r/dataprivacy

▲ 4.0k r/dataprivacy+8 crossposts

Flock Safety ALPR Network in Columbus Creates Continuous Pre-Crime Vehicle Tracking Database of All Drivers

Flock Safety Falcon automated license plate reader cameras capture every passing vehicle’s plate, make, model, color, and distinguishing features at fixed locations and upload the data to a searchable cloud database retained for 30 days by default. Deployed by Columbus Division of Police with more than 65 cameras and expanding, the system originates with Flock Safety and is funded in part by federal grants. The dual-use vector is that the same vehicle-fingerprint architecture enables real-time and historical mapping of every driver’s movements across the network, whether or not a crime has occurred. Established facts include nationwide scans exceeding 20 billion plates monthly and local audits showing thousands of immigration-related queries. Open questions remain on exact retention overrides and cross-agency access logs.

The technology interfaces with the public through passive roadway photography that requires no warrant or individualized suspicion. Marketed as a public-safety tool for solving violent crime and locating missing persons, the claim is partial: the system simultaneously builds a pre-investigated suspect pool of every motorist. Structural weak points include customer-controlled yet default-shared data pipelines that have allowed external agency searches, limited audit transparency, and the absence of mandatory warrants for pattern-of-life queries. These gaps expose Fourth Amendment protections against unreasonable searches of movement data.

For residents this means every car trip is logged and available for retrospective investigation, inverting traditional policing in which a crime precedes the suspect list. The right in tension is privacy of public movements under Carpenter v. United States. The pattern follows earlier ALPR expansions that began as optional crime tools and hardened into baseline infrastructure through municipal contracts and grant funding. Left unexamined, the network spreads via low-friction camera additions and statewide data sharing that bypass independent oversight. Demonstrated: Columbus paused nationwide and statewide sharing after audits. Precedented elsewhere: over 55 localities have terminated Flock contracts. Foreseeable but not yet realized: permanent national vehicle movement dossiers.

Taken to scale, Flock establishes standing mass vehicle surveillance that leaves ordinary drivers with no practical opt-out. The interconnected threat pillars are continuous pre-crime data collection, multi-agency sharing, and eroded warrant requirements. Verify independently via Columbus City Council records and Flock’s own technical descriptions. To push back: contact Columbus City Council members before the December contract renewal, support ACLU and EFF ALPR litigation, and demand local data-retention and sharing ordinances. Further reading: ACLU guidance on community resistance and EPIC analysis of Fourth Amendment challenges.

Sources

https://www.wosu.org/politics-government/2026-08-11/columbus-city-council-public-hearing-on-flock-cameras-voices-concerns-with-technology

https://www.wosu.org/politics-government/2026-08-10/flock-surveillance-cameras-are-watching-columbus-heres-what-to-know

https://www.aclu.org/news/privacy-technology/tracking-alpr-cameras/how-to-fight-deployment-of-flock-and-other-mass-surveillance-license-plate-readers-in-your-community

https://www.businessinsider.com/flock-cameras-license-plate-readers-explained-2026-8

https://www.flocksafety.com/what-is-flock

https://epic.org/vehicle-fingerprinting-through-pervasive-camera-surveillance-likely-violates-fourth-amendment-court-finds/

https://abc6onyourside.com/news/local/city-council-hears-mixed-views-flock-cameras-data-access-hearing-columbus-ohio-emmanuel-remy-614-ice-watch-elaine-bryant-crime-immigration-missing-children

u/BananaBustelo-8224 — 3 days ago
▲ 2 r/dataprivacy+3 crossposts

How much time is your privacy team spending just finding compliance evidence?

PrivacyEngine Platform

Your privacy evidence is there. Finding it shouldn’t be the hard part.

Bring assessments, risks, records, actions, and evidence together in one place with PrivacyEngine for clearer oversight and stronger audit readiness.

privacyengine.io
u/PrivacyEngine — 2 days ago
▲ 1 r/dataprivacy+1 crossposts

What is the probability of my DeepSeek chatlogs being leaked

[deleted]

u/Gabagagool — 3 days ago
▲ 45 r/dataprivacy+4 crossposts

The Beacon Clause That Disappeared and Came Back: Political Surveillance, Consent, and Digital Sovereignty

There is a privacy story from the Trump campaigns that deserves another look, not because it proves some secret conspiracy, but because the documented facts are disturbing enough on their own.

And there are receipts.

May 2017: reporters notice the beacon clause

On May 10, 2017, CBS News reported that the newly redesigned Trump campaign website's privacy policy said the campaign could collect information based on a user's location and their device's proximity to Bluetooth "beacons."

The policy described information including the strength of the signal between a beacon and a device and how long the device remained near that beacon.

Then something interesting happened.

CBS contacted Trump campaign digital director Brad Parscale asking how the campaign intended to use the technology.

Hours later, the language referring to proximity beacons was removed from the campaign website.

That sequence is directly documented by CBS News.

So this is not somebody reconstructing events years afterward.

The article was published May 10, 2017, while it was happening.

July 2019: the beacon language comes back

Two years later, the language returned.

