What Does Google Know About You
My Activity, Google’s own central dashboard at myactivity.google.com, is the honest starting point for this question, since it’s the closest thing to a direct answer Google provides itself. It shows your searches, sites visited, YouTube history, and app interactions in one place. That’s the visible layer. What’s changed recently is what happens after collection: Google’s newer AI features don’t just store these data points separately anymore. They connect them.
The Six Categories Google Actually Collects
Search and browsing activity covers what you’ve typed into Search and which sites you’ve clicked through to. Location data includes GPS coordinates, your IP-based approximate location, and any places you’ve explicitly labeled, like “home” or “work.” YouTube history tracks every video watched and every search performed on the platform. Content you create, emails in Gmail, photos in Photos, documents in Drive, is stored directly rather than just referenced. Device and app information includes your phone model, operating system, and installed apps. And activity on third-party sites using Google services, sites running Google Analytics or Google Ads, feeds back into your account as well, the same mechanism covered in what information do websites get when you visit them.
| Category | What’s Included | Where to Check |
|---|---|---|
| Search and browsing | Search terms, sites visited, ads clicked | My Activity, Web and App Activity |
| Location | GPS, IP address, labeled places | Timeline, if enabled |
| YouTube | Videos watched, searches, interactions | My Activity, YouTube History |
| Content | Emails, photos, files, documents | Gmail, Photos, and Drive separately |
| Device info | Phone model, OS, installed apps | Collected automatically by Google |
Where to Actually See What’s Stored
My Activity is the primary dashboard, showing search, browsing, and YouTube history in a single, searchable timeline. Timeline, a separate feature, holds your precise location history if you’ve enabled it. Privacy Checkup walks through your account’s privacy settings step by step, surfacing toggles that aren’t obvious from the main settings menu. Checking all three gives a genuinely complete picture, since each one covers a different slice of what’s collected.
Personal Intelligence: When Storage Becomes Reasoning
This is the shift almost no consumer explanation has caught up with yet. A newer Gemini feature called Personal Intelligence lets Google’s AI reason across Gmail, Photos, Search history, and YouTube simultaneously, rather than treating each as a separate, siloed dataset. In practice, this means the system can infer things nobody explicitly told it: that your parents already visited based on calendar and photo patterns, your car’s license plate from a photo you took of your vehicle, or your car insurance renewal date pulled directly from an email you never asked it to analyze. This is a genuinely different category of privacy concern than simple data storage. It’s the difference between Google holding separate facts about you and Google actively connecting them into conclusions you never stated directly.
The Device Usage Study Loophole
A separate, opt-in research program called the Device Usage Study collects an unusually deep tier of data from participants: typed passwords, on-screen content, and full URL data, including HTTPS pages, across all app interactions. This collection reportedly continues even inside Chrome Incognito, since Incognito’s protections are local-only, the same limitation covered in what does incognito mode do and what it doesn’t. Combined with an existing Google account, this data becomes personally identifiable rather than anonymous. Participation is opt-in, but the depth of what’s collected once someone opts in goes well beyond what most people assume “research participation” involves.
Turning Off a Setting Isn’t the Same as Deleting Data
Disabling Web and App Activity stops Google from saving new activity going forward. It does not retroactively delete what was already collected, since Google can retain historical data for business or legal purposes independent of your current setting. This distinction mattered enough to result in a $425 million class action verdict, where a jury found Google had continued collecting data from millions of users even after those users had specifically turned off the relevant tracking setting. Google has appealed the ruling. The practical lesson holds regardless of the appeal’s outcome: flipping a setting off controls what happens next, not what already happened.
Deleting Your Data: What Actually Works
Turning off Web and App Activity, YouTube History, and Timeline stops future collection in each category. Past activity needs to be deleted separately and manually, or you can set an auto-delete schedule, choosing 3, 18, or 36 months, so older data clears out automatically going forward. Worth knowing: deletion isn’t always total. If someone else shared content involving you, a tagged photo, a shared document, that content can persist in their account regardless of what you delete from yours. And data doesn’t stay deleted passively either: creating new content, sending an email, uploading a new photo, immediately generates new data points, meaning this is ongoing maintenance, not a one-time cleanup.
