<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>Best remote collaboration tools for teams in 2026</title><link>https://proton.me/business/blog/remote-collaboration-tools</link><guid isPermaLink="true">https://proton.me/business/blog/remote-collaboration-tools</guid><description>Compare the best remote collaboration tools for messaging, meetings, and project management.</description><pubDate>Fri, 14 Aug 2026 15:06:05 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Hybrid and &lt;a href=&quot;https://proton.me/business/vpn/remote-work&quot;&gt;remote work&lt;/a&gt; now depend on more than chat apps and video calls. Teams need reliable ways to communicate, share files, manage projects, and make decisions without losing context.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Virtual &lt;a href=&quot;https://proton.me/business&quot;&gt;team collaboration tools&lt;/a&gt; support the core parts of day-to-day work, from messaging and meetings to file sharing, project tracking, and document editing. No single collaboration software will cover everything, and many teams rely on a combination that best fits how they work.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Best collaboration tools for remote teams by category&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Video meetings&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Choosing the right tool comes down to reliability and how your data is handled.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;638&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_638,c_scale/f_auto,q_auto/v1786710884/wp-pme/screenshot-2026-08-14-at-1-34-27-pm/screenshot-2026-08-14-at-1-34-27-pm.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-272124 wp-image-272125&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;728 KB&quot; data-optsize=&quot;44 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;94&quot; data-version=&quot;1786710884&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_638,c_scale/f_auto,q_auto/v1786710884/wp-pme/screenshot-2026-08-14-at-1-34-27-pm/screenshot-2026-08-14-at-1-34-27-pm.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_187,c_scale/f_auto,q_auto/v1786710884/wp-pme/screenshot-2026-08-14-at-1-34-27-pm/screenshot-2026-08-14-at-1-34-27-pm.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_478,c_scale/f_auto,q_auto/v1786710884/wp-pme/screenshot-2026-08-14-at-1-34-27-pm/screenshot-2026-08-14-at-1-34-27-pm.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786710884/wp-pme/screenshot-2026-08-14-at-1-34-27-pm/screenshot-2026-08-14-at-1-34-27-pm.png?_i=AA 1044w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Proton Meet&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;End-to-end encrypted video conferencing tool for private collaboration.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Private client calls, internal strategy discussions, and teams handling sensitive information.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;End-to-end encryption&lt;/a&gt; protects audio, video, and chat content, even from Proton.&lt;/li&gt;



&lt;li&gt;No tracking or data collection, so conversations are not used to train AI models.&lt;/li&gt;



&lt;li&gt;Join instantly from a browser, with no account required for guests.&lt;/li&gt;



&lt;li&gt;Supports up to 50 participants on free plans and larger meetings on paid plans.&lt;/li&gt;



&lt;li&gt;Uses Messaging Layer Security (MLS) to protect video sessions.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/meet&quot;&gt;Start a free meeting&lt;/a&gt;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Zoom&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Video conferencing platform with support for meetings, webinars, and events.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Hosting large external meetings, webinars, and presentations.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Supports high-quality video calls with large participant limits.&lt;/li&gt;



&lt;li&gt;Includes breakout rooms, screen sharing, and recording.&lt;/li&gt;



&lt;li&gt;Widely adopted, making it easy to connect with external participants.&lt;/li&gt;



&lt;li&gt;Integrates with a wide range of business and productivity tools.&lt;/li&gt;
&lt;/ul&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Google Meet&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Video conferencing service integrated with &lt;a href=&quot;https://proton.me/business/google-workspace-alternative&quot;&gt;Google Workspace&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Quick meetings for teams already using Google tools.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Runs directly in the browser with no software installation required.&lt;/li&gt;



&lt;li&gt;Integrates with Google Calendar, &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail&lt;/a&gt;, and other Workspace apps.&lt;/li&gt;



&lt;li&gt;Eligible plans support screen sharing, live captions, and meeting recordings.&lt;/li&gt;



&lt;li&gt;Simple interface that is easy to use for internal and external calls.&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Team messaging&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Messaging tools replace internal email and make communication faster and more organized.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Slack&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Team messaging platform for real-time and asynchronous communication.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Fast-moving teams and cross-functional collaboration.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Organizes conversations into channels for projects, teams, and topics.&lt;/li&gt;



&lt;li&gt;Supports async work with status updates, threads, and notifications.&lt;/li&gt;



&lt;li&gt;Integrates with a wide range of collaboration and productivity tools.&lt;/li&gt;



&lt;li&gt;Enables quick calls and screen sharing within the platform.&lt;/li&gt;
&lt;/ul&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Microsoft Teams&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Collaboration platform that combines messaging, meetings, and file sharing.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Organizations using &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Microsoft 365&lt;/a&gt; and enterprise environments.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Provides admin controls and security features for enterprise use.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Combines chat, video meetings, and file sharing in one platform.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Integrates with Microsoft 365 apps such as &lt;a href=&quot;https://proton.me/business/mail/outlook-alternative&quot;&gt;Outlook&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/microsoft-word-alternative&quot;&gt;Word&lt;/a&gt;, and SharePoint.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Supports channels, group chats, and scheduled meetings.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Missive&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shared inbox platform that combines &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business email&lt;/a&gt;, chat, and task management.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Shared inboxes and client communication.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Brings email, chat, and tasks together in a single workspace.&lt;/li&gt;



&lt;li&gt;Allows teams to collaborate on emails with internal comments and assignments.&lt;/li&gt;



&lt;li&gt;Supports guest access for working with external clients and partners.&lt;/li&gt;



&lt;li&gt;Integrates with tools such as Slack, Trello, and &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Project management&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Project management tools help teams track work, assign tasks, and stay aligned on deadlines.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Trello&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Simple, visual project management based on boards, lists, and cards.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Small teams and straightforward workflows.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Uses a Kanban-style system to track tasks visually.&lt;/li&gt;



&lt;li&gt;Easy to set up and use with minimal training.&lt;/li&gt;



&lt;li&gt;Supports collaboration through comments, attachments, and checklists.&lt;/li&gt;



&lt;li&gt;Integrates with tools such as Slack and Google Drive.&lt;/li&gt;
&lt;/ul&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;monday.com&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Work management platform with flexible dashboards and automation features.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Teams that need customizable workflows and visibility across projects.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Provides customizable boards and views for different workflows.&lt;/li&gt;



&lt;li&gt;Automates repetitive tasks and notifications.&lt;/li&gt;



&lt;li&gt;Supports collaboration across teams and departments.&lt;/li&gt;



&lt;li&gt;Integrates with a wide range of business tools.&lt;/li&gt;
&lt;/ul&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Asana&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Task management platform for structured project planning and coordination.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Cross-team coordination and complex project tracking.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Organizes tasks with timelines, dependencies, and milestones.&lt;/li&gt;



&lt;li&gt;Supports collaboration with comments, updates, and task ownership.&lt;/li&gt;



&lt;li&gt;Provides visibility across teams and projects.&lt;/li&gt;



&lt;li&gt;Integrates with tools such as Slack, Google Workspace, and Microsoft Teams.&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;File sharing&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;File sharing tools let teams store, access, and share documents securely.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-full&quot;&gt;&lt;img width=&quot;916&quot; height=&quot;558&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_916,h_558,c_scale/f_auto,q_auto/v1786711239/wp-pme/screenshot-2026-08-14-at-1-40-10-pm/screenshot-2026-08-14-at-1-40-10-pm.png?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-272124 wp-image-272149&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;315 KB&quot; data-optsize=&quot;28 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;91.1&quot; data-version=&quot;1786711239&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786711239/wp-pme/screenshot-2026-08-14-at-1-40-10-pm/screenshot-2026-08-14-at-1-40-10-pm.png?_i=AA 916w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_183,c_scale/f_auto,q_auto/v1786711239/wp-pme/screenshot-2026-08-14-at-1-40-10-pm/screenshot-2026-08-14-at-1-40-10-pm.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_468,c_scale/f_auto,q_auto/v1786711239/wp-pme/screenshot-2026-08-14-at-1-40-10-pm/screenshot-2026-08-14-at-1-40-10-pm.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 916px) 100vw, 916px&quot; /&gt;&lt;/figure&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Proton Drive&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Secure file storage and sharing platform with end-to-end encryption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Storing and sharing sensitive business files securely.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Files are protected with end-to-end encryption by default.&lt;/li&gt;



&lt;li&gt;Share documents using secure links with access controls.&lt;/li&gt;



&lt;li&gt;End-to-end encryption prevents Proton from accessing file contents.&lt;/li&gt;



&lt;li&gt;Works across devices with secure cloud-based syncing.&lt;/li&gt;



&lt;li&gt;Part of a privacy-focused ecosystem for secure collaboration.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/l/business/drive/cloud-storage-for-business-pfm-bft-v2?visitorId=go-Cj0KCQjw-frTBhCvARIsADv4XY4BcgbhGBwfMwf-X3wsE9-6P8rd8IBYAdHmbuI5MWr2yCNkfh0uX18aAiNfEALw_wcB-73&amp;amp;utm_campaign=ww-all-2b-all-gro_src-g_acq_mix_search-selfserve&amp;amp;utm_source=google.com&amp;amp;utm_medium=src_ad&amp;amp;utm_content=194934639045&amp;amp;utm_term=secure%20cloud%20storage&amp;amp;ctype=b2b&amp;amp;utm_campaign=ww-all-2b-all-gro_src-g_acq_mix_search-selfserve&amp;amp;utm_source=google.com&amp;amp;utm_medium=src_ad&amp;amp;utm_content=194934639045&amp;amp;utm_term=secure%20cloud%20storage&amp;amp;aid=%7Baffiliate_id%7D&amp;amp;hfp=false&amp;amp;gad_source=1&amp;amp;gad_campaignid=23859862039&amp;amp;gbraid=0AAAAACoJdQ1Scd64XQvjY4PGcmWxNCQVN&amp;amp;gclid=Cj0KCQjw-frTBhCvARIsADv4XY4BcgbhGBwfMwf-X3wsE9-6P8rd8IBYAdHmbuI5MWr2yCNkfh0uX18aAiNfEALw_wcB&quot;&gt;Try Proton’s business cloud storage&lt;/a&gt;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Google Drive&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cloud storage platform with built-in collaboration across Google Workspace.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Teams already using Google tools for everyday work.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Stores and organizes files in a shared cloud workspace.&lt;/li&gt;



&lt;li&gt;Supports real-time collaboration across Docs, Sheets, and Slides.&lt;/li&gt;



&lt;li&gt;Integrates with Gmail, Calendar, and other Google services.&lt;/li&gt;



&lt;li&gt;Makes sharing and access management simple across teams.&lt;/li&gt;
&lt;/ul&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Dropbox&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cloud storage platform focused on file syncing and sharing.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Reliable file syncing and external file sharing.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Syncs files across devices with strong reliability.&lt;/li&gt;



&lt;li&gt;Supports sharing through links and shared folders.&lt;/li&gt;



&lt;li&gt;Keeps version history and file recovery options.&lt;/li&gt;



&lt;li&gt;Integrates with a range of productivity tools.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Find out why you should consider an &lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;alternative to Dropbox&lt;/a&gt;.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Document collaboration tools&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Document tools support virtual collaboration, allowing teams to create, edit, and comment in real time.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Proton Drive, Proton Docs, and Proton Sheets&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;End-to-end encrypted document editor for secure collaboration.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Creating and sharing sensitive documents securely.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;End-to-end encryption protects every keystroke, even from Proton.&lt;/li&gt;



&lt;li&gt;Supports real-time editing with live cursors and updates.&lt;/li&gt;



&lt;li&gt;Includes comments, suggestions, and version control.&lt;/li&gt;



&lt;li&gt;Allows secure sharing with internal and external collaborators.&lt;/li&gt;



&lt;li&gt;Prevents document content from being used for AI training or profiling.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Explore &lt;a href=&quot;https://proton.me/business/drive/pricing&quot;&gt;business cloud storage plans&lt;/a&gt;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Notion&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Workspace platform that combines documents, notes, and lightweight project management.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Teams that want documents and workflows in one place.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Combines documents, notes, and task management in a single workspace.&lt;/li&gt;



