Just Worth Sharing

Anyone Can Track You Now

Your weather app knows where you slept last night.

Not in a spooky way. In a boring, buried-in-paragraph-14 way. It knows because you tapped “Allow” once, years ago, and it has been quietly writing it down ever since.

So does the game you play on the train. So does the dating app you deleted but never actually revoked.

And all of it is for sale.

Where your Tuesday ends up

One data broker’s file. One day. 380 million location points across 137 countries, pulled out of roughly 40,000 different apps (including WetterOnline, Candy Crush, Tinder, Flightradar24, Kleinanzeigen, Focus Online). On that one day, tens of thousands of WetterOnline users were pinpointed across Germany, some of them apparently down to the metre.

You installed it to find out whether to take a jacket. Germany’s data protection authority in North Rhine-Westphalia has since opened a fine procedure against the app.

None of this is hidden, by the way. It’s the business model: brokers collect, brokers sell, buyers pay. When a group of Swiss researchers started poking at this, a broker mailed them location data on 800,000 phones, free of charge. A sample, basically, in the hope they’d come back for the paid version.

Eight hundred thousand people. As a taster.

So no, not literally anyone can follow you around this afternoon. But the thing standing between you and someone who wants to isn’t a firewall and it isn’t a law. It’s whether they can be bothered to spend the money.

Spoiler: it’s getting a lot cheaper.

“But it’s anonymised”

This is the reassurance everyone reaches for. It stopped being true in 2013.

That year a study in Nature went through fifteen months of movement data from 1.5 million people and found that four location points are enough to pick out 95% of individuals. Two points still single out more than half.

Four. Not four hundred.

Work out what four points look like for you. Where your phone is at 3am. Where it is at 11am on a Tuesday. That’s two already, and they’re the two that count — one is your home, one is your work, and both are written down somewhere public.

Taking the name off a location trail was never anonymisation. It was a head start.

What actually changed

That maths is thirteen years old. So why are we writing about it now instead of in 2013?

Because back then, actually doing it was expensive. In 2007 someone tried exactly this (pull home addresses out of GPS traces, look them up in a directory) and managed to name about 5% of his subjects. It took weeks.

This June, Swiss researchers pointed AI agents at the same problem, using volunteers who’d agreed to take part, and walked away. The agents read the trail, worked out the home and the workplace, then went hunting through public registers and the open web for a matching name.

They got 72% of the people who were identifiable at all, with nobody watching it work.

And the thing doing the work was Claude. Not a bespoke surveillance system, not a custom-trained model — the same off-the-shelf AI assistant a lot of people have open in another tab right now. They pointed it at a file of coordinates and let it get on with it. (About two dollars’ worth of tokens a person, if you’re wondering.)

Weeks of expert work and 5% became an unattended afternoon and 72%. The data didn’t change. The hard part just got automated.

And it isn’t only about location. ETH Zurich fed ordinary forum posts to a language model and had it guess people’s city, income and age. 85% accuracy, roughly 100× cheaper and 240× faster than paying a human to do the same job.

The excuse that stopped working

Right. So let’s talk about “I have nothing to hide.”

We get it. Most of us aren’t doing anything interesting. But that sentence quietly assumes the question is about hiding. It isn’t. It’s about who gets to decide what’s known about you.

A location trail doesn’t record your secrets. It records the addresses that give them away — and addresses have signs on the door.

The oncology practice you’ve visited every third Thursday since spring, months before you’re ready to tell your family. The mosque, or the church, or the synagogue, same time every week. The flat you leave at seven in the morning that isn’t the one you live in. The addiction clinic. The fertility clinic. The divorce lawyer. The demonstration you went to on Saturday.

Nobody had to read your messages. They only had to know where your phone was.

You might not think of any of that as a secret. It’s still yours, and you didn’t hand it over. An app you use to check the weather did.

And there’s a version of “nothing to hide” that isn’t confidence at all. Ask people straight out and 73% say they have little or no control over what companies do with their data. 67% say they don’t really understand what companies do with it. 61% say they doubt anything they do will make a difference.

That last one isn’t apathy. That’s people who gave up. 😐

“Fine, I’ll just reject the cookies”

Sorry. Mostly theatre.

When someone actually measured it, more than 75% of the tracking happened before anyone got to click anything, or after they’d rejected everything. And across the 10,000 most popular UK sites, only 11.8% of cookie banners cleared the legal minimum.

Which is roughly what your gut told you every time you hunted for the “reject” button and couldn’t find it.