Downloading Everything Google Has: Google Takeout
Google Takeout lets you export data from more than 40 separate Google services at once, emails, photos, contacts, Calendar entries, Drive files, and more, either as a direct download or transferred to another provider like Dropbox, Box, or Microsoft 365 through the Data Transfer Project. This is the most complete way to actually see the full scope of what’s accumulated across every service, rather than checking each one individually.
The Three-Step Privacy Routine
A practical, repeatable approach: audit everything through My Activity and Privacy Checkup periodically, delete what you don’t need to keep, whether manually or through an auto-delete schedule, and download a full copy through Takeout if you want a complete record of what’s currently stored before clearing anything out. None of this is a single fix. Given how quickly new data accumulates and how AI features like Personal Intelligence now connect it, this works better as a recurring habit than a one-time cleanup.
How This Fits the Bigger Picture
Everything Google collects can, in aggregate, function similarly to the profiles covered in what is a shadow profile and feed into the broader data broker ecosystem indirectly, through advertising partnerships and shared signals. And regardless of what Google itself stores, your ISP has separate visibility into your traffic entirely, covered in what your ISP can see when you browse.
FAQ
What does Google actually know about me?
Your search history, browsing activity, location, YouTube activity, device information, and any content stored in Gmail, Photos, or Drive. Newer AI features can also infer additional details by connecting these categories together. See the sections above for exactly where to check each one.
Does turning off Web and App Activity delete my past data?
No. It stops Google from saving new activity going forward, but historical data can be retained separately for business or legal reasons unless you delete it manually or set up auto-delete.
Does Incognito mode stop Google from collecting my data?
Not entirely. Incognito only prevents local storage on your own device. Separately, participants in Google’s opt-in Device Usage Study have reportedly had activity collected even within Incognito sessions, a much deeper tier of collection tied to explicit research participation.
1. Real SERP Gap Analysis What the Top 10 Results Cover: Data brokers are companies that collect and sell your personal information, often without your knowledge, generating an estimated $200 billion annually You have legal rights to opt out under laws like CCPA, CPRA, and GDPR (in 21 states), bu
pasted
/seo
Orchestrated structured entity alignment framework
Orchestrated structured entity alignment framework
Meta Title: How to Delete Your Data from Data Broker Sites
Meta Description: You can request removal from data brokers, and an EPIC audit found the process is built to make you give up before you finish. Here’s what actually works.
Target Keyword: how to find and delete your data from data broker sites
Primary Keyword: data broker removal
Secondary Keywords:
- remove personal information from data brokers
- data broker opt-out guide
- how to delete yourself from people search sites
- CCPA data broker removal request
Tags: data broker removal, opt-out, CCPA, DROP, GDPR, people search sites, EPIC
Category: 16
Article:
How to Find and Delete Your Data from Data Broker Sites
An audit by EPIC, the Electronic Privacy Information Center, examined 38 major data broker companies and found eight distinct manipulative design patterns built specifically to frustrate, confuse, and discourage people from successfully opting out. That finding reframes the whole topic. Removal isn’t just tedious by accident. In a documented number of cases, it’s tedious by design, and knowing that changes how you approach the process.
Step 1: Find Where Your Data Actually Lives
Search your full name, city, and state directly on the major people-search sites: Whitepages, Spokeo, BeenVerified, Intelius, PeopleFinder, and Radaris. If it’s available in your account, Google’s “Results about you” dashboard surfaces some of this automatically. Keep a simple tracker as you go, listing the exact URL where your listing appears, what specific data is shown, the date you submitted a removal request, and a follow-up date to recheck. This tracker becomes essential later, since re-listing, covered below, means a one-time check isn’t enough.
Step 2: Submit the Right Kind of Opt-Out
Use each site’s direct opt-out page rather than a general contact form, since a generic inquiry often gets routed nowhere useful. And here’s a distinction almost no consumer guide gets right: when a site offers both “Delete” and “Do Not Sell” or “Opt-Out,” choose the opt-out option, not delete, wherever it’s available.
This runs against intuition, but it matters. Choosing full deletion often removes the broker’s entire record of you, including their record that you requested removal in the first place. Choosing “do not sell” instead flags your listing as opted out while keeping a marker that prevents easy re-listing. Pick delete, and you can end up more exposed to reappearing later, since there’s no longer any record blocking your re-addition.
