The Quiet Death of Privacy (and the Free Market) in America
Run a business? See how this affects your compliance obligations.
By: David A. Prado, Esq – The Prado Law Firm
George Orwell's 1984 imagined a state that watched its citizens through telescreens in every home. More than seventy-five years after the novel's publication, the telescreen has been replaced by something far more effective: the smartphone in your pocket, the camera on the corner, the drone overhead, and the software that stitches it all together. In America today, we carry the device willingly, buy the cameras that watch our neighborhoods, and grant the app permissions that let companies sell our location to the government and market players.
Some readers will shrug. They already have everything on me, so what is the point of resisting? Resignation is exactly what this architecture depends on. A population that believes privacy is already gone will never demand it back, and the systems described below count on that apathy far more than they count on secrecy. I, for one, am not going to make it any easier for the U.S. government, or anyone else, to track me around the clock.
Your Phone's ID: What Is an IMSI?
The International Mobile Subscriber Identity is a unique number stored on your phone's SIM card that identifies your subscription to the cellular network. It is usually 15 digits: a country code, a carrier code, and a subscriber number, and it is the identity your carrier uses to authenticate your device, route your calls, and bill you. It is not your phone number. Think of it as the fingerprint your phone leaves on the network.
When your phone attaches to a cell tower, it identifies itself, usually with a temporary alias but sometimes with the IMSI itself. On 2G, 3G, and 4G networks, a tower can demand the IMSI in plain text, and the phone has no way to verify that the tower is legitimate before answering. That single design choice is what makes the surveillance described in this article possible. Anyone who can convincingly impersonate a tower can make your phone announce who it is.
5G was designed to close this hole. The standard encrypts the IMSI before the phone transmits it, so a fake tower receives only a scrambled identifier it cannot tie to a subscriber (Khan & Niemi, 2018). The catch is that the protection only works on what carriers call standalone 5G, meaning a network built on a true 5G core. Most "5G" connections in the United States still run in non-standalone mode, which delivers 5G speeds over a 4G core and carries 4G's security along with it. As one of the researchers who demonstrated the problem put it, users are getting the high-speed connection with the security level of 4G (Newman, 2021). The 5G icon on your status bar tells you nothing about whether your IMSI is protected.
How Stingrays Exploit This Vulnerability
The Cato Institute's policy analysis Stingray: A New Frontier in Police Surveillance explains how this weakness once used by clandestine services is now a regularly used law enforcement tool. Stingray devices, also called cell-site simulators or IMSI catchers, imitate a legitimate cell tower and broadcast a stronger signal than the real ones nearby. Because phones are built to connect to the strongest available signal, every phone in range switches over to the impostor without the user or the carrier noticing (Bates, 2017).
This is a man-in-the-middle attack in the plainest sense. The Stingray positions itself between your phone and the network, intercepting what passes between them without your knowledge or consent.
What the IMSI Enables: Tracking, Metadata, and Content
Once an agency knows a target's IMSI, or is willing to collect everyone's, a cell-site simulator opens three tiers of surveillance, each more invasive than the last.
1. Location tracking
The primary function of an IMSI catcher is to pinpoint a phone's physical location. Because the phone is talking directly to the device, the operator can triangulate the signal strength and direction with a precision carriers cannot match. In a federal case in Arizona, the government acknowledged that agents used such a device to locate a suspect's aircard inside a specific apartment (United States v. Rigmaiden, 2012), and officials have testified to accuracy within a few feet (Bates, 2017).
This tracking happens in real time. As you move from home to work to a doctor's office to a protest, your phone keeps announcing itself to the strongest tower. If that tower is a Stingray, the movements are logged live. That doctor's office may have been your OB/GYN, That protest might have been a no-kings protest. And now you begin to see a full picture of what states and governments are doing to track individuals.
The precision raises constitutional problems. Maryland's intermediate appellate court held in 2016 that using a cell-site simulator to locate a phone inside a home is a Fourth Amendment search requiring a warrant, relying on Kyllo v. United States (2001), where the Supreme Court held that using sense-enhancing technology to gather information from inside a home is a search (State v. Andrews, 2016).
2. Metadata
Beyond location, a simulator can log the who, when, and how long of your calls: the numbers involved, whether a call was incoming or outgoing, its date, time, and duration, and the cell sector the phone was using. The Justice Department's own Electronic Surveillance Manual lists these fields as data the device displays, and adds that such devices may be capable of intercepting the contents of communications (U.S. Department of Justice, 2008, as cited in Bates, 2017).
