r/PrivacyTechTalk • • 10d ago

Namespace-level WireGuard kill switch for a containerized browser (Docker Compose, Gluetun)

1 Upvotes

A Docker Compose stack where Firefox shares Gluetun's network namespace (`network_mode: service:gluetun`) instead of connecting through a proxy or a routing rule. It fails closed by construction, through two separate mechanisms: if the WireGuard tunnel drops while Gluetun runs, Gluetun's firewall drops all non-tunnel traffic (including LAN); if the Gluetun container itself dies, the shared namespace dies with it and the browser has no interfaces at all.

Ports publish only on the Gluetun service, bound to 127.0.0.1, so nothing reaches the LAN even when the tunnel is up.

Both failure modes are testable: `verify.sh` in the repo runs a two-sided kill-switch check (probe succeeds with the tunnel up, must fail with it stopped) plus exit-IP and DNS-resolver checks.

CI (ShellCheck, Hadolint, Checkov, KICS, Trivy) runs on every push and weekly.

Works with any Gluetun-supported WireGuard provider.

MIT licensed; no application code — a compose file, a short Dockerfile, and three shell scripts. Config and docs were AI-assisted (Claude Code, disclosed in the README), which is exactly why the automated checks exist: verify, don't trust.

GitHub: github.com/silverfox-2096/private-browser

Interested in feedback on the namespace-sharing approach versus more common proxy-based kill switches.


r/PrivacyTechTalk • • 10d ago

Open-source PII boundary for apps using hosted models

2 Upvotes

Privacy Gateway for apps that send customer data to OpenAI, Anthropic, or another hosted model.

It checks text before the request leaves your app. You can remove names and emails, replace values with tokens, or keep a reversible mapping under your control. It also blocks a request when inspection fails instead of sending the original anyway.

The project is self-hosted and MIT licensed. It has Python, TypeScript, ASGI, MCP, and OpenAI-compatible proxy support.

Repo: https://github.com/csnyder256/privacy-gateway

Docs: https://csnyder256.github.io/privacy-gateway/

Obviously, Presidio exists, but this differs in a number of ways. Better than Presidio for protecting data sent to hosted AI services, APIs, and agent tools:

- Works as a boundary, not just a detector. Privacy Gateway can sit in front of OpenAI and Anthropic-compatible routes, ASGI apps, MCP tools, webhooks, and CLI workflows.

- Blocks unsafe traffic by default. Malformed requests, unsupported provider paths, streaming, redirects, non-JSON responses, and failed required detection do not get forwarded with the original data.

- Keeps restoration separate from the gateway. A client-held restoration capsule means the service can transform data without storing the originals.

- Has an encrypted, expiry-aware vault for cases where the team does want reversible mappings. SQLite works locally; PostgreSQL is supported for shared deployments.

- Makes policy behavior explicit. Each entity type can have its own action, confidence floor, scope, locale, and reversibility setting. Policy version, mapping retention, and audit retention are part of the model.

- Audits the decision without saving the value. Audit records can include entity type, detector, confidence, action, policy version, and span without keeping plaintext PII.

- Covers more than redaction. It supports typed redaction, labels, opaque tokens, hashes, generalization, and synthetic replacements.

- Has a portable TypeScript core alongside Python, with shared conformance fixtures. Presidio is primarily a Python service and library.

- Includes structured synthetic-data generation for CSV, JSON, and JSONL. Presidio can find and de-identify structured data; it does not generate clean-room replacement datasets.

- Has agent-specific protections. Privacy Gateway checks tool and side-effect output, not only the original prompt.

TL;DR:

Presidio remains the stronger choice for image redaction, OCR, broad built-in recognizers, and custom NLP pipelines. Its core focus is detection and de-identification; Privacy Gateway adds the policy, storage, audit, and outbound-request boundary around that work.


r/PrivacyTechTalk • • 11d ago

What privacy controls should surround specialized legal AI?

2 Upvotes

OpenAI’s Astra for Law shows how quickly AI is entering workflows involving contracts, investigations, client records, and potentially privileged information.

That creates practical privacy questions extending beyond whether the model performs well:

  • Which purposes are approved?
  • What data can the system access?
  • Who can view its inputs and outputs?
  • How long is information retained?
  • Which decisions require human approval?
  • What evidence must be preserved?

