Your data is everywhere. Here is how to take back some control

Illustration of a home network: a router and DNS filter in the middle, with phones, laptops, a television, cameras and a printer around it; some paths continue to the internet and some stop
A household network at a glance. This is an illustration of the idea, not an exact diagram of any one home.

Your television can recognise what is playing on its screen. Your car can record where it went and how hard it braked. Your phone can reveal a pattern of places that looks a lot like home, work, school, a clinic or a place of worship.

That does not mean binning every connected device. It means no longer treating every data flow as the unavoidable price of modern life.

One ordinary day can generate an extraordinary record

Your phone records that it moved from home to the office. Your car notes the route, speed and braking. A weather app asks an advertising software kit for your location. At night the television identifies the program on screen, and you ask an AI assistant to summarise a sensitive document.

Each event looks boring on its own. Together they describe routine, health, money, relationships, work and intent.

The Australian Competition and Consumer Commission says consumers generate data through activities that used to be anonymous and are generally unaware of how much is collected, used and shared. Its 2024 examination of data firms added that many firms in the data chain have no direct relationship with the people the data describes (ACCC report). So "I never gave that company my information" is no longer a reliable test.

Your television may recognise what is on the screen

Automatic content recognition, or ACR, identifies what is playing on a television. Depending on the system it can cover streaming apps, antenna, set-top boxes or HDMI devices.

In 2017 the US Federal Trade Commission and New Jersey alleged that Vizio televisions captured second-by-second viewing information from 11 million consumer TVs without informed consent. Vizio settled, paid US$2.2 million and accepted consent, deletion and privacy-program requirements (FTC).

That case does not prove every current television behaves the same way. It does show why the privacy menu on a TV matters, and why a streaming box on HDMI is not necessarily outside an ACR system's view. Read the full smart TV investigation.

Your car can produce a behavioural record

In its case against General Motors and OnStar, the FTC alleged that driving data included precise location, hard braking, speeding and late-night driving. It also alleged that consumer reporting agencies used information supplied by GM in reports insurers used when setting rates or denying insurance. The matter ended in a final consent order: regulator allegations resolved by an order, not proof that every manufacturer or insurer does the same (FTC final order release).

A record that feels like feedback on your driving can carry financial consequences once it enters an insurance or consumer-reporting system. See what your car records.

A location trail can reveal more than a name

Location data does not need to start with your name. A mobile advertising identifier linked to repeated coordinates can suggest where a person sleeps and works, and visits can point to medical facilities, religious organisations, schools or unions.

The FTC alleged that InMarket used location data to create almost 2,000 advertising audiences, including segments based on family, religious and health-related descriptions (InMarket complaint). Separately, it alleged that X-Mode ingested billions of location points linked to persistent identifiers (X-Mode final order release). These are US enforcement examples, not statements of Australian law. Follow the chain through the location data industry.

Health data can be as small as an email address plus a sensitive action

The FTC alleged that online counselling provider BetterHelp disclosed email addresses, IP addresses and answers to health questions to advertising platforms despite privacy promises. Its final 2023 order prohibited sharing health data for advertising and required US$7.8 million for partial refunds, and the order's notice said the allegation did not involve therapy messages, transcripts or session data (FTC final order). A platform does not need to send your most intimate words for an advertising partner to learn that an identifiable person sought a particular kind of service. The FTC's Flo case made similar allegations about a fertility-tracking app (FTC final order release).

A privacy product can collect data too

In 2024 the FTC alleged that Avast collected detailed browsing information through antivirus software and browser extensions, then sold it through its Jumpshot subsidiary to more than 100 third parties. The final order banned specified browsing-data sales, required deletion of the data and products derived from it, and imposed a US$16.5 million payment (FTC).

The lesson is not that every security tool is dangerous. It is that a product's label (security, privacy, wellness or productivity) does not answer the data question. Read the actual collection, use, sharing and retention terms.

Voice recordings can outlive the moment

A voice assistant has to process speech somewhere; the questions are where, for how long and under whose control.

In 2023 the FTC and US Department of Justice alleged that Amazon kept children's Alexa voice recordings indefinitely unless a parent asked for deletion, and did not delete some transcripts from all databases after requests. The resulting order imposed deletion, privacy and use restrictions plus a US$25 million civil penalty (FTC).

A vendor can switch a product's brains off

The features that make a device "smart" often live in the vendor's cloud, not in the device. Google's support page says its Nest Learning Thermostat (1st gen, 2011), 2nd gen (2012) and the 2nd gen Europe version (2014) stopped connecting to the Google Nest and Google Home apps from 25 October 2025. That meant no remote control, no notifications, no phone settings, no Home/Away Assist, and no more software or security updates. The dial still works, with its on-device schedule and modes (Google Nest support).

A feature that depends on the vendor's servers belongs to the vendor's product decisions, not to you. Gear that can be controlled locally keeps working when the cloud side ends; see how a local-first smart home is built.

AI changes what "useful data" means

Advertising made behaviour valuable because it helped predict what someone might click or buy. AI broadens that. Support tickets, email, chat, code and documents show how people and teams work. They can feed training, evaluation, retrieval, safety work and product improvement, and those are different processes that should not be blurred together.

