Live Signal · Updated 2026-10-09
Every Sovereign Beacon™ rating
Each rating below is an editorial opinion grounded in cited public reporting, dated and methodology-bound. Click any card for the full Sovereign Beacon™ Grade Card on sovereignware.org — the canonical archive containing the full claim, named sources, methodology version, right-of-reply contact, and corrections log.
Editorial disclosure: opinion · cited · dated · methodology-bound · right-of-reply offered
Vivaldi Browser
Vivaldi Browser is rated green due to its strong commitment to user privacy, highlighted by its "zero-tracking policy" and explicit statement in its privacy policy (last updated December 15, 2023) that it "do[es] not share or sell information to any third party." The browser implements end-to-end encryption for its Sync service, meaning Vivaldi cannot decrypt user data such as passwords or browsing history. While a unique user ID and anonymized IP address (last octet removed) are sent daily for aggregate active user statistics, browsing activity remains local to the device. This privacy stance has been consistent, with Vivaldi's CEO criticizing Google's data practices as early as 2017, and the browser further enhancing protection with a built-in ad and tracker blocker by 2021.
Opinion · Cited sources · As of 2026-10-09
System76 Laptops
System76 demonstrates a strong commitment to user privacy, explicitly stating in its 2026 privacy policy update that it "does not sell your data." The company's Pop!_OS operating system, often pre-installed on its laptops, is designed with privacy in mind, featuring full-disk encryption by default since 2018 and implementing Network Time Security (NTS) for encrypted time synchronization by 2022. Furthermore, the policy states that "System76 does not collect or store any information from Pop!_OS user installations," with minimal OS and hardware data used only temporarily for updates and connectivity verification, and no telemetry or error reports collected. This commitment extends to hardware, as seen in 2017 when System76 announced its intention to disable the Intel Management Engine (ME) firmware due to security concerns. The company also publicly voiced concerns in 2026 regarding proposed age verification laws, arguing they could compromise user privacy.
Opinion · Cited sources · As of 2026-10-09
Ring
Ring is a significant privacy threat due to a history of severe security failures and internal misuse of customer data. In May 2023, the FTC filed a complaint, leading to a $5.8 million settlement in June 2023, for allowing employees unrestricted access to customer videos and failing to implement adequate security, enabling hackers to take control of accounts. This followed an acknowledgment in January 2020 of employees improperly accessing customer videos, with one employee viewing thousands of recordings in 2017. Furthermore, in December 2019, over 3,600 account credentials were leaked after hackers exploited vulnerabilities. While Ring's privacy notice (S0) states it collects "video or audio recordings, live video or audio streams" and claims to "maintain administrative, technical and physical safeguards," these incidents demonstrate a failure to protect this sensitive data. A class-action lawsuit in June 2026 also alleges the "Familiar Faces" feature collects biometric data without consent.
Opinion · Cited sources · As of 2026-10-09
Montana Senate Bill 375
Montana Senate Bill 375 (SB 375), passed in 2025, primarily regulates the sale of edible hemp products containing THC and does not contain specific provisions related to user privacy. While categorized as a privacy law, its technical mechanism focuses on product regulation rather than data collection, sharing, or retention. Unlike other Montana legislation such as the Montana Consumer Data Privacy Act (MCDPA) enacted in 2023, which establishes consumer rights regarding personal data, SB 375 does not address the collection, use, or protection of personal information. Therefore, it neither enhances nor diminishes user privacy, leading to a neutral impact in this category.
Opinion · Cited sources · As of 2026-10-09
Llama.cpp
Llama.cpp, despite its local-first design, poses a significant privacy threat due to numerous critical security vulnerabilities. For instance, in April 2024, a remote code execution (RCE) vulnerability (CVSS 9.6) was found in `llama-cpp-python` due to improper handling of chat templates, allowing arbitrary code execution. Furthermore, in April 2026, CVE-2026-34159 identified another critical RCE in the RPC backend, enabling unauthenticated attackers to read and write arbitrary process memory. The project's security policy explicitly warns users under "Data privacy" that "To protect sensitive data from potential leaks or unauthorized access, it is crucial to sandbox the model execution," and advises against using the RPC backend in untrusted environments, acknowledging the inherent risks. These vulnerabilities can lead to unauthorized data access and breaches if not properly mitigated by users.