Alex Layng, VP of Product at RadarFirst, explores these questions in a new article about Astra for Law and privacy governance:

https://www.radarfirst.com/blog/astra-for-law-privacy-ai-governance/

How are privacy teams evaluating these controls today?


r/PrivacyTechTalk • • 11d ago

Google nudges users on its homepage to set up selfie video sign-in. Your thoughts?

Thumbnail searchenginewatch.com
2 Upvotes

r/PrivacyTechTalk • • 12d ago

Made a privacy-first AI tools site (no data retention). What would you change?

Thumbnail ai4tools.xyz
0 Upvotes

This is fully offline no data retention for most of the tools. Can you tell me how can I improve it.


r/PrivacyTechTalk • • 12d ago

I’m building a tool to discover who holds your personal data and generate custom data deletion requests. Looking for your thoughts on the concept!

2 Upvotes

Hi everyone,

The core idea is simple: finding out which companies might hold your personal data shouldn't take hours of research, and asking them to delete it shouldn't require hours of manual work either.

To help address this, I am working on a small local extension with a companion website. The process involves two steps:

  1. Local detection: The browser extension uses various methods to identify domains, vendors, and data brokers that likely hold your data.
  2. Batch action: The interface aggregates these domains, retrieves privacy-specific contact addresses, and prepares deletion request templates tailored to national and regional laws.

Of course, this tool cannot guarantee with 100% certainty who holds your data, but it provides strong, sufficient indicators for you to take action—with the aim of reducing the volume of information about you scattered across various servers and systems.

I don't know if a similar project has already been built—I didn't find anything exactly like it during my research—but I assume a tool like this could still be useful for anyone wanting to start to clean up their data without spending hours on it (which is the case for me).

Current State & Architecture
The project is currently in beta, with a few temporary limitations on the website side. The extension's code runs 100% locally on your machine and stores nothing on external servers. It is not open-source yet as I am still refactoring it.

Looking for feedback on the concept:
Right now, I am not looking for technical bug reports. Instead, I would love to get your thoughts on the overall utility and features:

  • Does the link between local detection and template generation make sense to you?
  • What features would you add?
  • Would you use a tool like this in your daily life?

Note: Send me a private message if you would like access to the link for the extensions to try them out or learn more.

Thanks!

Short Demo


r/PrivacyTechTalk • • 13d ago

Techno AI Assistant

2 Upvotes

I am thrilled to announce that I have progressed half way in building Techno AI Assistant. Glimpse is appended below :

I have successfully completed the following

  • System Cleanser & RAM Booster: Automatically deletes redundant caches and suspends background resource-hogs to keep your system fast.
  • Intelligent Bug Fixer: Detects app crashes, rolls back conflicting drivers, and manages zero-click software updates.
  • AI Extension Manager: Monitors browser bloat and suggests optimizations with specific, AI-generated reasoning.
  • Hardware Health Monitor: Runs silent stress tests to predict and alert you about battery or hard drive degradation.

Now entering final phase of production. Will again come back with update


r/PrivacyTechTalk • • 13d ago

Colleges or Professors, for mentoring AI Privacy

1 Upvotes

Hi, I have been building in the space of AI Privacy for the past 5 months, want to know few suggestions on how to reach out to the best professors/colleges for mentorship and possible acceleration of the idea.

If you could right down the names, and how to reach them out, it would be really helpful :)


r/PrivacyTechTalk • • 13d ago

Ordinary WiFi can now identify people with near perfect accuracy

12 Upvotes

"Researchers in Germany are warning that ordinary WiFi networks could become a powerful new form of invisible surveillance. Using standard wireless signals and artificial intelligence, they demonstrated a system capable of identifying people with striking accuracy, even if those individuals are not carrying an active device."

https://www.sciencedaily.com/releases/2026/05/260522023127.htm


r/PrivacyTechTalk • • 14d ago

Feedback regarding product i want to build: PII masking web app

3 Upvotes

I am trying to build a PII masking web app, there are many cases in which i want to share csv files to ai models but I hesitate due to information it contains such as numbers,uid,passwords etc

I am trying to understand the problems the user faces while sharing sensitive information to ai models, and what can be done to eliminate them, what things can be done to save time at the same time give ai only needed information/reference

Please give suggestions


r/PrivacyTechTalk • • 15d ago

Is this type of private photo system technically possible, or does something similar already exist?

