Welcome back to a series I’m calling Encrypted Pigeons. Why? Because it’s a frankly terrible phrase and I love it.
Now that we’ve established my overall opinions on privacy, it’s time to get into the nitty-gritty of it, and work out what privacy actually is in the 21st century.
First of all, let’s clear the air: being interested in privacy does not mean that you have something to hide. Quite the opposite. It means that you don’t want your life to be stolen from you by the very software you’re using.
That’s particularly relevant as our data becomes increasingly useful for AI. There is something fundamentally uncomfortable about a platform deciding that the personal information we entrusted to it is suddenly more valuable as training data than it is as something that should remain private.
But what does private actually mean?
I’ve had several answers to that question over the last six months.
First, privacy meant Europe
In about February of this year, I used Windows 11, stored everything on Google Drive, used WhatsApp for everything messaging, and had only a vague sense that I wasn’t really in control of my data.
Then I came across reports about Microsoft’s Copilot and its collection of information from users’ computers. That made me wonder just how much a handful of American technology companies controlled. A bit of research later, and it turned out to be rather a lot.
So my first step towards privacy was essentially anti-Big Tech. I systematically went through most of the apps on my phone, replacing them with British or European alternatives where possible.
There were exceptions. I was already paying for ExpressVPN, and Duolingo doesn’t really have a reasonable competitor that matches it. But generally, I started trying to move away from the American technology companies that had quietly become responsible for enormous parts of my digital life.
My first definition of privacy was therefore quite simple:
Don’t give my data to Big Tech.
Then Spotify complicated things.
Spotify began as a Swedish company, but its approach to tracking and profiling users made me realise that being European didn’t automatically make a service private. Maybe even Europe wasn’t enough.
Then, privacy meant open source
My attempt to replace Spotify introduced me to the wider FOSS community.
AntennaPod replaced my podcast app. F-Droid became my main source of applications. Fossify replaced Google’s stock Android apps. Termux gave me a terminal on my phone.
I also discovered something that appealed to me enormously: open source software. If the source code is publicly available, the kind of hidden behaviour that proprietary software can conceal becomes considerably harder to hide.
Unless you’re especially sneaky with it, obviously. 🤣
Spotify itself sort of fell away from being a priority during this phase. I eventually reconciled myself to the fact that there isn’t really an open-source equivalent that provides the same combination of discovery, catalogue and frictionless listening.
Sorry.
But this definition of privacy had a problem too.
Then, privacy meant self-hosting
An unexpected birthday present of a USB full of music files introduced me to the idea of running my own media server. Before long, I was running a server for much more than music.
I started self-hosting services, storing my own files and learning how the infrastructure underneath everything actually worked. Tailscale let me connect back to it when I was away.
And this was perhaps the most hands-on my definition of privacy became:
If I don’t want someone else to have my data, I’ll keep it myself.
But even that wasn’t quite the answer.
Tailscale, for example, is open source and its Android application is available through F-Droid. Yet when I initially tried to sign up, authentication depended on an external identity provider such as Google or Microsoft.
That was frustrating, but it was also useful. It showed me that privacy isn’t simply a matter of finding software with the right ideology. There are practical constraints everywhere, and sometimes the thing you want simply isn’t available in the form you’d like.
The same applied to Android itself.
Google Play Services sit underneath a huge amount of Android functionality, and many applications depend on them. I removed Google’s apps where I could and replaced them with FOSS alternatives, mostly from the Fossify suite.
Contacts moved to my own server. Calendar and email moved to Proton. Photos became another project entirely. Eventually I deleted my Google account.
Then I discovered that my code editor was still sending traffic to Google.
You can bet that app got deleted pretty quickly. 🤣
Then I found the actual problem
Eventually, I realised that I’d been looking at the problem from the wrong direction.
It wasn’t fundamentally that software was American.
It wasn’t that software was proprietary.
It wasn’t even that software was cloud-based.
The thing that bothered me was that I often didn’t know what was happening to my data.
So the next phase was considerably less dramatic. I started going through the applications and websites I actually used, looking for telemetry and statistics settings and turning off whatever I could.
And that was the point where my definition of privacy changed again.
I stopped asking:
“Is this a privacy-friendly company?”
and started asking:
“What exactly is this software doing, and am I happy with it?”
That distinction matters.
I don’t think self-hosting is automatically better. I don’t think open source is automatically trustworthy. I don’t think European companies are automatically good, or American companies automatically bad.
And I certainly don’t think convenience is the enemy of privacy.
So, what does “private” mean?
Six months after wondering why so much of my data was going to the US, I now have a de-Googled phone, a subscription to Proton, a Linux computer and a homeserver full of things I probably shouldn’t be trusted to maintain. Along the way, I’ve learned rather more about software, data and infrastructure than I expected.
My definition of privacy has changed several times.
First it was European.
Then it became open source.
Then it became self-hosted.
Eventually, it became something much simpler:
Understanding.
Understanding what happens when I open a computer or pick up a phone. Understanding what data leaves it, who receives it, why they want it, and what choices I have.
“Private” doesn’t mean rejecting society. It doesn’t mean being paranoid. It doesn’t mean refusing anything convenient, proprietary or commercial.
It means understanding the trade you’re making.
And, ultimately, deciding whether you’re happy to make it.
Leave a Reply