It is equally wrong to say that every AI prompt is automatically used for training. Policies differ by provider, product and setting. OpenAI says content from individual services may be used to improve models depending on settings, while business and API data is not used for training by default. Anthropic says consumer users can choose whether chats and coding sessions may improve models, while Claude for Work and API data has separate rules. Google's Gemini controls and retention rules differ again, including separate treatment for temporary chats and human-reviewed conversations (Google). Microsoft says prompts, responses and Graph data in Microsoft 365 Copilot are not used to train foundation models, while interactions can be stored for history, audit and eDiscovery (Microsoft). Policies checked 9 September 2026.

Read the full investigation into how AI changes the value of your data.

Combining data changes its meaning

A single coordinate is not a home and one television program is not a profile, but repeated records joined to other datasets can support cross-device advertising, suggest identity or match an email hash to an existing account. Data collected for a modest purpose today may become useful for a purpose that did not exist when it was collected.

Total privacy is unrealistic. Reduction is practical.

You cannot stop a mobile network recording the operation of its own network while you use it. A retailer needs some information to deliver an order. Banks, employers and governments have legal record-keeping duties.

You can still make meaningful changes. Three common network controls have different jobs:

Household firewall example: a phone may control a TV, a laptop may print, cameras may send video to a local recorder and the TV may stream. Printers and local-only cameras cannot reach the internet, IoT devices cannot start connections into trusted Wi-Fi, and replies to approved connections are allowed.
This is an example policy, not a universal recipe. Cloud-dependent cameras and printers may need narrow, tested exceptions. Open the full-size diagram
  1. Turn off collection you do not need. Review TV viewing-data settings, app permissions, advertising controls, account histories and AI model-improvement settings.
  2. Put smart devices you do not fully trust in their own room. A guest or IoT network can stop a television or camera opening new connections to your laptops and storage, while the firewall can still let your phone cast, print or view a local camera. The room alone does not block internet access; the firewall rules do that. Australian cyber guidance recommends considering what a device collects, whether it needs internet access and whether it can be isolated (ACSC).
  3. Block selected destinations at the address-book stage. Pi-hole, AdGuard Home or a supported UniFi gateway can refuse listed domain names for devices using that controlled DNS path, so the unwanted connection often never starts. Australian gateway guidance says protective DNS can deny known-malicious names and may interrupt some malware command-and-control traffic (ASD). Alien IT treats that as an underrated early defence. It is incomplete: direct IP addresses, alternate DNS and mobile connections can get around it, it cannot separate an advert from wanted content on the same domain, and it does not remove malware already on a device.
  4. Choose local-capable smart-home devices. Home Assistant can store its core data locally and talk directly to supported devices. "Supported" matters: cloud-only integrations stay cloud-dependent (Home Assistant).
  5. Keep selected files and workloads in-house. A maintained NAS, private file service or local AI system can keep routine sensitive processing on equipment you control, along with responsibility for access, patches, monitoring, backups and tested recovery.
  6. Use the cloud on purpose. A good managed service can be safer than a neglected server. Review the provider, tier, contract, exit path and data sensitivity, and keep the systems that matter local where the trade-off makes sense.

Start with one data flow

Do not try to rebuild your digital life in a weekend. Pick one system that is sensitive and poorly understood: the smart TV, the family cameras, company documents or staff use of consumer AI accounts. Map what it collects, where it sends data, why, for how long, and what breaks if you restrict it. Then make one deliberate change and test it. I test one change at a time, so when something stops working I know why.

Where to go next

Investigations

The evidence behind the examples above.

Practical guides

One control per guide, including where each falls short.

Done-for-you setups

These Alien IT setups match the guides above.

Own the parts that matter

Owning infrastructure is about custody and choice, not collecting servers. Keep sensitive data in-house where practical, use the cloud deliberately, understand what leaves your network and maintain what you choose to run.

Tell me which device or system you want to start with. Call 02 9707 0999 or use the contact page.

Frequently asked questions

Can I stop all companies collecting data about me?

No. Some processing is necessary to provide services, run networks, fulfil transactions or meet legal duties. The realistic goal is to reduce unnecessary collection and restrict avoidable data flows.

Does a VPN stop tracking?

A VPN encrypts traffic to the VPN endpoint and changes the public IP address a destination sees. It does not stop account-based tracking, cookies, fingerprinting, app analytics or information you give a service directly.

Does Pi-hole make my network private?

No. It can block selected domains and show DNS activity from participating devices, but it cannot inspect or stop every communication channel. Its value is measurable reduction and visibility, not anonymity.

Is self-hosting always safer than cloud software?

No. A well-run managed service can be safer than an unpatched server with weak backups. Self-hosting makes sense when control, data custody, resilience or customisation justify the operating responsibility.

Is every AI prompt used to train a model?

No. Treatment varies by company, product, account tier, setting and contract. Check the exact service before entering sensitive information and recheck its policy periodically.

What should a business do first?

Inventory where sensitive information lives and which services receive it. Separate consumer AI accounts from approved business tools, review administrator access, confirm that backups restore, and find the first workload where local custody would materially reduce risk.