Opinion · Cited sources · As of 2026-10-09
Startpage
Startpage is a privacy-focused search engine that explicitly states it does not collect personal data for searches. Since 2009, it has not recorded IP addresses, and its policy confirms, "We don't record your IP address" and "We don't record your search queries." Technical mechanisms include anonymizing search queries before sending them to providers and using HTTPS encryption with SSL/TLS for all searches, a feature launched in 2011. Although acquired by System1 in 2019, Startpage maintains that its founders retain control over privacy implementations, and independent audits confirm its practices, including not building advertising profiles or selling personal data. A supplemental policy for accounts collects necessary billing and contact information, but explicitly states, "Having a Startpage account does not change how we treat your searches."
Opinion · Cited sources · As of 2026-10-09
X Corp.
X Corp. (formerly Twitter) has a history of privacy failures and a privacy policy that permits extensive data collection and sharing. In May 2022, Twitter agreed to a $150 million penalty with the FTC for misrepresenting that phone numbers and email addresses, collected for security, would not be used for advertising, a clear breach of trust. The current privacy policy (S0, effective January 15, 2026) explicitly states, "Based on your consent, we may collect and use your biometric information for safety, security, and identification purposes," and "We may collect and use your personal information (such as your biographical information, employment history, educational history...)" for job recommendations and sharing with employers. Furthermore, the policy allows sharing with "Third-party collaborators" who "may use it for their own independent purposes... including, for example, to train their artificial intelligence models." This broad data collection, coupled with past regulatory actions like the December 2020 GDPR fine for a data breach, demonstrates a significant threat to user privacy.
Opinion · Cited sources · As of 2026-10-09
Delaware Personal Data Privacy Act
The Delaware Personal Data Privacy Act (DPDPA), signed into law on September 11, 2023, significantly enhances consumer privacy by granting residents rights to access, correct, delete, and opt-out of the sale of their personal data, targeted advertising, and certain profiling activities. A key mechanism is the requirement for explicit consent to process "sensitive data," which broadly includes categories like racial origin, religious beliefs, health conditions, and status as transgender or nonbinary, as defined in § 12D-102(30) of the official text. The law, effective January 1, 2025, also uniquely applies to non-profit organizations. Further strengthening protections, House Bill 380, signed on September 2, 2026, lowers applicability thresholds and expands safeguards for minors, including prohibiting processing sensitive data of children under 13 without parental consent. While lacking a private right of action, enforcement is exclusively handled by the Delaware Department of Justice.
Opinion · Cited sources · As of 2026-10-09
BetterHelp
BetterHelp has a history of sharing sensitive user data for advertising purposes. In March 2023, the Federal Trade Commission (FTC) settled with BetterHelp for $7.8 million over allegations that it shared consumers' health data, including email addresses, IP addresses, and health questionnaire responses, with platforms like Facebook and Snapchat between 2017 and 2020, despite promising privacy. While BetterHelp's current policy states, "To be clear, we don't share any data or information you share with your Therapist with any Third Party advertisers," and uses "industry-standard encryption technologies" (SSL) for data in transit, the past actions demonstrate a significant breach of trust. The policy also notes that if users opt-in to "Advertising cookies and web beacons," some "Visitor Data" (excluding therapy data) may be shared for advertising, which in California may be considered a "sale" of personal information. Furthermore, data like "Clinical Health Record" and communications are retained for 10 years after the last login if therapy was started and erasure was not requested.
Opinion · Cited sources · As of 2026-10-09
Microsoft Pluton
Microsoft Pluton, announced in November 2020, is a security processor integrated directly into the CPU, designed to protect credentials, identities, personal data, and encryption keys from physical attacks by eliminating the communication channel to a discrete TPM. This technical mechanism significantly enhances on-device security. Microsoft's privacy statement (S0) generally commits to "protecting the security of your personal data" and using "a variety of security technologies and procedures" including encryption. However, Microsoft's broader privacy record includes a June 2023 FTC fine for COPPA violations related to collecting children's data without consent, and a January 2024 disclosure of a corporate email system data breach. While Pluton offers robust hardware-level protection, these incidents highlight ongoing company-wide privacy and security challenges.