Metadata is more revealing than it sounds. It maps your social network, your daily rhythms, and who was standing near you at the same moment. Justice Sotomayor warned in United States v. Jones (2012) that she doubted people would accept government access to a list of every website they had visited without complaint, and the same logic applies to a log of every call. Deploy a simulator at a protest, a rally, or a place of worship, and the result is a roster of attendees at constitutionally protected activity (Bates, 2017, n. 13).
3. Content on legacy networks
The most invasive capability is interception of actual content: the audio of calls and the text of SMS messages. In practice this is limited to older 2G and 3G connections, where encryption is weak or absent and there is no way to verify a base station's authenticity (Restore the Fourth, n.d.; TechRadar, 2022). Modern simulators do not wait for a phone to be on 2G. They can push a 4G or 5G phone down to the older protocol, a technique known as a downgrade attack, and then read what passes through (TechRadar, 2022).
Restore the Fourth (n.d.) reports that certain catchers can also capture unencrypted web traffic, mount denial-of-service attacks, and, in at least one suspected case involving journalists in Morocco in 2020, inject malware onto a target phone.
The Justice Department's 2015 policy states that its devices must be configured as pen registers and may not collect content (U.S. Department of Justice, 2015). That is an administrative policy, not a statute, and it binds only DOJ components. It does not claim the devices lack the capability; it says they are not configured to use it (Bates, 2017).
Two limits are worth stating plainly, and one qualification. Traffic on 4G and 5G is encrypted, so a simulator that captures it gets ciphertext. End-to-end encrypted apps such as Signal, WhatsApp, and iMessage add a layer the simulator cannot remove. The downgrade attack is the way around both, which is why the 2G setting discussed at the end of this article matters. The qualification is that the downgrade only matters for content. The first two tiers, location and metadata, need nothing more than your IMSI, and on 4G and non-standalone 5G the phone still hands that over on request. A simulator does not have to push you onto 2G to know where you are and who you are calling. It only has to ask.
The Scope of Stingray Surveillance
The scale is larger than most realize. As of 2016, state or local police in at least 23 states and the District of Columbia had been documented using the devices, alongside the FBI, DEA, NSA, and Department of Homeland Security (Bates, 2017). In Baltimore, a detective estimated his unit had used the devices more than 4,300 times in routine cases, with no public policy governing them (Bates, 2017).
Departments cited terrorism to obtain the equipment and then used it for ordinary crime. Records the ACLU obtained from Florida police showed the devices used mostly for minor offenses, meaning bystanders' rights were swept into investigations of theft and similar crimes (Restore the Fourth, n.d.). Whether simulators have been used against protesters is not conclusively proven, but in 2014 Chicago demonstrators reported phone malfunctions near a police vehicle suspected of carrying one, and contemporaneous police communications suggested the local fusion center was tracking phones at the protest (Restore the Fourth, n.d.). The Electronic Frontier Foundation's Rayhunter detection project has since gathered reports from protests nationwide and, as of September 2025, had found no evidence of simulator use at U.S. protests, while cautioning that absence of detection is not proof of absence (Electronic Frontier Foundation, 2025).
ICE has used the devices to locate people for immigration arrest and deportation, often without disclosing the technology in the resulting cases (Restore the Fourth, n.d.). A 2023 Homeland Security Inspector General audit found the Secret Service and ICE Homeland Security Investigations did not always comply with statute and policy when using simulators (U.S. Department of Homeland Security, Office of Inspector General, 2023), and federal spending records show ICE paid more than $1.6 million in 2024 and 2025 for vehicles fitted with them (Franceschi-Bicchierai, 2025).
Secrecy and the Erosion of Oversight
The most troubling feature of Stingray surveillance is the systematic effort to hide it from courts, legislators, and the public. The FBI required state and local agencies to sign nondisclosure agreements before acquiring the devices, and the Erie County, New York agreement went so far as to require the sheriff to seek dismissal of a prosecution at the FBI's request rather than reveal information about the equipment (Bates, 2017).
Bates (2017) opens with a Tallahassee armed robbery in which prosecutors had the defendants cold, until defense counsel asked how police found them so fast. Rather than answer, the state offered probation with no jail time. In 2014, U.S. Marshals seized Stingray records from the Sarasota Police Department to keep the department from complying with a state public records order (Bates, 2017).
Police have also obscured the technology through vague language in warrant applications, as in Rigmaiden, and a Florida department admitted in emails to using parallel construction, building a second evidentiary trail to conceal that a simulator generated the original lead (Restore the Fourth, n.d.). The FBI's own memorandum to Oklahoma City police directed that simulator information be used for lead purposes only and corroborated with other methods admissible at trial (Bates, 2017).