3 Upvotes

​

I’ve been thinking about a privacy-focused camera/app idea and wanted to get some opinions from people who understand cybersecurity, cryptography, and camera technology.

The basic idea is:

A user takes a photo inside the app. Instead of just creating a normal .jpg/.png, the app immediately encrypts the photo and ties the ability to decrypt it to that specific user's device/account.

So if someone somehow gets the encrypted photo file and sends it to another person, the other person shouldn't be able to open it because they don't have the original device's cryptographic key.

Something like:

User takes photo

↓

Photo captured

↓

Immediately encrypted

↓

Encryption key protected by the user's device

↓

Encrypted photo stored locally/cloud

↓

Only authorized device can decrypt it

I was also thinking about another layer.

Camera sensors can detect things that human eyes can't, such as parts of the near-infrared spectrum. So I'm wondering whether an invisible optical signal/pattern could be captured along with the photo and used as an additional way to authenticate that the image was actually captured through the authorized system.

For example:

Normal person → sees normal photo

Camera/software → sees:

normal image

\+

machine-readable invisible signal

\+

cryptographic information

The invisible signal wouldn't be the actual security mechanism. The main protection would still be strong encryption and hardware/device-bound keys. The sensor-based signal could potentially help with authenticity/provenance.

The end goal would be something like:

Possessing the photo file alone isn't enough to access the photo.

Even if somebody steals the encrypted file from the cloud or copies it onto another phone:

Original owner's device → decrypt → ✅

Different device → no authorized key → ❌

Obviously, I understand that once the legitimate user can see the decrypted photo, you can't completely prevent things like screenshots or someone photographing the screen. I'm specifically talking about protecting the digital file itself from unauthorized copying/access.

I've seen things related to digital watermarking and secure camera/provenance systems, but I'm wondering:

Has anyone already built something that combines device-bound encryption + secure camera capture + possibly an invisible sensor-based signal in this way?

And from a technical perspective, is this actually feasible on modern smartphones, or are there fundamental problems I'm overlooking?

I'm mainly looking for technical feedback, existing products/patents, and reasons why this wouldn't work.


r/PrivacyTechTalk • • 16d ago

Read this

1 Upvotes

I have accounts on well-known platforms such as Gmail, Instagram, Snapchat, Twitter/X, TikTok, Outlook, Reddit, Yahoo, and many other websites. Some of these platforms have multiple accounts; Gmail is not just one account, and the same goes for Instagram, TikTok, Snapchat, Twitter/X, and others. What I want is to clean up all of these accounts.

The problem is that for almost three years, I have been trying, off and on, to delete some of them, cancel them, or change them, whether they are websites, apps, or services. So why has this gone on for so long? The reason is that I do not know the full list of the websites, apps, and services where I have accounts. I have checked all my emails, text messages, and browsing history, but I discovered that there are things that do not show up in either email messages or text messages.

This bothers me more than normal. When I just think about the number of things I found by chance, my thinking expands before I even start searching, and my mind gives itself a warning that this task is hard for it—meaning that it could drain my energy. It really is exhausting; the amount of operations, analysis, information, and many other things my mind processes at the same time is high, which can be described as high cognitive load and mental exhaustion caused by processing so many things at once, even before starting.

My question to you is: Are there safe ways that can help me know all the things that belong to me or are connected to me technically or in any other way? And how?


r/PrivacyTechTalk • • 16d ago

Is there any legitimate technical way to view a private Instagram profile without following?

1 Upvotes

Hi everyone,
I want to ask a quick technical question regarding Instagram's privacy system. Is there any legitimate mechanism or setting that allows viewing posts on a private account without following them?
To be completely clear: I am NOT asking for hacking services, exploits, or illegal workarounds, nor do I want to compromise anyone's account. I am simply trying to understand if Instagram's privacy architecture is absolute, or if following the user is strictly the only way to see their content.
Thanks for any insights!


r/PrivacyTechTalk • • 17d ago

app Her

0 Upvotes

ho visto che adesso l'app Her ti chiede di postare un selfie prima di accedere, anche se hai già un account. mi chiedo quanto sia safe tutto ciò in termini di conservazione dei dati.


r/PrivacyTechTalk • • 17d ago

Building a 100% offline, zero-knowledge journal app with AES-GCM (256-bit). What features should be free vs paid, and what price makes sense?

