Your data is everywhere. Here is how to take back some control

Your television can recognise what is playing on its screen. Your car can record where it went and how hard it braked. Your phone can reveal a pattern of places that looks a lot like home, work, school, a clinic or a place of worship.
That does not mean binning every connected device. It means no longer treating every data flow as the unavoidable price of modern life.
One ordinary day can generate an extraordinary record
Your phone records that it moved from home to the office. Your car notes the route, speed and braking. A weather app asks an advertising software kit for your location. At night the television identifies the program on screen, and you ask an AI assistant to summarise a sensitive document.
Each event looks boring on its own. Together they describe routine, health, money, relationships, work and intent.
The Australian Competition and Consumer Commission says consumers generate data through activities that used to be anonymous and are generally unaware of how much is collected, used and shared. Its 2024 examination of data firms added that many firms in the data chain have no direct relationship with the people the data describes (ACCC report). So "I never gave that company my information" is no longer a reliable test.
Your television may recognise what is on the screen
Automatic content recognition, or ACR, identifies what is playing on a television. Depending on the system it can cover streaming apps, antenna, set-top boxes or HDMI devices.
In 2017 the US Federal Trade Commission and New Jersey alleged that Vizio televisions captured second-by-second viewing information from 11 million consumer TVs without informed consent. Vizio settled, paid US$2.2 million and accepted consent, deletion and privacy-program requirements (FTC).
That case does not prove every current television behaves the same way. It does show why the privacy menu on a TV matters, and why a streaming box on HDMI is not necessarily outside an ACR system's view. Read the full smart TV investigation.
Your car can produce a behavioural record
In its case against General Motors and OnStar, the FTC alleged that driving data included precise location, hard braking, speeding and late-night driving. It also alleged that consumer reporting agencies used information supplied by GM in reports insurers used when setting rates or denying insurance. The matter ended in a final consent order: regulator allegations resolved by an order, not proof that every manufacturer or insurer does the same (FTC final order release).
A record that feels like feedback on your driving can carry financial consequences once it enters an insurance or consumer-reporting system. See what your car records.
A location trail can reveal more than a name
Location data does not need to start with your name. A mobile advertising identifier linked to repeated coordinates can suggest where a person sleeps and works, and visits can point to medical facilities, religious organisations, schools or unions.
The FTC alleged that InMarket used location data to create almost 2,000 advertising audiences, including segments based on family, religious and health-related descriptions (InMarket complaint). Separately, it alleged that X-Mode ingested billions of location points linked to persistent identifiers (X-Mode final order release). These are US enforcement examples, not statements of Australian law. Follow the chain through the location data industry.
Health data can be as small as an email address plus a sensitive action
The FTC alleged that online counselling provider BetterHelp disclosed email addresses, IP addresses and answers to health questions to advertising platforms despite privacy promises. Its final 2023 order prohibited sharing health data for advertising and required US$7.8 million for partial refunds, and the order's notice said the allegation did not involve therapy messages, transcripts or session data (FTC final order). A platform does not need to send your most intimate words for an advertising partner to learn that an identifiable person sought a particular kind of service. The FTC's Flo case made similar allegations about a fertility-tracking app (FTC final order release).
A privacy product can collect data too
In 2024 the FTC alleged that Avast collected detailed browsing information through antivirus software and browser extensions, then sold it through its Jumpshot subsidiary to more than 100 third parties. The final order banned specified browsing-data sales, required deletion of the data and products derived from it, and imposed a US$16.5 million payment (FTC).
The lesson is not that every security tool is dangerous. It is that a product's label (security, privacy, wellness or productivity) does not answer the data question. Read the actual collection, use, sharing and retention terms.
Voice recordings can outlive the moment
A voice assistant has to process speech somewhere; the questions are where, for how long and under whose control.
In 2023 the FTC and US Department of Justice alleged that Amazon kept children's Alexa voice recordings indefinitely unless a parent asked for deletion, and did not delete some transcripts from all databases after requests. The resulting order imposed deletion, privacy and use restrictions plus a US$25 million civil penalty (FTC).
A vendor can switch a product's brains off
The features that make a device "smart" often live in the vendor's cloud, not in the device. Google's support page says its Nest Learning Thermostat (1st gen, 2011), 2nd gen (2012) and the 2nd gen Europe version (2014) stopped connecting to the Google Nest and Google Home apps from 25 October 2025. That meant no remote control, no notifications, no phone settings, no Home/Away Assist, and no more software or security updates. The dial still works, with its on-device schedule and modes (Google Nest support).
A feature that depends on the vendor's servers belongs to the vendor's product decisions, not to you. Gear that can be controlled locally keeps working when the cloud side ends; see how a local-first smart home is built.
AI changes what "useful data" means
Advertising made behaviour valuable because it helped predict what someone might click or buy. AI broadens that. Support tickets, email, chat, code and documents show how people and teams work. They can feed training, evaluation, retrieval, safety work and product improvement, and those are different processes that should not be blurred together.
It is equally wrong to say that every AI prompt is automatically used for training. Policies differ by provider, product and setting. OpenAI says content from individual services may be used to improve models depending on settings, while business and API data is not used for training by default. Anthropic says consumer users can choose whether chats and coding sessions may improve models, while Claude for Work and API data has separate rules. Google's Gemini controls and retention rules differ again, including separate treatment for temporary chats and human-reviewed conversations (Google). Microsoft says prompts, responses and Graph data in Microsoft 365 Copilot are not used to train foundation models, while interactions can be stored for history, audit and eDiscovery (Microsoft). Policies checked 9 September 2026.
Read the full investigation into how AI changes the value of your data.
