Home Resources Blog Request Veel+
Back to Blog Home
Privacy

Your Privacy, For Real This Time

Perpelix
Perpelix Founder & Lead
April 2026

Here's something we want to be upfront about: until recently, we didn't give you a real choice when it came to your data. Analytics ran for everyone — no opt-in, no way out. Google Analytics, Vercel Analytics, our own internal tracker. If you were on Veel, we were collecting.

That's changed. We've built a proper consent system — and when we say proper, we mean the kind that actually does something. Clicking "Decline" now blocks every tracker on the site, deletes any cookies already set, and keeps it that way across every page for every future visit. Your choice, actually respected.

Let's walk through exactly what changed — then we'll get into why any of this matters, because the internet at large has been treating user data like an all-you-can-eat buffet for a long time, and you deserve to know how bad it got.

What We Actually Changed on Veel

If you clicked "Decline" on our cookie banner now, here's what genuinely happens:

Google Analytics — fully blocked We set Google's official kill-switch flag before their script even initialises. It doesn't phone home. Any GA cookies already sitting in your browser get deleted on the spot.
Vercel Analytics — never loads Instead of a static script tag that always fires, we now load Vercel Analytics conditionally. If you declined, the script is never downloaded. At all. It's not running in the background pretending to behave — it simply doesn't exist for your session.
Veel Internal Tracker — replaced with no-ops Our own analytics system tracks searches, clicks, download counts, scroll depth, and session duration. When you decline, every single one of those functions is replaced with silent no-ops. It runs nothing, sends nothing, stores nothing.

And this isn't just for the homepage. Every page on Veel now runs a tiny privacy gate script at the very top — before any tracking code gets a chance to initialise — so if you've ever declined, your decision is respected everywhere, on every page load, for as long as that preference sits in your browser.

We should have built it with consent from day one. We didn't. Now we have, and we're not going backwards. If you've been on Veel for a while — thanks for sticking around while we got our act together on this one.

A Brief History of the Internet Lying to Your Face

Here's the thing though: Veel doing shady cookie theatre is embarrassingly small potatoes compared to what the actual big players have gotten away with. Strap in, because the history of online privacy is genuinely one of the most brazen long cons in modern history.

Facebook & Cambridge Analytica (2018) — The one that broke everyone's brain

87 Million Users Affected

A researcher built a Facebook quiz app that, thanks to Facebook's API at the time, harvested not just the quiz taker's data but all of their friends' data too. That data — interests, location, political views, relationship statuses — ended up in the hands of Cambridge Analytica, a political consulting firm that used it to build psychographic profiles of US voters and sell targeted influence campaigns to the Trump 2016 campaign and Brexit advocates.

Facebook CEO Mark Zuckerberg sat in front of Congress and said "Senator, we run ads" with the energy of a man who knows he's not going to face real consequences. He was right. Facebook paid a $5 billion FTC fine — which sounds enormous until you realise that was about three weeks of their revenue at the time.

The real gut punch of Cambridge Analytica wasn't even the data theft. It was learning that you could take social media behaviour data, build a surprisingly accurate psychological model of a person, and then use that to serve them specifically crafted political messaging. Your Facebook likes about hiking and The Office were, apparently, enough to figure out how to manipulate your vote.

Yahoo's "small" breach (2016) — All 3 billion of them

3,000,000,000 Accounts — yes, three billion

Yahoo got breached in 2013. They found out in 2016. They initially said it was "only" 1 billion accounts. Then, during the Verizon acquisition due diligence process — you know, when someone is trying to buy your company and you actually have to be honest — they quietly revised that number upward to all three billion accounts that existed at the time.

Every single Yahoo account. All of them. Names, email addresses, telephone numbers, dates of birth, hashed passwords. If you had a Yahoo account in 2013 — and you almost certainly did because it was 2013 — your data is out there.

The genuinely funny-if-it-wasn't-so-sad part is that Yahoo found this out and still managed to only knock $350 million off the Verizon sale price. Verizon bought a company whose entire user database had been stolen and still paid $4.48 billion for it. What a time to be alive.

Google tracking you in "incognito" mode (settled 2024)

$5 Billion Class Action Settlement

For years Google collected user data even when people were browsing in Chrome's incognito mode — using Google Analytics, Google Ad Manager, and other tools embedded in third-party websites. Users thought the little spy icon meant they were private. They were not. A class action lawsuit filed in 2020 went all the way through the courts and Google settled in late 2023 for $5 billion, while deleting billions of data records collected during the period.

