How your data is handled,
one industry at a time
We read privacy policies across a whole industry and write down what repeats. Not one company's promises, and not legal advice: the pattern you should expect before you hand anything over, and what stays behind after you leave.
38 industries written up · retention, deletion, carve-outs, and what a leak actually costs
How this research is done
We take the privacy policies of the main companies in a trade and read them side by side. We write down what repeats: what they collect, how long they say they keep it, who they pass it to, and the wording that allows it.
Each trade then gets four grades: whether it is worth tracking, what a leak would expose, how long to expect them to keep it, and whether you have to prove who you are. The grades come from the pattern across the whole trade. A single company can be better or worse than its grade, and its own policy is what applies to it.
Every file shows the date it was last reviewed. When policies change, we re-read them and update the file. The files are free to read here, and anyone can fetch them by machine.
On file
Every trade we have read, A to Z.
38Whatever the trade
Some files follow what you are to a company, not what the company is. These hold across every trade above, and for companies in none of them.
The six clauses
What almost every policy is assembled from, and the move against each.
One rule before any of it
A request only makes sense where they can already name you. If all a company has is an IP address and a device, writing in hands them an email address they did not have. Where that is not true, or where asking is worth it anyway, the industry's own page says so.
And what you keep
A setting is their record. They can narrow what it covers or reset it, and nothing tells you. A reply is their words in your hands: dated, and still in your inbox long after the account is gone. Whether it is true is not the point. It exists, and they wrote it.
Whoever they are
None of this needs the trade. These are the clauses almost every policy is built from, and the three things worth asking any company that holds something about you.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.
The move An objection tells them to use your data to run the service and nothing more.
“we do not sell your personal information”
Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.
The move Use the do-not-sell switch where there is one, and put an objection in writing as well.
“service providers, partners, and affiliates”
This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.
The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.
“aggregated or de-identified information”
Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.
The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.
The move Which reasons apply to you, and how long each runs, is a request of its own.
“you grant us a licence to use your content”
This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.
The move Their terms say whether the licence ends when the account does. Close the account and log the date here.
Ask what they hold. All of it, not a summary by category, and where each part came from. The answer is the only inventory you will ever have of a file you cannot open.
Ask them to stop using it for advertising, profiling or training, while the account carries on. It is the narrowest of the three, and the only one that needs nothing deleted to work.
Ask them to erase it, and expect parts to stay. Their reply names which parts and on what ground, which is worth as much as the deletion.
Their own policy is the one that binds them. Pin it down with a request, and keep the reply.