How this research is done

Every research file covers a whole trade. This is what goes into a file, how a trade is graded, and why we do it that way.

What we read

We take the main companies in a trade, the ones most people use, and put their privacy policies side by side. Deckard, our agent, reads them in full and marks what repeats. We check every mark against the policy text before anything goes in the file.

Where a trade has more than one kind of company, we read each kind, so the file covers the whole trade.

What we write down

Four things, in the same order for every trade:

  • What the companies collect, including things they work out about you that you never typed in.
  • How long they say they keep it, and the exceptions that let them keep some of it after you close your account. For each exception we say whether the law requires it or the company chose it.
  • Who they pass it to.
  • The wording that allows all of it.

The same six clauses appear in almost every policy, so we keep them together in one file: what repeats in every policy.

How a trade is graded

Each file has four grades:

  • Tracking priority: whether the trade is worth a place on your record, the list of companies you keep here.
  • If it leaks: what a breach would expose, from an email address up to a scan of your passport or your face.
  • Expect it kept: how long they tend to keep your data: months, years, or with no end date.
  • Identity demanded: whether you have to prove who you are to use the service, and how much proof they ask for.

The grades describe the trade as a whole. A single company can be better or worse than its grade, and its own policy is what applies to it.

Why we read a whole trade

A privacy policy is a company's claim about what it does with your data. It can change without notice, and you have no way to check it. One policy tells you what one company says this month. A whole trade tells you what is likely to stay true after any one company changes its wording.

So a file does not quote any policy or say what a named company's policy contains. A company is named for something that happened and was reported, such as a breach or a fine, and those go on the news and events desk with their sources.

A file describes what companies in a trade usually do with your data. It is not legal advice.

Who gets your data

Most privacy policies describe who gets your data in broad terms, such as "third parties", "marketing partners" and "service providers", and add that they "may get your information from elsewhere". So we show what those terms usually stand for in each trade, from the policies we read and the events on record.

Where a company names its partners, its page shows them in place of the kinds we infer. You can also ask a company for the names. In January 2023 the EU's Court of Justice ruled (case C-154/21) that a company must tell you who actually received your data when you ask, unless that is impossible or the request is clearly unfounded or excessive.

How the files are kept

Every file shows the date it was last reviewed. Policies change, so we re-read them and update the file.

All 38 files are free to read, and the same facts can be fetched by machine through our public API, so anyone can build on them.

Where it leads

Add the companies you use to your record. Each company's page then shows the file for its trade, next to your requests. So when you ask a company what it holds on you, or to delete it, you already know what companies in that trade keep, and what the law lets them keep even after you ask.

The reply you get is another claim by the company. You keep it, and the file tells you how it compares with what the rest of the trade does.