u/Incogni_hi

New research finds that half of Americans now assume their data will leak at some point

New research finds that half of Americans now assume their data will leak at some point

For most regular internet users, the idea of their data being exposed online is no longer seen as a mere risk but as something increasingly difficult to avoid.

In our latest study, we surveyed 1,000 US adults asking whether "the breach of [their] personal data is a statistical inevitability." 52% responded “yes” while only 11% disagreed. Yet 63% of all respondents still report feeling anxious about the possibility of a data breach.

The study was meant to measure privacy attitudes. What it captured is people giving up on their data staying private, on their feeds being real, and on control being available to everyone, regardless of their income bracket.

Breach fatalism is highest in the generations that have been online the longest. Gen X (56%) and Millennials (55%) were the most pessimistic generations. The pessimism is valid in the sense that data breaches have become an increasingly typical consequence of being active online. As of July 2026, Have I Been Pwned has counted 17.7 billion breached accounts, including a single 2-billion-email ingest in November 2025 and 183 million infostealer records the month before.

AI slop is also pushing people off the internet. 48% claim AI-generated content has made it harder to know what's real online (59% among Baby Boomers). And 27% report that the flood of low-quality AI content is making them want to spend significantly less time online. What email spam did to inboxes in the '90s, AI slop is doing to the entire internet now.

https://preview.redd.it/1qzkvsg2yakh1.png?width=1080&format=png&auto=webp&s=20a6fc63ff94602e94045b71ebce5573ea3a2a45

58% have already deleted an account over this. Stress and anxiety drove 47% to do so, while privacy concerns were the dealbreaker for 41% of respondents. Separately, 1 in 2 Americans regret having shared personal information online—including 61% of Gen Z women, who report having shared something they later wished they’d kept private.

A private internet might also become a separate paid tier. 29% claimed they’d pay for an internet with no tracking and no algorithmic feeds. But willingness nearly doubles when you compare higher income respondents (38%) to lower income ones (22%).

If privacy only exists behind a paywall, then surveillance will become the default product, and privacy will be a class marker. At what point do we stop calling that a market and start calling it what it is?

Read the full study: https://blog.incogni.com/attitudes-toward-internet-stressed-exposed/

reddit.com
u/Incogni_hi — 1 day ago

How wiping your phone at the border could now be treated as a crime

Border phone searches in the US hit a record high

An Atlanta activist is facing a federal case after authorities allege he used a GrapheneOS security feature, a duress passcode that wipes the phone, during a border search. Even the Electronic Frontier Foundation (EFF) says they haven't seen a case like this before.

GrapheneOS has publicly defended itself, saying: "We have no obligation to weaken any of the security protections it provides." And once a phone is wiped, the data is gone. There's no backdoor recovery.

But this case raises a much bigger question: can the use of a legitimate privacy tool be treated as evidence destruction?

It's a question that affects more people than most realize. In FY2025 alone, U.S. Customs and Border Protection (CBP) searched 55,424 devices, up from just 8,503 a decade ago, a whopping 551.8% increase. 

Now it's continuing to escalate, from passive tracking to the criminalization of digital self-defense. GrapheneOS is widely regarded as one of the strongest mobile security platforms available, purpose-built to resist spyware and forensic extraction. When a legitimate security feature gets framed as evidence destruction, the authorities are effectively treating cryptography as contraband.

Our Information Security Manager, Miguel Fornés, put it this way:

"In an environment where our personal data is constantly scraped, leaked, breached, demanded, and sold by opaque corporations, taking steps to defend our digital sovereignty should not be treated as an admission of guilt. The message is chilling: Lock your own digital door, and the state may treat the lock itself as suspicious."

Still, public pressure can change the course of surveillance technology. After public backlash over the weaponization of home-security cameras, Amazon reportedly ended its Ring partnership with Flock Safety. The same applies here: privacy tools shouldn't be criminalized simply because they're effective.

Read more: https://blog.incogni.com/signal-phone-wipe-legal-test/

reddit.com
u/Incogni_hi — 9 days ago

We ranked the most popular job-search platforms in the US, based on how they handle your data

Our researchers at Incogni studied the most popular job-search platforms in the US to determine whether they exploit job seekers for their personal data.

  • Snagajob — even though it's the least privacy-invasive platform in the study, Snagajob was still found to sell user data according to the CCPA definition.
  • Nexxt — sells user data (as per the CCPA definition) and collects personal information from "public sources" and data brokers.
  • FlexJobs — sells and shares user data with ad networks and third parties for marketing, advertising and research. There have also been reports of scam warnings associated with this platform.
  • Glassdoor — sells user data and shares it with advertising partners and ad exchanges. It also stirred controversy by adding real names and job titles to previously anonymous profiles.
  • Indeed & SimplyHired — Indeed sells user data and shares it with employers, affiliates, and marketers, and uses AI to process application data to generate summaries. SimplyHired doesn't have its own privacy policy, instead linking to Indeed's, raising concerns about which entity is actually processing user data.
  • Monster — ranked as the most privacy-invasive platform in the study. It makes inferences about users, collects "publicly available" data, and shares data with poorly defined affiliates and business partners. It also faces antitrust allegations suggesting it and other job/resume brands may operate under the same ownership while appearing as competitors.
  • LinkedIn — Microsoft (owner) was fined 310M euros by the EU in late 2024 for targeted advertising practices, and in April 2026 faced two class action complaints for allegedly scanning users' browser extensions. LinkedIn also tracks non-member visits for targeted advertising and is rolling out AI-powered screening interviews.
  • ZipRecruiter — suffered a 2018 data breach exposing users' names and email addresses. Additionally, its privacy policy disclaims responsibility for outdated posts on privacy issues, potentially leaving users misinformed.

