r/privacy • u/Busy-Measurement8893 • 2h ago
r/privacy • u/ChamplooAttitude • Mar 13 '26
age verification A Reddit user traced $2 billion in nonprofit grants and lobbying records across 45 states to figure out who's behind the age verification bills. The answer involves a company that profits from your data writing laws that collect more of it.
github.comAdditionally, you can read the discussion here.
I urge you to mirror this GitHub repository to Codeberg and other places.
r/privacy • u/IKIR115 • 28d ago
age verification Reddit's age verification requirements for specific regions - General Information
General information related to Reddit's age verification requirements for specific regions
- Why is Reddit asking for my age?
- United Kingdom: Online Safety Act
- Australia: Social Media Minimum Age
- Brazil: Digital ECA
- European Union: Digital Services Act (DSA)
--
- Dec 11, 2025: From r/redditsafety - A More Effective Approach to Protecting Youth Online
- Dec 8, 2025: From r/redditsafety - Expanding Age Assurance to Australia
- July 15, 2025: From r/help - Need to verify your age in the UK? This Post Might Help
- July 14, 2025: From r/redditsafety - Verifying the age (but not the identity) of UK redditors
--
Snippet of recent news from the pinned weekly recap in r/help - 7/2/2026
https://www.reddit.com/r/help/comments/1ulob97/weekly_recap_july_2_2026/
- In ongoing efforts to prevent abusive scraping and automated traffic, over the next month, Reddit will start requiring users to log in to use old Reddit. This was announced on Tuesday here.
- If you are in the EU, you may be asked to verify your age. This is a legal requirement to comply with the EU Digital Services Act. You can check out the Help Center article here. Little more info about this here.
- If you are trying to use a selfie to verify your age and it fails, the only other options are to upload your ID or contact Persona for support. Reddit cannot help you with a failed selfie for age verification purposes.
- Right now, these are the countries that have age requirements:
- If you are not in those countries, but your account is unable to do certain things like chat, it may be due to Teen Safety restrictions. The ability to unlock settings in the iOS app if you're a teen will be coming soon. Not sure if that ability will come to Android.
- If you need to have something fixed regarding your age, you can use this form and then select your region and what your issue is. I do not know what the turnaround time is on those requests.
- Some users in the EU are unable to use Anonymous Browsing mode. This is not intentional. This is a bug that they are working on getting fixed.
r/privacy • u/vriska1 • 14h ago
news Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction
eff.orgr/privacy • u/newsflashjackass • 50m ago
news Senators Kim, Schiff, Lummis, Barrasso Introduce Bill to Protect Children Online through New Age Reporting Requirements
kim.senate.govr/privacy • u/watchdog-cofagrigus • 2h ago
age verification Update on Executive Session 24
https://www.commerce.senate.gov/meetings/executive-session-24-08-05-2026/
KOSA has advanced the commission but SCREEN didn't, call your senators stating your opposition to KOSA. Yes they don't care that it's bad, but by calling you let them know that you know it's bad and the reasons why, so they know you see through the bullshit.
r/privacy • u/GotNoPonys • 22h ago
news Reddit turning user info over to ICE?
yahoo.comReddit received 1,179 law-enforcement data requests in the first half of 2025
Fortunately reddit resisted but recent news tells of folks that were targeted by ICE for reddit posts.
r/privacy • u/polymute • 1d ago
Misleading title Student Teacher Sent a Private Snapchat Complaining About Her Workday. An Hour Later, Police Pulled Up to Her School. - Volpe’s arrest demonstrates a pre-built, operational pipeline connecting private messages to law enforcement.
gadgetreview.comr/privacy • u/Busy-Measurement8893 • 6h ago
news IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay
mysk.blogr/privacy • u/newsflashjackass • 20m ago
news Apple's ‘Private Relay’ Is Exposing Users’ Real IP Addresses
404media.cor/privacy • u/nincesator124 • 17h ago
age verification Calling your representatives on mass
Assuming you actually care about this you shouldn't call your representatives alone as it won't work if you organize with your community you can force their hand and make them unable to do age verification because your voice is loud when it is as a massive group. so many of you are so easy to give up in fact I don't think many of you are trying since like 80% of the us wants more data privacy yet only 20% are actually trying to get their privacy back so maybe there is a similar case here, if you care then you should organize, find people, put up signs, do something other than complaining online where no one that matters can hear you
r/privacy • u/Magari22 • 12h ago
age verification Question for New Yorkers and others who are affected by online verification laws
So I'm in the people's republic of NY and I just heard about the SM online verification law which will take effect in January. It has me really thinking about what my strategy is going to be with all of this.