&lt;li&gt;Supports real-time collaboration with comments and updates.&lt;/li&gt;



&lt;li&gt;Offers flexible layouts for different types of content.&lt;/li&gt;



&lt;li&gt;Integrates with tools such as Slack, GitHub, and Google Drive.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Looking to replace Notion? Discover the best &lt;a href=&quot;https://proton.me/drive/notion-alternative&quot;&gt;Notion alternative&lt;/a&gt;.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Google Docs&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Online document editor with real-time collaboration and sharing.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Simple document editing and collaboration across teams.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Enables real-time editing with comments and suggestions.&lt;/li&gt;



&lt;li&gt;Makes sharing easy with link-based access controls.&lt;/li&gt;



&lt;li&gt;Supports version history and document recovery.&lt;/li&gt;



&lt;li&gt;Integrates with Google Workspace tools such as Drive and Gmail.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Discover the best &lt;a href=&quot;https://proton.me/drive/google-docs-alternative&quot;&gt;Google Docs alternative&lt;/a&gt;.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Knowledge sharing&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Documentation and knowledge-sharing tools help teams store, organize, and share internal information.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Proton Drive&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Secure file storage and sharing platform for sensitive information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Sharing and storing sensitive internal documents securely.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;End-to-end encryption protects files by default.&lt;/li&gt;



&lt;li&gt;Share securely with links and access controls.&lt;/li&gt;



&lt;li&gt;Designed to protect sensitive business data from unauthorized access.&lt;/li&gt;



&lt;li&gt;Prevents files from being accessed or analyzed by the provider.&lt;/li&gt;



&lt;li&gt;Useful for storing confidential documents that should not be exposed in standard knowledge tools.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Try the best &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;cloud storage for businesses&lt;/a&gt;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Notion&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Workspace platform often used for documentation and internal knowledge bases.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Teams that want flexible knowledge sharing and documentation in one place.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Stores documents, notes, and processes in a structured workspace.&lt;/li&gt;



&lt;li&gt;Supports real-time collaboration and updates.&lt;/li&gt;



&lt;li&gt;Organizes content using pages, databases, and templates.&lt;/li&gt;



&lt;li&gt;Integrates with tools such as Slack, GitHub, and Google Drive.&lt;/li&gt;
&lt;/ul&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Confluence&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Documentation platform designed for structured knowledge management.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Larger teams managing detailed internal documentation.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Organizes company knowledge into structured pages and spaces.&lt;/li&gt;



&lt;li&gt;Supports versioning, permissions, and audit trails.&lt;/li&gt;



&lt;li&gt;Integrates with tools such as Jira and other Atlassian products.&lt;/li&gt;



&lt;li&gt;Designed for scaling documentation across teams and departments.&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Whiteboards and visual collaboration software&lt;/h3&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Miro&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Collaborative whiteboard platform for brainstorming and visual planning.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Brainstorming, workshops, and visual planning.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Provides an infinite canvas for mapping ideas and workflows.&lt;/li&gt;



&lt;li&gt;Includes templates for agile, design thinking, and strategy sessions.&lt;/li&gt;



&lt;li&gt;Supports real-time and asynchronous collaboration.&lt;/li&gt;



&lt;li&gt;Integrates with tools such as Slack, Jira, and Google Drive.&lt;/li&gt;
&lt;/ul&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;FigJam&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lightweight visual collaboration tool designed for quick ideation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for:&lt;/strong&gt; Design teams and lightweight visual collaboration.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Offers a simple interface for fast brainstorming and feedback.&lt;/li&gt;



&lt;li&gt;Integrates closely with design workflows in Figma.&lt;/li&gt;



&lt;li&gt;Supports real-time collaboration with comments and reactions.&lt;/li&gt;



&lt;li&gt;Works well for product, design, and UX teams.&lt;/li&gt;
&lt;/ul&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Mural&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Visual collaboration platform designed for structured workshops.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Best for: &lt;/strong&gt;Structured workshops and enterprise collaboration.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Provides facilitation tools for running guided sessions.&lt;/li&gt;



&lt;li&gt;Supports remote workshops, training, and team exercises.&lt;/li&gt;



&lt;li&gt;Organizes content across boards and collaborative spaces.&lt;/li&gt;



&lt;li&gt;Designed for larger teams and enterprise environments.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Mistakes to avoid with remote collaboration tools&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even the best remote collaboration tools can create problems without clear structure and priorities. Teams often focus too heavily on features while overlooking usability, security, and communication habits.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Tools that are difficult to learn may go unused or create inconsistent workflows across teams. At the same time, some collaboration platforms collect large amounts of metadata or customer content in the background, which can create privacy concerns for sensitive work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Clear communication guidelines, defined tool ownership, and strong privacy standards help remote collaboration stay organized, secure, and easy to manage.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to choose remote collaboration tools for your team&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Choosing the right tools depends less on features and more on how your team works.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Match tools to your workflow&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Start by identifying how your team communicates, shares information, and makes decisions. Choose tools that support those patterns instead of forcing new ones.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Reduce tool overload&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Using several tools is normal, but too many can slow teams down and create confusion. Give each tool a clear role within your workflow.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Protect sensitive conversations&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Remote collaboration tools often handle internal discussions, client data, and strategic decisions. Many platforms collect metadata or use customer content to improve AI systems.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Check integrations and admin controls&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your tools should work together. Admin controls are also important for managing access, permissions, and security across the organization.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/&quot;&gt;Try Proton Workspace&lt;/a&gt;
&lt;/div&gt;
</content:encoded><category>For business</category><author>Tom Odlin</author></item><item><title>Google is ending Gmail “Send as” support for third-party accounts</title><link>https://proton.me/blog/gmail-ends-send-as-third-party</link><guid isPermaLink="true">https://proton.me/blog/gmail-ends-send-as-third-party</guid><description>The Gmail “Send as” feature is disappearing. See what&apos;s changing, who will be affected, and where you can find a more private alternative.</description><pubDate>Fri, 14 Aug 2026 09:27:58 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you are using &lt;a href=&quot;https://proton.me/blog/is-gmail-secure&quot;&gt;Gmail&lt;/a&gt; to send messages from your &lt;a href=&quot;https://proton.me/business/mail/outlook-alternative&quot;&gt;Microsoft Outlook&lt;/a&gt; or Yahoo email address, that feature is going away. Here&amp;#8217;s what&amp;#8217;s you need to know.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google announced that it&amp;#8217;s ending support for Gmail “Send as,” a setting that lets you send messages from a third-party address through Gmail&amp;#8217;s own interface, citing “disproportionate maintenance resources.”&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is happening in stages: Google has begun restricting new Gmail “Send as” configurations for third-party addresses on the web, while existing configurations will continue to work during the transition. The feature will be fully removed in January 2027. At that point, according to Google&amp;#8217;s own support page, &amp;#8220;you will no longer be able to send mail from third-party email accounts in Gmail on the web or in the Gmail mobile apps.” You will still be able to read and check third-party emails inside the Gmail app.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The company is also ending Gmailify in January 2027, a feature that extends Gmail&amp;#8217;s own spam protection and &lt;a href=&quot;https://proton.me/business/blog/email-management&quot;&gt;inbox organization&lt;/a&gt; to third-party accounts.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to check if you can still send as a third-party email address in Gmail&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you previously set up Gmail’s “Send as” feature for a third-party email address, your existing configuration should continue to work for now. To check, start composing a new message and look at the &lt;strong&gt;From&lt;/strong&gt; field. If another email address appears there, you can still select it and send from that address.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1080&quot; height=&quot;1289&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1080,h_1289,c_scale/f_auto,q_auto/v1786692046/wp-pme/gmail-send-as/gmail-send-as.png?_i=AA&quot; alt=&quot;The Gmail From field on Android&quot; class=&quot;wp-post-272097 wp-image-272098&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;120 KB&quot; data-optsize=&quot;32 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;73.7&quot; data-version=&quot;1786692046&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786692046/wp-pme/gmail-send-as/gmail-send-as.png?_i=AA 1080w, https://res.cloudinary.com/dbulfrlrz/images/w_251,h_300,c_scale/f_auto,q_auto/v1786692046/wp-pme/gmail-send-as/gmail-send-as.png?_i=AA 251w, https://res.cloudinary.com/dbulfrlrz/images/w_858,h_1024,c_scale/f_auto,q_auto/v1786692046/wp-pme/gmail-send-as/gmail-send-as.png?_i=AA 858w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_917,c_scale/f_auto,q_auto/v1786692046/wp-pme/gmail-send-as/gmail-send-as.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1080px) 100vw, 1080px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you never set up a third-party “Send as” address, there’s little reason to start now, given that the feature is scheduled to disappear in January 2027.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Not the first time when Google ends useful features&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This isn&amp;#8217;t the first time Google has retired a feature related to privacy or security after deciding that maintaining it was no longer worthwhile.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/google-discontinues-dark-web-report&quot;&gt;Dark Web Report&lt;/a&gt;, which scanned for your name, email, passwords, and other personal data surfacing in breaches, was shut down in early 2026 because, as the company put it, the feature “failed to provide useful follow-up steps.” Google said it would instead focus on tools that offer clearer, actionable steps, but it has not introduced a direct replacement for Dark Web Report.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/privacy-sandbox-dead&quot;&gt;Privacy Sandbox&lt;/a&gt;, Google&amp;#8217;s six-year effort to replace third-party cookies with a less invasive way to target ads, was also scaled back significantly in 2025. Google retired many of its core advertising technologies after citing “low levels of adoption,” although some Privacy Sandbox technologies remain supported.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Send from your Gmail address in Proton Mail&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Mail offers similar “Send as” convenience to the functionality Google is removing: Through &lt;a href=&quot;https://proton.me/easyswitch&quot;&gt;Easy Switch&lt;/a&gt;, you can connect your Gmail account to Proton Mail and send and receive messages from your Gmail address without leaving Proton Mail&amp;#8217;s interface.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Easy Switch also imports your existing Gmail message history and forwards new incoming Gmail messages to your Proton Mail inbox. Messages forwarded from Gmail also benefit from Proton Mail&amp;#8217;s other privacy protections: Proton &lt;a href=&quot;https://proton.me/support/email-tracker-protection&quot;&gt;removes known email trackers&lt;/a&gt;, blocks &lt;a href=&quot;https://proton.me/blog/pixel-tracking&quot;&gt;spy pixels&lt;/a&gt;, cleans tracking links, filters spam, and stores messages with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-access encryption&lt;/a&gt;. You can also set up &lt;a href=&quot;https://proton.me/business/mail/custom-email-domain&quot;&gt;custom domains&lt;/a&gt; to send and receive messages to @yourbusiness.com addresses.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As long as you&amp;#8217;re still sending from your Gmail address, however, Gmail remains part of the delivery process for messages sent to non-Proton recipients, which means Google will still be able to access your data — unless you use &lt;a href=&quot;https://proton.me/support/password-protected-emails&quot;&gt;password protection&lt;/a&gt;. If you eventually decide to leave Google behind, you can &lt;a href=&quot;https://proton.me/blog/delete-gmail-account&quot;&gt;delete your Gmail account&lt;/a&gt; and fully move to Proton Mail for a more private &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail alternative&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>News</category><author>Elena Constantinescu</author></item><item><title>Employee offboarding security: how to protect your business</title><link>https://proton.me/business/blog/employee-offboarding-security</link><guid isPermaLink="true">https://proton.me/business/blog/employee-offboarding-security</guid><description>Learn how to secure employee offboarding by revoking access, rotating credentials, and preventing data exposure after staff leave.</description><pubDate>Thu, 13 Aug 2026 13:14:05 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;When organizations evaluate what’s threatening their enterprise security, they often focus on preventing large-scale attacks. However, the most critical risks are far less visible: the mishandling of account access and credentials when an employee leaves a company can be just as dangerous.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The risk isn’t only what former employees take with them, it’s what they can still access after they’ve left. Simple oversights such as failing to remove an admin from a cloud drive or leaving shared credentials unrotated can create weeks of exposure. In business environments, especially those with remote teams or high turnover, ensuring that data is handled safely during offboarding can feel like trying to contain a slow, persistent leak.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We’ll explore this often-overlooked security layer to help your organization improve &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt;. This includes what makes ex-employee access so dangerous, how orphaned or unrevoked credentials impact organizations, and – most importantly – what practical steps can reduce this risk.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Understanding security hazards during offboarding&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employee offboarding security is critical for every organization, no matter what size. According to Security Magazine, as of 2025, &lt;a href=&quot;https://www.securitymagazine.com/articles/101683-the-security-risk-no-one-talks-about-during-layoffs-offboarding&quot;&gt;nearly 90% of former employees&lt;/a&gt; maintain access to sensitive corporate systems and data after their departure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A single missed login can leave a gap in your defenses that may be exploited. Not revoking access for those former employees creates significant risk. Even a single instance of misuse could lead to prolonged, undetected data exposure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The most common risks include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Retained access to business tools such as email, cloud platforms, and CRM systems — or, even worse, a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Shared or unrotated credentials&lt;/li&gt;