Challenging this kind of surveillance requires expertise most defense lawyers and defendants do not have. The National Association of Criminal Defense Lawyers' Fourth Amendment Center exists to fill that gap, providing litigation resources and direct assistance on cases involving new surveillance tools (National Association of Criminal Defense Lawyers, 2026).
You = IMSI + Your Car + Flock Cameras & Drones + Facial Recognition + Data Brokers
The IMSI is one node in an increasingly interconnected system. Once an identifier is known, it can be combined with a suite of tools that together erase any meaningful expectation of privacy in public life.
1. Flock cameras and license plate readers
Flock Safety operates automated license plate reader (ALPR) cameras in thousands of communities across 49 states, generating billions of scans each month. The cameras record plate numbers along with make, model, color, dents, roof racks, and bumper stickers, and store the results in a searchable database that can reconstruct where a person works, worships, and spends their days (DeFlock, n.d.; Institute for Justice, 2026). The cameras log every passing vehicle regardless of suspicion (DeFlock, n.d.).
The system has already been abused. A Sarasota, Florida officer was arrested after using Flock to search a single plate more than 300 times. A leaked Flock training webinar showed officers how to watch live footage of a No Kings protest, and a company employee described monitoring a car show and initiating traffic stops once drivers were far enough away (Institute for Justice, 2026). Flock's software platform, FlockOS, combines plate readers, drones, gunshot detectors, 911 data, and third-party cameras into what the company calls a single pane of glass (Institute for Justice, 2026). (She Got an Abortion. So A Texas Cop Used 83,000 Cameras to Track Her Down)
No federal law governs police use of ALPRs. Thomson Reuters' plate recognition database holds more than 20 billion scans, and ICE agents can retrieve a vehicle's travel history from a phone in the field. In 2025, at least eight Washington State agencies allowed Border Patrol access to their ALPR networks despite a state law barring ALPR use for immigration enforcement, some apparently without realizing the sharing feature was enabled (Institute for Justice, 2026).
2. Facial recognition
The Secret Service uses a mobile app called Sentry, and ICE uses Mobile Fortify, both of which compare face and fingerprint scans against government databases holding hundreds of millions of images. An internal DHS document states that people cannot decline to be scanned and that facial images are retained for 15 years regardless of citizenship (Institute for Justice, 2026). DHS has also used Clearview AI, whose database of roughly 70 billion scraped images was used during Operation Metro Surge in Minnesota to compile photos of protesters; court filings showed false matches that tied innocent people to targets in DHS files (Institute for Justice, 2026).
3. Purchased location data
ICE buys location data harvested from ordinary apps, including weather apps, through brokers such as Venntel, allowing near-real-time tracking of where a person lives, works, worships, sends their children to school, and protests, all on a purchase order rather than a warrant. ICE spent more than $60 million on location data contracts in 2025 and 2026, and in January 2026 posted a request for information that referenced ad tech for the first time in its procurement documents (Institute for Justice, 2026). The FTC sued Gravy Analytics and Venntel in December 2024 for selling sensitive location data without consent (Federal Trade Commission, 2024). The purchases continued.
4. Geofence warrants
A geofence warrant compels a company such as Google to hand over data on every device in a defined area during a defined window, turning a neighborhood into a suspect pool. On June 29, 2026, the Supreme Court held in Chatrie v. United States that acquiring a person's cell phone location data from a tech company is a Fourth Amendment search, even for a short period and even though a third party stores the data, while leaving for the lower court whether the particular warrant satisfied probable cause and particularity (Chatrie v. United States, 2026). Because a Stingray collects location directly, without any company in the middle, the privacy argument against it is at least as strong, though the Court has not yet addressed cell-site simulators specifically.
5. Drones and aircraft
ICE drones can detect a person from 7.5 miles and identify them from 0.8 miles, many with thermal and night-vision cameras. Between April 2025 and February 2026 the FAA cleared more than 1,000 public safety agencies to fly beyond visual line of sight, and agencies including the NYPD and Las Vegas Metropolitan Police may now have one pilot oversee up to four drones at once (Institute for Justice, 2026). The FBI has for years flown a fleet of surveillance aircraft registered to front companies, some carrying cellphone-tracking equipment capable of identifying thousands of phones below (Gillum & Sullivan, 2015).
