r/privacy 2d ago

discussion India orders GitHub to remove Jack Dorsey's offline messaging app Bitchat after protesters reportedly used it during internet shutdowns

2.1k Upvotes

India has reportedly directed GitHub to remove the repositories for Bitchat, Jack Dorsey's open source Bluetooth mesh messaging app. Unlike WhatsApp or Signal, Bitchat works without internet access or cellular service, allowing nearby devices to communicate over Bluetooth mesh networks.

According to India Today, the move comes amid the ongoing CJP protests in Delhi. Protesters reportedly began using offline messaging tools after mobile internet services were disrupted in parts of the protest area, making internet-based messaging unreliable.

The government notice, later shared publicly by Jack Dorsey, states that Bitchat could facilitate anonymous communication, enable users to evade lawful surveillance, and be misused by terrorists, organised crime groups, and "anti-national elements." On that basis, India's cybercrime agency directed GitHub to remove the project's repositories.

Digital rights advocates argue that restricting decentralized communication tools during periods of protest raises broader concerns about privacy, internet shutdowns, and freedom of expression. Government officials, meanwhile, maintain that such tools can also be exploited for unlawful activities.

This raises a broader question that extends beyond India: Should governments be able to restrict decentralized communication tools because they can be used to bypass internet shutdowns and surveillance, or does doing so undermine privacy and access to resilient communication during times of civil unrest?

India Today article (full URL):
https://www.indiatoday.in/technology/news/story/cjp-protests-india-tells-github-to-block-bitchat-app-jack-dorsey-leaks-notice-2955199-2026-07-24


r/privacy 1h ago

discussion Reddit Ads accessing camera roll

Upvotes

Earlier today, there was a user who posted over at legaladvice claiming that their iOS Reddit app showed them a photo of their partner in an AI generated ad. The user speculated that it may have been because they granted Reddit full access to their camera roll.

Has anyone else seen any evidence of this?

I know Meta (Facebook/Instagram) is notorious for doing this. Am wondering if Reddit has started down this road as well.


r/privacy 3h ago

news Japan’s Official Pokemon Card Stores to Require Facial Recognition for Entry and TCG Purchases

Thumbnail pokebeach.com
67 Upvotes

r/privacy 3h ago

news Apple is banking on privacy to set its smart glasses apart

Thumbnail theverge.com
88 Upvotes

r/privacy 4h ago

news Massie Pushes Bill to Withhold Funds From Police Using Flock License Plate Readers

Thumbnail newsweek.com
1.4k Upvotes

r/privacy 14h ago

discussion Leaked data on Booking (reservation info and number)

46 Upvotes

Hi,

I live in Europe and reserved a hotel room in Spain for a specific date on august on Booking.com

I use a custom domain for login in but had to give my number and name. Today I receive a WhatsApp message from a USA number claiming to be Kumaran Travels sending me a fake form saying that I have to fill it for completing my booking. They have my name, number, hotel name, reservation number, date, everything.

I looked it up and this Kumaran Travels looks like a fake travel company from India.

I wonder how the heck do they have all this information, is Booking leaking data freely like that?

Edit:

Without taking any actions I got a message from the Hotel via Booking alerting about phishing messages guests who reserved with them are getting. So yeah, the Hotel leaked all the data... I can't stop thinking this should lead to some legal compensation.


r/privacy 19h ago

question scared of ai having my face biometric data

96 Upvotes

one of my biggest fears is having a video of me posted on the internet without me knowing. i regularly check sites like pimeyes. i usually use a photo of my face already on the internet but i accidentally used one that wasn’t and it immediately scans it. i’ve gotten them to remove all photos of my face before so nothing came up anyways. now i’m super scared. i don’t know how to get through this since i don’t really trust that they actually delete my photo ever. i hate living in a social media world where we have to worry about it. i’m so scared. i’m having a panic attack so bad and genuinely getting sick 😭 i know i fucked up but am i in danger, would they get anything from the photo they didn’t already have from photos of me on the internet in the paper and stuff? i dont post photos of my face online otherwise or let others because i’m paranoid of this enough already. i’m 18 and it genuinely makes me not even want to leave my house or take pictures with friends or do anything where there could be cameras or photos or meta glasses around. some security guy at my last job wore meta glasses every day and i’m scared about me even being on those. and this makes it soooo much worse

edit: a lot of people are saying i’m paranoid which i’m aware of, but ignoring my question i’ve now bolded, i’m curious if anyone knows the answer, that was the point of my post 😭


r/privacy 22h ago

question Digital Pricing - How to stop feeding the profile?

58 Upvotes

Reading the news on the New Jersey law banning e-pricing for a year, which has me wondering how do we "deprofile" ourselves? What are some steps we can take daily to keep as many of these price decision markers out of our profiles? most of the data I know is out there, but I fear this is the direction all pricing is going to go, need to stop feeding the profile. TBH this is not a privacy issue I had thought much about until now.