&lt;li&gt;Active admin or privileged accounts with elevated system access&lt;/li&gt;



&lt;li&gt;Forgotten service accounts and API keys&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;The consequences of overlooking offboarding&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here’s how weak credential management during offboarding translates into real-world impact:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Data exfiltration:&lt;/strong&gt; A departing employee may retain access to repositories, internal systems, or sensitive data sources.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Credentials that outlive the employee relationship:&lt;/strong&gt; Shared credentials that are not rotated can remain usable even after an employee moves to a new employer.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Intentional misuse or sabotage:&lt;/strong&gt; In cases of conflict, lingering access can be used to delete, alter, or expose data.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Compliance and regulatory exposure:&lt;/strong&gt; Regulations such as &lt;a href=&quot;https://proton.me/business/gdpr&quot;&gt;GDPR&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/healthcare&quot;&gt;HIPAA&lt;/a&gt; require strict control over data access. Failure to revoke credentials can result in fines and legal consequences.&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These are real, recurring issues that can lead to data breaches, operational disruption, reputational damage, and financial loss.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The specific risks of unmanaged credentials&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;Credential management&lt;/a&gt; is one of your greatest tools when it comes to smooth, secure offboarding. Despite this, many businesses fail to deploy a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; effectively, increasing their exposure. Some of the most common credential issues when it comes to offboarding include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Shared vaults: &lt;/strong&gt;If a team uses a shared &lt;a href=&quot;https://proton.me/business/pass/password-vault&quot;&gt;password vault&lt;/a&gt; and the departing employee isn’t removed instantly, they might keep logging in undetected.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Superuser and privileged credentials: &lt;/strong&gt;High-privilege accounts — think HR portals, finance tools, server dashboards — pose outsized risk if access isn&amp;#8217;t revoked immediately.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;SaaS business tool logins: &lt;/strong&gt;Many companies accumulate a sprawl of SaaS tools, each with separate logins. It’s easy to overlook a few.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Cloud storage and collaboration platforms: &lt;/strong&gt;Tools like &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;, &lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt;, and &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Microsoft 365&lt;/a&gt; often hold years of sensitive documents that remain accessible if access isn&amp;#8217;t revoked.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;High-level accounts are especially hazardous if the departing employee (or someone who later compromises their still-active credentials) realizes they can still interact with sensitive business info, download files, or change records undetected. Shared logins multiply the risk.&lt;br&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A security checklist for offboarding&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Since forgetting just one access point can create a gap in an organization’s defenses, establishing IT offboarding best practices is key.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Immediately:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Revoke &lt;a href=&quot;https://proton.me/business/blog/sso-integration&quot;&gt;SSO&lt;/a&gt;, email, and password manager access immediately upon termination or resignation.&lt;/li&gt;



&lt;li&gt;Lock out all connected devices: laptops, mobiles, tablets – remotely, if possible.&lt;/li&gt;



&lt;li&gt;Disable access to cloud storage, internal portals, and admin dashboards.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Within 24 hours:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Rotate any shared credentials the employee had access to. This includes shared logins, vendor accounts, and server or infrastructure credentials.&lt;/li&gt;



&lt;li&gt;Update API keys or service tokens used or generated by the departing employee.&lt;/li&gt;



&lt;li&gt;Notify team leads and IT so they can double-check lesser-known tools.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;By the end of the week:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Conduct a detailed audit for possible “orphan” privileges. Look for continuing access in SaaS tools, cloud platforms, admin consoles, and development environments.&lt;/li&gt;



&lt;li&gt;Review admin roles and permissions across critical apps for any that still reference the departed user.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;30-day review:&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Confirm, once again, that the former employee&amp;#8217;s credentials and access points are all disabled, and no logins or activity have occurred.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It is important to document each step and save audit logs to meet compliance needs and keep things straight for internal reviews.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For a full guide, our &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding checklist&lt;/a&gt; can help your business treat offboarding as a complete security operation.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Regulatory risks of poor offboarding&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data breaches&lt;/a&gt; aren’t the sole risk when it comes to offboarding. Companies subject to GDPR, HIPAA, or financial reporting rules must prove they restrict access to personal and confidential data as soon as someone leaves. Failure to revoke digital credentials is often considered a compliance failure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Additionally, the rise of remote work has made credential management during offboarding a lot harder. Devices can be miles away, and sometimes users forget they are still logged in. With cloud apps everywhere, even a single unrevoked permission can mean weeks of silent exposure.&lt;br&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If ex-employees can still touch company data (and especially &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;personally identifiable information&lt;/a&gt;), it’s a potential breach – and you can still be fined even if no one abuses the privilege. Zero-knowledge vaults, like those provided by Proton Pass for Business, offer an extra layer of assurance.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is why proactive offboarding is essential for maintaining high compliance standards: keep in mind that it’s faster and safer to restore access than to clean up after an attack or leak. If you’re in doubt, disable first and audit later. &lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Password managers: the smart solution for secure offboarding&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As more companies work remotely and rely on dozens or even hundreds of online tools, manual processes just can’t keep up. In modern, distributed environments, a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business can make offboarding almost instant – and much safer.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;br&gt;As a leader in privacy and compliance, Proton has developed a whole security ecosystem. From the beginning, Proton Pass for Business has been designed&lt;strong&gt; &lt;/strong&gt;to ease security routines for companies.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Using Proton Pass for Business, administrators can revoke access immediately and verify, through secure audit logs, that no unauthorized activity occurs after departure, and that no unauthorized activity took place afterward.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You’ll find more information about Proton’s security principles and solutions on &lt;a href=&quot;https://proton.me/business/trust&quot;&gt;Proton Trust Center&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business is open source and audited, allowing business leaders and &lt;a href=&quot;https://proton.me/business/pass/for-it-teams&quot;&gt;IT teams&lt;/a&gt; to verify how credentials are stored and what happens when a vault is revoked. You can ensure consistent security across distributed teams to support better offboarding practices in future, including:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Admin controls that make removing access to the password manager a one-step job.&lt;/li&gt;



&lt;li&gt;Vault and access logs, so you always know who did what through the password manager, even after employment ends.&lt;/li&gt;



&lt;li&gt;Alignment with privacy laws, backed by Swiss regulations, for added legal confidence; even in the busiest season or turbulent staff changes, no gap is left open by accident.&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Settle for nothing less than airtight offboarding&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Organizations can’t afford to leave access gaps during employee transitions. A structured, security-first approach — supported by tools like Proton Pass — helps protect critical assets and maintain trust.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security incidents often stem from small oversights, but a simple, automated system can remove human error from the most unpredictable moment.&lt;br&gt;&lt;br&gt;Employee offboarding security shouldn’t be treated as an isolated HR or IT task. Instead, organizations must build a security culture that includes both onboarding and offboarding, with employee awareness, adherence to best practices, compliance, and adequate technology to mitigate risks.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data breaches don’t wait for process perfection. If you want to strengthen your digital walls and support a culture of security, find out more about how Proton Pass for Business helps you enhance offboarding cybersecurity by &lt;a href=&quot;https://proton.me/business/contact?pd=pass&quot;&gt;contacting our sales team&lt;/a&gt;.&lt;br&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Frequently asked questions about secure employee offboarding&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What is employee offboarding security?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employee offboarding security is the process of protecting an organization’s digital assets and data by ensuring that departing staff can no longer access sensitive accounts, credentials, or resources after they leave. This includes revoking logins, rotating shared credentials, and confirming that all privileges are removed to prevent unauthorized access.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Why is offboarding important for security?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Offboarding is key for security because ex-employees who retain access can cause accidental or intentional data leaks, compliance violations, or service interruptions. Without strict offboarding, confidential business information and customer data are at risk even after someone has left.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What steps ensure secure offboarding?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To ensure secure offboarding, we recommend this approach:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Terminate SSO/password manager access immediately after notice or on the last day.&lt;/li&gt;



&lt;li&gt;Rotate any shared or admin passwords within 24 hours.&lt;/li&gt;



&lt;li&gt;Audit all tools and platforms for lingering permissions within a week.&lt;/li&gt;



&lt;li&gt;Do a final review after 30 days to catch missed access points.&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How can I revoke ex-employee access?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can revoke access from ex-employees by disabling their accounts on all services, removing them from shared vaults, and using dedicated admin controls in a password manager like Proton Pass for Business. Immediate action is best — the sooner you cut off access, the lower the chance of a security incident.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>How to create a data breach response plan: a step-by-step guide for SMBs</title><link>https://proton.me/business/blog/data-breach-response-plan</link><guid isPermaLink="true">https://proton.me/business/blog/data-breach-response-plan</guid><description>Learn how to build a data breach response plan for SMBs, with clear steps for detection, containment, investigation, and recovery.</description><pubDate>Thu, 13 Aug 2026 12:40:54 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breach&lt;/a&gt; can escalate quickly for a small or mid-sized business (SME). What begins as a suspicious login, a misdirected file, a compromised mailbox, or a minor &lt;a href=&quot;https://proton.me/business/blog/ransomware-threats-smbs&quot;&gt;ransomware&lt;/a&gt; incident can turn into operational disruption, customer concern, and urgent legal questions in a matter of hours.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For many businesses, the pressure is both technical and regulatory. In most jurisdictions, a personal data breach may trigger decisions about internal escalation, evidence preservation, customer communication, and whether notification to a data protection authority — such as the ICO in the &lt;a href=&quot;https://proton.me/business/blog/data-breach-prevention-uk&quot;&gt;UK&lt;/a&gt; or an EU supervisory authority under GDPR — is required within a limited timeframe.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A practical data breach response plan gives SMBs something much more useful than a long document full of abstract policy language: A clear working guide that helps them assess what happened, contain the incident, communicate with the right people, and document each step properly.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This article is designed to be that kind of reference: something your team can build on, save, and return to when you&amp;#8217;re under pressure. &lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What a data breach response plan should do&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data breach response plan is different from a broader&lt;a href=&quot;https://proton.me/blog/incident-response&quot;&gt; incident response&lt;/a&gt; document. An incident response plan may cover a wide range of cybersecurity events, including &lt;a href=&quot;https://protonvpn.com/blog/what-is-malware&quot;&gt;malware&lt;/a&gt; infections, service outages, insider misuse, and &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt; issues.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By contrast, a data breach response plan is more specific. It focuses on incidents involving personal data and on the actions required when that data is lost, exposed, altered, accessed without authorization, or made unavailable in a way that creates risk for individuals.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A generic &lt;a href=&quot;https://proton.me/business/blog/incident-response&quot;&gt;cybersecurity incident response plan&lt;/a&gt; can help teams stabilize systems, but it may not provide enough guidance on what to do when the event involves personal data, potential harm to individuals, and reporting obligations.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many privacy regulations define personal data breaches broadly enough to include not only deliberate attacks, but also accidental disclosure, loss, destruction, and availability failures. For example, the ICO and GDPR both recognize that breaches can result from malicious incidents as well as human error or system failures.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In practice, a strong data breach response plan should help your business do six things well:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Identify whether a personal data breach may have taken place&lt;/li&gt;



