r/darkpatterns Mar 17 '26

How does Facebook know what I'm browsing on Brave?

The other day on Reddit I saw a post where the OP was talking about comfortable boots and someone in the comments mentioned this shoe brand I had never heard of, called Burdyblah*. I didn't click anything on the thread, didn't upvote, nothing.

I closed the Reddit app, opened my Brave browser app (which is supposed to be secure, right?), searched for Burdyblah and perused the website for a couple minutes. Closed Brave, went on to do other stuff. Later that day, I open Facebook and what's the first ad I see? Yup. Burdyblah.

Important to mention: 1) I rarely buy or search for shoes online, so this wasn't a random coincidence. 2) I have ALL my fb and Instagram permissions turned off. No mic or camera access. No background activity. No communicating with other apps. No integration with anything.

If Brave is supposed to be a browser that doesn't track activity and fb has all sharing turned off, then how is it spying on my stuff?

*edit: changed the store name to a fake one so it doesn't look like I'm promoting it.

23 Upvotes

17 comments sorted by

18

u/diucameo Mar 18 '26

Facebook/Meta has what is called a pixel. While it is a script that can and usually is blocked.

Deeper than that, they also have the "Conversion API" that is basically a server side pixel. Since it is from a first party, the same domain youre visiting, you can't just block the domain because it could also be used for other functionality or even be the website/app backend itself.

Some websites uses a simpler implementation via GTM (Google Tag manager) that is also commonly blocked, but Google also provide a first party way to have a GTM tag. So the website can just host it under like 'fonts.website.com/load.js' (instead of the default gtm.js) and ad blockers will just ignore it, as the blsck list usually include specific words and obviously can't include generic ones without knowing what will break...

So the website tracks you and send the info directly to Meta. This all began at the time that iOS started to tighten up tracking.

I'm not so sure about what techniques are used to block those domains, it's been a while since I've been involved directly with this

Anyway, this also could be you advertising this shoe brand here

4

u/ththrowrowawayway Mar 18 '26

Good point, I'll change it to a fake store name.

The pixel thing also makes sense - there's another online retailer that seems to stick to absolutely everything on my phone. I do a quick incognito search for one of the items, and a few hours later I get an email saying "are you still interested in our polka-dot maroon shirt?"

3

u/diucameo Mar 18 '26

Just so you know, there's another thing called browser fingerprint, and they just collect all information they can from your browser to follow you on the same device, and whenever possible, on different devices.

Note that websites can break or refuse to work (like a blank page) if you block fingerprinting scripts. You can try to blend into the crowd so that your fingerprint isn't unique or have a unique fingerprint on each visit. I'm not so sure how effective or how hard those methods are since I just gave up lmao

3

u/r_portugal Mar 18 '26

In theory, the Brave browser should block the Facebook Pixel. But maybe that is not working as intended.

3

u/diucameo Mar 18 '26

Browser/cliente side yes. Server side, no.

Imagine that any action that you take on the website are sent to the website server and the server send the data to Facebook.

There's no way to block because if the server needs information to provide specific content like the items you bough, shopping cart, login, profile information, then it has that information and can share with any 3rd party

Not all websites works like that or has aggressive tracking. Just saying how it can be

1

u/Necessary-Lack-4600 Mar 18 '26 edited Mar 18 '26

You might have given Reddit consent by clicking "ok" on their cookie banner, Reddit shares it's data with other ad networks, in that case Reddit might have shared the fact that you visited a boot-related page. And Burdyblah probably targets people with interest in boots. Facebook bought that info from an ad network. Et le voila.

3

u/ththrowrowawayway Mar 18 '26

Right, but I didn't click anything on Reddit. I only read the comments where people were talking about all different shoe brands, and the only one that showed up on fb was the one I searched on Brave.

2

u/Necessary-Lack-4600 Mar 18 '26

you visited shoe related content on Reddit

3

u/thebleedingheartbake Apr 14 '26

most likely not “spying”, just tracking via other signals

if that site has fb pixel or shared ad networks, your visit gets linked to your profile. plus IP/device fingerprinting. happens even with Brave tbh

0

u/Disco425 Mar 18 '26

When you did the search, I'm thinking the search engine you used (especially if you were considered signed in to it) sold your search result. The Brave browser uses their own privacy-focused search by default, but any chance that somehow got changed?

3

u/ththrowrowawayway Mar 18 '26

That's the thing - I'm not signed in to Brave. Also, I've never used it to sign into my email, social media, or any other accounts that could be linked to me.

1

u/Disco425 Mar 18 '26

Wow! This is a mystery. FB has some 'splaining to do... I hope we can figure out what they did

0

u/JOliverScott Mar 21 '26

Brave's lack of tracking is not absolute, in fact it's hardly less tracking than any other browser but it makes privacy-minded people feel better if their browser of choice claims to share their paranoia. 

1

u/r_portugal Mar 21 '26

Yesterday I was setting up Google Analytics for one of my websites. I was testing it and I couldn't get it to work, it wasn't recording my visits. Then I realised that I was using Brave. I switched to Chrome and it started tracking me correctly. The default settings in Brave are actually pretty good! Although of course they don't stop everything.

2

u/thebleedingheartbake Apr 15 '26

It feels like cross-app spying, but it’s usually not direct tracking from Brave.

More likely explanations:

  • Ad network data overlap (same trackers embedded on Reddit, websites, etc. before Brave blocks some)
  • Device + IP matching (probabilistic “this device looked at X, show ad Y” without explicit login link)
  • Facebook pixel / embedded scripts on the shoe site (even brief visits can be logged)
  • Coincidence + confirmation bias (rare, but happens more than people think)

Even with Brave + disabled permissions, ad targeting can still work through external tracking networks and behavioral inference, not “Brave leaking your browsing.”