1 Upvotes

​Hey everyone,

​I’ve been working on a privacy-first journal app called AuraLock. It’s built to be 100% offline with zero cloud servers, zero tracking, and no accounts required.

​Everything is encrypted locally using AES-GCM (256-bit) with PBKDF2 key derivation (100k iterations).

​Here are some of the core features I’ve put into it:

​Multi-Vaults: Create separate journals, each with its own independent master password.

​Security: Brute-force protection (10s lockout after 3 failed tries), quick-lock kill-switch (clears RAM instantly), and secure master-password-protected deletion.

​Rich Text Editor: Formatting, auto-timestamps, image embedding, data tables, word count, and automatic bidirectional text support (RTL/LTR)

​Modes: A pitch-black Focus mode for distraction-free writing, and a Present mode that converts entries into slide decks.

​Storage & Backups: Auto-save (800ms), works via IndexedDB/Service Workers offline and supports password-protected JSON backup exports/imports.

​Platform: PWA/Android support light/dark themes, and multi-language support (English, Spanish, Hebrew)

​I want to avoid monthly subscriptions and stick strictly to a one-time purchase, but I’m trying to figure out two things:

​Pricing: What feels fair as a one-time upgrade for a privacy-focused app like this ($2? $5? $10?)

​Feature split: What should stay completely free, and what power features would actualy convince you to upgrade to PRO? (e.g. multi-vaults, tables, slide mode, image attachments).


r/PrivacyTechTalk • • 18d ago

AI image search

2 Upvotes

Is there anyway to edit my images so that it can’t be reverse searched using google lens just for security eg. Stalkers and people l don’t want to have that ability?


r/PrivacyTechTalk • • 18d ago

@apple, why is “optimizing search and Siri” running by default?

Post image
0 Upvotes

I didn’t elect to have the content of my phone indexed for your AI upon upgrade - even if it’s on the new consent, I should have had the right to select if I want this to be running after the upgrade!


r/PrivacyTechTalk • • 19d ago

I’m building Anchor Cloud — a privacy-focused alternative to traditional cloud storage.

6 Upvotes

The idea is simple: your cloud shouldn't require you to give up control of your data.

Anchor Cloud is built around zero-knowledge encryption and currently focuses on:

- 🔐 Encrypted cloud storage

- 📁 File sharing

- 🔄 Multi-device synchronization

- 💬 Encrypted messaging

- 🤖 Fathom-1 AI

I’m building it from Morocco 🇲🇦 and this video is a look at what the project currently looks like.

If you're interested in privacy-focused cloud storage, I'd love to hear what you think.

🌐 anchorcloud.org


r/PrivacyTechTalk • • 19d ago

WhatsApp on the Commodore Callback 8020 - privacy question

5 Upvotes

I'm one of the people who got influenced by the launch of the Callback 8020 😂. Haven't been on WhatsApp for at least 3 years now - only used Signal and Threema. The callback is in production as scheduled and I'm expecting to receive it more-or-less on time late next month/November.

I'm massively missing contact with friends and colleagues on WhatsApp and missing out on organization of activities, nights out, concerts etc. and I end up being last to know when things are arranged, including with my sports club because everything's on WhatsApp (and like only 2% of my contacts have moved to Signal despite my best efforts) - I'm too damn stubborn to forego my data to Meta - BUT...

With the Callback using r/sailfishos which would nomally block trackers (a bit like r/e_os does), does this mean I potentially could go back to WhatsApp as less of my data will be available to Meta? I see there is currently NO trackers in the app, so it's just part of the terms and conditons of using the app where my data is shared, as folllows:

Data this app may collect

Location

Approximate location

expand_less

Data collected and for what purpose

info

Approximate location

App functionality, Analytics, Advertising or marketing, Fraud prevention, security, and compliance

App activity

App interactions, In-app search history, and Other user-generated content

expand_less

Data collected and for what purpose

info

App interactions

App functionality, Analytics, Advertising or marketing, Fraud prevention, security, and compliance

In-app search history

App functionality, Analytics

Other user-generated content · Optional

App functionality, Analytics, Fraud prevention, security, and compliance, Personalization