&lt;li&gt;Assess the likely risk to individuals&lt;/li&gt;



&lt;li&gt;Contain further exposure quickly&lt;/li&gt;



&lt;li&gt;Coordinate internal, regulatory, and external communication&lt;/li&gt;



&lt;li&gt;Investigate the cause and preserve evidence&lt;/li&gt;



&lt;li&gt;Recover safely and improve the plan afterwards&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It should also make ownership clear. In a real incident, confusion around roles wastes time. Your plan should dictate who leads technical containment, who assesses reporting thresholds, who approves notifications, who communicates with customers or partners, and who keeps the breach log and documentation up to date.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;1. Detect the breach and make an initial assessment&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The first step is to establish whether a personal data breach has actually occurred and whether the regulatory clock may already be running.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Under the GDPR, the 72-hour window starts when an organization becomes aware of a reportable personal data breach, rather than when the underlying incident first occurred. Regulators such as the UK&amp;#8217;s ICO also recommend starting a breach log immediately, even before it is clear whether notification will ultimately be required.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A business data breach response plan should tell staff exactly what to do when they spot something suspicious. That might be an employee reporting a phishing-related account takeover, a cloud folder shared publicly by mistake, a lost laptop, ransomware affecting file access, or a processor warning you about potential customer data exposure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At this point, you need to collect enough information to classify the event without wasting time trying to get situated.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At this stage, your plan should prompt a short initial assessment:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;What happened, and how was it detected?&lt;/li&gt;



&lt;li&gt;What systems, accounts, or devices are affected?&lt;/li&gt;



&lt;li&gt;What categories of personal data may be involved?&lt;/li&gt;



&lt;li&gt;How many individuals may be impacted?&lt;/li&gt;



&lt;li&gt;Is the data encrypted, pseudonymized, or otherwise protected?&lt;/li&gt;



&lt;li&gt;Is the data merely at risk, or is there evidence of access, exfiltration, alteration, or loss of availability?&lt;/li&gt;



&lt;li&gt;What immediate harms could follow for individuals?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Regulators consistently emphasize that breach risk should be assessed in terms of the potential negative consequences for individuals, including identity theft, fraud, financial loss, reputational damage, and loss of confidentiality. This is the framework your plan should use from the beginning.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;2.  Contain the breach before it spreads&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once there is a credible indication that &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;personally identifiable data&lt;/a&gt; may be exposed, containment becomes the priority. Containment is simple: the aim is to stop further unauthorized access, disclosure, or loss.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your containment actions will depend on the breach type. Usually, they should include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Disabling compromised accounts&lt;/li&gt;



&lt;li&gt;Revoking shared or exposed credentials&lt;/li&gt;



&lt;li&gt;Forcing password resets&lt;/li&gt;



&lt;li&gt;Rotating admin credentials, API keys, and access tokens&lt;/li&gt;



&lt;li&gt;Isolating affected endpoints or servers&lt;/li&gt;



&lt;li&gt;Removing malicious forwarding rules or persistence mechanisms&lt;/li&gt;



&lt;li&gt;Locking down file-sharing permissions&lt;/li&gt;



&lt;li&gt;Suspending risky integrations or third-party access&lt;/li&gt;



&lt;li&gt;Preserving affected systems in place when forensic review is likely&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credential security is often central to managing a breach and preventing further events. Proton’s 2026 &lt;a href=&quot;https://proton.me/business/blog/data-breach-observatory-2026&quot;&gt;Data Breach Observatory&lt;/a&gt; update found that passwords were exposed in 47% of incidents, while names and email addresses appeared in nearly 9 out of 10 breaches. Many breaches create a follow-on credential risk even when the original attack path is still being investigated.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A strong plan should separate “containment” from “recovery.” Containment is about shutting down the breach, and recovery comes later. If teams rush straight into cleanup without preserving what happened, they may lose evidence, miss the root cause, or make regulatory reporting more difficult.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;3. Communicate internally, externally, and to regulatory agencies&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even when the technical response is moving in the right direction, communication can still break down quickly. Usually this is because different teams have different levels of visibility into the incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In addition, leadership may need answers before the facts are fully confirmed. Legal and privacy leads may be assessing reporting thresholds while customer-facing teams are already being asked for reassurance. Without a clear structure, the result is often delay, inconsistency, or messaging that creates more confusion than clarity.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;During an incident, the aim is to give stakeholders, customers, and regulators the information they need in a timely and responsible way, without sharing unnecessary details that could increase risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In practice, your plan should separate communication into three distinct tracks:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Internal communication&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Start with a clear escalation path. As soon as a potential breach is identified, the right people must be informed quickly and aligned on the same facts. In most SMBs, that usually includes the incident lead, IT or security, senior management, the legal or privacy owner, as well as any operational lead responsible for the affected data. At this stage, the priority is clarity: what is known, what is still uncertain, what is already being done, and what decisions need to happen next.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Regulatory communication&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If the breach is likely to result in a risk to individuals&amp;#8217; rights and freedoms, it needs to be reported to the relevant data protection authority. Under the GDPR, for example, this notification generally must be made within 72 hours of becoming aware of the breach.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many supervisory authorities also recognize that organizations may provide additional information in phases if all the facts are not yet available at the time of the initial notification. Your plan should make ownership clear here: who assesses the reporting threshold, who prepares the notification, and who approves it before submission.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Communication with affected individuals&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some breaches also require direct communication with the people affected. When the incident is likely to result in a high risk to individuals’ rights and freedoms, they must be informed without undue delay.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That communication should be clear, direct, and practical, explaining:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;What happened&lt;/li&gt;



&lt;li&gt;What are the likely consequences&lt;/li&gt;



&lt;li&gt;What the organization is doing in response&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Templates can save time and help keep messaging consistent under pressure.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;4.&amp;nbsp; Investigate the cause and preserve evidence&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once the incident is stabilized,&lt;strong&gt; &lt;/strong&gt;the investigation needs to begin properly. Aim to answer three questions:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;How did the breach happen?&lt;/li&gt;



&lt;li&gt;What data was affected?&lt;/li&gt;



&lt;li&gt;Is the threat still present?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy regulations generally require organizations to maintain effective breach detection, investigation, and internal reporting procedures. Under the GDPR, organizations must also document personal data breaches regardless of whether notification is ultimately required.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your investigation doesn’t always mean conducting a full-scale forensic engagement from the first hour. However, your plan should define when outside expertise is needed. This may include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Ransomware or suspected exfiltration&lt;/li&gt;



&lt;li&gt;Compromise of privileged accounts&lt;/li&gt;



&lt;li&gt;Uncertainty over the volume or type of data accessed&lt;/li&gt;



&lt;li&gt;Incidents involving regulated or especially sensitive data&lt;/li&gt;



&lt;li&gt;Third-party processors or cloud providers with incomplete visibility&lt;/li&gt;



&lt;li&gt;Any event likely to draw regulatory scrutiny or legal claims&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Evidence preservation is especially important at this stage. Any data pertaining to the breach may become relevant later, so preserve:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Logs&lt;/li&gt;



&lt;li&gt;Affected endpoints&lt;/li&gt;



&lt;li&gt;Email headers&lt;/li&gt;



&lt;li&gt;Authentication records&lt;/li&gt;



&lt;li&gt;Firewall data&lt;/li&gt;



&lt;li&gt;Screenshots&lt;/li&gt;



&lt;li&gt;Access-control changes&lt;/li&gt;



&lt;li&gt;Vendor communication&lt;/li&gt;



&lt;li&gt;Evidence of internal decisions &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If teams wipe devices, rebuild servers, or rotate everything without recording what changed, they may make it harder to prove the scope of the breach or demonstrate that the response was appropriate.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;5. Recover and reduce the chance of repeated exposure&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recovery is the stage where operations start moving back towards normal, but it should not mean simply turning systems back on. A breach that is technically “over” can still create ongoing risk if stolen credentials remain valid, weak controls stay in place, or exposed data is already being misused elsewhere.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your recovery plan should cover:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Restoring systems from clean backups where appropriate&lt;/li&gt;



&lt;li&gt;Confirming that malicious access has been removed&lt;/li&gt;



&lt;li&gt;Rotating credentials across affected users, admins, shared accounts, integrations, and service accounts&lt;/li&gt;



&lt;li&gt;Reviewing MFA enforcement&lt;/li&gt;



&lt;li&gt;Tightening access controls based on actual job needs&lt;/li&gt;



&lt;li&gt;Checking logging and alerting gaps&lt;/li&gt;



&lt;li&gt;Validating third-party remediation where processors or vendors were involved&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is also a good moment to revisit credential hygiene at a broader level. Proton’s &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data Breach Observatory&lt;/a&gt; exists partly because many breaches never become public promptly, even though leaked data may already be circulating on the dark web. Its 2026 analysis found that contact information appeared in 75% of breaches and passwords in 47%, which shows how often a single incident can create broader account compromise risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recovery should include checking whether exposed credentials, reused passwords, or unmanaged shared logins could turn one breach into several more. A secure &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; can support recovery and long-term control by making credential rotation, access review, and secure sharing more manageable at scale.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;6. Run a post-incident review and update the plan&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A breach response plan is only useful if it improves after real use. Even just practicing your response plan can help you understand how it will work during a real breach, because both exercises and real incidents reveal gaps that documents alone will not show.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your review should be honest and specific. Start with questions like these:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;How quickly was the breach detected?&lt;/li&gt;



&lt;li&gt;When did the business become aware?&lt;/li&gt;



&lt;li&gt;Was the reporting threshold assessed correctly and quickly enough?&lt;/li&gt;



&lt;li&gt;Did roles and approvals work in practice?&lt;/li&gt;



&lt;li&gt;Were customers or staff left waiting because templates or ownership were unclear?&lt;/li&gt;



&lt;li&gt;What evidence was challenging to gather?&lt;/li&gt;



&lt;li&gt;Did credential management slow down containment or recovery?&lt;/li&gt;



&lt;li&gt;What controls, training, or vendor requirements now need to change?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You should also document the rationale behind your decisions, especially if you decided not to notify individuals or report to the relevant supervisory authority. Record-keeping is required for all personal data breaches, not just notifiable ones.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Over time, this review process should turn your plan into a living document: clearer thresholds, better contacts, better templates, better logging, better credential controls, and more realistic playbooks for the incidents your business is actually likely to face.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Keep your breach response practical before you need it&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data breach response plan is meant to help your team make better decisions under pressure. For SMBs, the difference usually comes down to preparation: knowing how to recognize a reportable breach, who owns the first response, how to contain it, what applicable data protection regulations require, and how to communicate clearly while facts are still developing.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A plan built in advance will not remove the pressure in case of a breach, but it can make the response faster, clearer, and easier to defend when time is limited.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The more your business depends on digital systems, shared access, cloud apps, and customer data, the less room there is for improvised &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt; during an incident.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business can support your data breach response plan with:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Enhanced visibility into employee activity with detailed reporting and logs&lt;/li&gt;



&lt;li&gt;Enforceable, customizable team policies to ensure 2FA and strong passwords protect your business network&lt;/li&gt;



&lt;li&gt;Secure data storage with end-to-end encryption &lt;/li&gt;



&lt;li&gt;Dark web monitoring that actively scans for your business data &lt;/li&gt;



