What Does Google Know About You? Full Breakdown

Google's Gemini can now infer your car's license plate from a photo and your insurance renewal date from an email. Here's what's actually stored, and how to check it.

Table of Contents

What Does Google Know About You

My Activity, Google’s own central dashboard at myactivity.google.com, is the honest starting point for this question, since it’s the closest thing to a direct answer Google provides itself. It shows your searches, sites visited, YouTube history, and app interactions in one place. That’s the visible layer. What’s changed recently is what happens after collection: Google’s newer AI features don’t just store these data points separately anymore. They connect them.

The Six Categories Google Actually Collects

Search and browsing activity covers what you’ve typed into Search and which sites you’ve clicked through to. Location data includes GPS coordinates, your IP-based approximate location, and any places you’ve explicitly labeled, like “home” or “work.” YouTube history tracks every video watched and every search performed on the platform. Content you create, emails in Gmail, photos in Photos, documents in Drive, is stored directly rather than just referenced. Device and app information includes your phone model, operating system, and installed apps. And activity on third-party sites using Google services, sites running Google Analytics or Google Ads, feeds back into your account as well, the same mechanism covered in what information do websites get when you visit them.

CategoryWhat’s IncludedWhere to Check
Search and browsingSearch terms, sites visited, ads clickedMy Activity, Web and App Activity
LocationGPS, IP address, labeled placesTimeline, if enabled
YouTubeVideos watched, searches, interactionsMy Activity, YouTube History
ContentEmails, photos, files, documentsGmail, Photos, and Drive separately
Device infoPhone model, OS, installed appsCollected automatically by Google

Where to Actually See What’s Stored

My Activity is the primary dashboard, showing search, browsing, and YouTube history in a single, searchable timeline. Timeline, a separate feature, holds your precise location history if you’ve enabled it. Privacy Checkup walks through your account’s privacy settings step by step, surfacing toggles that aren’t obvious from the main settings menu. Checking all three gives a genuinely complete picture, since each one covers a different slice of what’s collected.

Personal Intelligence: When Storage Becomes Reasoning

This is the shift almost no consumer explanation has caught up with yet. A newer Gemini feature called Personal Intelligence lets Google’s AI reason across Gmail, Photos, Search history, and YouTube simultaneously, rather than treating each as a separate, siloed dataset. In practice, this means the system can infer things nobody explicitly told it: that your parents already visited based on calendar and photo patterns, your car’s license plate from a photo you took of your vehicle, or your car insurance renewal date pulled directly from an email you never asked it to analyze. This is a genuinely different category of privacy concern than simple data storage. It’s the difference between Google holding separate facts about you and Google actively connecting them into conclusions you never stated directly.

The Device Usage Study Loophole

A separate, opt-in research program called the Device Usage Study collects an unusually deep tier of data from participants: typed passwords, on-screen content, and full URL data, including HTTPS pages, across all app interactions. This collection reportedly continues even inside Chrome Incognito, since Incognito’s protections are local-only, the same limitation covered in what does incognito mode do and what it doesn’t. Combined with an existing Google account, this data becomes personally identifiable rather than anonymous. Participation is opt-in, but the depth of what’s collected once someone opts in goes well beyond what most people assume “research participation” involves.

Turning Off a Setting Isn’t the Same as Deleting Data

Disabling Web and App Activity stops Google from saving new activity going forward. It does not retroactively delete what was already collected, since Google can retain historical data for business or legal purposes independent of your current setting. This distinction mattered enough to result in a $425 million class action verdict, where a jury found Google had continued collecting data from millions of users even after those users had specifically turned off the relevant tracking setting. Google has appealed the ruling. The practical lesson holds regardless of the appeal’s outcome: flipping a setting off controls what happens next, not what already happened.

Deleting Your Data: What Actually Works

Turning off Web and App Activity, YouTube History, and Timeline stops future collection in each category. Past activity needs to be deleted separately and manually, or you can set an auto-delete schedule, choosing 3, 18, or 36 months, so older data clears out automatically going forward. Worth knowing: deletion isn’t always total. If someone else shared content involving you, a tagged photo, a shared document, that content can persist in their account regardless of what you delete from yours. And data doesn’t stay deleted passively either: creating new content, sending an email, uploading a new photo, immediately generates new data points, meaning this is ongoing maintenance, not a one-time cleanup.

Downloading Everything Google Has: Google Takeout

Google Takeout lets you export data from more than 40 separate Google services at once, emails, photos, contacts, Calendar entries, Drive files, and more, either as a direct download or transferred to another provider like Dropbox, Box, or Microsoft 365 through the Data Transfer Project. This is the most complete way to actually see the full scope of what’s accumulated across every service, rather than checking each one individually.

