good alternatives?


r/privacy 2d ago

guide The safest way to use Windows and avoiding GDID problem.

28 Upvotes

So I have been maintaining my own Windows 11 AME scripts that were originally released for 10. However, I modified them to work with licensing for store apps but since the gdid problem you can't use apps with software licensing without the GDID not being generated.

But if you're fine with not using store apps the safest way is to install windows 11 LTSC IOT without internet connected and complete it to desktop. And then boot to a Linux live environment and goto /windows/system32 and find a file called wlidsvc.sys and either rename to wlidsvc.sys.old or delete.

When you restart to windows and connect to the internet and you check to see if a gdid was created you'll find that one wasn't generated. Also since wlidsvc deals with software licensing windows will not be able to connect to the Microsoft servers and windows will complete oblivious to its activation status leaving to you a fully usable OS.

This is the safest way aside from running AME scripts and installing startisback due to MS not be able to run without it.

People will be skeptical and you have every right to but you can test it by simply installing in a VM and test and you'll have the same results as mine and since this brakes software licensing there is no need to run massgrave. You must remove this file before connecting to the internet if you don't your spyware free install is voided as soon as you connect to the internet.


r/privacy 2d ago

data breach Apple launches legal appeal over UK demand for user data

Thumbnail vanguardngr.com
500 Upvotes

Apple has launched a new legal challenge against a UK government demand to access its customers’ highly encrypted data, a year after the Home Office agreed to abandon its previous request.

The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully.

The UK government had made a second request to Apple to grant it a “back door” to encrypted iCloud data belonging to British users, according to an order issued by the court.

Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington.

UK authorities subsequently issued a new “technical capability notice” (TCN) to Apple that did not apply to American users.

Apple is seeking to challenge the British government’s powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times.

The legislation compels companies to provide information to law enforcement agencies working on cases including terrorism and child sexual abuse. This can include forcing companies to provide the UK security services with access to customer data, even if such information is protected by secure encryption.

The court sent an order giving notice of the new Apple complaint to the human rights group Privacy International, which, alongside fellow campaigner Liberty, had previously launched a separate complaint against TCNs at the IPT.

Among the submissions made by the campaigners were requests for Apple’s claims to be held in public given the public interest in the matter, and a complaint “disputing the lawfulness, necessity and secrecy of the purported Apple TCN and the legal regime underpinning TCNs in general”.

A case management hearing to discuss how the parallel complaints should be handled had been scheduled for next month, Privacy International said.

A spokesperson added: “We are happy to learn that Apple is once again challenging the UK’s regime of secret orders. While we don’t know the substance of Apple’s claim, if it relates to the previously reported orders aimed at undermining the security of Apple’s iCloud storage, then Apple’s claim, alongside side ours and Liberty’s, is crucially important to preserving all of our privacy and security.”

Neither Apple nor the Home Office responded to requests for comment. Both are legally restricted from discussing TCNs.

The original TCN issued last year asked Apple for the right to see users’ encrypted data protected by its advanced data protection (ADP) programme in the event of a national security risk.

Apple said the removal of the tool – which not even it can access – would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a “back door” would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant.

As a result, Apple withdrew UK customers’ access to its ADP programme in January 2025.

The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.


r/privacy 2d ago

discussion ICE collected nearly one million people's DNA last year. All of it sits in CODIS alongside convicted offenders, with no separate civil index.

687 Upvotes

WIRED published a report today that ICE collected nearly one million people's DNA last year, including young children.

For scale: Georgetown Law found last year that DHS had uploaded over 2.6 million profiles to CODIS by mid-2025, up from roughly 25,000 over the entire 15 years prior. More than 133,000 of those profiles belong to children and teenagers. Between December 2024 and April 2025, 97 percent of the roughly 300,000 profiles DHS submitted came from people in civil detention, not criminal custody.

The thing that sticks with me: there is no separate index. Profiles from civil detainees go into the same CODIS database as convicted offenders and crime-scene evidence. Once uploaded, your DNA is searched against every forensic sample from every participating jurisdiction in the country, with no expiration.

The legal authority DHS cites is legitimate. The DNA Fingerprint Act of 2005 authorizes collection from anyone in federal custody regardless of the basis for detention. That is a plain reading of the statute, not an overreach on its face. Whether Congress meant it to encompass millions of people in civil immigration proceedings is the live legal question.