Step 3: Verify and Document
Many opt-out requests require email or SMS verification before they actually process. Using a dedicated email alias for this entire process, rather than your primary address, keeps the paper trail contained and easier to manage. After submitting, wait 30 to 90 days, then recheck the listing directly. Re-listing is common enough that this recheck step isn’t optional caution, it’s a near-certainty you should plan around from the start.
Why the Process Is Built to Wear You Down
EPIC’s audit identified eight specific manipulative design patterns across the companies it reviewed:
- Opt-out forms that accept a submission but don’t actually change anything on the backend
- Opt-out pages deliberately hidden from search engines, found on 35 of 499 sites analyzed in a separate review
- Requiring account creation before you’re allowed to opt out at all
- Requiring payment to complete a removal request
- Forcing users through multiple separate forms for what should be a single request
- Preselected toggles that visually appear active but don’t actually opt you out
- Offering only URL-by-URL listing removal with no broader “do not sell” option covering the underlying data sale
- Requiring sensitive verification, sometimes a government ID or Social Security number, as the literal price of exercising your opt-out right
That last one deserves its own mention. Being asked to hand over more sensitive personal data specifically to limit a company’s collection of your personal data is a genuine paradox, and it’s one several brokers build directly into their process rather than avoiding.
Removing a Listing Doesn’t Stop the Underlying Sale
This is the single most misunderstood part of the entire process. Removing your specific listing from Spokeo or Whitepages addresses that one URL. It does not necessarily stop the broker from continuing to sell your underlying data through other channels. Spokeo, Whitepages, and National Public Data have specifically been flagged for offering only URL-by-URL removal with no global “do not sell” setting, meaning your information can resurface from an entirely different listing next month, because the actual sale of your data behind the scenes never stopped in the first place.
California’s DROP Platform: A Real Shortcut
California residents have access to something most states don’t: the Delete Request and Opt-Out Platform, or DROP, which lets you submit a single deletion request that reaches every data broker registered in the state simultaneously, rather than filing individually with each one. This meaningfully changes the math for California residents specifically. Most other states offer narrower protections, and the EU’s equivalent, GDPR’s right to erasure under Article 17, still requires individual requests to each company rather than a single bulk mechanism.
DIY vs Paid Removal Services
Doing this manually across roughly 190 known data broker sites has been estimated to take a focused half-day of work, and that’s before accounting for the recurring rechecks. Services like Mozilla Monitor, McAfee Personal Data Cleanup, and PrivacyHawk automate this scanning and submission process for a recurring fee, with Mozilla Monitor’s paid tier specifically including monthly rechecks built in. The tradeoff is trust: using one of these services means handing your personal information to yet another company, which is worth weighing against the actual time savings for your specific situation.
Removal Is Temporary Without Ongoing Monitoring
Data brokers continuously scrape new sources across the web, which means even a fully successful removal isn’t permanent. You’ll commonly get re-listed from a source entirely separate from wherever you originally found your data, since the broker’s scraping never stops just because one listing was removed. This is exactly why Mozilla Monitor frames its paid service around monthly rechecks rather than a single one-time scan: the underlying problem here is ongoing, not a task you complete once and close out.
Legal Rights Exist, Enforcement Doesn’t Always Follow
CCPA and CPRA give California residents a legal right to opt out of data sale, and similar protections now exist in a growing number of states, alongside GDPR’s right to erasure in the EU. None of this guarantees a smooth practical process, as EPIC’s audit findings above make clear. Having a legal right to request deletion and having that request actually processed correctly are two different things, and the gap between them is where most of the frustration in this entire process actually lives. For the fuller picture of how this data gets aggregated in the first place, see what is a data broker, and for how removed or retained data still contributes to a larger inferred picture of you, see what is a shadow profile.
FAQ
How do I find and delete my data from data broker sites?
Search major people-search sites for your name and location, submit opt-out requests using each site’s direct removal page, and recheck every 30 to 90 days since re-listing is common. See the step-by-step process above for the full protocol, including which option to choose when both delete and opt-out are offered.
Should I choose “delete” or “opt-out” when a data broker offers both?
Choose opt-out or “do not sell” when it’s available. Choosing full deletion often erases the broker’s record that you requested removal at all, which can make you more likely to be silently re-listed later.
Why does my information keep reappearing after I remove it?
Data brokers continuously scrape new sources across the web and frequently re-add people from a source unrelated to wherever the original listing came from. Removal without ongoing monitoring is rarely permanent.