Four places your personal information leaks, and the control for each
Ask most people where their personal information goes and they will say "cookies". That was a reasonable summary around 2010. The FTC’s current privacy hub is organised around a much wider set of surfaces — online tracking and people-search sites, health apps and DNA test kits, internet-connected devices including televisions, vehicles, voice assistants and smartwatches, and online abuse including stalkerware. This article takes four of those surfaces and gives the specific control for each, because they are genuinely different problems with genuinely different fixes.
One surface at a time
- Browser: FTC — privacy settings "give you some control over the information websites collect about you", including whether to block personalised ads.
- Phone: FTC — a setting "that lets you opt out of personalized ads from the company that makes the operating system"; CISA — "Disable your Ad ID."
- Apps: FTC — "Go to the privacy settings on your smartphone to see what information they can access from your device."
- Living room: FTC directs you to review privacy settings on internet-connected TVs and streaming devices too.
- Brokers: FTC — people-search sites compile property, driving, voter registration, criminal, civil, birth, marriage, divorce and death records.
The browser: what settings actually reach
Start here because it is where people expect to start, and be clear about the boundary. The FTC’s wording is careful — browser privacy settings give you some control over what websites collect. Two things are worth setting: cookie restrictions, which CISA describes as changing your settings "to limit and clear cookies to minimize the amount of data third parties might be able to access", and the personalised-advertising preference, which the FTC lists separately.
Then the two industry opt-out tools the FTC names: the Digital Advertising Alliance’s AdChoices and the Network Advertising Initiative tool. Both are stored per browser, which is why the FTC adds "If you opt out, be sure to opt out on each device and browser."
What this surface does not include: anything you are signed in for. A service you log into knows what you do inside it regardless of these settings.
The phone: two controls, in different menus
The mobile operating system maintains an advertising identifier that apps can read. It is not a browser setting and clearing your browser does nothing to it. The FTC describes the opt-out as a phone setting covering personalised ads from the company that makes the operating system; CISA’s instruction to people at elevated risk is simply to disable the Ad ID and to consider asking data brokers and other platforms to delete data held about you.
The second control on the phone is app permissions, and it is set on the device rather than inside each app. The FTC’s direction is to go to the phone’s privacy settings and see what information apps can access. This is where you find the torch app with your contacts and the game with your location.
The living room: televisions, speakers and cars
This is the surface most privacy articles omit entirely, and the FTC’s hub gives it a whole category — internet-connected devices, including smart home and vehicle data, voice assistants and smartwatches. The FTC’s practical instruction is direct: review the privacy settings on internet-connected TVs and streaming devices.
The settings to look for are usually labelled around viewing data, interest-based advertising, or content recognition. They are typically buried several menus deep and enabled by default. A vehicle with a connected app has an equivalent set, and a voice assistant will have controls over whether recordings are retained.
None of these devices care what your browser is set to.
The brokers: public records, repackaged
The fourth surface is not something you leaked at all. The FTC describes people-search sites compiling property records, driving records, voter registration information, criminal records, civil actions and judgments, and birth, marriage, divorce and death records — then buying from other data brokers and collecting from social media profiles that are public or viewable by everyone.
You can opt out, free, one site at a time; the FTC says so explicitly, and adds that if you pay a service instead you should establish "how many websites it covers", whether it provides "a report about the sites it’s opted you out of", and "how often it’ll scan those sites".
Be realistic about the result. The FTC’s caveats are that information "could re-appear for sale" when public records change, "may still appear in the reports of your relatives, neighbors, or associates", and that opting out "doesn’t delete your information from public records." Its instruction is to check the sites periodically.
What all four leave standing
Every control above governs collection. None of them governs disclosure — what you type into a form, tell a support agent, or post publicly. That remains the largest single channel and it has no setting.
Nor do they help once information has been misused. If privacy loss has turned into fraud, the FTC’s fraud reporting site is the place for it, and IdentityTheft.gov if it has become identity theft. There is also a specific, often-forgotten control the FTC provides: opting out of prescreened credit and insurance offers, which reduces the mailed pre-approvals that identity thieves make use of.
Sources: FTC — Protecting your privacy online (hub) · FTC — How to protect your privacy online · CISA — Best practices against tracking technologies and spyware · FTC — What to know about people search sites · FTC — What to know about prescreened offers
Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC and CISA. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.