The incognito mode thing is worth repeating because it's important: incognito mode only stops your device from recording your history. It does nothing to prevent websites, your ISP, or your network from seeing what you're doing. If you thought incognito meant invisible, you've been living in a fantasy, and Google was very happy to let you believe that.

The Snowden revelations (2013) — when we found out governments were at it too

NSA PRISM — Mass surveillance of internet users globally

Edward Snowden leaked classified NSA documents revealing PRISM: a mass surveillance programme where the NSA had direct access to the servers of Microsoft, Yahoo, Google, Facebook, PalTalk, YouTube, Skype, AOL, and Apple. The US government was collecting emails, chats, videos, photos, stored data, VoIP calls, file transfers, and social networking details on a global scale. From its own citizens too, not just foreign targets.

The tech companies all denied knowledge of the programme. Some of those denials were technically true in ways carefully designed not to be actually true. None of them covered themselves in glory.

The Snowden leaks fundamentally changed how a lot of people think about privacy — or at least they should have. The uncomfortable reality is that within a few years most people just... went back to using the same services and trusting the same companies. Because convenience is a hell of a drug.

TikTok's data practices (2022–ongoing)

ByteDance employees accessed US user data from China

BuzzFeed News obtained leaked audio from 80 internal TikTok meetings in which employees discussed the fact that US user data was repeatedly accessed by staff based in China, directly contradicting TikTok's public claims about data being stored and accessible only in the US and Singapore. One engineer was recorded saying "everything is seen in China." TikTok has spent the years since then in regulatory battles in the US, EU, and UK, with varying outcomes depending on which government is currently in a mood about it.

None of this means TikTok is uniquely evil compared to American platforms — Meta and Google aren't exactly paragons of data sovereignty either. It's more that the whole industry operates on the assumption that your data is theirs to do what they want with, and the rules only matter when regulators actually enforce them.

Equifax (2017) — the breach that hurt the most

147 Million Americans — Social Security numbers, full names, dates of birth, addresses

Equifax, one of the three major credit bureaus that holds financial data on essentially every American adult, had a vulnerability in their system exploited for two and a half months before anyone noticed. The data stolen included Social Security numbers — the foundational piece of identity in the US financial system. Their "solution" was a website where you could check if you were affected. That website also had security issues. Their CEO retired with a full package. Multiple executives sold stock before the breach was made public.

The Equifax breach is the one that genuinely frightens security professionals because unlike most data breaches you can change your password. You cannot change your Social Security number. That data is permanently compromised for 147 million people and there's nothing any of them can do about it.

Okay. So What Can You Actually Do?

Right, enough doom. Here's what the privacy community has collectively figured out actually works. We're going to go tool category by category. Pick what's relevant to your threat level — you don't need to implement all of this to meaningfully improve your privacy.