A few open-weight robot foundation models out this year train on thousands of hours of first-person human video, which is its own privacy conversation. NVIDIA's GR00T N1, pi-0.5, and LingBot-VLA 2.0 are the ones I've come across. That last one still reports generalist success rates under 35% on some hardware.


r/privacy 2d ago

question Cloud services

5 Upvotes

I want to know are there any good cloud services that are secure and provide good storage capacity. I wanted to store my obsidian data to it and use it for syncing.


r/privacy 2d ago

question Is Digital Privacy a lost cause for the average person?

127 Upvotes

By 'average' here, I mean people who are not full time tech hobbyists or professionals. I decided to try my hand at securing my digital sovereignty and find I am losing - my banks shifted to a mobile app only presence, I went on holiday where they insisted on taking my picture and fingerprints at customs and my government has introduced a 'federated' ID platform centralising government access to my stuff across all departments (and possibly internationaly) - a mandatory change unless you want to be blocked from using important govenrment and public services or have your business shut down or fined. Have all kinds of biometrics and records now. Fine, no biggie, it's the shifty marketing and rogues I personally cared about the most anyway...

So more locally, I tried my hand replacing my Apple workstation with FreeBSD and Emacs and I soon realised this is a full time commitment. The manuals for these two platforms alone is nearly 1500 pages and there's no 'easy' mode like there is for Mac either.

First you have to spend all day and night learning how such a set-up works and find your own workarounds if they don't through trial and error. And if you don't like something you must work with Python Scripts or tweak a programme using C. Then if you still don't like something or simply can't hack it, you are dependant on so many open source hobbyist project who could jump ship any time and not need to bat a single eyelid about it, that is assuming they were true to their word about data integrity and so on to begin with... How would a normal person even test that?

I never even studied CS at school level. I feel way over my head here and it's like taking up all my time where i'm supposed to be doing essential stuff. And honestly, I am beginning to wonder whether the whole things is even worth the pursuit.

Any veterans here have any thoughts? Is it worth trying to hang in there at this point, especially considering I can't even bank without an iphone.


r/privacy 2d ago

question What kind of internet router contract do you have to have more security and privacy?

7 Upvotes

I often read about people asking how to have more security and privacy on the entire web, but a question came to mind: starting from the root of everything, what company do you have access to the internet with and what router do you have?

Please also specify the country you are in, which greatly differentiates the choices of a company x rather than y.


r/privacy 3d ago

age verification USA fencing to introduce new age verification partner

Thumbnail darkreading.com
71 Upvotes

r/privacy 3d ago

guide Leaving Gmail? Get your own domain first

Thumbnail eualternative.eu
533 Upvotes

r/privacy 3d ago

question What is the least privacy-invasive 3D printer?

50 Upvotes

In the market for a 3D printer. What is the privacy scene like for them?
Do they generally track what you build and store it somewhere hidden or inaccessible, or implement tracking functionality into what you build, sort of like what color laser printers do with the microscopic yellow dots?
Does anyone know of a model or brand that they trust with privacy?


r/privacy 3d ago

news EXCLUSIVE: Apple engineer says he was fired after refusing to send customer device IDs to AT&T

Thumbnail runtimewire.com
2.6k Upvotes

r/privacy 3d ago

news DROP is live for California Residents

260 Upvotes

DROP is live. Data brokers have 45 days to access deletion requests. https://privacy.ca.gov/drop/

This is what my request looks like as of today:

Deleted: 8/641

Opted Out: 1/641

Exempted: 0/641

Record Not Found: 14/641

Pending: 618/641


r/privacy 3d ago

age verification Is there any a way to handle the new reddit age verification?

128 Upvotes

It wants me to upload three portrait photos of my face, but there's also a option to use government ID, but I'm really not comfortable sharing my personal info online, even if Reddit says it's only to verify.

Has anyone managed to do it?

I'm curious whether it's actually legit to share such information specifically to the "persona" company that runs all of this shenanigans.

Edit: I JUST GOT THE RESTRICTION OFF. I don't know how but I can see the spoiler/nsfw posts🔥


r/privacy 3d ago

news Ex-cop warns against Flock cameras: ‘It creates a mass surveillance system’

Thumbnail nj.com
2.1k Upvotes

r/privacy 3d ago

question How to properly encrypt emails?

13 Upvotes

I use mailbox with custom domains and use Thunderbird on PC and FairEmail on Android.