The Data Brokers
Everything described so far involves an agency pointing a tool at you. The data broker industry works the other way around. It collects continuously, from products you bought and invited into your life, and sells the result to whoever pays. The Federal Trade Commission studied nine brokers a decade ago and found one holding information on more than 1.4 billion consumer transactions and 700 billion data elements, and another adding more than 3 billion new data points every month, all of it assembled without consumers' knowledge (Federal Trade Commission, 2014). The industry has only grown since. What follows are three sources most people never think of.
1. Your car is watching you drive
Modern vehicles are sensor platforms with seats. Mozilla reviewed 25 major car brands in 2023 and concluded that cars are the worst product category it has ever examined for privacy: every brand failed, 21 of the 25 said they may share personal information with service providers and data brokers, 19 said they may sell it, and 14 said they share it with government or law enforcement on request (Mozilla Foundation, 2023; Claburn, 2023). Several brands reserved the right to collect categories that have nothing to do with driving, including health and genetic information (Mozilla Foundation, 2023).
This is not hypothetical. The FTC alleged in January 2025 that General Motors and OnStar collected drivers' precise geolocation, in some cases as often as every three seconds, along with every instance of hard braking, speeding, and late-night driving, and sold it to consumer reporting agencies that folded it into reports insurers used to deny coverage and set rates (Federal Trade Commission, 2025a). The Commission finalized its order on January 14, 2026, barring GM from sharing that data with consumer reporting agencies for five years (Federal Trade Commission, 2026).
2. The always-on home
A smart speaker is a microphone you paid for and placed in your kitchen. The FTC and Justice Department charged Amazon in 2023 with keeping children's Alexa voice recordings, transcripts, and geolocation data indefinitely, retaining them even after parents asked for deletion, and using the recordings to train its speech recognition systems (Federal Trade Commission, 2023).
The trajectory since has been toward less local control, not more. On March 28, 2025, Amazon removed the "Do Not Send Voice Recordings" setting that had allowed a handful of Echo models to process requests on the device, routing all voice requests to its cloud instead, a change the company attributed to the processing demands of generative AI features (Claburn, 2025). Whatever the justification, the practical effect is that the option to keep your voice inside your own house is gone.
The exposure is broader than the audio itself. A home assistant knows when you wake, when the house is empty, what you play, what you buy, and which rooms you occupy at which hours.
3. Your card statement, resold
The third source is the one people find hardest to believe. Payment networks monetize transaction data as a product line. U.S. PIRG's review of Mastercard's practices found the company packaging the amount, frequency, location, date, and time of purchases, sorting cardholders into inferred categories such as high spenders in a given retail segment, applying predictive scoring, and distributing the results through commercial data marketplaces including Amazon Web Services Data Exchange, LiveRamp, Snowflake, and The Trade Desk, where advertisers, hedge funds, and data brokers buy them (Cross, 2023). Mastercard's own division built these products atop a transaction history the company has publicly described as a gold mine (Cross, 2023).
Purchase data is uniquely revealing because it is behavioral rather than declared. It does not record what you told a survey, it records what you actually did, where, and how often. Combined with the location feeds described earlier, it resolves the difference between driving past a building and going inside and spending money there.
How the Pieces Fit Together
7:42 a.m. est. The plate reader at the end of your street logs your car leaving. Your own car reports the speeding on the connector and the hard braking that followed, and scores you for both. The cell-site simulator parked downtown takes your IMSI as you drive past, and every other phone on the block with it. Facial recognition puts your face at the door of your doctor's office. Purchased app data holds the ninety minutes you were inside, the ninety minutes you have not told anyone about. A geofence warrant served months from now will name everyone else who was in that building with you. The drone keeps the lot in frame the whole time. Your card settles the co-pay and files the visit into a purchase profile anyone can buy. That night your home assistant is listening while you and your partner fight about the result. Nine systems. Nine fragments. One ordinary Tuesday in your life, reassembled in full by people you will never meet, never face, and never be told about.
None of these tools operates alone. Each was built for a narrow purpose, and each is useful to the others. The IMSI binds the whole record to one specific device, and through it to you. Pieces captured by separate systems become a single dossier, without your knowledge or consent.
Surveillance Pricing: The Same Data That Tracks You Charges You More
The apparatus described above is not only an instrument of government. It is a business model. The same personal data that flows through Stingrays, plate readers, and brokers is increasingly used to set individualized prices for everyday goods.
Imagine this scenario. A close relative has just died. You spend an evening researching end-of-life plans, funeral homes, and grief counseling. The next morning you book a flight home. The price you see is not necessarily the price the person in the next seat paid. It may reflect what a pricing engine inferred about you from that browsing history: that you are traveling on short notice, that you are not comparison shopping, and that you will pay whatever it takes. The FTC's own study found companies using browsing history, precise location, and demographic data to set individualized prices (Federal Trade Commission, 2025b), and senators have flagged AI pricing tools in the airline industry as a leading example of the practice (Warner et al., 2025).