The Three-Step Privacy Routine

A practical, repeatable approach: audit everything through My Activity and Privacy Checkup periodically, delete what you don’t need to keep, whether manually or through an auto-delete schedule, and download a full copy through Takeout if you want a complete record of what’s currently stored before clearing anything out. None of this is a single fix. Given how quickly new data accumulates and how AI features like Personal Intelligence now connect it, this works better as a recurring habit than a one-time cleanup.

How This Fits the Bigger Picture

Everything Google collects can, in aggregate, function similarly to the profiles covered in what is a shadow profile and feed into the broader data broker ecosystem indirectly, through advertising partnerships and shared signals. And regardless of what Google itself stores, your ISP has separate visibility into your traffic entirely, covered in what your ISP can see when you browse.

FAQ

What does Google actually know about me?
Your search history, browsing activity, location, YouTube activity, device information, and any content stored in Gmail, Photos, or Drive. Newer AI features can also infer additional details by connecting these categories together. See the sections above for exactly where to check each one.

Does turning off Web and App Activity delete my past data?
No. It stops Google from saving new activity going forward, but historical data can be retained separately for business or legal reasons unless you delete it manually or set up auto-delete.

Does Incognito mode stop Google from collecting my data?
Not entirely. Incognito only prevents local storage on your own device. Separately, participants in Google’s opt-in Device Usage Study have reportedly had activity collected even within Incognito sessions, a much deeper tier of collection tied to explicit research participation.

1. Real SERP Gap Analysis What the Top 10 Results Cover: Data brokers are companies that collect and sell your personal information, often without your knowledge, generating an estimated $200 billion annually You have legal rights to opt out under laws like CCPA, CPRA, and GDPR (in 21 states), bu

pasted

/seo

Orchestrated structured entity alignment framework

Orchestrated structured entity alignment framework

Meta Title: How to Delete Your Data from Data Broker Sites

Meta Description: You can request removal from data brokers, and an EPIC audit found the process is built to make you give up before you finish. Here’s what actually works.

Target Keyword: how to find and delete your data from data broker sites

Primary Keyword: data broker removal

Secondary Keywords:

  • remove personal information from data brokers
  • data broker opt-out guide
  • how to delete yourself from people search sites
  • CCPA data broker removal request

Tags: data broker removal, opt-out, CCPA, DROP, GDPR, people search sites, EPIC

Category: 16

Article:

How to Find and Delete Your Data from Data Broker Sites

An audit by EPIC, the Electronic Privacy Information Center, examined 38 major data broker companies and found eight distinct manipulative design patterns built specifically to frustrate, confuse, and discourage people from successfully opting out. That finding reframes the whole topic. Removal isn’t just tedious by accident. In a documented number of cases, it’s tedious by design, and knowing that changes how you approach the process.

Step 1: Find Where Your Data Actually Lives

Search your full name, city, and state directly on the major people-search sites: Whitepages, Spokeo, BeenVerified, Intelius, PeopleFinder, and Radaris. If it’s available in your account, Google’s “Results about you” dashboard surfaces some of this automatically. Keep a simple tracker as you go, listing the exact URL where your listing appears, what specific data is shown, the date you submitted a removal request, and a follow-up date to recheck. This tracker becomes essential later, since re-listing, covered below, means a one-time check isn’t enough.

Step 2: Submit the Right Kind of Opt-Out

Use each site’s direct opt-out page rather than a general contact form, since a generic inquiry often gets routed nowhere useful. And here’s a distinction almost no consumer guide gets right: when a site offers both “Delete” and “Do Not Sell” or “Opt-Out,” choose the opt-out option, not delete, wherever it’s available.

This runs against intuition, but it matters. Choosing full deletion often removes the broker’s entire record of you, including their record that you requested removal in the first place. Choosing “do not sell” instead flags your listing as opted out while keeping a marker that prevents easy re-listing. Pick delete, and you can end up more exposed to reappearing later, since there’s no longer any record blocking your re-addition.

Step 3: Verify and Document

Many opt-out requests require email or SMS verification before they actually process. Using a dedicated email alias for this entire process, rather than your primary address, keeps the paper trail contained and easier to manage. After submitting, wait 30 to 90 days, then recheck the listing directly. Re-listing is common enough that this recheck step isn’t optional caution, it’s a near-certainty you should plan around from the start.