Opinion · Cited sources · As of 2026-10-09
Fathom Analytics
Fathom Analytics is a privacy-first web analytics solution, designed for GDPR and ePrivacy compliance by not using cookies or fingerprinting for tracking (2019). It avoids persistent user profiles by generating site-specific visitor signatures using a daily rotating salt, IP address (stripped), and user-agent, without storing raw IP addresses. The privacy policy explicitly states, "We do not rent, buy or sell personal data from or to others," and "We process minimal personal data on your behalf" (IP address and User-Agent). In May 2020, Fathom undertook a comprehensive GDPR project, formalizing policies and appointing a Privacy Officer, and ensures EU visitor data is processed on European servers with IP addresses stripped within the EU. Data retention is limited to legal obligations.
Opinion · Cited sources · As of 2026-10-09
Acxiom
Acxiom, a data and marketing company, poses a significant threat to user privacy due to its extensive data collection and sharing practices. In 2002-2003, the company experienced a major data theft where 1.6 billion customer records were stolen from its FTP servers, highlighting severe security vulnerabilities. Its business model has repeatedly drawn scrutiny, including a 2003 complaint by EPIC to the FTC for sharing personal information without consent, and 2018 GDPR complaints by Privacy International alleging unlawful processing of data for profiling. The privacy policy, updated June 1, 2026, confirms its role in marketing data products, offering opt-out mechanisms for marketing and limiting sensitive personal information use, but this does not negate its fundamental practice of collecting and processing vast amounts of personal data for commercial purposes. Furthermore, a 2024 Bavarian data protection authority ruling implicated Acxiom in the alleged secret trading of personal data, and a 2026 lawsuit by the Texas AG alleged Netflix shared consumer profiles with data brokers like Acxiom.
Opinion · Cited sources · As of 2026-10-09
RoomGPT
RoomGPT is rated yellow due to its data collection and sharing practices, which present potential privacy risks for users. The privacy policy (S0) states that personal information, including name, email, and phone number, along with usage data like IP addresses, may be collected upon signup. While RoomGPT does not sell user data, it "may share your data with third-party service providers" (S0), who are obligated to keep information confidential but whose specific data handling for AI training is not explicitly detailed. An August 2026 review highlighted potential privacy concerns related to uploading personal photos to the platform, and discussions in September 2026 emphasized the need for users to confirm whether inputs are used for model training (S4, S5). Although generated images are not saved to user accounts as of August 2026, the ambiguity regarding the use of sensitive input data for AI model training and sharing with third parties warrants a cautious approach.
Opinion · Cited sources · As of 2026-10-09
Firefox Focus
Firefox Focus is designed with privacy in mind, offering features like tracker blocking and clearing browsing data. Its privacy notice (S0, effective April 22, 2025) states that "Your browsing data is cleared from your device whenever you close your browser" and that "Focus and Klar process technical and settings data... on your device." However, Mozilla has faced scrutiny for its data practices. In 2024, Mozilla was criticized for sending data, including advertising ID and IP address, to Adjust GmbH from Firefox for Android and iOS to track ad installs without prominent disclosure, leading to the Adjust SDK's removal by August 2024. While the app offers strong privacy controls, the collection of "minimal technical and interaction data" for daily usage pings, retained for 25 months, and past third-party data sharing incidents prevent a fully green rating.
Opinion · Cited sources · As of 2026-10-09
DuckDuckGo AI Chat
DuckDuckGo AI Chat is designed with strong privacy protections, ensuring conversations are not used for AI model training and personal information like IP addresses is removed before being sent to underlying AI model providers. The service explicitly states it does not save or share chat history, with recent chats stored locally on the user's device by default. For longer-term storage, users can enable encrypted Sync & Backup, where decryption keys remain solely on user devices. Furthermore, DuckDuckGo introduced private chat sharing in October 2026, encrypting shared content on the user's device without DuckDuckGo accessing the decryption key, reinforcing its commitment to user-controlled data privacy.
Opinion · Cited sources · As of 2026-10-09
Shein
Shein is a significant privacy threat due to a history of data mismanagement and regulatory non-compliance. In June 2018, its then-parent company, Zoetop, suffered a data breach affecting 39 million accounts, leading to a $1.9 million settlement in October 2022 for failing to adequately secure customer data, despite its policy stating, "We maintain physical, electronic, and procedural safeguards designed to guard and prevent misuse of your personal information." Furthermore, the company's broad data sharing practices, outlined in its policy as "We may disclose and share your personal information with the parties as described below," have drawn scrutiny, including a February 2026 Texas AG lawsuit alleging potential accessibility of consumer data to the Chinese government. Shein also faced a €150 million fine from France's CNIL in September 2025 for violating cookie laws by placing advertising cookies without user consent, contradicting the policy's "Your Choices" section which implies user control. These repeated failures and ongoing investigations highlight a systemic disregard for user privacy and data protection.