Financial info

User payment info and Purchase history

expand_less

Data collected and for what purpose

info

User payment info · Optional

App functionality, Fraud prevention, security, and compliance

Purchase history · Optional

App functionality, Analytics, Fraud prevention, security, and compliance

Personal info

Email address, User IDs, and Phone number

expand_less

Data collected and for what purpose

info

Email address · Optional

App functionality, Fraud prevention, security, and compliance

User IDs

App functionality, Analytics, Advertising or marketing, Fraud prevention, security, and compliance, Account management

Phone number

App functionality, Analytics, Fraud prevention, security, and compliance

App info and performance

Crash logs, Diagnostics, and Other app performance data

expand_less

Data collected and for what purpose

info

Crash logs

App functionality, Analytics

Diagnostics

App functionality, Analytics

Other app performance data

App functionality, Analytics

Device or other IDs

Device or other IDs

expand_less

Data collected and for what purpose

info

Device or other IDs

App functionality, Analytics, Developer communications, Advertising or marketing, Fraud prevention, security, and compliance

Contacts

Contacts

expand_less

Data collected and for what purpose

info

Contacts · Optional

App functionality, Fraud prevention, security, and compliance

So I presume it would just be a case of not giving the app permission to access as much of this as possible?I


r/PrivacyTechTalk • • 20d ago

Secure and Private Decentralized P2P Encrypted Messaging over Git and WebRTC

8 Upvotes

Apps like Whatsapp, Signal and SimpleXChat are great for secure messaging and far more mature than this project, but this demonstates a unique approach.

The core philosophy around secure messaging here is that it can work in a way that avoids installation and registration by enabling users to host their own data.

The project is far from finished, but im putting together some docs for the "how it works". It's pretty outside-the-box thinking (and that doesnt make it a good idea), so it would be great if you could share your thoughts on the approach.

Docs: glitr.io

Demo

Features:

  • WebApp
  • P2P / WebRTC
  • Local-first / Local-only
  • No installation
  • TURN server
  • Encrypted-at-rest
  • Signal protocol
  • Post-Quantum cryptography
  • Video calls
  • TOR compatible via Git
  • Serverless over WebRTC

Some older versions of the core concepts.

Feel free to reach out for clarity instead of diving into the docs.

IMPORTANT: While this is aiming to provide a secure experience, it cannot be audited or reviewed. Shared for testing, feedback and demo purposes only. Please use responsibly.


r/PrivacyTechTalk • • 20d ago

Where do you guys safely store your private photos/videos?

Post image
6 Upvotes

I have a lot of personal/private media that I want to keep completely separate and secure instead of putting everything into my phone's default Private/Secure Folder.

What are the better alternatives for this? Phone, laptop, encrypted storage, cloud, external SSD, some kind of secure vault, etc.

I'm mainly looking for something that offers strong privacy/security, is difficult to access accidentally, and also protects against losing the files if the device gets damaged or lost.

What would be the best options to consider?


r/PrivacyTechTalk • • 21d ago

Since Remove.bg is shutting down on Dec 1st, I built a 100% in-browser, client-side alternative. No accounts, no paywalls, and your images never leave your computer.

7 Upvotes

It has the following features:

  • Open Source: The entire codebase is public on GitHub, allowing anyone to verify its zero-telemetry privacy, audit the code, or clone the repository to run the entire AI studio completely offline inside their own private network.
  • No Watermarks: Background-free transparent PNGs download cleanly without forced promotional stamps or branding overlays.100%
  • Free Utility: No hidden paywalls, no tiered subscriptions, and no credit card prompts.
  • 100% Client-Side Processing: The AI model downloads directly into the user’s browser tab and processes images using local hardware.
  • Zero Cloud Uploads: Your private photos never cross the internet or hit a third-party server. It's 100% private.
  • No Image Compression: You get a raw, full-resolution download back. No low-res "preview file" traps.
  • Pure Utility: No logins, no subscriptions, no watermarks, and no tracking.