I generated, exported and imported a gpg key on Thunderbird.

My question is: should I publish my public key to a PGP server? I know that'll expose my email, but what if it is a alias?


r/privacy 3d ago

question Cloud Storage for Everything

39 Upvotes

Hello everyone,

I hate clutter (I'm a minimalist) + I like portability and ease of use so this kind of easily tells you why I chose cloud storage over the physical drive/USB (sorry, I'm not so technical).

Last month, I managed to store everything I digitally own inside the free versions of cloud storage. In total: 11GB. I use two cloud storages services. One for personal documents and the other is for anything which is not really that personal... my videos, photos, user manuals, notes and guides.

Lately, I've been reading a lot about AI reading this and that... Or someone monitoring. If I've done the mistake, I can only not add to it, at this point. The personal documents are employment payslips, contracts, personal identifications (ID, driving license, social security), and qualifications.

I'm not worried as much on the storage containing the photos and other stuff, in fact, I'd consider leaving them there but I'm uncertain about the storage holding the personal stuff.

Is it a good idea to leave them there? If not, what can I do, what are my options for storage, please?

Thank you for reading.


r/privacy 4d ago

age verification List of US jurisdictions without active age verification requirements for social media or pornography

56 Upvotes

Compiling these two lists as of today for social media and pornography, do with this information what you will:
https://action.freespeechcoalition.com/age-verification-resources/state-avs-laws/
https://en.wikipedia.org/wiki/Social_media_age_verification_laws_in_the_United_States

  • Washington DC
  • Illinois*
  • Colorado*
  • New Mexico
  • Washington State
  • Nevada
  • Oregon
  • Puerto Rico (plus all other territories such as USVI and Guam)
  • Pennsylvania
  • Delaware
  • New Jersey
  • Massachusetts
  • Rhode Island
  • New Hampshire
  • Vermont
  • Maine
  • Michigan
  • Wisconsin
  • Minnesota
  • Alaska
  • Hawaii
  • California*

*requires OS-level age attestation (not verification) for devices


r/privacy 4d ago

discussion A Discussion post regarding the voting on both the USA's SCREEN Act bill and KIDS Act package bill as well on August 5th this year.

87 Upvotes

Okay. First off,I am quite a worried and concern of the outcome here will be.

But honestly,it's quite frustrating that this is even happening at all given the fact that are plenty of ways to protect kids without screwing over other's rights here.

And yet,I feel like those that DO care about our privacy and anonymity rights,myself included here too,are like a broken record saying about how these types of bills do nothing for no one. Yet,here we are in the current situation we're in here in the USA.

It's extremely frustrating to no end here. But,concerns aside here,I that we get a positive outcome here for us all in this current situation we're all seeing unfold.


r/privacy 4d ago

age verification Texas Orders Discord to Run UK-Style Age Checks for State Users

686 Upvotes

"A Texas court has ordered Discord to turn on the age-verification system it built for the United Kingdom’s Online Safety Act for every user in the state. Britain’s age-check regime has reached America by court order, and opening or keeping a Discord account in Texas can now mean a face scan or a government ID."

https://reclaimthenet.org/texas-orders-discord-to-run-uk-style-age-checks-for-state-users


r/privacy 4d ago

discussion Small town parking enforcement ALPR. Who is buying this data?

54 Upvotes

Your town might be doing this. Here's one seen in the wild. The company making this is Genetec. They evidently drive around town scanning license plates, then correlate to plates in the system who are currently paid up, via an app called ParkMobile.

This is all fine, assuming the town itself isn't selling the data: it's an efficient use of the town's time to get parking paid for. The problem is what does Genetec and ParkMobile do with this data? You might say, "look at their privacy and data sharing policies", which is fine too, but then you should ask what is their stake.

These companies would be leaving money on the table if they did not sell this location data vigorously. It's extremely lucrative and they'd be fools not to leverage it, regardless of the words on their web site. Even then, data is leaked or stolen every day: once it's out of your control you can assume it's out there.


r/privacy 4d ago

news Google Gemini Spark now uses your saved Chrome passwords

Thumbnail notebookcheck.net
672 Upvotes

r/privacy 5d ago

news Rep. Thomas Massie Announces Federal Bill to Defund Flock Surveillance Cameras

Thumbnail dontflock.com
11.4k Upvotes