Opinion · Cited sources · As of 2026-10-09
Telegram
Telegram's privacy posture has significantly weakened, particularly after its September 2024 privacy policy update. The company now explicitly states it "may disclose your IP address and phone number to the relevant authorities" if a user is suspected of criminal activities violating Terms of Service, a major shift from its previous stance. This change followed CEO Pavel Durov's arrest in August 2024 and was reflected in January 2025 transparency reports showing data disclosure for over 2,200 users in 2024. While "Secret Chats" offer end-to-end encryption, default "Cloud Chats" use client-server encryption, meaning Telegram retains access to message content, and a 2016 API flaw also exposed user data.
Opinion · Cited sources · As of 2026-10-04
Flock Safety Falcon & Condor Cameras
Flock Safety's surveillance systems force constant video, situational telemetry, and audio captures straight to a unified vendor cloud. The hardware functions with zero standalone or isolated network profiles, meaning all device data feeds cross-agency searching without a distinct warrant. Investigations by civil liberties groups confirm updated contractual stipulations extend expansive corporate data brokerage permissions and drop previous 'no-sale' protections, pushing the hardware strictly to Critical.
Opinion · Cited sources · As of 2026-06-24
Pine64 PinePhone Pro
The PinePhone Pro places ultimate hardware control back in user hands. Beneath its removable rear case sit six physical DIP switches capable of disconnecting circuit lines for the cellular modem, Wi-Fi/Bluetooth chips, microphone, front camera, rear camera, and headphone jack. Because the entire platform runs on community-audited Linux operating systems with zero vendor-mandated cloud services or baked-in diagnostic telemetry pipelines, it achieves absolute local data sovereignty.
Opinion · Cited sources · As of 2026-06-24
Threema Mobile Messaging App
Threema uses an architecture that generates a unique, anonymous 8-digit Threema ID for each client instance, ensuring messaging maps and profile networks are isolated from cellular identity trails. Group structures and contacts are handled entirely client-side rather than centralized on remote servers. While its business model relies strictly on up-front application sales (avoiding ad-tech monetization vectors), it requires centralized routing infrastructure to sync and transit payload streams, capping its final tier at Clear.
Opinion · Cited sources · As of 2026-06-24
Adobe Creative Cloud Applications
Adobe's modern software stack features mandatory integrations with its centralized Creative Cloud environments. Deep investigations into Adobe's service agreements reveal that standard accounts automatically opt creators into global 'Content Analysis' loops, allowing remote server arrays to scan active project binaries to refine generative algorithms. Because these diagnostic telemetry systems run out of the box and verification layers depend entirely on closed corporate trust, it drops to the Warning tier.
Opinion · Cited sources · As of 2026-06-24
AnythingLLM Framework
AnythingLLM functions completely isolated from vendor network arrays. All contextual documents, chat interaction histories, and embedded databases are maintained within the local disk space of the client machine. Anonymous telemetries are fully transparent and can be permanently deactivated within the initial settings window. Because it supports completely auditable open-source validation without mandatory external callbacks, it achieves a Sovereign rating.
Opinion · Cited sources · As of 2026-06-24
Midjourney Generative AI
Midjourney lacks any local computing architecture, channeling all client image synthesis loops through commercial cloud rendering clusters. Its basic operating policies permanently retain image inputs, vector generations, and personal interaction profiles for internal platform optimization and modeling metrics. Because the pipeline relies on un-verifiable black-box processes, features no safe defaults, and functions entirely through a mandatory cloud network, it ranks at Critical.
Opinion · Cited sources · As of 2026-06-24
SearXNG Metasearch
SearXNG establishes a proxy barrier between individual seekers and commercial web indexing structures. It discards user profile paths completely, omitting contextual search logs and script trackers. While private self-hosted instances can approach a sovereign footprint, general web deployment sites still require clear routing over standard web clouds to query data sources, capping the platform state firmly at Clear.
Opinion · Cited sources · As of 2026-06-24
LinkedIn Professional Network
LinkedIn utilizes a cloud framework optimized to chart behavioral networks. Policy reviews disclose that the platform deploys standard opt-out configurations for corporate AI modeling, automatically indexing user communications and resume assets to cultivate machine networks. Because the baseline system configurations operate unsafely without a manual adjustment, its placement settles at Warning.