Grief, in other words, has a price, and someone is calculating it.
What it is
Surveillance pricing is the practice of using personal data to charge different people different prices for the same product, with the goal of inferring each shopper's maximum willingness to pay (Federal Trade Commission, 2025b). A December 2025 investigation by Consumer Reports and Groundwork Collaborative found Instacart prices for identical items at the same store varying by more than 20 percent from shopper to shopper, and advocates estimate the practice could cost some households as much as $1,200 a year in groceries (Klobuchar et al., 2025; Electronic Privacy Information Center, 2026). The FTC opened a study of the practice in July 2024, published staff findings in January 2025, and has said companies' failure to disclose data-based pricing can violate Section 5 of the FTC Act (Federal Trade Commission, 2025b; House Committee on Oversight and Government Reform, 2026).
The pattern is not new. A 2012 investigation found Staples quoting higher prices to shoppers whose ZIP codes were farther from a competitor (Valentino-DeVries et al., 2012). ProPublica found the Princeton Review charging more in ZIP codes with larger Asian American populations (Angwin & Larson, 2015). Tinder charged users over 30 more for its premium tier, a practice California courts found to be unlawful age discrimination (Candelore v. Tinder, Inc., 2018). And an Uber researcher acknowledged that riders with low phone batteries were willing to pay more, a data point the company said it did not exploit but which captures the logic exactly: find the moment of need and price to it (Chen, 2016).
Why it corrodes the market
In a working market, sellers compete by lowering prices to win customers, and shoppers compare. Surveillance pricing breaks both mechanisms. Prices become opaque and individual, so you cannot know whether the person beside you paid less, and you cannot comparison shop when every seller holds the same intimate data on you. As a group of senators wrote to the FTC in December 2025, pricing built on personal data lets firms set prices on willingness to pay rather than market factors, and raises barriers to competition and comparison shopping (Klobuchar et al., 2025). Firms are rewarded not for efficiency but for extraction, and the largest, which can afford the most third-party data, gain an edge over local competitors (American Economic Liberties Project, 2026).
For families already stretched, this functions as a hidden tax. A markup of even five percent on groceries and household goods costs hundreds of dollars a year (American Economic Liberties Project, 2026). It is a transfer from consumers to corporations, enabled by the same infrastructure that tracks our movements.
Where the Law Stands
The federal response has moved backward. The Consumer Financial Protection Bureau proposed a rule in December 2024 that would have treated data brokers selling certain personal information as consumer reporting agencies, subject to the Fair Credit Reporting Act's accuracy, notice, and permissible-purpose requirements. The Bureau withdrew it on May 15, 2025, citing a revised reading of the statute and questions about its own authority (Consumer Financial Protection Bureau, 2025). Nothing has replaced it. The brokers described above remain outside the one federal statute built to govern exactly this conduct.
The states have moved in the opposite direction, and fast. Lawmakers in at least eleven states considered surveillance pricing bills in 2026, and three enacted them: Connecticut in June, Maryland in April, and New Jersey in July (Sequeira, 2026). Maryland's Protection From Predatory Pricing Act, signed April 28, 2026 and effective October 1, bars food retailers above 15,000 square feet and third-party delivery platforms from using personal data to set higher prices, enforced by the Attorney General at up to $10,000 per violation (Skadden, Arps, Slate, Meagher & Flom LLP, 2026a). New Jersey went further. Its Fair Price Protection Act, signed July 23, 2026 and effective August 1, 2027, is the first in the nation to give consumers a private right of action, including class actions, with treble damages for willful violations and up to $50,000 per violation in Attorney General enforcement (Skadden, Arps, Slate, Meagher & Flom LLP, 2026b). Congress has noticed without acting: the SLASH Prices Act, introduced in June 2026, would require companies to disclose surveillance pricing prominently and let consumers opt out of the data collection behind it, but it has not been enacted (SLASH Prices Act, 2026).
For businesses, that patchwork is the compliance problem. Counsel advising on pricing should assume exposure well beyond the three states with statutes on the books: Section 5 of the FTC Act reaches undisclosed data-based pricing, state unfair and deceptive practices statutes reach it in every state, the Robinson-Patman Act reaches price discrimination that harms competitors, and an algorithm that prices by proxy for a protected class raises disparate impact risk regardless of intent (Holland & Knight, 2026). The practical steps are the familiar ones: audit the pricing algorithms across every channel, review what vendors are permitted to do with the data and who indemnifies whom, run disparate impact testing, document the business justification for each pricing differential at the time it is set, and put human oversight and audit trails around the model (Holland & Knight, 2026). Companies that treat this as a marketing question rather than a legal one are the ones that will find out the difference in litigation.
