Lesson 4 of 4 · 8 min
Reducing your data trail on a Mac and phone
Concrete, built-in settings on macOS and iPhone that reduce what reaches data brokers, without disabling anything that protects you.
The earlier lessons described where data brokers get their material. This lesson is about the settings you already have, on a Mac and an iPhone, that reduce how much of it comes from you: app permissions, tracker blocking in the browser, and cutting down on the identifiers you hand out, such as your real email and phone number.
Control which apps can see what, on the Mac
Every Mac has a central place to review this. Apple’s own instructions: go to “Apple menu > System Settings, then click Privacy & Security in the sidebar.” From there, each category — Location Services, Contacts, Camera, Microphone, Photos, Bluetooth, Local Network and more — lists the apps that have requested access, and you can approve or remove each one individually. It is worth reviewing this list occasionally rather than only at install time: an app that legitimately needed your location once for a one-time feature does not need standing access to it forever.
On iPhone: App Tracking Transparency names the destination directly
On iPhone, iPad and Apple TV, Apple’s App Tracking Transparency feature is unusually specific about what it protects against. Apple defines “tracking” as when information that identifies you or your device, collected in one app, is linked with information collected elsewhere for advertising, “or when the information collected is shared with data brokers.” Go to Settings, then Privacy & Security, then Tracking, to see which apps have asked and to turn permission on or off per app; turning off “Allow Apps to Request to Track” in that same screen treats every future request as already declined. This is the one setting on the phone that is explicitly, officially, about data brokers rather than a general privacy label.
Block cross-site tracking in the browser
In Safari on the Mac, Apple’s instructions are to go to “Safari > Settings, then click Privacy” and select “Prevent cross-site tracking.” With that on, cookies and data from a third-party content provider are deleted unless you actually visit and interact with that provider as a first-party site — which is exactly the third-party tracking cookie behaviour described in the earlier lesson on how your data gets out. Safari also limits fingerprinting by presenting “a simplified version of your system configuration” to sites, and blocks social media “Like” or “Share” buttons from tracking you until you actually choose to use them. The same setting exists in Safari on iPhone. If you use a different browser, look for an equivalent option, usually named tracking prevention or cross-site tracking protection, and consider adding a dedicated tracker-blocking extension such as EFF’s Privacy Badger, which blocks third parties it observes tracking you across sites.
Stop handing out your real email and reduce what a phone number ties together
A large share of what ends up with data brokers starts with a form: a newsletter sign-up, an account creation, a warranty registration. Apple’s Hide My Email, part of iCloud+, lets you “generate unique, random email addresses…so you don’t have to share your real email address”, on iPhone, iPad, Mac or iCloud.com; mail sent to that address forwards to your real inbox, and you can delete an address later if it starts attracting spam or turns out to have been resold, without touching your main address at all. The same logic applies to phone numbers where you have a choice: a number given out for every sign-up, delivery or loyalty card is a stronger, more permanent link between accounts than an email alias, so it is worth being as selective about handing it out as you would be with your main email address, and using a masked address instead wherever a service accepts one.
| Setting | Where | What it limits |
|---|---|---|
| Privacy & Security app permissions | Mac: System Settings > Privacy & Security | Standing access apps have to location, contacts, camera, microphone and more |
| Tracking permission | iPhone/iPad: Settings > Privacy & Security > Tracking | Apps linking your data to other companies’ apps or sharing it with data brokers |
| Prevent cross-site tracking | Safari > Settings > Privacy | Third-party cookies and data following you from site to site |
| Hide My Email | iCloud+, on iPhone, iPad, Mac or iCloud.com | Your real email address being collected at every sign-up |
Key takeaways
- Review System Settings > Privacy & Security on the Mac periodically, not just when an app first asks for access.
- iPhone’s App Tracking Transparency is explicitly defined by Apple to cover sharing your data with data brokers, not just in-app ads.
- Turning on “Prevent cross-site tracking” in Safari removes third-party cookies unless you actually interact with that third party directly.
- Hide My Email lets you give out a disposable address instead of your real one, and delete it later without affecting your main inbox.
- Treat your phone number with the same caution as your main email address: it links accounts together more permanently than most people realise.
Check yourself
1. Where do you review which apps can access your camera, microphone or location on a Mac?
- App Store > Updates
- System Settings > Privacy & Security — Right.
- Finder > Preferences
- Safari > Extensions
Apple’s own instructions place all per-app data permissions under System Settings > Privacy & Security.
2. What does Apple explicitly say App Tracking Transparency protects against?
- Only slow app performance
- Linking your data across apps for advertising, or sharing it with data brokers — Right.
- Viruses and malicious software
- Running out of storage space
Apple’s own definition of “tracking” names both cross-app/cross-site linkage for advertising and sharing with data brokers.
3. What happens to third-party cookies when “Prevent cross-site tracking” is turned on in Safari?
- They are encrypted but kept
- They are deleted unless you actually visit and interact with that third party as a first-party site — Right.
- Nothing changes
- Only cookies from Apple are affected
Apple’s documentation states this setting deletes a third party’s cookies and data unless you interact with it directly.
4. What does Hide My Email actually do?
- Deletes your iCloud account
- Generates a random address that forwards to your real inbox, so you avoid sharing your real email — Right.
- Blocks all incoming email
- Automatically unsubscribes you from newsletters
Apple describes Hide My Email as creating unique, random addresses that forward to your personal inbox.
Do it with FireAI
Put this lesson into practice on your own Mac.
- Block an app from the internet, or just one company or domain for it — Cut off exactly what you mean to — the whole app, or just one company it talks to.
- Find out where an app sends data, on the World map — See exactly which company and country one app is quietly talking to.
- What stays on your Mac, and the only times FireAI goes online by itself — Read the whole list of what FireAI sends, instead of taking a firewall’s word for it.
Sources
- Apple Support: Control access to information in apps on Mac
- Apple Support: If an app asks to track your activity
- Apple Support: Prevent cross-site tracking in Safari on Mac
- Apple Support: Create unique, random email addresses with Hide My Email and iCloud+
- EFF: Privacy Badger
Put it into practice on your Mac
Try every feature free for 17 days, no card needed.