Two-panel illustration: in 2007 a researcher buried in paper files, in 2026 the same person relaxing while a laptop does the work
The data didn’t get better. The tooling did.

So we read the privacy policies. All of them.

Here’s where this got personal for us.

If location data is the problem, then every tool that quietly collects a little of it is part of the problem, including tools in our own corner of the internet. So we sat down and read the privacy policies of the ten biggest polling and scheduling tools out there. Properly. Including the cookie tables and the subprocessor lists.

We’re not naming names on the quotes below. These are real products built by real people, several of them small teams doing their best, and we’re not interested in a takedown. The good ones we’ll name gladly. But the quotes are worth your time, because they’re all public, and they’re all from tools that thousands of people use to pick a date for dinner.

One tool’s privacy policy tells you, unprompted, that what it collects is the legally sensitive kind:

“The geolocation data we collect may be ‘precise geolocation’ data, which is ‘sensitive personal information,’ as those terms are defined under the CCPA.”

And then reserves the right to join it to everything else it knows about you:

“We may link location data to other information we have collected about you.”

Its own marketing page, meanwhile: “No. We never store or share any location data.” Both pages are live right now.

Another keeps location forever:

“We maintain a permanent record of anonymized location, demographic and survey data.”

You’ll have spotted the word doing all the heavy lifting in that sentence.

A third asks visitors to accept, in the words of its own consent banner, “your precise location (within a radius of less than 500 metres).” Its consent screen lists 108 third-party advertising hosts. Its published list of data processors names nine. And this is the one that genuinely annoyed us. Its consent system is configured as opt-in for visitors in the EU and opt-out for visitors in Switzerland. Same site. Same company. Swiss users get the weaker default.

A fourth asks every participant to “Select your location:”. A labelled dropdown, right there on the voting page, so the tool can line up time zones across a group. Perfectly sensible. Its privacy policy then never mentions location once, in any form.

And one of the most-used scheduling tools on the internet has no privacy policy at all. Not a thin one. Not an outdated one. None, and there never has been one. We checked twenty years of web archives.

Two of the ten were genuinely excellent, and we’re happy to name those. Nuudel, run by the German non-profit Digitalcourage, switches off its own server logs so that no IP address is ever written down anywhere — “only the content you enter into the forms.” Framadate, from the French non-profit Framasoft, loads not a single third-party script and puts it about as plainly as anyone could:

“Our goal is to host a tool that serves you and does not use you. Contrary to the adage, here, you are not the product.”

So it can be done. It just doesn’t pay.

What we do instead

It doesn’t pay for us either. We do it anyway.

Letsfind started in 2020 because the tool we were using to find a date for dinner had more ads than actual poll. Every decision since has come back to the same question: what’s the least we can get away with knowing about you?

Six years of answering that question, and Letsfind is a free, ad-free online poll maker built in Switzerland. Dates, text polls, live polls, availability. One link, no account needed to create or vote.

So: the same questions we just asked everyone else, answered about us.

We don’t set cookies. Not “essential only”, none. That’s why Letsfind has never shown you a consent banner. There’s no third-party analytics: Matomo runs on our own servers with anonymised IPs and shares nothing with anyone. We don’t write down your IP address. No ads, no ad partners. You can create a poll and vote without ever telling us who you are. And we don’t sell your data, which isn’t so much a promise as a description. There’s no version of Letsfind where that changes. It’s all in our privacy policy, in plain language.

We’re not doing this because it’s a clever differentiator. We’re doing it because it’s the whole reason Letsfind exists, and because the features we don’t build are as much a product decision as the ones we do. Ads would have been the easy way to pay for this. We picked a small monthly subscription instead, and the free tier stays free.

Turns out that’s not a niche opinion. In the 2026 DigitalBarometer, 76% of people in Switzerland said they care more about protecting their personal data than about convenience. Only 18% said it the other way round.

One small thing

You’re not going to fix the data broker industry this week. But you can do the ten-minute version:

Open your phone’s settings and look at which apps have location permission. Set the ones that don’t obviously need it to “Never” or “While Using”. Your weather app does not need to know where you are at 3am. Then reset your advertising ID while you’re in there. It’s a one-tap thing in both iOS and Android settings.

That’s it. It won’t make you invisible. It’ll make you a lot less cheap to find.

If there’s a privacy feature you wish we had, tell us — contact@letsfind.app. A fair number of the ones we do have started out as somebody’s email.

Otherwise: go make a poll. Nobody’s watching.

Look after yourselves out there. 🇨🇭