What Privacy Is Now, and What You Can Do
Orwell's telescreen is pretty much useless today. Today's version is distributed across your carrier, your car, your apps, and a hundred vendors you have never heard of, which is exactly why resignation is the wrong response. Privacy in America today is not something you have. It is something you have to keep taking back.
Start with the phone. On most Android devices you can disable 2G under Settings, Network & Internet, SIMs, which closes the door to the downgrade attack; on iPhone, Lockdown Mode does the same at the cost of other features (Electronic Frontier Foundation, 2023). Understand what that setting does and does not do. It stops a simulator from reading your calls and texts. It does not stop one from collecting your IMSI, because a phone can still be nudged from standalone 5G onto 4G or non-standalone 5G, where the identifier is exposed, and no phone maker gives you a switch to refuse those networks (Newman, 2021). Carriers will keep 4G running for years for backward compatibility, so this gap is not closing on its own (Newman, 2021). Use end-to-end encrypted messaging. Deny location permission to apps that do not need it, and assume any app with location access may be selling it. Send deletion requests to data brokers, and if you are a California resident, use the state's DROP platform to do it in bulk. Ask your city council what surveillance contracts it has signed and whether the data is shared with federal agencies. And when a company's price seems to know too much about you, ask, in writing, whether it does.
Then look at the carrier itself. This entire article turns on one fact: your IMSI is a durable identifier your phone hands to any tower that asks for it. A small number of carriers have started treating that as a defect rather than a feature. Cape, which launched nationwide in January 2026, operates its own mobile core and rotates each subscriber's IMSI every twenty-four hours, so a catcher that logged you yesterday is logging a stranger today, and it collects minimal personal information at signup (Cape, 2026). That approach matters more than it first appears. Every other mitigation in this article depends on which network your phone happens to be on. Rotating the IMSI works on 2G, 4G, and either flavor of 5G, because it attacks the durability of the identifier rather than the channel that leaks it. Efani attacks the adjacent problem, hardening your account against SIM swap with layered verification and a port delay. Both run roughly $99 a month. That is real money, and whether it is worth it depends on your exposure. For a journalist, an attorney carrying sensitive matters, a domestic violence survivor, or anyone for whom location is itself the sensitive fact, it is a rational purchase rather than a luxury.
Removing yourself from the broker ecosystem is worth doing, and worth automating. You can file deletion and opt-out requests yourself, and a growing number of state privacy statutes give you the right to, but there are hundreds of brokers and the requests have to be repeated, because records get rebuilt from new sources as fast as they are deleted. DeleteMe and Incogni do this on a subscription, in the range of $130 to $180 a year, with DeleteMe locating your records before requesting removal and Incogni sending requests across its broker list. Neither service is complete and neither is permanent. What they do is convert an impossible manual chore into a maintained one, which is the honest case for paying for either.
If you are technically inclined, the cleanest answer to the always-on microphone is to stop sending your voice off your own network. Amazon moved in the opposite direction in March 2025 when it removed local processing from Echo, but the open-source side went the other way. Home Assistant Voice Preview Edition, a $69 speaker, handles wake word and common commands on the device, and full local speech to text is available if you run Home Assistant on hardware with roughly an Intel N100 processor or better (Home Assistant, n.d.). Paired with Home Assistant Green or a server you already own, the audio, the automations, and the logs stay inside the house.
None of this is a complete defense, and I will not pretend otherwise. But every step raises the cost of watching you, and the systems described here were built on the assumption that you would not bother.
Works Cited
American Economic Liberties Project. (2026). Testimony on surveillance pricing before the Maryland General Assembly [Testimony].
Angwin, J., & Larson, J. (2015, September 1). The tiger mom tax: Asians are nearly twice as likely to get a higher price from Princeton Review. ProPublica. https://www.propublica.org/article/asians-nearly-twice-as-likely-to-get-higher-price-from-princeton-review
Bates, A. (2017, January 25). Stingray: A new frontier in police surveillance (Policy Analysis No. 809). Cato Institute. https://www.cato.org/policy-analysis/stingray-new-frontier-police-surveillance
Candelore v. Tinder, Inc., 19 Cal. App. 5th 1138 (2018).