&lt;li&gt;Proton Sentinel, a high security program that prevents account takeovers.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Protect your credentials before a breach happens — try a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business.&lt;/p&gt;
</content:encoded><category>For business</category><author>Ben Wolford</author></item><item><title>How to improve your Google privacy settings and why you should</title><link>https://proton.me/blog/google-privacy-settings</link><guid isPermaLink="true">https://proton.me/blog/google-privacy-settings</guid><description>A step-by-step guide to Google privacy settings on Google Account, Android, and Chrome – and where they have fallen short, cited in lawsuits.</description><pubDate>Thu, 13 Aug 2026 10:18:39 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google runs on an ad-based business model, with its parent company Alphabet generating more than 70% of its total revenue from online advertising. The problem is that targeted advertising becomes &lt;a href=&quot;https://proton.me/blog/what-is-your-data-worth&quot;&gt;more valuable when it is backed by more data&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;And that comes with a steep price: your privacy.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;What you search for, where you go, what you watch, which apps you use, and the websites you visit are &lt;a href=&quot;https://proton.me/blog/what-is-your-data-worth-to-google&quot;&gt;all valuable signals to Google&lt;/a&gt;. If you find that level of data collection intrusive, tightening your Google privacy settings is a good place to start.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Advertising is not the only reason to pay attention to how Google handles your data. In 2026, Google &lt;a href=&quot;https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/&quot;&gt;changed its Search privacy controls&lt;/a&gt; so that saved media — including images, files, and audio or video recordings uploaded through services such as Search, Lens, Translate, and Maps — could be used to develop and improve its AI models (such as &lt;a href=&quot;https://proton.me/lumo/ai/is-gemini-safe&quot;&gt;Gemini&lt;/a&gt;) unless you opted out.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google privacy settings are scattered across several places, and changing one setting doesn’t necessarily stop data collection elsewhere. This guide walks through the Google Account, Android settings, and Google Chrome settings worth changing to reduce how much activity Google saves, links to you, and uses for advertising, personalization, and AI development.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#how-to&quot;&gt;How to lock down your Google privacy settings&lt;/a&gt;
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#google-account&quot;&gt;Google Account privacy settings&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#android&quot;&gt;Android privacy settings&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#chrome&quot;&gt;Google Chrome privacy settings&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#lawsuits&quot;&gt;What lawsuits reveal about Google privacy settings&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#degoogle&quot;&gt;DeGoogle your life, starting with email&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;how-to&quot; class=&quot;wp-block-heading&quot;&gt;How to lock down your Google privacy settings&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s how you can control how much Google knows about you by configuring the default Google Account settings and Android OS permissions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you use a &lt;a href=&quot;https://proton.me/business/google-workspace-alternative&quot;&gt;Google Workspace&lt;/a&gt; account for work or school, your organization may manage or restrict some account and device settings. How much control you have depends on whether you’re using a personal device with a work profile or a fully managed company or school device.&lt;/p&gt;