Web Browsers
Block trackers, fingerprinting & surveillance at the source
  • Tor Browser MAXIMUM ANONYMITY — Routes all traffic through the Tor network. Slowest option but the hardest to trace back to you. Non-negotiable for high-risk activities. Desktop & Android.
  • Brave BEST DAILY DRIVER — Privacy-by-default: built-in ad/tracker blocking, HTTPS enforcement, fingerprinting resistance. Fast, Chromium-based, mobile too. Genuinely good without tweaking anything.
  • LibreWolf OPEN SOURCE — Hardened Firefox fork. Stripped of telemetry, focused on anti-fingerprinting. Great for desktop users who want Firefox DNA without Firefox's baggage.
  • Mullvad Browser — Built with Tor Project's anti-fingerprinting tech but without the Tor network. Pairs perfectly with Mullvad VPN. Aims to make you look identical to every other Mullvad Browser user — a solid anonymity strategy.
  • Firefox (with tweaks) FREE — Strong Enhanced Tracking Protection out of the box. Extend with uBlock Origin + other extensions. More setup needed but highly customisable.
  • DuckDuckGo Browser — Simple, clean, good tracker blocking. Best option on mobile if you want zero configuration.
  • Others worth knowing: Ungoogled Chromium, Waterfox, Firefox Focus (mobile, auto-clears sessions).
Search Engines
Search without building a profile of everything you've ever wondered about
  • DuckDuckGo MOST POPULAR — Doesn't track searches or build profiles. Decent results, getting better. Also has tracker blocking built into the browser extension.
  • Brave Search — Independent index (doesn't just launder Google results). Privacy-first with optional AI summaries, no profiling. Worth using as a daily driver.
  • Startpage — Proxies Google results anonymously. You get Google quality without Google knowing it's you. Solid middle ground.
  • MetaGer — European privacy-focused metasearch. Good choice if you're in the EU and care about GDPR compliance from your search engine too.
VPNs
Hide your IP from websites & encrypt traffic from your ISP
  • Mullvad MOST PRIVATE — Accepts cash and Monero payments. No email required to sign up. Audited no-logs policy. Sweden jurisdiction. Genuinely built for anonymity, not just marketing it.
  • Proton VPN HAS FREE TIER — Swiss-based, open-source, audited. Integrates with Proton Mail and Drive. Strong privacy reputation. Free tier is actually useful (unlimited bandwidth, limited servers).
  • IVPN — Minimal, audited, based in Gibraltar. Similar privacy philosophy to Mullvad. Good alternative if Mullvad is unavailable in your region.
  • Surfshark / NordVPN — Feature-rich, fast, support many devices simultaneously. Not as privacy-pure as Mullvad but audited and functional for most people. NordVPN has WireGuard-based NordLynx protocol.
  • Hard rule: Free VPNs are almost always garbage. If you're not paying, you're the product — which is the exact problem you're trying to solve. The only exception is Proton VPN's free tier.
Password Managers
Unique passwords everywhere — the single highest-ROI security habit
  • Bitwarden BEST OVERALL OPEN SOURCE — Free, audited, self-hostable if you're paranoid enough. Cross-platform, browser extensions, mobile apps. Zero reasons not to use this.
  • Proton Pass — From the Proton ecosystem. Includes email aliasing. Good if you're already using Proton Mail.
  • KeePassXC — Fully offline, local storage only, open-source. Your vault never touches the internet. Maximum control, needs a bit more setup for sync across devices.
  • 1Password / NordPass — Audited commercial options. More polished UX. Fine choices if you want to pay for the experience.
  • Enable passkeys wherever you can — they're phishing-resistant by design and make your accounts significantly harder to compromise.
Encrypted Email
Replace Gmail — Google reads your emails to serve you better ads, surprise surprise
  • Proton Mail GOLD STANDARD — End-to-end encrypted, Swiss-based, open-source. Integrates with the whole Proton suite. Free tier gets you a solid amount of storage.
  • Tuta (formerly Tutanota) — End-to-end encrypted, open-source, German-based. Strong encryption, simple interface, very reasonably priced paid plans.
  • StartMail — Netherlands-based, built for privacy, easy migration from existing email.
  • Email aliasing — use it: SimpleLogin (now part of Proton) or Addy.io let you generate throwaway addresses that forward to your real inbox. Websites get the alias. Your real address stays private. When spam starts hitting an alias, you delete it.
Encrypted Messaging
Because iMessage and WhatsApp have asterisks on their "encryption" claims
  • Signal GOLD STANDARD — The benchmark everything else is judged against. E2EE for messages and calls, open-source, audited, non-profit. Set disappearing messages on by default. Just use Signal.
  • Element (Matrix protocol) — Decentralised and federated. More complex to get right but doesn't rely on any single company's server. Good for groups that want to self-host.
  • Session — No phone number required for sign-up. Built on a decentralised network. Great if you want Signal-level security without linking to a phone number.
  • Threema — Swiss-based, no personal information required, one-time purchase (no subscription). Good option for European users.
Browser Extensions
Make any browser significantly more private in 5 minutes
  • uBlock Origin ESSENTIAL — The most effective ad and tracker blocker that exists. Free, open-source, low memory usage. Install this first, everything else is secondary. Works in Firefox; Chromium-based browsers now limit its capabilities due to Manifest V3 — another reason to consider Firefox.
  • Privacy Badger — EFF's tracker blocker. Learns to block invisible trackers based on their behaviour rather than a static blocklist. Good complement to uBlock Origin.
  • NoScript — Blocks all JavaScript by default, whitelist what you trust. Extremely effective, extremely annoying to set up. Worth it if you're serious.
  • Decentraleyes / LocalCDN — Intercepts requests to CDN services (like Google Fonts, jQuery CDN) and serves them locally instead, preventing those companies from tracking your visits to sites using their CDNs.
Operating Systems & Device Privacy
When you want privacy at the hardware level
  • GrapheneOS BEST ANDROID — Hardened Android fork for Pixel devices. No Google services by default, though you can run them sandboxed with almost no permissions. Used by journalists, security researchers, and people who read too much Snowden.
  • /e/OS — De-Googled Android that's more beginner-friendly than Graphene. Compatible with a wider range of devices.
  • Linux (desktop) — Fedora, Ubuntu, Pop!_OS etc. are significantly better than Windows for privacy out of the box. Windows 11 has telemetry baked in at a level that's basically impossible to fully disable.
  • Tails OS MAXIMUM ANONYMITY — Bootable from a USB drive, routes everything through Tor, leaves zero trace on the computer when you shut it down. Literally amnesic by design. For when things are serious.
  • Qubes OS — Security by compartmentalization. Different activities run in different virtual machines so a compromised browser can't reach your files. Used by Snowden himself. Steep learning curve.
  • Enable full-disk encryption on whatever OS you use — FileVault (macOS), BitLocker (Windows), or LUKS (Linux). If your laptop gets stolen, encryption means the data is useless to whoever has it.
DNS & Network Protection
Block ads and trackers before they even reach your browser
  • Quad9 — Private DNS that blocks known malware and tracker domains. Free, non-profit, Swiss-based. Dead simple to set up on any device or router.
  • NextDNS — Fully customisable DNS with detailed logs (or no logs). Blocks ads, trackers, malware by category. Free tier, small paid plan. Excellent balance of power and usability.
  • Mullvad DNS — No logging, strong blocking lists, obvious pairing with Mullvad VPN but usable standalone.
  • Pi-hole — Self-hosted network-wide ad blocker running on a Raspberry Pi (or any Linux box). Blocks tracking at the DNS level for every device on your network, including smart TVs and game consoles that don't support extensions. Bit of setup but once it's running it's magic.
Other Tools Worth Knowing
The full arsenal
  • 2FA / MFA — Aegis Authenticator (Android, open-source, encrypted local backups) or a hardware key like YubiKey. Enable 2FA on everything that offers it. SMS 2FA is better than nothing but SIM-swap attacks make it the weakest option.
  • VeraCrypt — Free, open-source encrypted containers or full disk encryption. Creates encrypted vaults for sensitive files. Successor to TrueCrypt after its mysterious shutdown in 2014 (there's a whole conspiracy about that, look it up).
  • Secure cloud storage — Proton Drive or self-hosted Nextcloud. Regular cloud storage (Google Drive, OneDrive, Dropbox) can read your unencrypted files. E2EE cloud storage providers cannot.
  • OnionShare — Share files, host websites, or have chats anonymously over Tor. Great for sending sensitive files without any third-party involved.
  • Metadata strippers — MAT2 or ExifTool. Photos contain EXIF data including GPS coordinates, camera model, and sometimes serial numbers. Strip this before sharing photos online. This is not a hypothetical risk.
  • Data removal services — DeleteMe or manual GDPR/CCPA requests. Data brokers are companies whose entire business model is collecting and selling your personal information. You can opt out, it's just tedious. Services like DeleteMe do it for you. If you're in the EU, GDPR gives you the right to erasure — use it.