Opinion · Cited sources · As of 2026-06-24
European Union Artificial Intelligence Act (EU AI Act)
The EU AI Act safeguards user autonomy by declaring automated biometric and predictive scoring architectures as 'unacceptable risks,' rendering them entirely prohibited across the European market. It establishes rigid machine-readability and transparency mandates on models to block covert content extraction. However, because it relies on centralized regulatory databases and allows specific law enforcement cloud exemptions in tracking public threats, it does not achieve local offline status, placing it at Clear.
Opinion · Cited sources · As of 2026-06-24
US FISA Section 702 (RISAA Reauthorizations)
Section 702 serves as a sweeping domestic spy tool, compelling commercial electronic communication service providers to pipeline data signals to intelligence databases without individualized warrants. Modern reauthorizations (RISAA) have actively expanded the types of businesses forced to cooperate with state collection nodes. With persistent, documented internal agency violations and zero end-user verification vectors, it maps unequivocally to Critical.
Opinion · Cited sources · As of 2026-06-24
YubiKey
YubiKey is a physical cryptographic security key that executes authentication operations entirely on-chip within its secure element. The hardware has zero network capabilities, does not contain tracking firmware, and does not require a cloud connection to function. Rigorous third-party testing for its FIPS 140-2 certification in 2023 verified that its cryptographic keys are physically un-extractable, ensuring absolute sovereign possession.
Opinion · Cited sources · As of 2026-06-07
Purism Librem 5
The Purism Librem 5 is a security-focused smartphone that operates completely on local user-owned hardware with no mandatory cloud integrations. It features physical hardware kill switches that disconnect the camera, microphone, Wi-Fi, Bluetooth, and cellular baseband from power. Independent reviews and Privacy Guides have confirmed that its baseband processor is isolated from the main CPU, ensuring no background data harvesting can bypass user controls.
Opinion · Cited sources · As of 2026-06-07
PrivateGPT
PrivateGPT is an open-source AI application designed to provide a completely offline conversational interface for document analysis. Since the application, embedding database, and LLMs execute entirely on local CPU/GPU hardware, no telemetry or prompt history is transmitted to any cloud servers. The full source is auditable on GitHub and the project explicitly documents that no remote API requests are made during ingestion or inference, ensuring physical and cryptographic custody of sensitive files.
Opinion · Cited sources · As of 2026-06-07
Mullvad VPN
Mullvad VPN is an application and routing service designed with absolute privacy-by-design principles, requiring no email address or personal details to register. Although it routes traffic through a cloud infrastructure, the service is built to prevent user data logging or profiling. In April 2023, a Swedish police search of Mullvad's offices demonstrated that the company stores zero customer data, as the authorities were unable to retrieve any user logs.
Opinion · Cited sources · As of 2026-06-07
Bitwarden
Bitwarden is an open-source credential manager that secures all user data with zero-knowledge, client-side encryption before syncing to the cloud. Its software architecture is fully open for public audit, and the company routinely publishes third-party security assessments. An independent code audit completed in 2024 confirmed that the cryptographic implementation is robust and that Bitwarden has no ability to decrypt or profile customer vaults.
Opinion · Cited sources · As of 2026-06-07
ProtonMail
ProtonMail provides zero-access encrypted email storage, meaning messages are encrypted client-side before being written to Proton's Swiss-based servers. An independent cryptographic audit completed in late 2024 confirmed that the web interface handles encryption processes correctly without leaking private keys. Because it relies on a trusted external operator, it does not achieve true sovereign status, but its structural design prevents data profiling.
Opinion · Cited sources · As of 2026-06-07
Brave Search
Brave Search is an independent search engine that operates on its own proprietary web index without building user behavioral profiles or tracking queries. The platform serves search results without utilizing third-party cookies or scripts that monitor cross-site behavior. In mid-2023, Brave officially removed all remaining Bing search API dependencies, making its search results completely independent of major surveillance-based search providers.
Opinion · Cited sources · As of 2026-06-07
macOS with iCloud
Apple's macOS operates locally but automatically prompts users to sync highly sensitive personal files, photos, and keychains to iCloud servers under default settings. In January 2023, the French regulator CNIL fined Apple 8 million euros for failing to obtain explicit user consent before presenting personalized App Store advertisements. Achieving a secure environment requires users to manually activate Advanced Data Protection and disable telemetry tracking.