Cape. (2026, January 27). Privacy-first mobile carrier Cape launches nationwide service to consumers [Press release]. Business Wire. https://www.businesswire.com/news/home/20260127583129/en/Privacy-first-Mobile-Carrier-Cape-Launches-Nationwide-Service-to-Consumers
Chatrie v. United States, No. 25-112 (U.S. June 29, 2026). https://www.supremecourt.gov/opinions/25pdf/25-112_0am4.pdf
Chen, K. (2016, May 17). Interview with S. Vedantam. Hidden Brain, NPR.
Claburn, T. (2023, September 6). Mozilla flunks 25 major car brands for data privacy fails. The Register. https://www.theregister.com/2023/09/06/mozilla_vehicle_data_privacy/
Claburn, T. (2025, March 17). Amazon to kill off local Alexa processing, all voice requests shipped to the cloud. The Register. https://www.theregister.com/2025/03/17/amazon_kills_on_device_alexa/
Consumer Financial Protection Bureau. (2025, May 15). Protecting Americans from harmful data broker practices (Regulation V); Withdrawal of proposed rule. Federal Register, 90 Fed. Reg. 20,569. https://www.federalregister.gov/documents/2025/05/15/2025-08644/protecting-americans-from-harmful-data-broker-practices-regulation-v-withdrawal-of-proposed-rule
Cross, R. J. (2023, September 20). How Mastercard sells its "gold mine" of transaction data. U.S. PIRG Education Fund. https://pirg.org/edfund/resources/how-mastercard-sells-data/
DeFlock. (n.d.). What are ALPRs? https://deflock.org/what-is-an-alpr
Electronic Frontier Foundation. (2023, September 13). Apple and Google are introducing new ways to defeat cell site simulators, but is it enough? https://www.eff.org/deeplinks/2023/09/apple-and-google-are-introducing-new-ways-defeat-cell-site-simulators-it-enough
Electronic Frontier Foundation. (2025, September 18). Rayhunter: What we have found so far. https://www.eff.org/deeplinks/2025/09/rayhunter-what-we-have-found-so-far
Electronic Privacy Information Center. (2026). Surveillance pricing [Issue brief].
Federal Trade Commission. (2014, May 27). Data brokers: A call for transparency and accountability. https://www.ftc.gov/reports/data-brokers-call-transparency-accountability-report-federal-trade-commission-may-2014
Federal Trade Commission. (2023, May 31). FTC and DOJ charge Amazon with violating children’s privacy law by keeping kids’ Alexa voice recordings forever and undermining parents’ deletion requests [Press release]. https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-doj-charge-amazon-violating-childrens-privacy-law-keeping-kids-alexa-voice-recordings-forever
Federal Trade Commission. (2024, December 3). FTC takes action against Gravy Analytics, Venntel for unlawfully selling location data tracking consumers to sensitive sites [Press release].
Federal Trade Commission. (2025a, January 16). FTC takes action against General Motors for sharing drivers’ precise location and driving behavior data without consent [Press release]. https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-takes-action-against-general-motors-sharing-drivers-precise-location-driving-behavior-data
Federal Trade Commission. (2025b). Surveillance pricing. https://www.ftc.gov/news-events/features/surveillance-pricing
Federal Trade Commission. (2026, January 14). FTC finalizes order settling allegations that GM and OnStar collected and sold geolocation data without consumers’ informed consent [Press release]. https://www.ftc.gov/news-events/news/press-releases/2026/01/ftc-finalizes-order-settling-allegations-gm-onstar-collected-sold-geolocation-data-without-consumers
Franceschi-Bicchierai, L. (2025, October 7). ICE bought vehicles equipped with fake cell towers to spy on phones. TechCrunch. https://techcrunch.com/2025/10/07/ice-bought-vehicles-equipped-with-fake-cell-towers-to-spy-on-phones/
Gillum, J., & Sullivan, E. (2015, June 2). FBI behind mysterious surveillance aircraft over US cities. Associated Press.
Holland & Knight. (2026, August 5). Surveillance pricing and dynamic pricing: What general counsels need to know. https://www.hklaw.com/en/insights/publications/2026/08/surveillance-pricing-and-dynamic-pricing-what-general-counsels
Home Assistant. (n.d.). Home Assistant Voice Preview Edition. https://www.home-assistant.io/voice-pe/
House Committee on Oversight and Government Reform. (2026, September 9). Comer continues investigation into surveillance pricing practices and their impact on American consumers [Press release]. https://oversight.house.gov/release/comer-continues-investigation-into-surveillance-pricing-practices-and-their-impact-on-american-consumers/
Institute for Justice. (2026). Surveillance state: How the government is tracking Americans [Report]. https://ij.org/report/surveillance-state/
Khan, H., & Niemi, V. (2018). Defeating the downgrade attack on identity privacy in 5G. arXiv. https://arxiv.org/pdf/1811.02293
Klobuchar, A., Booker, C., et al. (2025, December 17). Letter to FTC Chair Andrew Ferguson regarding Instacart's dynamic pricing. U.S. Senate. https://www.klobuchar.senate.gov/public/index.cfm/2025/12/klobuchar-booker-colleagues-press-the-ftc-to-investigate-instacart-s-dynamic-pricing
Kyllo v. United States, 533 U.S. 27 (2001).