&lt;h3 id=&quot;google-account&quot; class=&quot;wp-block-heading&quot;&gt;Google Account privacy settings&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your Google Account ties most of your activity with Google&amp;#8217;s servers, whether you&amp;#8217;re watching something on &lt;a href=&quot;https://protonvpn.com/blog/youtube-alternatives&quot;&gt;YouTube&lt;/a&gt;, sending an email using &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail&lt;/a&gt;, or searching restaurants on Google Maps.&amp;nbsp;The settings below determine how much of that data gets saved when you&amp;#8217;re signed in to Google, for how long, and what it&amp;#8217;s used for.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off Personalize Search&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By default, Google shows your personalized results in Search based on data saved in your account, which can be used for things like auto-complete suggestions. In &lt;strong&gt;Data &amp;amp; privacy&lt;/strong&gt;, select &lt;strong&gt;Personalize Search&lt;/strong&gt; (google.com/search-personalization/) and toggle off &lt;strong&gt;Personalize Search&lt;/strong&gt; for a more private experience.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1378&quot; height=&quot;918&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1378,h_918,c_scale/f_auto,q_auto/v1786604480/wp-pme/gogle-privacy-settings-1/gogle-privacy-settings-1.png?_i=AA&quot; alt=&quot;Google Account settings show to turn off Personalize Search&quot; class=&quot;wp-post-271421 wp-image-271446&quot; style=&quot;width:600px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;126 KB&quot; data-optsize=&quot;27 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;78.4&quot; data-version=&quot;1786604480&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604480/wp-pme/gogle-privacy-settings-1/gogle-privacy-settings-1.png?_i=AA 1378w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_200,c_scale/f_auto,q_auto/v1786604480/wp-pme/gogle-privacy-settings-1/gogle-privacy-settings-1.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_682,c_scale/f_auto,q_auto/v1786604480/wp-pme/gogle-privacy-settings-1/gogle-privacy-settings-1.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_512,c_scale/f_auto,q_auto/v1786604480/wp-pme/gogle-privacy-settings-1/gogle-privacy-settings-1.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1378px) 100vw, 1378px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you feel like Google Search is too intrusive, consider these &lt;a href=&quot;https://proton.me/learn/european-alternatives/european-search-engines&quot;&gt;European search engines&lt;/a&gt;.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off Web &amp;amp; App Activity&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This logs searches, websites visited via Chrome, and app usage, feeding into Google&amp;#8217;s ad and recommendation systems. Go to &lt;strong&gt;Data &amp;amp; privacy&lt;/strong&gt; → &lt;strong&gt;Web &amp;amp; App Activity&lt;/strong&gt; (myactivity.google.com/personalization/settings/waa), click &lt;strong&gt;Turn off&lt;/strong&gt; → &lt;strong&gt;Turn off and delete activity&lt;/strong&gt;, and deselect everything under &lt;strong&gt;Subsettings&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1302&quot; height=&quot;1842&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1302,h_1842,c_scale/f_auto,q_auto/v1786604488/wp-pme/gogle-privacy-settings-2/gogle-privacy-settings-2.png?_i=AA&quot; alt=&quot;Google Privacy settings shows how to turn off Web &amp;amp; App Activity&quot; class=&quot;wp-post-271421 wp-image-271470&quot; style=&quot;width:700px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;334 KB&quot; data-optsize=&quot;80 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;76.2&quot; data-version=&quot;1786604488&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604488/wp-pme/gogle-privacy-settings-2/gogle-privacy-settings-2.png?_i=AA 1302w, https://res.cloudinary.com/dbulfrlrz/images/w_212,h_300,c_scale/f_auto,q_auto/v1786604488/wp-pme/gogle-privacy-settings-2/gogle-privacy-settings-2.png?_i=AA 212w, https://res.cloudinary.com/dbulfrlrz/images/w_724,h_1024,c_scale/f_auto,q_auto/v1786604488/wp-pme/gogle-privacy-settings-2/gogle-privacy-settings-2.png?_i=AA 724w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1087,c_scale/f_auto,q_auto/v1786604488/wp-pme/gogle-privacy-settings-2/gogle-privacy-settings-2.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1086,h_1536,c_scale/f_auto,q_auto/v1786604488/wp-pme/gogle-privacy-settings-2/gogle-privacy-settings-2.png?_i=AA 1086w&quot; sizes=&quot;auto, (max-width: 1302px) 100vw, 1302px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you prefer to keep&amp;nbsp;Web &amp;amp; App Activity on but still limit how long Google holds onto your data, click &lt;strong&gt;Choose an auto-delete option&lt;/strong&gt; instead of &lt;strong&gt;Turn off&lt;/strong&gt; and pick a window between 3, 18, and 36 months. If you&amp;#8217;re looking for an alternative to Google Chrome, consider switching to a &lt;a href=&quot;https://proton.me/learn/european-alternatives/european-web-browsers&quot;&gt;European web browser&lt;/a&gt; or explore our selection of &lt;a href=&quot;https://proton.me/blog/best-browser-for-privacy&quot;&gt;the best browsers for privacy&lt;/a&gt;.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off Search Services History and Save Media&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In June 2026, Google split what used to be part of Web &amp;amp; App Activity into two separate settings: &lt;strong&gt;Search Services History&lt;/strong&gt; and &lt;strong&gt;Search Services Personalization&lt;/strong&gt;. This covers Search, Lens, Translate, Maps, Shopping, Flights, Hotels, and News — and by default, media you upload through these (photos snapped for a Lens search, voice recordings from Search Live or Translate) can be saved and used to train Google&amp;#8217;s AI models unless you opt out.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you already turned off Web &amp;amp; App Activity expecting it to cover Search, this update means it no longer does.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To stop this, go to &lt;strong&gt;Data &amp;amp; privacy&lt;/strong&gt; → &lt;strong&gt;Search Services History&lt;/strong&gt; (myactivity.google.com/search-services/settings), uncheck &lt;strong&gt;Save Media&lt;/strong&gt;, and switch off &lt;strong&gt;Search Services History&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1484&quot; height=&quot;1274&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1484,h_1274,c_scale/f_auto,q_auto/v1786604500/wp-pme/gogle-privacy-settings-3/gogle-privacy-settings-3.png?_i=AA&quot; alt=&quot;Google Account settings shows how to disable Save media and Search Services History&quot; class=&quot;wp-post-271421 wp-image-271494&quot; style=&quot;width:600px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;449 KB&quot; data-optsize=&quot;78 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;82.6&quot; data-version=&quot;1786604500&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604500/wp-pme/gogle-privacy-settings-3/gogle-privacy-settings-3.png?_i=AA 1484w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_258,c_scale/f_auto,q_auto/v1786604500/wp-pme/gogle-privacy-settings-3/gogle-privacy-settings-3.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_879,c_scale/f_auto,q_auto/v1786604500/wp-pme/gogle-privacy-settings-3/gogle-privacy-settings-3.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_659,c_scale/f_auto,q_auto/v1786604500/wp-pme/gogle-privacy-settings-3/gogle-privacy-settings-3.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1484px) 100vw, 1484px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off YouTube History&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Activity involving the videos you watched or music you played on YouTube is saved separately. Go to &lt;strong&gt;Data &amp;amp; privacy&lt;/strong&gt; → &lt;strong&gt;YouTube History&lt;/strong&gt; → &lt;strong&gt;Saving your YouTube history &lt;/strong&gt;(myactivity.google.com/product/youtube/controls), click &lt;strong&gt;Turn off&lt;/strong&gt;,&lt;strong&gt; &lt;/strong&gt;and select &lt;strong&gt;Manage history&lt;/strong&gt; → &lt;strong&gt;Delete&lt;/strong&gt; → &lt;strong&gt;Delete all time&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1302&quot; height=&quot;1842&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1302,h_1842,c_scale/f_auto,q_auto/v1786604506/wp-pme/gogle-privacy-settings-4/gogle-privacy-settings-4.png?_i=AA&quot; alt=&quot;Google Account settings shows how to turn off YouTube History&quot; class=&quot;wp-post-271421 wp-image-271518&quot; style=&quot;width:700px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;254 KB&quot; data-optsize=&quot;59 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;76.9&quot; data-version=&quot;1786604506&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604506/wp-pme/gogle-privacy-settings-4/gogle-privacy-settings-4.png?_i=AA 1302w, https://res.cloudinary.com/dbulfrlrz/images/w_212,h_300,c_scale/f_auto,q_auto/v1786604506/wp-pme/gogle-privacy-settings-4/gogle-privacy-settings-4.png?_i=AA 212w, https://res.cloudinary.com/dbulfrlrz/images/w_724,h_1024,c_scale/f_auto,q_auto/v1786604506/wp-pme/gogle-privacy-settings-4/gogle-privacy-settings-4.png?_i=AA 724w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1087,c_scale/f_auto,q_auto/v1786604506/wp-pme/gogle-privacy-settings-4/gogle-privacy-settings-4.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1086,h_1536,c_scale/f_auto,q_auto/v1786604506/wp-pme/gogle-privacy-settings-4/gogle-privacy-settings-4.png?_i=AA 1086w&quot; sizes=&quot;auto, (max-width: 1302px) 100vw, 1302px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you prefer to keep&amp;nbsp;YouTube History on on but still limit how long Google holds onto your data, click &lt;strong&gt;Choose an auto-delete option&lt;/strong&gt; instead of &lt;strong&gt;Turn off&lt;/strong&gt; and pick a window between 3, 18, and 36 months.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off Location History / Timeline&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google moved Timeline to be stored on-device by default in late 2024, a change made partly in response to the location tracking lawsuits. To &lt;a href=&quot;https://proton.me/blog/how-to-disable-location-history&quot;&gt;disable Google location history&lt;/a&gt; and prevent the company from learning your routes, go to &lt;strong&gt;Data &amp;amp; privacy&lt;/strong&gt; → &lt;strong&gt;Timeline&lt;/strong&gt; (myactivity.google.com/activitycontrols?settings=location), click &lt;strong&gt;Turn off&lt;/strong&gt; → &lt;strong&gt;Turn off and delete activity&lt;/strong&gt;, and deselect everything under &lt;strong&gt;Subsettings&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1302&quot; height=&quot;1778&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1302,h_1778,c_scale/f_auto,q_auto/v1786604569/wp-pme/gogle-privacy-settings-5/gogle-privacy-settings-5.png?_i=AA&quot; alt=&quot;Google Account shows how to disable Timeline&quot; class=&quot;wp-post-271421 wp-image-271542&quot; style=&quot;width:700px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;326 KB&quot; data-optsize=&quot;82 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;74.8&quot; data-version=&quot;1786604569&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604569/wp-pme/gogle-privacy-settings-5/gogle-privacy-settings-5.png?_i=AA 1302w, https://res.cloudinary.com/dbulfrlrz/images/w_220,h_300,c_scale/f_auto,q_auto/v1786604569/wp-pme/gogle-privacy-settings-5/gogle-privacy-settings-5.png?_i=AA 220w, https://res.cloudinary.com/dbulfrlrz/images/w_750,h_1024,c_scale/f_auto,q_auto/v1786604569/wp-pme/gogle-privacy-settings-5/gogle-privacy-settings-5.png?_i=AA 750w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1049,c_scale/f_auto,q_auto/v1786604569/wp-pme/gogle-privacy-settings-5/gogle-privacy-settings-5.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1125,h_1536,c_scale/f_auto,q_auto/v1786604569/wp-pme/gogle-privacy-settings-5/gogle-privacy-settings-5.png?_i=AA 1125w&quot; sizes=&quot;auto, (max-width: 1302px) 100vw, 1302px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you prefer to keep&amp;nbsp;Timeline on on but still limit how long Google holds onto your data, select &lt;strong&gt;Auto-delete&lt;/strong&gt; instead of &lt;strong&gt;Turn off&lt;/strong&gt; and choose a window between 3, 18, and 36 months.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off My Ad Center&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This controls how Google personalizes ads on services such as Search and YouTube. Go to &lt;strong&gt;Data &amp;amp; privacy&lt;/strong&gt; → &lt;strong&gt;My Ad Center&lt;/strong&gt; (myadcenter.google.com/controls) and click &lt;strong&gt;On&lt;/strong&gt; → &lt;strong&gt;Turn off&lt;/strong&gt;. Keep in mind that ads are not removed but less tailored to you.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1302&quot; height=&quot;1196&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1302,h_1196,c_scale/f_auto,q_auto/v1786604518/wp-pme/gogle-privacy-settings-6/gogle-privacy-settings-6.png?_i=AA&quot; alt=&quot;Google Account shows how to disable personalized ads in My Ad Center&quot; class=&quot;wp-post-271421 wp-image-271566&quot; style=&quot;width:700px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;217 KB&quot; data-optsize=&quot;47 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;78.4&quot; data-version=&quot;1786604518&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604518/wp-pme/gogle-privacy-settings-6/gogle-privacy-settings-6.png?_i=AA 1302w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_276,c_scale/f_auto,q_auto/v1786604518/wp-pme/gogle-privacy-settings-6/gogle-privacy-settings-6.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_941,c_scale/f_auto,q_auto/v1786604518/wp-pme/gogle-privacy-settings-6/gogle-privacy-settings-6.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_705,c_scale/f_auto,q_auto/v1786604518/wp-pme/gogle-privacy-settings-6/gogle-privacy-settings-6.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1302px) 100vw, 1302px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Turning off this setting also disables personalized ads on Google&amp;#8217;s partner network. It&amp;#8217;s the setting called &lt;strong&gt;Personalized ads settings &lt;/strong&gt;—&lt;strong&gt; &lt;/strong&gt;the large set of non-Google sites and apps that show Google-served ads.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off Linked Google Services&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By default, all Google services can interact with each other and share activity data, including Search, YouTube, Chrome, Maps, Google Play, Shopping, and Google Ads. Under the &lt;a href=&quot;https://proton.me/blog/digital-markets-act-explained&quot;&gt;EU Digital Markets Act&lt;/a&gt;, you can unlink these services: Go to &lt;strong&gt;Data &amp;amp; privacy&lt;/strong&gt; → &lt;strong&gt;Linked Google Services&lt;/strong&gt; (myactivity.google.com/linked-services), deselect &lt;strong&gt;Google services you can link&lt;/strong&gt; to automatically clear all boxes, then click &lt;strong&gt;Next&lt;/strong&gt; → &lt;strong&gt;Confirm&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1302&quot; height=&quot;1826&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1302,h_1826,c_scale/f_auto,q_auto/v1786604537/wp-pme/gogle-privacy-settings-7/gogle-privacy-settings-7.png?_i=AA&quot; alt=&quot;Google Account settings shows how to deselect linked Google services&quot; class=&quot;wp-post-271421 wp-image-271590&quot; style=&quot;width:700px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;246 KB&quot; data-optsize=&quot;49 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;80.1&quot; data-version=&quot;1786604537&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604537/wp-pme/gogle-privacy-settings-7/gogle-privacy-settings-7.png?_i=AA 1302w, https://res.cloudinary.com/dbulfrlrz/images/w_214,h_300,c_scale/f_auto,q_auto/v1786604537/wp-pme/gogle-privacy-settings-7/gogle-privacy-settings-7.png?_i=AA 214w, https://res.cloudinary.com/dbulfrlrz/images/w_730,h_1024,c_scale/f_auto,q_auto/v1786604537/wp-pme/gogle-privacy-settings-7/gogle-privacy-settings-7.png?_i=AA 730w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1077,c_scale/f_auto,q_auto/v1786604537/wp-pme/gogle-privacy-settings-7/gogle-privacy-settings-7.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1095,h_1536,c_scale/f_auto,q_auto/v1786604537/wp-pme/gogle-privacy-settings-7/gogle-privacy-settings-7.png?_i=AA 1095w&quot; sizes=&quot;auto, (max-width: 1302px) 100vw, 1302px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Note: Unlinking does not completely prevent Google from sharing data with these services. Some Google services can&amp;#8217;t be unlinked under any circumstances and may continue sharing data with each other, such as Android Auto, Android TV, Chrome OS, &lt;a href=&quot;https://proton.me/blog/is-google-photos-safe&quot;&gt;Google Photos&lt;/a&gt;, Gemini Apps, and Waze.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Review third-party app connections&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Over time, you likely granted various apps and sites access to parts of your Google Account through &amp;#8220;Sign in with Google,&amp;#8221; or by connecting things like a note-taking app to &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;, or a social network to your contacts. Each of these is a standing data-sharing relationship that keeps working until you revoke it, and most people never go back to check what&amp;#8217;s still connected.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once you delete a connection, that app or site loses access to whatever Google data it had, though it doesn&amp;#8217;t retroactively delete data it may have already collected. This setting is concerned with outside developers and distinct from Linked Google Services covered above, which is about Google&amp;#8217;s own products sharing data with each other.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In your Google Account, go to &lt;strong&gt;Security &amp;amp; sign-in&lt;/strong&gt; → &lt;strong&gt;See all linked apps&lt;/strong&gt;, review the list, click on any app you no longer use or don&amp;#8217;t recognize, and select &lt;strong&gt;Delete all&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1332&quot; height=&quot;1400&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1332,h_1400,c_scale/f_auto,q_auto/v1786604525/wp-pme/gogle-privacy-settings-8/gogle-privacy-settings-8.png?_i=AA&quot; alt=&quot;Google Account shows to remove all links and stop sharing your Google Account data with YouTube on TV&quot; class=&quot;wp-post-271421 wp-image-271614&quot; style=&quot;width:700px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;187 KB&quot; data-optsize=&quot;39 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;79&quot; data-version=&quot;1786604525&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604525/wp-pme/gogle-privacy-settings-8/gogle-privacy-settings-8.png?_i=AA 1332w, https://res.cloudinary.com/dbulfrlrz/images/w_285,h_300,c_scale/f_auto,q_auto/v1786604525/wp-pme/gogle-privacy-settings-8/gogle-privacy-settings-8.png?_i=AA 285w, https://res.cloudinary.com/dbulfrlrz/images/w_974,h_1024,c_scale/f_auto,q_auto/v1786604525/wp-pme/gogle-privacy-settings-8/gogle-privacy-settings-8.png?_i=AA 974w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_807,c_scale/f_auto,q_auto/v1786604525/wp-pme/gogle-privacy-settings-8/gogle-privacy-settings-8.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1332px) 100vw, 1332px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;(Optional) Remove personal info using Google&amp;#8217;s &amp;#8220;Results about you&amp;#8221; tool&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google&amp;#8217;s &amp;#8220;Results about you&amp;#8221; tool is designed to let you monitor and request removal of search results that expose your contact details or sensitive identifiers. Google expanded it in February 2026 to also cover government-issued IDs (driver&amp;#8217;s license, passport, Social Security number), on top of the phone numbers, email addresses, home addresses, and non-consensual explicit images it already covered.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your sensitive information will be removed from Google Search results, but it will remain on the sites that originally published it, so it can still be found if that site is accessed directly or if someone uses a different search engine like Bing. To get it removed at the source and subsequently all search engine results, contact the webmaster.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Note: &lt;strong&gt;This tool requires handing Google information you may not have given it before&lt;/strong&gt;, like your home address, specifically so it can search for that information on your behalf. Google states that this data &amp;#8220;isn&amp;#8217;t shared or used to personalize your experience across other Google products,&amp;#8221; and that it&amp;#8217;s &amp;#8220;used and stored to process your requests, improve the removal request process, and to allow you to view the status of your past removal requests over time.&amp;#8221; If you don&amp;#8217;t want Google to know more about you, feeding it more of your personal information may not be a good option.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s how to use Google&amp;#8217;s &amp;#8220;&lt;strong&gt;Results about you&lt;/strong&gt;&amp;#8221; tool:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Go to myactivity.google.com/results-about-you, click &lt;strong&gt;Get started&lt;/strong&gt;, and follow the prompts.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1302&quot; height=&quot;1620&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1302,h_1620,c_scale/f_auto,q_auto/v1786604532/wp-pme/gogle-privacy-settings-9/gogle-privacy-settings-9.png?_i=AA&quot; alt=&quot;The Google &amp;quot;Results about you&amp;quot; tool&quot; class=&quot;wp-post-271421 wp-image-271638&quot; style=&quot;width:700px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;361 KB&quot; data-optsize=&quot;63 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;82.5&quot; data-version=&quot;1786604532&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604532/wp-pme/gogle-privacy-settings-9/gogle-privacy-settings-9.png?_i=AA 1302w, https://res.cloudinary.com/dbulfrlrz/images/w_241,h_300,c_scale/f_auto,q_auto/v1786604532/wp-pme/gogle-privacy-settings-9/gogle-privacy-settings-9.png?_i=AA 241w, https://res.cloudinary.com/dbulfrlrz/images/w_823,h_1024,c_scale/f_auto,q_auto/v1786604532/wp-pme/gogle-privacy-settings-9/gogle-privacy-settings-9.png?_i=AA 823w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_956,c_scale/f_auto,q_auto/v1786604532/wp-pme/gogle-privacy-settings-9/gogle-privacy-settings-9.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1234,h_1536,c_scale/f_auto,q_auto/v1786604532/wp-pme/gogle-privacy-settings-9/gogle-privacy-settings-9.png?_i=AA 1234w&quot; sizes=&quot;auto, (max-width: 1302px) 100vw, 1302px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h3 id=&quot;android&quot; class=&quot;wp-block-heading&quot;&gt;Android privacy settings&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re an Android user, the OS-level layer is where a meaningful share of Google&amp;#8217;s data collection happens. Here&amp;#8217;s how to lock down your Android settings:&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Disable app permissions&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;Security &amp;amp; privacy&lt;/strong&gt; (or &lt;strong&gt;Privacy&lt;/strong&gt;) → &lt;strong&gt;Permission manager&lt;/strong&gt; to view permissions by type (such as Location, Camera, and Microphone), rather than digging through each app individually.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1080&quot; height=&quot;2078&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1080,h_2078,c_scale/f_auto,q_auto/v1786604545/wp-pme/gogle-privacy-settings-10/gogle-privacy-settings-10.png?_i=AA&quot; alt=&quot;Android permission manager&quot; class=&quot;wp-post-271421 wp-image-271662&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;195 KB&quot; data-optsize=&quot;24 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;87.4&quot; data-version=&quot;1786604545&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604545/wp-pme/gogle-privacy-settings-10/gogle-privacy-settings-10.png?_i=AA 1080w, https://res.cloudinary.com/dbulfrlrz/images/w_156,h_300,c_scale/f_auto,q_auto/v1786604545/wp-pme/gogle-privacy-settings-10/gogle-privacy-settings-10.png?_i=AA 156w, https://res.cloudinary.com/dbulfrlrz/images/w_532,h_1024,c_scale/f_auto,q_auto/v1786604545/wp-pme/gogle-privacy-settings-10/gogle-privacy-settings-10.png?_i=AA 532w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1478,c_scale/f_auto,q_auto/v1786604545/wp-pme/gogle-privacy-settings-10/gogle-privacy-settings-10.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_798,h_1536,c_scale/f_auto,q_auto/v1786604545/wp-pme/gogle-privacy-settings-10/gogle-privacy-settings-10.png?_i=AA 798w, https://res.cloudinary.com/dbulfrlrz/images/w_1064,h_2048,c_scale/f_auto,q_auto/v1786604545/wp-pme/gogle-privacy-settings-10/gogle-privacy-settings-10.png?_i=AA 1064w&quot; sizes=&quot;auto, (max-width: 1080px) 100vw, 1080px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;For location specifically, check which apps are set to &amp;#8220;Allow all the time&amp;#8221; and downgrade everything to &amp;#8220;Allow only while using the app,&amp;#8221; except the essential apps (such as navigation apps). Camera and microphone should generally be &amp;#8220;Ask every time&amp;#8221; or app-specific.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Use one-time permissions&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When an app requests camera, microphone, or location access, Android&amp;#8217;s permission dialog includes an &amp;#8220;Only this time&amp;#8221; or &amp;#8220;Allow only while using the app&amp;#8221; option; the access expires once you leave the app. For apps that don’t need ongoing access, choosing this by default is an easy way to avoid having to revoke permissions later.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1080&quot; height=&quot;2090&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1080,h_2090,c_scale/f_auto,q_auto/v1786604552/wp-pme/gogle-privacy-settings-11/gogle-privacy-settings-11.png?_i=AA&quot; alt=&quot;&amp;quot;Allow only when using the app&amp;quot; location permissions on Waze on Android&quot; class=&quot;wp-post-271421 wp-image-271686&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;395 KB&quot; data-optsize=&quot;50 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;87.4&quot; data-version=&quot;1786604552&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604552/wp-pme/gogle-privacy-settings-11/gogle-privacy-settings-11.png?_i=AA 1080w, https://res.cloudinary.com/dbulfrlrz/images/w_155,h_300,c_scale/f_auto,q_auto/v1786604552/wp-pme/gogle-privacy-settings-11/gogle-privacy-settings-11.png?_i=AA 155w, https://res.cloudinary.com/dbulfrlrz/images/w_529,h_1024,c_scale/f_auto,q_auto/v1786604552/wp-pme/gogle-privacy-settings-11/gogle-privacy-settings-11.png?_i=AA 529w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1486,c_scale/f_auto,q_auto/v1786604552/wp-pme/gogle-privacy-settings-11/gogle-privacy-settings-11.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_794,h_1536,c_scale/f_auto,q_auto/v1786604552/wp-pme/gogle-privacy-settings-11/gogle-privacy-settings-11.png?_i=AA 794w, https://res.cloudinary.com/dbulfrlrz/images/w_1058,h_2048,c_scale/f_auto,q_auto/v1786604552/wp-pme/gogle-privacy-settings-11/gogle-privacy-settings-11.png?_i=AA 1058w&quot; sizes=&quot;auto, (max-width: 1080px) 100vw, 1080px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Check app permissions in Privacy Dashboard&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;Security &amp;amp; privacy&lt;/strong&gt; (or &lt;strong&gt;Privacy&lt;/strong&gt;) → &lt;strong&gt;Privacy dashboard&lt;/strong&gt; to see a timeline of exactly when each app accessed camera, microphone, or location over the past 24 hours and 7 days. If an app is quietly using a permission far more often than its function suggests, &lt;a href=&quot;https://proton.me/blog/how-to-stop-apps-running-in-background-android&quot;&gt;revoke all its permissions&lt;/a&gt; or uninstall the app to be safe.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;921&quot; height=&quot;1814&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_921,h_1814,c_scale/f_auto,q_auto/v1786604559/wp-pme/gogle-privacy-settings-12/gogle-privacy-settings-12.png?_i=AA&quot; alt=&quot;The Android privacy dashboard&quot; class=&quot;wp-post-271421 wp-image-271710&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;423 KB&quot; data-optsize=&quot;78 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;81.6&quot; data-version=&quot;1786604559&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604559/wp-pme/gogle-privacy-settings-12/gogle-privacy-settings-12.png?_i=AA 921w, https://res.cloudinary.com/dbulfrlrz/images/w_152,h_300,c_scale/f_auto,q_auto/v1786604559/wp-pme/gogle-privacy-settings-12/gogle-privacy-settings-12.png?_i=AA 152w, https://res.cloudinary.com/dbulfrlrz/images/w_520,h_1024,c_scale/f_auto,q_auto/v1786604559/wp-pme/gogle-privacy-settings-12/gogle-privacy-settings-12.png?_i=AA 520w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1513,c_scale/f_auto,q_auto/v1786604559/wp-pme/gogle-privacy-settings-12/gogle-privacy-settings-12.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_780,h_1536,c_scale/f_auto,q_auto/v1786604559/wp-pme/gogle-privacy-settings-12/gogle-privacy-settings-12.png?_i=AA 780w&quot; sizes=&quot;auto, (max-width: 921px) 100vw, 921px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Disable personalized ads and reset your advertising ID&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An advertising ID is a resettable identifier on your phone that apps and companies like Google can use to support advertising, such as measuring ad performance or building an advertising profile across apps. Your &lt;a href=&quot;https://proton.me/blog/ad-tech-privacy&quot;&gt;advertising ID can be linked to your device activity&lt;/a&gt; and, when combined with other information, may be used to identify or profile you.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To lock down your Google privacy settings, you can disable personalized ads and reset your advertising ID:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;Security &amp;amp; privacy&lt;/strong&gt; (or &lt;strong&gt;Privacy&lt;/strong&gt;) → &lt;strong&gt;Permission manager&lt;/strong&gt; → &lt;strong&gt;Ads and privacy&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Turn on &lt;strong&gt;Disable personalized ads&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Reset Ad-ID&lt;/strong&gt; and &lt;strong&gt;Reset&lt;/strong&gt; again to confirm.&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1080&quot; height=&quot;1075&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1080,h_1075,c_scale/f_auto,q_auto/v1786604564/wp-pme/gogle-privacy-settings-13/gogle-privacy-settings-13.png?_i=AA&quot; alt=&quot;Android shows how to disable personalized ads and reset the advertising ID&quot; class=&quot;wp-post-271421 wp-image-271734&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;181 KB&quot; data-optsize=&quot;32 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;82.1&quot; data-version=&quot;1786604564&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604564/wp-pme/gogle-privacy-settings-13/gogle-privacy-settings-13.png?_i=AA 1080w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_300,c_fill,g_auto/f_auto,q_auto/v1786604564/wp-pme/gogle-privacy-settings-13/gogle-privacy-settings-13.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_1019,c_scale/f_auto,q_auto/v1786604564/wp-pme/gogle-privacy-settings-13/gogle-privacy-settings-13.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_150,h_150,c_fill,g_auto/f_auto,q_auto/v1786604564/wp-pme/gogle-privacy-settings-13/gogle-privacy-settings-13.png?_i=AA 150w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_764,c_scale/f_auto,q_auto/v1786604564/wp-pme/gogle-privacy-settings-13/gogle-privacy-settings-13.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1080px) 100vw, 1080px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off Gemini&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google is replacing Assistant with Gemini as Android&amp;#8217;s default AI assistant, in many cases without an explicit opt-in. &lt;a href=&quot;https://proton.me/blog/turn-off-gemini-gmail&quot;&gt;Gemini can access Gmail&lt;/a&gt;, Google Calendar, &lt;a href=&quot;https://proton.me/blog/is-google-drive-secure&quot;&gt;Google Drive&lt;/a&gt;, Google Maps, and messaging apps to complete tasks on your behalf, and by default your conversations may be reviewed by human reviewers and stored for up to three years to help train Google&amp;#8217;s AI models.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To &lt;a href=&quot;https://proton.me/blog/turn-off-gemini-on-android&quot;&gt;turn off Gemini on Android&lt;/a&gt; and limit what it can see:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the Gemini app, tap your profile icon, and select &lt;strong&gt;Gemini Apps Activity&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Turn off&lt;/strong&gt; → &lt;strong&gt;Turn off and delete activity&lt;/strong&gt;, and follow the prompts.&lt;/li&gt;