Opinion · Cited sources · As of 2026-06-07
Perplexity AI
Perplexity AI is a conversational search engine that depends entirely on continuous cloud extraction and real-time indexing of web content. Its default terms allow the collection of user search habits, prompt history, and diagnostic data to train internal models. In mid-2024, a Wired investigation revealed that Perplexity bypassed standard robots.txt exclusions and scraped private sites without authorization. Since the platform's core model depends on aggressive data crawling and default logging, user configuration cannot guarantee complete privacy.
Opinion · Cited sources · As of 2026-06-07
Temu
Temu is an e-commerce application that operates on a business model driven by aggressive data extraction and consumer tracking. A June 2023 US Select Committee report highlighted major concerns regarding Temu's parent company, PDD Holdings, and its potential to harvest comprehensive mobile device data. In 2024, multiple consumer protection lawsuits were filed alleging that the application accesses contact lists, locations, and search histories without authorization.
Opinion · Cited sources · As of 2026-06-07
Apple Vision Pro
Apple Vision Pro introduces severe surveillance risks due to its vast array of always-on sensors, including multiple depth sensors, microphones, and 12 cameras. Although eye-tracking data is processed locally, the device continuously maps physical environments and tracks body movements in three dimensions to blend digital content with the physical world. This comprehensive environmental data collection creates unprecedented privacy concerns, as detailed 3D mapping could inadvertently expose intimate personal details, socio-economic status, and sensitive household items to third parties or malicious actors if exploited.
Opinion · Cited sources · As of 2026-06-05
Framework Laptop
Framework laptops are engineered with a heavy emphasis on user privacy, the right to repair, and open-source compatibility. By default, they feature physical hardware kill switches that completely sever power to the built-in microphone and webcam, ensuring they cannot be accessed surreptitiously by malware or background processes. Additionally, they are "Linux-first" friendly, offering pre-built options and official support for privacy-respecting operating systems like Ubuntu and Fedora, allowing users to entirely avoid the invasive telemetry associated with mainstream proprietary software.
Opinion · Cited sources · As of 2026-06-05
Amazon.com
Amazon's e-commerce platform relies on aggressive cross-site tracking and opaque data processing practices to build extensive behavioral profiles for targeted advertising. This systemic non-compliance with data protection standards culminated in a historic €746 million ($887 million) GDPR fine issued by Luxembourg's National Commission for Data Protection (CNPD) for failing to obtain explicit user consent before processing personal data. The site persistently monitors user activities across the web, capitalizing on vast amounts of personal metadata to consolidate its market advantage while ignoring fundamental privacy principles.
Opinion · Cited sources · As of 2026-06-05
DuckDuckGo
DuckDuckGo operates as a privacy-first search engine that actively mitigates cross-site tracking by refusing to store search history, collect IP addresses, or build personalized user profiles. Unlike mainstream competitors, it anonymizes every search request and delivers results without employing algorithms designed to harvest behavioral data. The platform further protects users by offering built-in tracker-blocking tools and HTTPS encryption enforcement, effectively neutralizing third-party tracking scripts that normally profile users as they browse the broader web.
Opinion · Cited sources · As of 2026-06-05
Ollama
Ollama is an open-source, local-first framework that allows organizations to run large language models (LLMs) entirely on their own hardware. It processes all prompts and data locally with zero external API calls or network requests after the initial download, ensuring complete data sovereignty and eliminating cloud leak risks. Its network-isolated operation prevents third-party tracking, making it a gold standard for privacy-compliant enterprise AI deployments.
Opinion · Cited sources · As of 2026-06-05
OpenAI ChatGPT (Consumer & Free Plans)
By default, OpenAI's consumer-facing ChatGPT and Plus accounts actively utilize user chats, uploaded files, and personal inputs to train future models. Unless a user manually navigates to settings to explicitly opt out, sensitive data is permanently processed on cloud servers and integrated into third-party datasets. Additionally, conversations are retained on OpenAI's servers for up to 30 days even with history disabled, representing a persistent risk of intellectual property exposure.
Opinion · Cited sources · As of 2026-06-05
California Privacy Rights Act (CPRA / CCPA)
The California Privacy Rights Act (CPRA) is widely considered the strongest consumer data privacy law in the United States. It provides robust, enforceable consumer rights, including the right to delete, correct, limit the use of sensitive personal information, and opt out of automated decision-making. Significantly, it is one of the very few state statutes to offer a limited private right of action for data breaches and features a dedicated enforcement watchdog, the California Privacy Protection Agency (CPPA).