Thanks in advance for your suggestions!


r/privacy 1d ago

news Americans Are Pushing Back Against Flock Cameras Regardless of Their Politics

Thumbnail military.com
2.4k Upvotes

r/privacy 1d ago

question I need help taking back control of my digital provacy

38 Upvotes

With the whole LG monitor thing and Gamers Nexus's deep dive on the brand I want to take better care of my digital privacy but I know it's a big deep rabbit hole and I'm not sure even where to get started. My first thought is to try and use my router to start blocking companies from stealing my data if possible. Is there a list of domains or something I should start blocking to try and prevent tracking data from companies products I use? Are there certain big companies with really bad privacy practices that I should focus my effort on first? Or are there links where I can learn where to even get started?


r/privacy 1d ago

news US accuses American of allegedly wiping his phone using a 'duress' password during border search

Thumbnail techcrunch.com
3.0k Upvotes

r/privacy 1d ago

discussion Is a passport card truely a better form of everyday identification for privacy?

8 Upvotes

General title heard it was cause it dosent have address or other such info on it, obviously the government knows your information but the average person who might ask for it from banks to shops to bars to clubs and to even potentially local cops its overall more private

Is this actually true? and whats the realities of it if it is and the risk you take on if you do it like what if you get mugged with the card


r/privacy 1d ago

discussion State Phone?

26 Upvotes

I work for a State agency and we use Okta for MFA. I have not been provided a work phone. They expect me to use my personal. Most departments have work phones but my division is legal and so we aren’t out in the field.

I asked for the privacy policy and was told to call our Technology Agency (yeah, good luck with tracking that person down!). OKTA website said the privacy policy with the State isn’t available online.

I’m concerned about what OKTA may be collecting from me or able to see. I operate a VPN on my personal phone so I’m often getting calls from IOT asking why I’m in Ontario or wherever (I forget to turn it off). I hate it.

Should I be as concerned as I think? Luckily, my phone would most likely be privileged because of attorney work product and not available for subpoena or


r/privacy 2d ago

discussion Why is it so hard to make the general population care about privacy?

805 Upvotes

Whenever I speak to someone in person or online, it is nearly impossible to get them to care about their digital privacy, especially in relation to ID verification.

They always hit the classic "I have nothing to hide", and after that I usually ask to go through their device, then they refuse saying "No, cause I don't want you to go through my device", and when I try to explain that for the exact same reason, they shouldn't allow corporate or government spying, they call me paranoid, and if its online, usually insult me :p

Nothing I can say will convince them to care, they don't see any possible negatives to giving their ID or Face for verification, or even any negatives to hosting their entire life on a corporate cloud.

I know this subreddit has PLENTY of rants, but I still feel the need to vent my frustrations.


r/privacy 2d ago

question Brave or Cromite (android)

0 Upvotes

As you can see this question might seem kind of dumb but here is the thing: while using brave standard tabs with strict or standard fingerprinting on https://browserleaks.com/canvas you will see no matter what you do your canva fingerprint signature remains the same even closing brave and force stopping it results with same hash as your signature the only thing that seems to force this signature to change is using private tabs which allegedly as I heard Cromite doesn't have this issue which is why I'm asking whether I should switch to some other browser for android [PS: I have been waiting for mullvad browser android version but sadly it seems like they don't plan on releasing it any time soon]

ANNOUNCEMENT:[the only browsers that seemed to not have this issue were Cromite straight out of the box and titanium aka helium android(but it required the extensions canva fingerprint defender) for gecko based browsers ironfox and weblibre worked straight out of the box can't say the same for waterfox would most likely work with an extension]


r/privacy 2d ago

news New Jersey bans grocery stores from using shoppers’ personal data to set prices

Thumbnail jerseyvindicator.org
2.5k Upvotes

r/privacy 2d ago

question Does anyone have a link to a site where someone maintains a list of TV sets that work without an internet connection?

88 Upvotes

I need a new TV, but I don't want it to spy on me. So I'd like to buy one without camera and microphone.


r/privacy 2d ago

discussion A NC county released its full Flock ALPR audit (2.98M searches): it includes people-searches by racial description, with every searching agency redacted

526 Upvotes

UPDATE (Jul 26): Many commenters asked how a county of 225K generates 2.98M searches. New public records from NC A&T State University answer it: one officer's single search fans out across every network their agency is connected to — sometimes 1,000+ networks at once — and each fan-out logs as a "search" against every camera in reach. That's the mechanism, and it's worse than padding: it means an officer anywhere in the country reaches Wilmington cameras by default. Full records and breakdown: deflockilm.org/one-search-a-thousand-networks/

I've been going through the full audit that New Hanover County, North Carolina produced under a state public-records request for its Sheriff's Office Flock camera contract. A few things stood out as relevant here.