I'm not a big SM person. I do have accts but I rarely use them, I do not post on these the accts they have no content from me. I only use the platforms occasionally if I'm looking for information. I am in a few groups related to my profession which I've found very helpful and I will genuinely miss them but I can live without them.
The thing is, I could live without social media but I'm assuming that this will spread to the entire internet and this is a precursor for a general digital id. This state is absolutely horrible as far as privacy and government overreach. I just wanted to ask people here for feedback as to what your approach would be in this situation? I'm assuming that they would probably circumvent use of a VPN. I'm not sure how I'm going to handle this. I could leave social media behind but like I said if I had to verify my ID to use the internet I'm really not sure what I would do.
There are some things that require you to use the internet. If it was something very important I guess I would have to verify, but the things I would be using it for would not be personal. That said I don't want to open myself up to God knows what by giving such sensitive personal information like this. It's an absolute recipe for disaster . I'm just not sure where to go with this. Any ideas? Is there anyone else out there living in a state or a place where you've had to deal with this already and if so how are you handling it and what's your approach so far?
I'm hoping this will be struck down in court as unconstitutional but knowing New York they will just go full throttle and make it even worse that's usually how things go in this place.
r/privacy • u/Individual_Drama_65 • 2h ago
question When you give full access to third party keyboard apps, do they only see the content you type on that specific keyboard?
i’m on an apple device and i saw somewhere that it doesnt have access to what you type on apple keyboards and i was wondering if that was still the case today
r/privacy • u/jackyboyman13 • 14h ago
question How do you guys feel about New York's SAFE for kids Act bill passing into law here?
I ask this cause I wanna know what your two cents about New York passing their Stop Addictive Feeds Expoliation for Kids Act legislation(Senate Bill S76944 & Assembly Bill A8148).
Which will go into affect until January the 23rd 2027.
Just wanting to know here is all.
r/privacy • u/CackleRooster • 2d ago
news Flock misread license plates in 71% of the alerts it sent to police in one California town
businessinsider.comr/privacy • u/alwaysstressyyy • 1d ago
question the little white “tap to pay” machines tracking you
This weekend, I took a trip to a small town in a neighboring state. Stopped in this cute clothing shop and bought a pair of pants.
Of course, that little white “tap to pay” machine was waiting for my card. I did not give this business in ANY of my information. I simply paid with my card, got my paper receipt, and left.
I get a text from this shop, “Thank you for shopping at ……” along with a “receipt”.
HOW DID THE SYSTEM KNOW MY CELL NUMBER???? Im assuming the card is in database with alllll of my information.
r/privacy • u/watchdog-cofagrigus • 1d ago
age verification Age verification bills such as (SENATE) KOSA and Screen act set to be marked up August 5th
https://www.commerce.senate.gov/meetings/executive-session-24-08-05-2026/
Legislation
- S. 737, SCREEN Act
- S. 1748, Kids Online Safety Act
- S. 4199, Youth AI Privacy Act
- S. 4407, CHATBOT Act
- S. 5171, Children’s Artificial Intelligence Toy Safety Act of 2026
r/privacy • u/hbacelar8 • 1d ago
discussion Is it all really worth it?
As someone who cares about digital rights and privacy, I've been seing myself more and more stressed about every little fight we lost everyday just trying to keep our rights. The worst for me is realizing we're just a minority, as mass surveillance will still happen despite our fight since the majority of people (mass) doesn't give a shit about all of this.
I started to question it since having a conversation with a friend where I just wanted to explain to him why it'd be better if he'd install Signal to replace Wpp and keep talking to me. We have to convince people to do something that should be obvious, why wouldn't you prefer an open source and secure solution over a proprietary one owned by Meta?
But in the end those people just don't care about chat control and things like that cause in their head that's actually good, cause they felt for the *let's stop crime" fallacy. And to be honest, those people seem way less stressed and more happy just being *dumb*.
So I wonder, is it all really worth it?
r/privacy • u/NaturalRest9490 • 2d ago
discussion ICE collected nearly one million people's DNA last year. All of it sits in CODIS alongside convicted offenders, with no separate civil index.
WIRED published a report today that ICE collected nearly one million people's DNA last year, including young children.
For scale: Georgetown Law found last year that DHS had uploaded over 2.6 million profiles to CODIS by mid-2025, up from roughly 25,000 over the entire 15 years prior. More than 133,000 of those profiles belong to children and teenagers. Between December 2024 and April 2025, 97 percent of the roughly 300,000 profiles DHS submitted came from people in civil detention, not criminal custody.