Opinion · Cited sources · As of 2026-06-05
Utah Consumer Privacy Act (UCPA)
The Utah Consumer Privacy Act (UCPA) is heavily criticized by digital rights advocates for prioritizing business interests over consumer safety. It fails to mandate fundamental data minimization principles, does not provide consumers with a private right of action, and severely limits enforcement authority to the state Attorney General. Due to its high monetary applicability thresholds and extensive business exemptions, the law is rated as highly deficient and effectively acts as a shield for corporate data-harvesting practices.
Opinion · Cited sources · As of 2026-06-05
Virginia Consumer Data Protection Act (VCDPA)
Passed as one of the earliest state-level frameworks, the VCDPA is rated RED by privacy advocates because it was heavily influenced by industry lobbyists and serves as the template for weak state-level legislation. The law lacks a private right of action, giving sole enforcement power to the state Attorney General, and includes broad exemptions for financial institutions and insurance companies. This creates a regulatory environment where corporate compliance is easily navigated without substantial changes to tracking behaviors.
Opinion · Cited sources · As of 2026-06-05
Iowa Consumer Data Protection Act (ICDPA)
The ICDPA is rated RED as it is one of the weakest state privacy laws passed in the United States. Unlike stronger statutes, it denies consumers the fundamental rights to correct inaccuracies in their collected personal data or to restrict automated profiling. With zero private right of action, no rulemaking authority for a dedicated regulator, and an extraordinarily generous 90-day cure period for non-compliant businesses, the law acts more as a rubber stamp for industry data practices than a consumer protection mechanism.
Opinion · Cited sources · As of 2026-06-05
eufy Home Security Cameras
In January 2025, the New York Attorney General secured a $450,000 settlement after finding that eufy's video streams were not end-to-end encrypted and could be accessed without authentication. This lack of proper encryption and risk of foreign surveillance has led to investigations by U.S. and Australian authorities in early 2026.
Opinion · Cited sources · As of 2026-05-31
GrapheneOS on Google Pixel
GrapheneOS is a hardened, open-source Android operating system that provides a tracking-free environment by disabling background telemetry and advertising IDs by default. It implements full-disk encryption and hardened app sandboxing to isolate and protect user data at the silicon level.
Opinion · Cited sources · As of 2026-05-31
TikTok
Despite transitioning to U.S.-based management in January 2026, TikTok's updated privacy policy has introduced expanded collection of precise location data. Additionally, the app collects and profiles metadata from all user interactions with its AI-powered features, creating extensive privacy tracking risks.
Opinion · Cited sources · As of 2026-05-31
Signal Private Messenger
Signal remains the gold standard for secure messaging in 2026, offering audited, end-to-end encryption by default for all communications and utilizing Sealed Sender technology to hide metadata. It is operated by a non-profit foundation, does not back up data to third-party clouds, and maintains a strict zero-data-retention policy.
Opinion · Cited sources · As of 2026-05-31
Replika AI Companion
In May 2025, Italy's data protection authority (Garante) fined Replika's developer, Luka Inc., 5 million euros for serious GDPR violations, including processing sensitive personal data without a valid legal basis. The platform permanently logs highly intimate chats, fails to implement age verification, and lacks transparent data retention notices.
Opinion · Cited sources · As of 2026-05-31
Jan.ai
Jan.ai is an open-source, local-first personal AI chat application that runs entirely on the user's hardware by default. It processes all conversations and documents locally, ensuring that no sensitive data or chat history is transmitted to or stored on third-party cloud servers.
Opinion · Cited sources · As of 2026-05-31
Tractor Supply Company
Tractor Supply Company's website was fined a record $1.35 million by the California Privacy Protection Agency in September 2025 for serious CCPA violations. The site failed to honor consumer opt-out requests, ignored Global Privacy Control signals, and shared user tracking data with third-party advertising networks.
Opinion · Cited sources · As of 2026-05-31
Plausible Analytics
Plausible Analytics is an open-source, GDPR-compliant web analytics platform designed to offer detailed metrics without using cookies or collecting personally identifiable information. It minimizes data exposure and is hosted on secure European infrastructure, ensuring complete compliance with global privacy standards.
Opinion · Cited sources · As of 2026-05-31
