THE INDUSTRY FILES

Technology

Filed here are the firms whose record of you did not begin with a sign-up: the identifier is the device, not the account, so there may be nothing to log into and no delete button, which reads as a dead end. The right to ask does not depend on having an account.

TRACKING PRIORITY RECOMMENDED

A broad, always-on profile worth keeping on the list.

IF IT LEAKS MODERATE
EXPECT IT KEPT INDEFINITELY

Once your data is called "anonymised" or "derived", most policies keep it with no end date at all.

IDENTITY DEMANDED OPTIONAL

Most sign-ups ask for nothing beyond an email; some add a face or ID check for high-value accounts.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

IF IT LEAKS

What leaks here is rarely dramatic alone: an identifier, a device, a list of apps. It matters because it is the thread that ties the rest together. The pieces are worth little apart and a great deal joined up.

What repeats in the policies

HOW IT STARTS

The relationship usually started inside something else

Filed here are the firms whose record of you did not begin with a sign-up: a device you bought, an operating system that came with it, a login button you pressed on another site, or their software sitting inside somebody else's app. In each case the company was never the thing you chose.

WHAT KEEPS THE LINK

The identifier is the device, not the account

Advertising IDs, install identifiers and device fingerprints are what hold a file like this together, and none of them is the password you can change or the account you can close. Clearing your history does not touch them. The link survives because it was never anchored to your name.

ASKING WITHOUT AN ACCOUNT

There may be nothing to log into

Where the data arrived through a device or another company's app, there is often no profile page, no settings screen and no delete button. That reads as a dead end and is not one: a written request needs no account, and the identifier they hold is enough for them to find you.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileBrowsing & ActivityPurchasesLocation Financial maybePhotos & Biometrics maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Where you go LIKELY

GPS and IP over time map where you live, work, and travel.

Money and net worth POSSIBLE

Purchase history and device tier hint at what you can spend.

What lawfully stays after you leave

Two kinds of hold. LAW SETS IT: a statute makes them keep it. THEY SET IT: a ground the company grants itself.

anonymised, aggregated, or AI-trained data OFTEN KEPT INDEFINITELY THEY SET IT

They treat it as no longer being about you, though such data can sometimes be re-identified.

tax and accounting records ABOUT 6 YEARS LAW SETS IT

Tax and company law makes them keep billing and payment records.

records tied to a live or potential dispute THE LIMITATION PERIOD OF THE CLAIM THEY SET IT

They can keep records to defend a live or possible legal claim.

Who wants this data

Device and app identifiers are the raw material of identity resolution, the trade of joining one person's activity across apps and sites that never shared an account. The joining is the product, and it works because the identifier outlives any single login.

SOLD OR SHARED HIGHLY LIKELY

Behaviour, purchases, and device data are the core of the ad and product-analytics economy.

AI TRAINING HIGH

Content and usage data increasingly train the company's own models, with opt-outs that only work going forward.

Even anonymised, this can still be you

Anonymised is their word. Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and four location points single out 95% of people (de Montjoye et al., 2013).

Name, date of birth, postcode TYPICAL

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces TYPICAL

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns TYPICAL

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

Face and voice SOMETIMES

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint TYPICAL

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

THE STUDIES Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.

THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.

“we do not sell your personal information”

Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.

THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.

“service providers, partners, and affiliates”

How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.

THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.

“aggregated or de-identified information”

Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.

THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.

THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.

“you grant us a licence to use your content”

A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.

THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.

“device identifiers and similar technologies”

A key tied to your hardware or your app install that persists across sessions and accounts, and sometimes across a password change. It identifies a device, and a device is usually one person.

THE MOVE The identifier is data about you, and an access request covers what is held against it. Their reply goes on your record.

“we collect information when you use apps and websites that use our tools”

Data reaching them through other companies' products, with no account, no sign-up and no notice at the point it was taken. You meet the company for the first time when you go looking for it.

THE MOVE A request does not depend on having an account with them. Their reply goes on your record.

“we share information across our family of companies”

One file assembled across every product the group owns, including ones you have never used. The brand you dealt with is a surface of it, not the whole of it.

THE MOVE A request aimed at the group rather than the product reaches the whole file. Their reply goes on your record.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply. Start your record →