The Privacy Habit · Chapter 1

“I have nothing to hide”

The illusion of invisibility

There is a phrase millions of people repeat every day, convinced that it protects them. A phrase that, in reality, does exactly the opposite.

Privacy isn’t secrecy, it’s control

To understand the scale of our exposure in the digital world, let’s start with a situation from the physical world that everyone knows.

You walk into a bookstore. You wander the aisles, look at the covers in silence, pick up a book, read the back cover, and finally return it to the shelf. If something catches your interest, you leaf through it at your own pace, without feeling that someone behind you is timing exactly how long your eyes rest on each paragraph. In that physical setting, you’re in complete control of the situation.

Now move that same experience into the digital world. Imagine that, as you enter the bookstore, an invisible assistant meticulously notes your every step: how long you stopped in front of a cookbook, which title made you hesitate, which sections you ignored entirely, and which topics made you turn back. Imagine, too, that this information doesn’t stay in the store but is sold immediately to advertising companies, insurers, or political analysts, without your explicit consent and without anyone asking you.

This is exactly what happens on the internet every day.

Protecting your privacy means being able to choose what you share, with whom, and in what context. Losing that ability doesn’t make us criminals, but it does turn us into transparent, vulnerable subjects facing entities 2 THE PRIVACY HABIT

that are, to us, completely opaque. Control over our privacy rests on three pillars: knowing who is watching us, deciding what we show, and controlling where that information ends up.

Privacy is a collective responsibility. When you protect your data, you’re also protecting the privacy of your contacts and the people closest to you.

The most comfortable argument

“I have nothing to hide” works as a psychological defense mechanism that lets us ignore the overwhelming complexity of digital surveillance. In practice, this mindset switches off our ability to protect ourselves.

Consider a concrete case. Ana searches for information about nighttime anxiety on her phone, in the privacy of her bedroom, without consulting any doctor, simply looking for relief or understanding. Ana has done nothing wrong, and she hasn’t shared her worry with anyone.

The next day, her browsing is flooded with ads for psychotherapy, paid meditation apps, and even medication. What happened? Tracking algorithms interpreted her search pattern, the time of the connection, and her reading time as a clear emotional signal, and automatically sorted her into a psychological profile: female, 30–40, possible anxiety disorder, high propensity to purchase medication.

That profile doesn’t stay isolated. It can be used to adjust the price of a life insurance policy, to deny a loan based on inferred health risks, or to bombard her with advertising at her most vulnerable moments. That is precisely what privacy protects: the things we don’t want others to interpret, exploit, or use in our name.

1. “I have nothing to hide” 3

Who collects our data?

When we browse the web, we are not alone. Three main types of entities collect our information, each with different goals.

User platforms are the visible faces of technology: operating systems, browsers, applications, games, online stores, search engines, and social networks. Their goal is to collect data to keep us inside their ecosystem and monetize our attention.

Data brokers are the invisible layer. These are companies that specialize in collecting, buying, aggregating, and reselling data from multiple sources. Most people never notice they exist, but they are the architects of shadow profiles: they cross-reference property records, purchase histories, and public records to build detailed files on any citizen. In the United States alone, an estimated 4,000-plus companies are dedicated exclusively to this trade in personal data.

Generative artificial intelligence companies are the newest actor on this stage. When we interact with tools like ChatGPT, Gemini, or Copilot, the information we type is processed on external servers. Depending on the settings, that data may be used to retrain the models, so that our private information becomes part of the machine’s “knowledge.”

What you reveal without knowing it: explicit, implicit, and inferred

You don’t need to fill out a form to hand over data. Information is extracted at three levels of depth.

Explicit information is the data we hand over voluntarily and consciously: our name, the email address we use to sign up, our phone number, or the photos we upload to a social network. It’s only the tip of the iceberg.

4 THE PRIVACY HABIT

Implicit information, or metadata, is the data we generate simply by using technology: what time we connect, from what location, on what device, how long we spend reading an article, or how fast we scroll. Metadata is often more revealing than the content itself.

Inferred information is the most valuable and the most dangerous. It consists of the conclusions algorithms draw from the two previous levels. A system can deduce with high probability whether a woman is pregnant before she announces it, what her political leanings are, her sexual orientation, or whether she’s about to quit her job, all of it based on statistical patterns. The system already knows who we are without our ever having introduced ourselves.

Invisible profiles: reconstructing a life

The combination of seemingly harmless permissions is what makes exhaustive profiling possible. A flashlight app that asks for access to your contacts, a children’s game that requests the microphone, a social network that logs your location in the background — each one seems like an isolated anecdote. But cross-reference that data and you get a complete X-ray of the person:

• Routines: where they live and where they work.

• Relationships: who they spend time with and who they sleep with.

• Psychology: what worries them and what makes them emotionally vulnerable.

• Finances: when they get paid and what they spend their income on.

None of this serves a philosophical purpose; it is purely economic and behavioral: the better a user’s behavior can be predicted, the more that user is worth in the data market.

1. “I have nothing to hide” 5

The cost of free

There’s a maxim in the digital world that almost everyone has heard by now: “If the product is free, you are the product.” It remains as true as ever. Free services fund themselves by turning the user’s experience into marketable data.

The risks of this lack of privacy aren’t theoretical; they are documented and affect millions of people:

• Price discrimination: companies can show you higher prices for the same product or insurance policy if they detect that you have greater purchasing power or an urgent need.

• Manipulation and social engineering: scammers no longer need sophisticated techniques. Knowing a few public details — your pet’s name, the school you went to — is enough to guess passwords or deceive you with personalized phishing, that is, fraudulent messages designed to look like legitimate communications.

• Physical safety risks: sharing your real-time location or your exercise routes can make stalking, or a burglary at your home, easier.

Reclaiming digital sovereignty

Digital privacy is a right, not a privilege reserved for people who understand technology, and like any right, you have to exercise it actively or it erodes. The next time you’re about to justify yourself with “I have nothing to hide,” try replacing it with “I have the right to decide what I share.” It’s a change of one sentence, but it completely changes who’s in control.

Privacy is lost through small acts of neglect: accepting cookies without adjusting them, granting permissions without reading them, installing apps you don’t need. And it’s recovered the same way, step by step, decision by decision, which is exactly what we’ll do together throughout this book.

6 THE PRIVACY HABIT

How many permissions have you granted this week without thinking twice?

IMMEDIATE ACTION: PERMISSION CLEANUP

Start taking control of your privacy with this five-minute exercise:

1. Go to your smartphone’s settings.

2. Find the Privacy or Permission manager section.

3. Check which apps have access to your location.

4. Change the permission to “Allow only while using the app”

(Android) or “While Using the App” (iOS) for every app that doesn’t need to know where you are 24 hours a day.

Want to keep reading?

Get The Privacy Habit in paperback or Kindle:

Promotional excerpt from The Privacy Habit © Angel Alonso. All rights reserved.