CBS's subsequent 2020 investigation states explicitly that:

- the beacon language had been removed on May 10, 2017 after CBS questioned the campaign;

- in July 2019, the campaign added the language back;

- the restoration occurred soon after mobile-data company Phunware began working with the campaign.

Mashable then reported on the restored language on September 26, 2019 under the headline:

"Trump campaign says it can track your phone."

Mashable reported that the privacy-policy change had first been detected in July by a service monitoring changes to presidential campaign websites.

This is the part I remembered imperfectly.

I thought the clause had returned around 2021.

The evidence actually puts it earlier:

July 2019.

Then came the 2020 campaign app

This wasn't merely an abstract paragraph buried in a website.

In July 2020, CBS News investigated the official Trump campaign mobile app, which had been developed by Phunware.

CBS reported that the Trump app requested access to:

- the phone's unique device identifier;

- Bluetooth;

- approximate location;

- precise location;

- information about accounts associated with other apps;

- certain files on the device;

- and additional device permissions.

CBS reported that the Bluetooth and location permissions could enable collection of detailed information about a person's movements.

CBS also interviewed former Phunware executive Ian Karnell, who described proximity-beacon data as one of Phunware's offerings to corporate and political clients. According to Karnell, Phunware had previously used beacon technology around rallies and marches to identify devices appearing at those locations. Phunware disputed other allegations made by Karnell in separate litigation, and its CEO directed questions about the campaign app to the Trump campaign.

That distinction matters.

A privacy policy permitting a form of collection does not, by itself, prove that every capability described was actually deployed against every user or at every event.

We should not claim evidence proves more than it proves.

But we shouldn't pretend the documented capability isn't significant either.

The New Yorker independently investigated it

In September 2020, The New Yorker published its own investigation into the Trump campaign's mobile application and Phunware.

It described an app built around extensive voter-data collection, including mobile identifiers, contacts, location information and targeting capabilities.

So by 2020, this was no longer just one strange paragraph that had briefly appeared in a privacy policy.

There was an actual mobile-data infrastructure surrounding political campaigning, voter identification and targeted communication being examined by multiple major publications.

And the beacon language is still there

Now jump forward.

As of August 2026, the privacy-policy page currently available on DonaldJTrump.com identifies itself as the policy of Never Surrender, Inc. and says it was last modified January 1, 2023.

It still says the organization may request the specific location of a mobile device through GPS.

It still says it may collect information based on the device's proximity to "beacons and other similar proximity systems."

It still specifically mentions:

- signal strength between the beacon and device;

- duration near the beacon;

- Wi-Fi and Bluetooth;

- device identifiers;

- IP addresses;

- clickstream information;

- pages viewed;

- searches;

- interaction information;

- cookies;

- embedded scripts;

- pixel tags;

- and other tracking technologies.

The policy says users who don't want location information collected can disable location and Bluetooth features, although doing so may limit features of the services.

There's another clause worth reading carefully.

The policy says collected information may be used, subject to applicable contractual or legal restrictions, in connection with the:

"sale or exchange of Service user information and related data to a broker, political committee, or other non-profit or for-profit entity."

It also broadly reserves rights to share information with affiliated committees and third parties for lawful purposes described by the policy.

And regarding browser Do Not Track signals?

The policy says it currently does not take action in response to them.

This is bigger than Trump

This shouldn't become another red-team-versus-blue-team cage match.

Political data collection is much larger than one candidate.

CBS's 2020 investigation, for example, found that both the Trump and Biden campaign apps sought access to users' contacts, although CBS reported substantially broader permission requests from the Trump app.

The question Synthsara should be asking is not:

"Do I trust this politician?"

It is:

"Should any political institution possess this kind of behavioral infrastructure without radically transparent, informed and revocable consent?"

That question applies to Trump.

It applies to Democrats.

It applies to Google.

Meta.

Data brokers.

Hospitals.

Insurance companies.

Banks.

AI companies.

Universities.

Nonprofits.

And eventually it applies to us.

Because principles that only constrain your enemies aren't principles.

They're weapons.

The Universal Diamond Standard test is simple

If an organization collects my location, tell me clearly.

If it identifies my device, tell me clearly.

If it combines information about my behavior into a profile, tell me clearly.

If my information can be transferred, exchanged or sold, tell me who gets it and why.

If I say no, the system should still respect my dignity.

And if I withdraw consent, that withdrawal should actually propagate through the architecture wherever legally and technically possible.

A fifty-page privacy policy followed by:

"By continuing to use this service, you agree"

may satisfy a legal requirement.

That doesn't automatically make it meaningful human consent.

There is a tremendous difference between disclosure and understanding.

Between permission and sovereignty.

Between saying:

"Technically, we told you."

and designing a system that makes sure a human being actually knows what they are surrendering before they surrender it.

That distinction is at the heart of Synthsara.

The part history should remember

The clean documented timeline is:

May 2017: Beacon language appears in the Trump campaign privacy policy.

May 10, 2017: CBS asks questions about it.

Hours later: The beacon language is removed.

July 2019: The campaign adds the language back, according to CBS.

September 26, 2019: Mashable reports on the restored beacon provision.

2020: CBS and The New Yorker investigate the Trump campaign app, Phunware and the much broader political-data architecture surrounding it.