Quick Wins — Do These Today

Use open-source tools Closed-source software can claim anything about privacy and you can't verify it. Open-source tools with public audits give you something to actually trust.
Audit your app permissions Go through your phone right now. Does your flashlight app need access to your contacts? Does a game need your location? Kill every permission that isn't obviously necessary.
Use different browsers for different purposes Firefox for daily browsing, Tor Browser for sensitive stuff. Separating contexts makes it harder to build a unified profile of you.
On mobile: use F-Droid F-Droid is an open-source Android app store with apps that have no trackers or ad SDKs. For privacy tools especially, prefer F-Droid versions.
Test your browser fingerprint EFF's Cover Your Tracks tool shows you how trackable you are. Panopticlick is another option. Most people are shocked by how unique their setup is.
Minimise accounts Every account is a potential breach. If you signed up for something and don't use it, delete the account. The best privacy posture for a service you don't need is not having an account.

The Reality Check

Here's the honest version: you probably can't opt out of the surveillance economy completely unless you're willing to make serious lifestyle changes. Google and Meta's infrastructure is so embedded in the web that even if you never use their products directly, you'll still have data about you collected through the sites you do visit.

But that doesn't mean doing nothing is rational. Every tool you add to your stack raises the cost of profiling you. It forces companies and bad actors to work harder. It keeps data out of breach databases. It means that when the next Cambridge Analytica happens — and there will be a next Cambridge Analytica — your data isn't in it.

Privacy isn't a binary. It's a dial. You're not trying to become a ghost. You're trying to move the dial meaningfully toward being less of a product.

For ongoing, actually maintained recommendations — not a blog post that'll be out of date in six months — bookmark PrivacyGuides.org. It's run by a community of privacy researchers and practitioners who vet tools rigorously and update their recommendations when things change. It's the most trustworthy resource in this space.

And for what it's worth: we're going to keep doing right by you on Veel. No fake consent banners. No quiet tracking while pretending not to. If we track something, we'll tell you exactly what and why. If you say no, we mean it.

Thanks for reading. Go install uBlock Origin if you haven't. Seriously, do it right now, this post will still be here when you get back.