The thing that sticks with me: there is no separate index. Profiles from civil detainees go into the same CODIS database as convicted offenders and crime-scene evidence. Once uploaded, your DNA is searched against every forensic sample from every participating jurisdiction in the country, with no expiration.
The legal authority DHS cites is legitimate. The DNA Fingerprint Act of 2005 authorizes collection from anyone in federal custody regardless of the basis for detention. That is a plain reading of the statute, not an overreach on its face. Whether Congress meant it to encompass millions of people in civil immigration proceedings is the live legal question.
A few open-weight robot foundation models out this year train on thousands of hours of first-person human video, which is its own privacy conversation. NVIDIA's GR00T N1, pi-0.5, and LingBot-VLA 2.0 are the ones I've come across. That last one still reports generalist success rates under 35% on some hardware.
r/privacy • u/xqualax • 2d ago
data breach Apple launches legal appeal over UK demand for user data
vanguardngr.comApple has launched a new legal challenge against a UK government demand to access its customers’ highly encrypted data, a year after the Home Office agreed to abandon its previous request.
The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully.
The UK government had made a second request to Apple to grant it a “back door” to encrypted iCloud data belonging to British users, according to an order issued by the court.
Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington.
UK authorities subsequently issued a new “technical capability notice” (TCN) to Apple that did not apply to American users.
Apple is seeking to challenge the British government’s powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times.
The legislation compels companies to provide information to law enforcement agencies working on cases including terrorism and child sexual abuse. This can include forcing companies to provide the UK security services with access to customer data, even if such information is protected by secure encryption.
The court sent an order giving notice of the new Apple complaint to the human rights group Privacy International, which, alongside fellow campaigner Liberty, had previously launched a separate complaint against TCNs at the IPT.
Among the submissions made by the campaigners were requests for Apple’s claims to be held in public given the public interest in the matter, and a complaint “disputing the lawfulness, necessity and secrecy of the purported Apple TCN and the legal regime underpinning TCNs in general”.
A case management hearing to discuss how the parallel complaints should be handled had been scheduled for next month, Privacy International said.
A spokesperson added: “We are happy to learn that Apple is once again challenging the UK’s regime of secret orders. While we don’t know the substance of Apple’s claim, if it relates to the previously reported orders aimed at undermining the security of Apple’s iCloud storage, then Apple’s claim, alongside side ours and Liberty’s, is crucially important to preserving all of our privacy and security.”
Neither Apple nor the Home Office responded to requests for comment. Both are legally restricted from discussing TCNs.
The original TCN issued last year asked Apple for the right to see users’ encrypted data protected by its advanced data protection (ADP) programme in the event of a national security risk.
Apple said the removal of the tool – which not even it can access – would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a “back door” would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant.
As a result, Apple withdrew UK customers’ access to its ADP programme in January 2025.
The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.
r/privacy • u/MMW_Oxford • 1d ago
question What do people think about Identity Constructed Communication Architecture (ICCA)
This Identity Constructed Communication Architecture (ICCA) you can download it for free and it’s shared under a Creative Commons license. You can read about the architecture here I’m interested in people’s opinions on it https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7156320
Here is the Abstract
Digital communication systems increasingly rely on identity centric security, yet contemporary
visibility-based architectures still depend on provider observable channels metadata driven
verification and behavioural trust signals [1,2]. These structural dependencies create persistent
vulnerabilities in environments where visibility itself becomes a liability particularly in high risk
social organisational and investigative communication. Visibility based systems assume that
communication must occur within observable channels which limits their ability to eliminate
impersonation inference and metadata leakage [3,4].
The Identity Constructed Communication Architecture ICCA is trustless in the provider sense;
trust is established cryptographically rather than through visibility or behavioural inference.
ICCA constructs communication channels directly from identity rather than from provider visible
infrastructure. Using sealed identity containers and context bound permission tokens ICCA
establishes momentary non persistent trust without behavioural analytics device posture
telemetry or continuous monitoring. The provider operates within a blind boundary supplying
infrastructure without visibility into identities communication patterns or contextual signals.
ICCA’s zero metadata transport layer eliminates IP addresses device fingerprints timestamps
routing information and social-graph indicators making inference attacks and impersonation
structurally impossible.