Full research read here: https://blog.incogni.com/are-job-search-platforms-exploiting-job-seekers-for-their-personal-data/

u/Incogni_hi — 14 days ago

Why the latest license plate reader upgrade is a privacy nightmare no one asked for

The new SignalTrace technology for law enforcement does more than just photograph your plate. It sweeps the air around your car and logs every wireless signal it picks up. This includes your Bluetooth earbuds, your phone, your laptop, your kid's tablet, and even your pet's RFID microchip.

According to our cybersecurity expert, Miguel Fornés, here's where it gets worse:

  • Private companies run the surveillance, not cops. The data isn't collected by law enforcement. It's hoisted by private corporations like Flock Safety, then sold back to police as a subscription. That means cops can track the movements of millions of people without ever getting a warrant — they just buy access.
  • The databases are a proven security disaster. Flock Safety already exposed law enforcement plate searches on public search engines. San Diego's massive Flock ALPR database was left wide open to federal agencies. In 2021, hackers gained "God Mode" access to 150,000 live Verkada surveillance camera feeds from hospitals, schools, and police departments. Clearview AI has been breached repeatedly. These are the companies being trusted with your real-time location and device data.
  • You become a suspect by proximity. If your Bluetooth earbuds get logged near a crime scene, you're now a data point in a database that an algorithm can flag. You didn't do anything, your digital footprint did. And now you're the one who has to prove you're innocent, because an automated system put you there.
  • There's no real data minimization. These systems are logging millions of people's daily movements and device signatures into centralized corporate cloud servers, creating what amounts to a honeypot for nation-state hackers, ransomware cartels, and rogue insiders. One breach and someone has a searchable map of where you've been, when, and what devices were with you.

As Miguel Fornes underlines: “If we do not ruthlessly demand data minimization and extreme digital hygiene, we will lock ourselves in a corporate panopticon where our own electronics serve as the wardens, and, eventually, even a digital accusatory finger.”

You can't opt out of the plate reader, but you can silence the invisible electronic signals broadcasting from inside your car. Turn off Bluetooth and Wi-Fi in your actual system settings (the shortcut toggle doesn't fully kill the radio). Toss keyless fobs and work badges in a Faraday bag. Enable randomized MAC addresses on your phone. Disable your car's Wi-Fi hotspot. And don't travel with the exact same cluster of active devices every day — that's how the algorithm groups everything into one trackable profile.

reddit.com
u/Incogni_hi — 15 days ago

New: Incogni app 1.6.1 update

Incogni app 1.6.1 update

Hi everyone,

Our mobile app team has shipped version 1.6.1 of the Incogni app on Android and iOS. The new version introduces features that were previously available only on our web version. 

What’s new?

  • Broker Compliance Dashboard
  • Broker and removal details
  • Broker and Exposures tab
  • Broker overview
  • Profile edit in app
  • Reset password in app
  • Authorization form versioning and signing

You can try our mobile app at:
iOSApple Store
AndroidGoogle Play

Note: The mobile app is currently available only on the US app stores.

As always, we’d love to hear your feedback. If you have any suggestions for improvements or what we should build next, let us know in the comments below.

Stay protected,
Incogni Team

reddit.com
u/Incogni_hi — 23 days ago

Why the EU’s new in-car camera mandate is a bigger privacy problem than regulators admit

As of July 7, 2026, every new car sold in the EU has to have an infrared camera bolted to the dashboard, staring at the driver's face the whole time you're driving. You can't opt out, nor permanently turn it off.

It's called ADDW (Advanced Driver Distraction Warning), and it's now baked into EU safety law. The idea is straightforward - detect drowsy or distracted drivers and alert them. The privacy aspect is a lot messier, though.