&lt;li&gt;Go back to your profile icon → &lt;strong&gt;Apps&lt;/strong&gt;, and toggle off all apps.&lt;/li&gt;



&lt;li&gt;If you&amp;#8217;ve used Gemini Deep Research, open &lt;strong&gt;Sources&lt;/strong&gt; and clear Gmail, Drive, and Chat — Deep Research can otherwise read and cross-reference their content.&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1080&quot; height=&quot;2095&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1080,h_2095,c_scale/f_auto,q_auto/v1786604620/wp-pme/gogle-privacy-settings-14/gogle-privacy-settings-14.webp?_i=AA&quot; alt=&quot;Android shows how to turn off Gemini Apps Activity&quot; class=&quot;wp-post-271421 wp-image-271758&quot; style=&quot;width:400px&quot; data-format=&quot;webp&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;81 KB&quot; data-optsize=&quot;64 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;21&quot; data-version=&quot;1786604620&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604620/wp-pme/gogle-privacy-settings-14/gogle-privacy-settings-14.webp?_i=AA 1080w, https://res.cloudinary.com/dbulfrlrz/images/w_155,h_300,c_scale/f_auto,q_auto/v1786604620/wp-pme/gogle-privacy-settings-14/gogle-privacy-settings-14.webp?_i=AA 155w, https://res.cloudinary.com/dbulfrlrz/images/w_528,h_1024,c_scale/f_auto,q_auto/v1786604620/wp-pme/gogle-privacy-settings-14/gogle-privacy-settings-14.webp?_i=AA 528w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1490,c_scale/f_auto,q_auto/v1786604620/wp-pme/gogle-privacy-settings-14/gogle-privacy-settings-14.webp?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_792,h_1536,c_scale/f_auto,q_auto/v1786604620/wp-pme/gogle-privacy-settings-14/gogle-privacy-settings-14.webp?_i=AA 792w, https://res.cloudinary.com/dbulfrlrz/images/w_1056,h_2048,c_scale/f_auto,q_auto/v1786604620/wp-pme/gogle-privacy-settings-14/gogle-privacy-settings-14.webp?_i=AA 1056w&quot; sizes=&quot;auto, (max-width: 1080px) 100vw, 1080px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Turning off Gemini Apps Activity reduces your data retention window from up to three years down to 72 hours, but doesn&amp;#8217;t fully stop collection: Google says it may still process your chats to &amp;#8220;create anonymized data to improve Google services.&amp;#8221; Gemini also can&amp;#8217;t be uninstalled on most devices, since Google is making it the default system assistant on Android.&lt;/p&gt;