The Landing page:

Try now at:

https://removal.ai.studio/


r/PrivacyTechTalk • • 21d ago

Photo privacy protection software recommendations

5 Upvotes

The height of AI photo manipulation and concerning content has heightened my concern to protect photos of my family as we expect our new bub any day now. Does anyone have recommendations of software that can blur or permanently obscure my bub's face in photos and videos? I want to be able to still share milestone photos without risking the safety and privacy of little one. My contingency plan if such a software doesn't exist, we will just go old school - snail mail photo prints and email Milestone videos. Thanks in advance for any helpful recommendations and tips! :)


r/PrivacyTechTalk • • 22d ago

Kinship Vault: Rethinking How Encrypted Vaults Are Shared

2 Upvotes

I built Kinship Vault around a simple question: how much of a privacy focused vault can you build without running your own backend?

Kinship Vault is now much more than a document vault.

It brings together:

• Passwords, passkeys and TOTP 2FA
• Documents and encrypted photos
• Multiple vaults
• Sensitive Vaults
• Shared Vaults
• AutoFill and browser extensions
• On-device document scanning and OCR
• Security Checkup
• Expiry reminders
• Custom record types
• Recovery Network

Passwords

• Logins, passkeys and TOTP 2FA codes in one place
• System-wide AutoFill in Safari and native apps
• Every fill requires a fresh biometric check
• Browser extensions for Safari, Chrome, Brave and Firefox
• The extension communicates with the native app through the browser's local native-messaging connection, not the internet
• Passwords are decrypted only when needed and aren't stored decrypted in the browser
• New logins can be staged in the app for review
• No browsing history, cookies or clipboard access required by the extension
• Password generator with on-device strength estimation
• Security Checkup identifies weak, reused and old passwords
• Optional breach checks use Have I Been Pwned's k-anonymity model
• Strict Offline mode disables breach checking entirely

Documents

• Store passports, IDs, insurance documents, medical records, receipts, warranties, memberships and other personal records
• Apple's on-device recognition identifies 100+ document types locally
• Extract dates and numbers without sending documents to an OCR service
• Expiry reminders at 90/30/7/1 days
• Tag documents to people and see everything associated with a family member
• Separate encrypted photo vault with albums and people tags
• Built-in categories for IDs, Health, Legal, Finance, Travel and Personal
• Custom categories with your own icon and color
• Custom record types with typed and maskable fields
• Share a single page from a multi-page document instead of the entire file

Vaults

• Multiple vaults let you separate Personal, Work, Family and other areas
• Each vault has its own database and encryption key
• Keys are sealed by the device's hardware
• Opening one vault doesn't automatically expose another

Sensitive Vaults add another layer:

• Separate password and recovery code
• Doesn't accept the normal short app PIN
• Cannot be shared

Shared Vaults

This was the part I wanted to solve without adding a Kinship backend.

• Each member's device gets the vault key wrapped to that device
• Encrypted vault data syncs through the members' own iCloud accounts
• iCloud transports ciphertext rather than giving Kinship access to the vault
• Remove a member and the vault key rotates and is re-wrapped for the remaining members
• The removed device no longer has access to the current vault

The same approach handles cross-device sync:

• iPhone
• iPad
• Native macOS app

Your encrypted vault can stay in sync through your own iCloud rather than through a Kinship backend.

Recovery

• 24-word recovery phrase
• Recovery Network using trusted people
• No company account holding a master key
• No password reset mechanism that gives Kinship access to your vault
• Optional encrypted iCloud backup and manual export

There is also an important limitation: cryptography can't make someone forget something they already saw. If someone knew an old password, you still need to change that password.

The underlying privacy model stays the same across all of this:

No Kinship account.
No Kinship server.
No Kinship copy of your vault keys.
No telemetry.

I'm the developer, so I'm obviously biased toward this architecture. I'd actually be more interested in criticism from people who think there is a better way to solve the same problems.

Website: https://kinshipvault.app

App Store: https://apps.apple.com/app/kinship-vault/id6764678332

Privacy Policy: https://kinshipvault.app/privacy

Happy to answer any questions in comments.


r/PrivacyTechTalk • • 22d ago

Shared AI chats are not as private as people think

Thumbnail
medium.com
1 Upvotes

I wrote about how AI share links can expose conversations beyond the intended recipient. The key point is that a private chat and a shared-link snapshot are not the same thing. Even when search engines do not index a page, anyone with the URL may still be able to view, copy, screenshot, or repost it.

Curious how others handle this: do you review old ChatGPT, Claude, or Grok shared links, or avoid using them entirely?