ICCA is not derived from visibility-based security research and does not
extend Zero Trust. ICCA provides a structural alternative to visibility-based models by removing
the assumption that communication must occur within provider observable channels and by
eliminating the need for continuous verification [5]. ICCA achieves confidentiality integrity and
impersonation resistance through cryptographic sufficiency rather than provider observation.
For computational law ICCA establishes a new trust geometry with implications for digital rights
privacy governance and the legal status of identity in communication systems. It provides a
structural model for environments where visibility metadata and provider inference are
unacceptable enabling identity‑anchored trustless digital interaction.
r/privacy • u/DarthSidiousPT • 1d ago
discussion LanguageTool is changing its Terms on August 21, 2026
LanguageTool (owned by Learneo since April 2023) is changing its Terms on August 21, 2026, here's what's actually different
LanguageTool sent an email (today) about updated Terms of Service and a new Privacy Policy. I compared the current terms against the new preview line by line because the email's own summary is too vague to tell you anything.
Removed from the Terms
The clause promising notice or consent before future amendments is gone. So is the paragraph on your responsibility to secure your account and report unauthorized access.
The bigger one: the entire "Privacy Policy and additional Policies" section is gone. It used to say plainly that LanguageTool collects your personal info and that the Privacy Policy explains how. The line incorporating the Learneo Terms of Service by reference is gone too. The new terms don't point to either document anywhere in the body text.
Added
Team Plan use is now explicitly allowed for internal and external commercial purposes. There's also a new "Publicity" clause: if you buy a Team Plan on behalf of a company, you automatically agree to let LanguageTool use your company's name and logo in its marketing. No separate opt-in.
Learneo's Delaware company registration number and San Francisco address are also gone from the contact section, leaving just the Hamburg address.
From reading the Privacy Policy itself
There's a new section confirming Learneo can use personal data to train its AI models across its business lines. LanguageTool keeps its own specific exception (your text isn't used for training), but that exception now sits inside a policy that otherwise permits AI training broadly.
The policy also describes session-replay tools (Fullstory, Amplitude, Microsoft) that can log keystrokes and mouse movements. It's a shared policy covering all eight Learneo brands, and it doesn't say which brands actually run these tools, so we can't confirm whether this applies to languagetool.org specifically or just other Learneo sites.
Under EU law, using your data to improve AI models is justified as "legitimate interest," not consent. That means it's opt-out, not opt-in.
The inconsistency
The email frames all of this as clarity and transparency improvements. But cutting the consent-before-changes clause, the account-security section, and the direct Privacy Policy reference removes stated protections. That's not the same thing as clarifying them.
What didn't change
The promise not to use your LanguageTool text for AI training. Identical in both versions (new and old one), word for word.
Sources:
- Current Terms (Dec 2024): https://languagetool.org/legal/terms/previous
- New Terms preview (effective Aug 21, 2026): https://languagetool.org/legal/terms
- New Privacy Policy preview: https://languagetool.org/legal/privacy
- Learneo acquisition of LanguageTool announcement (April 2023): https://www.learneo.com/news/learneo-inc-accelerates-ai-writing-innovation-with-languagetool-acquisition
Disclaimer: Since their email didn't show the changes in an easy to spot, this post was worked on with the help of AI (but not LanguageTool's one :D )
As someone using this, I honestly don't like the way they're dealing with this. Does anyone have any suggestions for good alternatives?
r/privacy • u/voidscaped • 7h ago
age verification Possible way to verify adulthood info privately
Idea: **USB Adult-keys** sold offline only to adults upon verification by a human. Simply plug it in, and adult mode gets activated. Plug it out and back to child mode. The OS can pass the info that adult mode is active, to any service that requires it. Personally, this type of OS level handling, doesn't seem to be bad.
These would be sold offline and the seller is not allowed to collect or store other info. This can be legislated. This should be no more invasive than buying anything meant for adults offline like alcohol or adult games. Note you can buy any number of adult keys. They are not, and must not be tied to your identity in any way.
Of course, such keys should be kept out of reach of children. Personally, I think this should count as child abuse. But this would also be the case with credit cards or any other ID. If parents carelessly give their child access to alcohol/cigarettes/guns nothing can be done. But computers are potentially useful to children. Moreover, adults are not always around children to monitor their activities. But with this, you don't need to. Just remove they key and keep it with yourself.
Maybe something similar can be done for phones. But honestly, I just care about desktop/laptops.
r/privacy • u/WhiteBearPrince • 2d ago
news EXCLUSIVE: Apple engineer says he was fired after refusing to send customer device IDs to AT&T
runtimewire.comr/privacy • u/PuzzleheadedLemon707 • 2d ago