Mozilla Foundation. (2023, September 6). Privacy nightmare on wheels: Every car brand reviewed by Mozilla, including Ford, Volkswagen and Toyota, flunks privacy test. https://www.mozillafoundation.org/en/blog/privacy-nightmare-on-wheels-every-car-brand-reviewed-by-mozilla-including-ford-volkswagen-and-toyota-flunks-privacy-test/
National Association of Criminal Defense Lawyers. (2026). Fourth Amendment Center. https://www.nacdl.org/Landing/FourthAmendmentCenter
National Public Radio. (2018, April 4). Feds say they've detected apparent rogue spy devices in D.C. https://www.npr.org/sections/thetwo-way/2018/04/04/599428495/feds-say-theyve-detected-apparent-rogue-spy-devices-in-d-c
Newman, L. H. (2021, August 10). A 5G shortcut leaves phones exposed to Stingray surveillance. WIRED. https://www.wired.com/story/5g-network-stingray-surveillance-non-standalone/
Pell, S. K., & Soghoian, C. (2014). Your secret Stingray's no secret anymore: The vanishing government monopoly over cell phone surveillance and its impact on national security and consumer privacy. Harvard Journal of Law & Technology, 28(1), 1–75.
Restore the Fourth. (n.d.). An issue brief on StingRays. https://restorethe4th.com/issues/stingrays/
Sequeira, R. (2026, August 4). States begin banning 'surveillance pricing' that uses personal data to charge more. Stateline. https://stateline.org/2026/08/04/states-begin-banning-surveillance-pricing-that-uses-personal-data-to-charge-more/
Skadden, Arps, Slate, Meagher & Flom LLP. (2026a, May 8). Maryland becomes the first state to restrict surveillance pricing in the food industry. https://www.skadden.com/insights/publications/2026/05/maryland-becomes-the-first-state-to-restrict-surveillance-pricing
Skadden, Arps, Slate, Meagher & Flom LLP. (2026b, July 31). New Jersey enacts first-in-the-nation private right of action for surveillance pricing. https://www.skadden.com/insights/publications/2026/07/new-jersey-enacts-first-in-the-nation
SLASH Prices Act, H.R. 9371, 119th Cong. (2026). https://www.congress.gov/bill/119th-congress/house-bill/9371/text
State v. Andrews, 227 Md. App. 350, 134 A.3d 324 (Md. Ct. Spec. App. 2016).
TechRadar. (2022). Android users can switch off 2G to enhance security and privacy. https://www.techradar.com/news/android-users-can-switch-off-2g-to-enhance-security-and-privacy
United States v. Jones, 565 U.S. 400 (2012) (Sotomayor, J., concurring).
United States v. Rigmaiden, 844 F. Supp. 2d 982 (D. Ariz. 2012).
U.S. Department of Homeland Security, Office of Inspector General. (2023, February 23). Secret Service and ICE did not always adhere to statute and policies governing use of cell-site simulators (Redacted). https://www.oig.dhs.gov/reports/2023/secret-service-and-ice-did-not-always-adhere-statute-and-policies-governing-use-cell-site-simulators-law-enforcement-sensitive-redacted
U.S. Department of Justice. (2008). Electronic surveillance manual. (As cited in Bates, 2017.)
U.S. Department of Justice. (2015, September 3). Department of Justice policy guidance: Use of cell-site simulator technology. https://www.justice.gov/opa/file/767321/download
Valentino-DeVries, J., Singer-Vine, J., & Soltani, A. (2012, December 24). Websites vary prices, deals based on users' information. The Wall Street Journal.
Warner, M. R., Gallego, R., & Blumenthal, R. (2025, July 22). Warner & colleagues demand answers from Delta on use of AI to set individualized ticket prices [Press release]. U.S. Senate. https://www.warner.senate.gov/newsroom/press-releases/warner-colleagues-demand-answers-from-delta-on-use-of-ai-to-set-individualized-ticket-prices/



