Every other report on this site describes something that made life measurably better: a house that manages itself, a diagnosis caught early, a payment that arrived in seconds, a specialist consulted from ninety kilometres away. This piece is about the invoice. Not because the improvements were not worth it — most of them plainly were — but because the price was quoted in a currency almost nobody has learned to count in.

The uncomfortable structure of the modern deal is this: the systems that serve you well do so because they know things about you, and the mechanism that makes them useful is the same mechanism that makes them dangerous. There is no version where you get the personalisation and keep the opacity. What you can change is who holds the knowledge, how long, and under what constraint.

What a data trail actually contains

People tend to think of privacy in terms of secrets, which is why "I have nothing to hide" feels like a reasonable position. But almost nothing in a modern data trail is a secret. It is a record of unremarkable facts, and its power comes entirely from volume and correlation.

  • Location, continuously. Four approximate points a day are enough to identify most individuals uniquely. A month of location data reveals home, work, place of worship, clinic attended, who you spend nights with, and whether you attended a protest.
  • Timing. When you wake, when you sleep, when you are anxious enough to be awake at 4 a.m., how that changed after March.
  • Association. Whose devices are repeatedly near yours. This reconstructs a social graph without anyone declaring a relationship.
  • Inference. The category that matters most. Pregnancy, illness, depression, job loss, sexual orientation, immigration status and religious practice are all routinely inferred from behaviour that discloses none of them directly — and inferences are not covered by the sensitive-data rules that would cover the underlying fact.

You are not protected by having nothing to hide. You are protected — or not — by who decides what counts as something to hide, and when.

4approximate location points typically sufficient to uniquely identify an individual
<1%of users who read a privacy policy before agreeing to it
76 daysestimated reading time per year to review the policies an average person accepts

Why consent stopped working

The regulatory answer to all of this has been consent: tell people what you collect, let them agree. It is a coherent idea that fails in practice for reasons that are now well understood.

The volume is impossible — nobody can read that many policies. The choice is not real — you cannot decline your employer's software, your bank's app, or the platform your family organises itself on. The interfaces are engineered to produce agreement, with accept as one bright button and decline as three grey screens. And most importantly, consent is asked at the moment of collection, when neither party knows what the data will later be used for. You cannot meaningfully consent to an inference that has not been invented yet.

The most useful shift in thinking has been away from consent and toward constraint: rules about what may be done with data regardless of what anyone clicked. Purpose limitation, retention limits, and outright prohibitions on certain uses do not depend on a user reading anything, which is their entire virtue.

What changed in practice

Three things genuinely improved, and they are worth acknowledging in a field where cynicism is the default register.

Encryption became normal. Encrypted transport is now the default rather than the exception, and end-to-end encrypted messaging is used by billions of people who have never thought about it. This is an enormous, largely invisible win.

On-device processing got viable. A great deal of what once required sending raw data to a server — speech recognition, photo classification, health inference, keyboard prediction — now runs locally. Sending a conclusion instead of a recording is the single most effective privacy engineering decision available, and it is increasingly also the cheaper one.

Data minimisation became a defensible engineering position. "Collect everything, we might need it" used to be prudent. After enough breaches, regulatory fines and subpoenas, unnecessary data is now widely understood as a liability sitting on a balance sheet. Not collecting it is the only reliable way to protect it.

What it costs to opt out

It is worth being honest that individual defence has real limits and real costs. You can reduce your exposure meaningfully — a browser that blocks trackers, encrypted messaging, location permissions granted only while in use, separate identities for separate purposes, reviewing app permissions once a year. All of that helps.

But privacy is not fundamentally an individual achievement. Your address book uploaded by a friend exposes you. A relative's genetic test partially exposes you. Your phone's presence in a crowd is recorded whether or not you consented to the crowd. And the person with the fewest resources — who cannot afford the paid tier, the second device, the time to read settings — gets the least protected version of every service. Privacy is becoming a premium feature, which is a bad thing for it to become.

The bill, itemised

Where the data trail causes concrete harm, it is rarely the harm people expect. It is not usually embarrassment. It is:

  • Price and eligibility discrimination — different offers, rates or availability based on inferred willingness to pay or inferred risk.
  • Employment and insurance consequences — decisions made on inferred health, stability or lifestyle, through intermediaries the subject never interacts with.
  • Targeted manipulation — persuasion aimed with precision at whatever the model has identified as your vulnerability, which is most damaging for people in crisis.
  • Retroactive exposure — data collected legally under one government or one policy, used later under a different one. This is the risk that renders "nothing to hide" incoherent, because the standard is not yours to set and not fixed in time.

None of which argues for refusing the technologies described elsewhere on this site. The early diagnosis is worth the heart-rate data. The instant payment is worth the transaction record. The argument is narrower and, we think, harder to dismiss: the exchange should be legible, the retention should be bounded, the processing should happen as close to the person as possible, and the party benefiting from the data should carry the liability for holding it. That is a design standard, not a personal virtue — and it is the one thing on this site that will not arrive on its own.

Key takeaways

  • Inference is the real exposure. Sensitive facts are derived from unremarkable behaviour, and derivations escape most protections.
  • Consent cannot carry the weight. Constraint on use works where clicking agree does not.
  • Local processing is the strongest available fix. Send conclusions, not recordings.
  • Privacy must not become a paid tier. Individual defence is real but limited, and it is unevenly affordable.