The camera data is required by law to be processed in a "closed loop," meaning the footage never leaves the car, and it's not technically "biometric data." Our cybersecurity expert is challenging both claims:

  • The "closed data loop" is a myth in connected cars. Cars get OTA updates and are online 24/7 for infotainment. Remember the 2022 SiriusXM hack where a researcher could remotely unlock and start Honda/Nissan/Infiniti/Acura cars just by knowing the VIN (visible through your windshield)? Same logic applies — one bad firmware push and that "local" camera feed isn't local anymore.
  • "Not biometric" is a technicality, not a fact. An IR camera reading your face and eyes in real time IS biometric data, full stop. The only thing stopping it from being used that way is the current software, which can change with a T&C update. And once biometric data leaks, you can't reset your face like a password. (See: the Mercor breach earlier this year — 4TB of data, including facial biometrics and SSNs stolen from a supply chain attack.)
  • No rules on how long footage is kept. So if you're in a crash, that footage is just sitting there waiting to get subpoenaed. This is already normal in the US — prosecutors regularly pull Tesla cabin camera footage in court cases.
  • "Consent" is fake. The system turns on automatically above 20 km/h and the consent to share the data is buried in a 100-page ToS you have to accept just to use your nav and Bluetooth. Mozilla found 84% of car brands say they'll share your data and 76% say they'll sell it — some brands' policies literally mention collecting "genetic information."

Our Information Security Manager, Miguel Fornés, shares that: "When a data breach leaks your credit card, your bank issues a new one. But when a hacker breaches your car's systems and steals your facial biometrics, you are compromised forever. You no longer own the car, but become its hostage."

reddit.com
u/Incogni_hi — 29 days ago

Over 51% of surveyed Americans would delete social media because of privacy concerns

Social media is supposed to keep us connected. But our recent study shows that nearly half (47%) of Americans have deleted a social media or messaging app because of stress and anxiety. Among Millennials, that number jumps to 61% and the reasons go beyond just "too much screen time."

With growing internet surveillance, user data being used to train LLMs, and the rise of polarizing political content, privacy concerns are now the #1 reason people would consider walking away. While 51% cite privacy and security as their main reason for deleting an account.

People who stay are also getting quieter. 55% say they post less than they did five years ago. 53% have restricted who can see their content. And more than half say maintaining an online presence feels like work (rising to 60% among Gen Z).

One part that doesn't get talked about enough: disconnecting doesn't actually solve the problem. More than one in five people experience anxiety after stepping away from social media, and 29% report FOMO after leaving messaging apps. The most common feeling is peacefulness (27%) that is barely ahead of anxiety.

We've reached a point where staying online is exhausting and leaving feels risky. But platforms that surveil, monetize, and polarize their users shouldn't be surprised when people start disappearing.

Have you deleted any social media apps recently? Did it actually help, or did the anxiety follow you offline too?

Full research: The great digital fatigue: How digital burnout is changing social media use

Stay safe (and let’s go touch grass),

The Incogni team

u/Incogni_hi — 1 month ago

Are job applications being used to collect and sell user data?

Job-search platforms promise to connect you with employers. That sounds simple enough—until you look closer and find that 8 out of 9 major job-search platforms sell user data to third parties. Third parties that potentially include data brokers.

Yet 37% of users still believe their data only reaches potential employers.

And the problem doesn't stop there. Nearly 50% of job seekers don't read—or only skim—privacy policies before uploading their resumes. 

Almost 40% never delete their profiles once the job search is over. And over a third have uploaded their details to 3 or more platforms. 

That's a massive amount of personal data sitting in systems most people stop thinking about the moment they land a job.

At a minimum, job-search platforms should be transparent about who they sell data to, give users real control over their data (including having it deleted), and stop burying data-sharing practices in policies they know virtually nobody reads.

Anything less is profiting off people at their most vulnerable—when they're trying to find a job.

Have you recently applied for a job using job-search platforms? Have you ever tried deleting your profiles from these platforms?

Stay safe (and read the privacy policy),

The Incogni team

u/Incogni_hi — 2 months ago

How safe are work apps and why you might not want them on your personal device

How many work apps do you have on your phone right now? Some of them may be exposing your personal information like contact details, financial data, and precise location to your employer’s software stack.

While essential for communication and teamwork, the invasiveness of some of these apps could have you reconsidering whether you want them on your personal devices.

We looked at 10 of the most common workplace apps, collectively accounting for over 12.5 billion Google Play downloads. Here’s what we found:

First of all, they collect a lot of data—19 data points per user, on average. Gmail leads the pack there, collecting 26, including approximate location, app interactions, and user IDs—explicitly for advertising. Notion shares 8 data types with third parties, including names and email addresses, with several used for ad targeting. Zoom and Microsoft Teams both collect your precise location, one of the most sensitive categories.

6 out of 10 apps collect data specifically for advertising: Gmail, Slack, Notion, Outlook, Todoist, and Zoom.

All of this becomes even more concerning when we consider that these apps don’t have the best breach history. A 96-gigabyte database containing 48 million Gmail credentials was found unencrypted and publicly accessible. Slack credentials were stolen via malware, exposing 17,000 employees at Nikkei. Trello had 15 million records scraped and sold on a hacking forum. Workday—an HR platform holding your salary, performance reviews, and employment history—won't even let you request deletion of your data.

You probably can’t avoid using these apps altogether, but your personal information on the line may be the nudge you need for a better work/life balance.

Which workplace app surprised you the most? Have you ever checked what permissions your work apps actually have on your phone?

Full research: https://blog.incogni.com/workplace-apps-on-personal-devices-research/

Stay safe,

The Incogni Team

u/Incogni_hi — 3 months ago