Combining data changes its meaning
A single coordinate is not a home and one television program is not a profile, but repeated records joined to other datasets can support cross-device advertising, suggest identity or match an email hash to an existing account. Data collected for a modest purpose today may become useful for a purpose that did not exist when it was collected.
Total privacy is unrealistic. Reduction is practical.
You cannot stop a mobile network recording the operation of its own network while you use it. A retailer needs some information to deliver an order. Banks, employers and governments have legal record-keeping duties.
You can still make meaningful changes. Three common network controls have different jobs:
- a VLAN is a separate room for a group of devices, usually the ones you trust less
- the firewall is the rules on the doors between rooms and the internet
- Pi-hole is an internet address book with a blocklist: a listed name gets no useful destination address
- Turn off collection you do not need. Review TV viewing-data settings, app permissions, advertising controls, account histories and AI model-improvement settings.
- Put smart devices you do not fully trust in their own room. A guest or IoT network can stop a television or camera opening new connections to your laptops and storage, while the firewall can still let your phone cast, print or view a local camera. The room alone does not block internet access; the firewall rules do that. Australian cyber guidance recommends considering what a device collects, whether it needs internet access and whether it can be isolated (ACSC).
- Block selected destinations at the address-book stage. Pi-hole, AdGuard Home or a supported UniFi gateway can refuse listed domain names for devices using that controlled DNS path, so the unwanted connection often never starts. Australian gateway guidance says protective DNS can deny known-malicious names and may interrupt some malware command-and-control traffic (ASD). Alien IT treats that as an underrated early defence. It is incomplete: direct IP addresses, alternate DNS and mobile connections can get around it, it cannot separate an advert from wanted content on the same domain, and it does not remove malware already on a device.
- Choose local-capable smart-home devices. Home Assistant can store its core data locally and talk directly to supported devices. "Supported" matters: cloud-only integrations stay cloud-dependent (Home Assistant).
- Keep selected files and workloads in-house. A maintained NAS, private file service or local AI system can keep routine sensitive processing on equipment you control, along with responsibility for access, patches, monitoring, backups and tested recovery.
- Use the cloud on purpose. A good managed service can be safer than a neglected server. Review the provider, tier, contract, exit path and data sensitivity, and keep the systems that matter local where the trade-off makes sense.
Start with one data flow
Do not try to rebuild your digital life in a weekend. Pick one system that is sensitive and poorly understood: the smart TV, the family cameras, company documents or staff use of consumer AI accounts. Map what it collects, where it sends data, why, for how long, and what breaks if you restrict it. Then make one deliberate change and test it. I test one change at a time, so when something stops working I know why.
Where to go next
Investigations
The evidence behind the examples above.
Smart TV tracking and ACR
How a television recognises what is on screen, and what you can switch off or block.
What your car records
The route, speed and braking records a connected car can create, and where they can end up.
The location data industry
How app software kits, ad auctions and data suppliers turn phone location into profiles.
How AI changes the value of data
Why email, chats, code and support logs are worth more once machines can learn from them.
Practical guides
One control per guide, including where each falls short.
What Pi-hole blocks and misses
How the address-book filter works, what its dashboard figures mean and where it needs help.
UniFi gateway security
Domain blocking, IPS and IoT isolation on a UniFi gateway, with the limits spelled out.
Putting IoT devices in their own room
How to isolate smart TVs, cameras and IoT devices without breaking updates or casting.
Pi-hole with Unbound
What running your own DNS resolver changes, what stays visible and how to test recovery.
A local-first Home Assistant home
A smart home that keeps control local, survives an internet outage and has tested backups.
Local AI and private document search
What must run locally for AI work to stay local, and when hosted AI is the safer choice.
Private storage and backup
Storage built around permissions, snapshots, separate backups and restore tests, not just a box of disks.
Done-for-you setups
These Alien IT setups match the guides above.
Alien Privacy Box
A maintained local DNS filter to see and reduce selected tracker, advertising and telemetry requests.
Alien Private Home
A smart home that keeps control local, isolates low-trust devices and keeps essential automations running when the internet is down.
Alien Private Business
Documented network segmentation, private storage, backups and controlled access, with optional local AI.
Alien Private AI Server
Selected AI inference and private document search on infrastructure you control, with documented data flows.
Own the parts that matter
Owning infrastructure is about custody and choice, not collecting servers. Keep sensitive data in-house where practical, use the cloud deliberately, understand what leaves your network and maintain what you choose to run.
Tell me which device or system you want to start with. Call 02 9707 0999 or use the contact page.
Frequently asked questions
Can I stop all companies collecting data about me?
No. Some processing is necessary to provide services, run networks, fulfil transactions or meet legal duties. The realistic goal is to reduce unnecessary collection and restrict avoidable data flows.
Does a VPN stop tracking?
A VPN encrypts traffic to the VPN endpoint and changes the public IP address a destination sees. It does not stop account-based tracking, cookies, fingerprinting, app analytics or information you give a service directly.
Does Pi-hole make my network private?
No. It can block selected domains and show DNS activity from participating devices, but it cannot inspect or stop every communication channel. Its value is measurable reduction and visibility, not anonymity.
Is self-hosting always safer than cloud software?
No. A well-run managed service can be safer than an unpatched server with weak backups. Self-hosting makes sense when control, data custody, resilience or customisation justify the operating responsibility.
Is every AI prompt used to train a model?
No. Treatment varies by company, product, account tier, setting and contract. Check the exact service before entering sensitive information and recheck its policy periodically.
What should a business do first?
Inventory where sensitive information lives and which services receive it. Separate consumer AI accounts from approved business tools, review administrator access, confirm that backups restore, and find the first workload where local custody would materially reduce risk.