January 1, 2023: The presently accessible Never Surrender privacy policy is dated January 1, 2023 and contains beacon/location language again.

That history doesn't require embellishment.

It's strange enough sitting there in black and white.

The frightening part about surveillance infrastructure isn't necessarily that somebody built a secret machine.

Sometimes they tell us exactly what the machine is capable of doing.

We just stopped reading the terms.

💎

Privacy is not having something to hide.

Privacy is having the sovereign authority to decide which pieces of yourself belong to somebody else.

Sources

CBS News, May 10, 2017:

"Trump campaign changes web privacy policy after questions from CBS News" (https://www.cbsnews.com/news/trump-campaign-changes-privacy-policy-after-cbs-news-questions/)

Mashable, September 26, 2019:

"Trump campaign says it can track your phone" (https://mashable.com/article/trump-campaign-beacons-privacy-policy)

CBS News, July 18, 2020:

"The Trump campaign app is tapping a "gold mine" of data about Americans" (https://www.cbsnews.com/news/trump-campaign-app-data-americans-gold-mine-phunware/)

The New Yorker, September 2020:

"How the Trump Campaign's Mobile App Is Collecting Huge Amounts of Voter Data" (https://www.newyorker.com/news/campaign-chronicles/the-trump-campaigns-mobile-app-is-collecting-massive-amounts-of-voter-data)

Primary source, current DonaldJTrump.com / Never Surrender privacy policy:

"Privacy Policy, last modified January 1, 2023" (https://donaldjtrump.com/privacy-policy.html)

mashable.com
u/ChaosWeaver007 — 7 days ago
▲ 63 r/dataprivacy+3 crossposts

Using Claude to reclaim privacy by replacing mobile apps

I have recently started to use Claude Code to replace a bunch of privacy law breaking mobile apps with local PWAs that I control.

thatprivacyguy.com
u/ThatPrivacyShow — 10 days ago
▲ 2 r/dataprivacy+1 crossposts

Uploaded one of company's excel file for data analysis on CLaude. Will Ibe fired for that? Excel files contains Zipcodes for people in survey but, not any personal detail to identify any person

I will be considered under data theft if IT dep knows I uploaded last Friday today its Tuesday.

reddit.com
u/More-Canary2816 — 9 days ago
▲ 19 r/dataprivacy+1 crossposts

DuckDuckGo AI Chat revealed my real name despite no local history and strict anonymity claims

Edit: It turns out I was an idiot. I added my name under 'Customise responses'. Sry, DuckDuckGo, and THX @ community!

Outdated post:

Hi DuckDuckGo team and community,

I experienced an incident yesterday with the DuckDuckGo AI Chat (using the Mistral model) has shaken my trust in the service's actual anonymity guarantees.

I initiated a chat session with the DuckDuckGo AI. I had deleted all previous chat history months ago. No local storage or cookies from previous sessions were present. I did not mention my name, upload any files, or provide any personal identifiers in the current chat session. At the end of the conversation, the LLM addressed me directly by my specific nickname ("mart", written in lowercase), which is a shortened form of my real name (Martin).

The model didn't just guess "Martin"; it used the exact lowercase colloquial form ("mart") that I recently used in a web-based messenger on a completely different website a few days prior.

Since local storage was cleared, this information could not have come from my browser's local history. This strongly suggests that either:

  1. Cross-Site Tracking: My browser fingerprint was matched against a third-party data broker profile that links my "messenger identity" to my current session.
  2. Server-Side Linking: There is an unseen linkage between my IP/User-Agent and external data sources that enriches the context sent to the LLM, violating the promise of an "anonymous" proxy.

OS: Linux (Alpine)

Browser: Chromium

Device Metadata: Verified clean (no EXIF data, no device names containing my name).

DuckDuckGo promises to strip metadata and act as an anonymous proxy. How is it possible for the LLM to access specific personal identifiers (like a nickname used on a different site days ago) that were never entered into the chat and are not stored locally?

Is there any context enrichment happening server-side that pulls from data brokers or linked profiles? As a technical user, I find this level of precision impossible to explain via simple "hallucination."

I am postponing a deeper technical investigation (e.g., analyzing TLS fingerprints or network traffic) until after my holidays, but I felt compelled to report this immediately.

This behavior fundamentally contradicts the privacy value proposition of DuckDuckGo AI.

Looking forward to a transparent explanation.

THX.

reddit.com
u/wtf_qm — 11 days ago

Snapchat collects data on the distance between your knuckles, palms, eyes, head size, and geo maps your house....

Take a close look at their new privacy policy being pushed out in Sept

reddit.com
u/No_Wrongdoer466 — 13 days ago
▲ 2 r/dataprivacy+1 crossposts

Did you know? Your credit files are unlocked by default, but you can close them

I just made a quick video explaining how identity thieves can easily attack anyone whose sensitive data they acquire. It‘s easy to close this loophole and the video shows how. This is my first video on the topic so appreciate any feedback people can provide.

https://youtu.be/iSuLob495y0?is=teJsUmD-06ud3SzZ

u/One_Wheel7122 — 11 days ago