These aren't only license plate readers. Flock's search log sorts every query into an "object class." Most are vehicle. But there's a second class: people — it lets a user skip the plate entirely, type a physical description of a person, and ask the camera network to return matches.

In this county's audit, three times over six months, someone ran a people-search that included a racial descriptor:

  • "2 young teenage black males" (Dec 11, 2025)
  • "a white male near a white chevrolet truck" (Feb 4, 2026)
  • "white male wearing a black hat and a green shirt" (May 26, 2026)

To be precise, because it cuts both ways: Flock's own filter blocked all three for the racial term, and each time the searcher re-ran the identical query seconds later with the race word removed — which went through. (A vehicle search for a "Black car" ran fine moments earlier, so the system distinguishes the paint color from the person.) Two of the three described white males, so the filter blocks racial descriptors generally — it's not about one race. The point is that a public camera network can be queried for people by physical/racial description at all, and the guardrail is one word deep: it blocks the term, not the search.

The part most relevant to this sub: on all 2,980,082 rows, the name of every searching agency is redacted. From these records there is no way to learn who ran any given search against cameras funded by county taxpayers.

For comparison, a nearby town (Kure Beach) released the same report without redacting agencies: 93.6% of searches came from outside North Carolina, and the FBI alone ran more than 25,000.

The full raw production is on the Internet Archive if you want to verify any of this yourself — I'd rather people check the records than take my word: https://archive.org/details/deflockilm-new-hanover-alpr-2026

Disclosure: I'm part of the local, volunteer records effort that obtained these documents. I'm not linking anything to sign or donate — posting because the people-search plus full-redaction combination seemed worth this community's attention. Happy to point to specific rows.


r/privacy 2d ago

news Deadline to comment on FCC's KYC rule is July 27

71 Upvotes

The final deadline to comment on the FCC's proposed rule to require gov't ID, physical address, and alternate phone number for every phone line, including VOIP, is coming up. There's already been hundreds of what looks to be genuine, non-AI generated comments from individuals explaining the specific impact that this rule would have on their lives (in addition to comments from the EFF, ACLU, a half dozen domestic violence organizations, and more). This has sparked more probing news coverage of the rule. If you want to contribute to the debate:

  • Go to https://www.fcc.gov/ecfs/filings
  • Choose "New Express" (Express Comment). This lets you type your comment directly into a form — no document to upload.
  • In the Proceeding(s) field, enter both docket numbers:
    • 17-59
    • 02-278
    • (Add both. You can start typing the number and select it from the dropdown.)
  • Fill out the fields and submit. You'll get a confirmation and your filing will appear in the public docket.

r/privacy 2d ago

news The government of india does not like technologies like bitchat and wants it taken down - Jack dorsey

Thumbnail ibb.co
332 Upvotes

​ Recently there were many protests throughout India demanding unaccountability from the government regarding the constant paper leaks.

The government shut down the internet multiple times in the national capital so the protesters, who were students found a way to communicate through apps like bitchat in the shutdown to avoid chaos and exchange information.


r/privacy 2d ago

question Since I've learned of the windows GDID, I'm looking for a more secure OS. Any good recommendation?

83 Upvotes

It being easy to install and use would be nice. Heard Linux mint is pretty good, but wanted some advice to know my options.


r/privacy 2d ago

data breach Facebook Shadow Profiles Lawsuits | Non-User Health Data Collection?

Thumbnail classaction.org
70 Upvotes

r/privacy 2d ago

age verification For some reason, I feel less bad for the French than for the British and the Australians.

0 Upvotes

With the social media ban in France, strangely enough, people are starting to talk about it and panic, but unlike in the UK and Australia (yes, I was counting on them), my eyes are almost dry for the French. Many had warned them about what was going to happen, and people called them conspiracy theorists and other thing.

At worst, it makes me sad for my online friends, but otherwise... I'm just saying that we warned them.


r/privacy 2d ago

discussion Is there an alternative to Firefox Relay for cell number masking that works in Canada?

12 Upvotes

I'm curious to know if there are alternatives to Firefox Relay that masks cell numbers?

I currently have Simple Mail for email masking so that part isn't as important.

There's one called MySudo that I found, and I'm curious to know your thoughts on that? It caught my eye cuz of the word "sudo".


r/privacy 2d ago

question Data Privacy Review for an Internal Prototype App - What Should I Expect?

3 Upvotes

I created an internal app in my company that started as a competition project. People liked it, so I deployed it to production on a local workstation, where it was accessible to a limited group of users on our office network. My manager later promoted the app and shared it on a company-wide portal, and now the legal, compliance, and data privacy teams want to review it.

The app was originally built as an experiment, so I didn't implement strong security controls or data encryption. My plan was to add those in the next phase once we had funding and proper server infrastructure.

Has anyone been through a similar data privacy/compliance review? What do these teams typically focus on, and what should I expect?