Why the Process Is Built to Wear You Down

EPIC’s audit identified eight specific manipulative design patterns across the companies it reviewed:

  1. Opt-out forms that accept a submission but don’t actually change anything on the backend
  2. Opt-out pages deliberately hidden from search engines, found on 35 of 499 sites analyzed in a separate review
  3. Requiring account creation before you’re allowed to opt out at all
  4. Requiring payment to complete a removal request
  5. Forcing users through multiple separate forms for what should be a single request
  6. Preselected toggles that visually appear active but don’t actually opt you out
  7. Offering only URL-by-URL listing removal with no broader “do not sell” option covering the underlying data sale
  8. Requiring sensitive verification, sometimes a government ID or Social Security number, as the literal price of exercising your opt-out right

That last one deserves its own mention. Being asked to hand over more sensitive personal data specifically to limit a company’s collection of your personal data is a genuine paradox, and it’s one several brokers build directly into their process rather than avoiding.

Removing a Listing Doesn’t Stop the Underlying Sale

This is the single most misunderstood part of the entire process. Removing your specific listing from Spokeo or Whitepages addresses that one URL. It does not necessarily stop the broker from continuing to sell your underlying data through other channels. Spokeo, Whitepages, and National Public Data have specifically been flagged for offering only URL-by-URL removal with no global “do not sell” setting, meaning your information can resurface from an entirely different listing next month, because the actual sale of your data behind the scenes never stopped in the first place.

California’s DROP Platform: A Real Shortcut

California residents have access to something most states don’t: the Delete Request and Opt-Out Platform, or DROP, which lets you submit a single deletion request that reaches every data broker registered in the state simultaneously, rather than filing individually with each one. This meaningfully changes the math for California residents specifically. Most other states offer narrower protections, and the EU’s equivalent, GDPR’s right to erasure under Article 17, still requires individual requests to each company rather than a single bulk mechanism.

DIY vs Paid Removal Services

Doing this manually across roughly 190 known data broker sites has been estimated to take a focused half-day of work, and that’s before accounting for the recurring rechecks. Services like Mozilla Monitor, McAfee Personal Data Cleanup, and PrivacyHawk automate this scanning and submission process for a recurring fee, with Mozilla Monitor’s paid tier specifically including monthly rechecks built in. The tradeoff is trust: using one of these services means handing your personal information to yet another company, which is worth weighing against the actual time savings for your specific situation.

Removal Is Temporary Without Ongoing Monitoring

Data brokers continuously scrape new sources across the web, which means even a fully successful removal isn’t permanent. You’ll commonly get re-listed from a source entirely separate from wherever you originally found your data, since the broker’s scraping never stops just because one listing was removed. This is exactly why Mozilla Monitor frames its paid service around monthly rechecks rather than a single one-time scan: the underlying problem here is ongoing, not a task you complete once and close out.

Legal Rights Exist, Enforcement Doesn’t Always Follow

CCPA and CPRA give California residents a legal right to opt out of data sale, and similar protections now exist in a growing number of states, alongside GDPR’s right to erasure in the EU. None of this guarantees a smooth practical process, as EPIC’s audit findings above make clear. Having a legal right to request deletion and having that request actually processed correctly are two different things, and the gap between them is where most of the frustration in this entire process actually lives. For the fuller picture of how this data gets aggregated in the first place, see what is a data broker, and for how removed or retained data still contributes to a larger inferred picture of you, see what is a shadow profile.

FAQ

How do I find and delete my data from data broker sites?
Search major people-search sites for your name and location, submit opt-out requests using each site’s direct removal page, and recheck every 30 to 90 days since re-listing is common. See the step-by-step process above for the full protocol, including which option to choose when both delete and opt-out are offered.

Should I choose “delete” or “opt-out” when a data broker offers both?
Choose opt-out or “do not sell” when it’s available. Choosing full deletion often erases the broker’s record that you requested removal at all, which can make you more likely to be silently re-listed later.

Why does my information keep reappearing after I remove it?
Data brokers continuously scrape new sources across the web and frequently re-add people from a source unrelated to wherever the original listing came from. Removal without ongoing monitoring is rarely permanent.

Picture of Tanzeel Ali

Tanzeel Ali

Ali is a WordPress developer and independent tech educator who built ExplainTheWeb to make the hidden side of the internet understandable for everyone. With years of hands‑on experience building and troubleshooting websites, he focuses on explaining DNS, web hosting, app tracking, and online privacy in plain, jargon‑free language. Every article on this site is written by him — no AI, no content farms, just real explanations from someone who remembers what it’s like to be confused by technical jargon.

Continue Reading

What Is Managed WordPress Hosting? 2026 Guide

Managed WordPress hosting isn't one thing. It's a spectrum from bare-minimum automation to full...

Does Web Hosting Affect SEO? The Real Answer

Yes, hosting affects SEO, but as a multiplier, not a fix. Bad hosting can undermine great content...

Why Do Hosting Companies Oversell? The Real Math

A single server can hold 400 hosting accounts when it should comfortably serve 100. Here's the...

What Does Google Know About You? Full Breakdown

Google's Gemini can now infer your car's license plate from a photo and your insurance renewal date...