&lt;blockquote class=&quot;wp-block-quote is-layout-flow wp-block-quote-is-layout-flow&quot;&gt;
&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re looking for more privacy without giving up the convenience of an &lt;a href=&quot;https://proton.me/lumo&quot;&gt;AI assistant&lt;/a&gt;, try Lumo. You should also check out these private &lt;a href=&quot;https://proton.me/learn/european-alternatives/european-phones&quot;&gt;European phones&lt;/a&gt; that run without Android or use &lt;a href=&quot;https://proton.me/blog/how-to-de-google&quot;&gt;deGoogled versions&lt;/a&gt; of Android.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;h3 id=&quot;chrome&quot; class=&quot;wp-block-heading&quot;&gt;Google Chrome privacy settings&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome is one of the biggest channels through which Google collects data, largely because it&amp;#8217;s designed to sign you in automatically and sync your activity the moment you log into any Google service. The best way to limit this is to &lt;strong&gt;stop using Chrome&lt;/strong&gt;. Alternatively, here&amp;#8217;s how to limit what it sends back without switching browsers:&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off automatic Chrome sign-in&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By default, signing into Gmail or any other Google service also signs you into Chrome itself, and starts sending your browsing activity to your Google Account — a step most people never explicitly agreed to.&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;You and Google&lt;/strong&gt; → &lt;strong&gt;Sync and Google services&lt;/strong&gt; (chrome://settings/syncSetup).&lt;/li&gt;



&lt;li&gt;Switch off &lt;strong&gt;Allow Chrome sign-in&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;If you&amp;#8217;re already signed in, click your profile icon in the top right and select &lt;strong&gt;Sign out&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;1992&quot; height=&quot;1070&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1992,h_1070,c_scale/f_auto,q_auto/v1786604580/wp-pme/gogle-privacy-settings-15/gogle-privacy-settings-15.png?_i=AA&quot; alt=&quot;Google Chrome shows how to disable Chrome sign-in&quot; class=&quot;wp-post-271421 wp-image-271782&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;221 KB&quot; data-optsize=&quot;53 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;75.9&quot; data-version=&quot;1786604580&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604580/wp-pme/gogle-privacy-settings-15/gogle-privacy-settings-15.png?_i=AA 1992w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_161,c_scale/f_auto,q_auto/v1786604580/wp-pme/gogle-privacy-settings-15/gogle-privacy-settings-15.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_550,c_scale/f_auto,q_auto/v1786604580/wp-pme/gogle-privacy-settings-15/gogle-privacy-settings-15.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_413,c_scale/f_auto,q_auto/v1786604580/wp-pme/gogle-privacy-settings-15/gogle-privacy-settings-15.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_825,c_scale/f_auto,q_auto/v1786604580/wp-pme/gogle-privacy-settings-15/gogle-privacy-settings-15.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_842,c_scale/f_auto,q_auto/v1786604580/wp-pme/gogle-privacy-settings-15/gogle-privacy-settings-15.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1992px) 100vw, 1992px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Stay signed in but limit syncing&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you do want to stay signed in for convenience, you can restrict which categories of data Chrome sends to Google.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;You and Google&lt;/strong&gt; → &lt;strong&gt;Sync and Google services&lt;/strong&gt; (chrome://settings/syncSetup). You have two options:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Click &lt;strong&gt;Turn off&lt;/strong&gt; next to your Gmail address to disable sync for all types of data&lt;/li&gt;



&lt;li&gt;Or, go to &lt;strong&gt;Manage what you sync&lt;/strong&gt;, select &lt;strong&gt;Customize sync&lt;/strong&gt;, and toggle off individual types of data you want to exclude from sync, such as History, Bookmarks, and Settings.&lt;/li&gt;
&lt;/ul&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;1992&quot; height=&quot;1070&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1992,h_1070,c_scale/f_auto,q_auto/v1786604590/wp-pme/gogle-privacy-settings-16/gogle-privacy-settings-16.png?_i=AA&quot; alt=&quot;Google Chrome shows how to customize sync data&quot; class=&quot;wp-post-271421 wp-image-271806&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;176 KB&quot; data-optsize=&quot;37 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;79.2&quot; data-version=&quot;1786604590&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604590/wp-pme/gogle-privacy-settings-16/gogle-privacy-settings-16.png?_i=AA 1992w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_161,c_scale/f_auto,q_auto/v1786604590/wp-pme/gogle-privacy-settings-16/gogle-privacy-settings-16.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_550,c_scale/f_auto,q_auto/v1786604590/wp-pme/gogle-privacy-settings-16/gogle-privacy-settings-16.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_413,c_scale/f_auto,q_auto/v1786604590/wp-pme/gogle-privacy-settings-16/gogle-privacy-settings-16.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_825,c_scale/f_auto,q_auto/v1786604590/wp-pme/gogle-privacy-settings-16/gogle-privacy-settings-16.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_842,c_scale/f_auto,q_auto/v1786604590/wp-pme/gogle-privacy-settings-16/gogle-privacy-settings-16.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1992px) 100vw, 1992px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off &amp;#8220;Make searches and browsing better&amp;#8221;&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This setting sends your browsing activity to Google beyond what&amp;#8217;s needed to actually load a page, to improve Google&amp;#8217;s own products.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;You and Google&lt;/strong&gt; and switch off &lt;strong&gt;Make searches and browsing better&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;1992&quot; height=&quot;1070&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1992,h_1070,c_scale/f_auto,q_auto/v1786604610/wp-pme/gogle-privacy-settings-17/gogle-privacy-settings-17.png?_i=AA&quot; alt=&quot;Google Chrome shows how to disable &amp;quot;Make searches and browsing better&amp;quot;&quot; class=&quot;wp-post-271421 wp-image-271830&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;297 KB&quot; data-optsize=&quot;67 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;77.3&quot; data-version=&quot;1786604610&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604610/wp-pme/gogle-privacy-settings-17/gogle-privacy-settings-17.png?_i=AA 1992w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_161,c_scale/f_auto,q_auto/v1786604610/wp-pme/gogle-privacy-settings-17/gogle-privacy-settings-17.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_550,c_scale/f_auto,q_auto/v1786604610/wp-pme/gogle-privacy-settings-17/gogle-privacy-settings-17.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_413,c_scale/f_auto,q_auto/v1786604610/wp-pme/gogle-privacy-settings-17/gogle-privacy-settings-17.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_825,c_scale/f_auto,q_auto/v1786604610/wp-pme/gogle-privacy-settings-17/gogle-privacy-settings-17.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_842,c_scale/f_auto,q_auto/v1786604610/wp-pme/gogle-privacy-settings-17/gogle-privacy-settings-17.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1992px) 100vw, 1992px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Turn off enhanced spell check&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Enhanced spell check sends text to Google&amp;#8217;s servers as you type it, including anything you type, change your mind about, and then delete before pressing Enter. This means that you may inadvertently share sensitive data with Google, including usernames, email addresses, and passwords. Security researchers have shown how the enhanced spellcheck features of Google Chrome and Microsoft Edge &lt;a href=&quot;https://web.archive.org/web/20220921032442/https://otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords&quot;&gt;exposed passwords even when clicking &amp;#8220;Show password&amp;#8221;&lt;/a&gt; to reveal masked text.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome&amp;#8217;s built-in spellchecker can&amp;#8217;t be disabled, but you can switch to Basic spell check, which uses a local dictionary and doesn&amp;#8217;t send anything to Google:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Go to &lt;strong&gt;Settings&lt;/strong&gt; → &lt;strong&gt;Languages&lt;/strong&gt; (chrome://settings/languages). You can:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Select &lt;strong&gt;Basic spell check&lt;/strong&gt;, which uses a local dictionary provided by Chrome or your operating system, and doesn&amp;#8217;t send anything to Google&lt;/li&gt;



&lt;li&gt;Or, toggle off &lt;strong&gt;Check for spelling errors when you type text on web pages&lt;/strong&gt;, which disables the spellchecker&lt;/li&gt;
&lt;/ul&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;1992&quot; height=&quot;1070&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1992,h_1070,c_scale/f_auto,q_auto/v1786604600/wp-pme/gogle-privacy-settings-18/gogle-privacy-settings-18.png?_i=AA&quot; alt=&quot;Google Chrome shows how to switch to &amp;quot;Basic spell check&amp;quot; or disable &amp;quot;Check for spelling errors when you type text on web pages&amp;quot;&quot; class=&quot;wp-post-271421 wp-image-271854&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;223 KB&quot; data-optsize=&quot;50 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;77.7&quot; data-version=&quot;1786604600&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786604600/wp-pme/gogle-privacy-settings-18/gogle-privacy-settings-18.png?_i=AA 1992w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_161,c_scale/f_auto,q_auto/v1786604600/wp-pme/gogle-privacy-settings-18/gogle-privacy-settings-18.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_550,c_scale/f_auto,q_auto/v1786604600/wp-pme/gogle-privacy-settings-18/gogle-privacy-settings-18.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_413,c_scale/f_auto,q_auto/v1786604600/wp-pme/gogle-privacy-settings-18/gogle-privacy-settings-18.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_825,c_scale/f_auto,q_auto/v1786604600/wp-pme/gogle-privacy-settings-18/gogle-privacy-settings-18.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_842,c_scale/f_auto,q_auto/v1786604600/wp-pme/gogle-privacy-settings-18/gogle-privacy-settings-18.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1992px) 100vw, 1992px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h2 id=&quot;lawsuits&quot; class=&quot;wp-block-heading&quot;&gt;What lawsuits reveal about Google privacy settings&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google’s public privacy messaging has repeatedly been found by regulators, juries, or Google’s own staff to overstate the actual protection its settings provided. Disputes involving Google never end with a jury verdict, as the company has repeatedly settled privacy cases while denying wrongdoing or liability. In 2025 alone, &lt;a href=&quot;https://proton.me/tech-fines-tracker&quot;&gt;Google was hit with roughly $4.24 billion in fines&lt;/a&gt;, which it could pay off with about three weeks of its free cash flow.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The worst part is that &lt;strong&gt;you don’t necessarily have to seek out Google products for your privacy to be compromised&lt;/strong&gt;. Google’s advertising, analytics, and other tools are embedded across a huge part of the web, so visiting an ordinary website or using a third-party app can still put your activity through Google-linked infrastructure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are a few examples of where Google’s privacy practices have contradicted its public messaging, though this is not an exhaustive list:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Location tracking continued after opt-out&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://www.techtarget.com/searchsecurity/news/252446877/Google-location-tracking-continues-even-when-turned-off&quot;&gt;2018 Associated Press investigation&lt;/a&gt; found that turning off Location History didn&amp;#8217;t stop Google from storing timestamped location data. Maps, weather checks, and unrelated searches still recorded it, despite Google&amp;#8217;s help page stating &amp;#8220;the places you go are no longer stored.&amp;#8221;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Litigation that followed surfaced internal Google communications describing the settings interface as designed to be &amp;#8220;possible, yet difficult enough that people won&amp;#8217;t figure it out.&amp;#8221; It also found that Google repeatedly nudged users to re-enable location even when apps didn&amp;#8217;t need it, and flagged the off/paused wording itself as misleading.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The core finding that Google collected location data from roughly 247 million Android users in the US after they had disabled Location History became the central claim across every settlement in following lawsuits.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Browsing data collected in incognito/private browsing mode&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When using Chrome in incognito mode (or any other browser in private browsing mode), Google still collects your browsing data through tools like Analytics and Ad Manager. This has led to a class action lawsuit that &lt;a href=&quot;https://thehackernews.com/2024/04/google-to-delete-billions-of-browsing.html&quot;&gt;Google settled in 2024&lt;/a&gt;, agreeing to delete billions of browsing records, make its privacy disclosures clearer, and block third-party cookies in Chrome&amp;#8217;s Incognito mode by default for five years. It never stopped server-side collection by Google or by any website you visit that runs Analytics, Ads, or similar embedded services.&lt;/p&gt;



&lt;blockquote class=&quot;wp-block-quote is-layout-flow wp-block-quote-is-layout-flow&quot;&gt;
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Instead of using Google Chrome, consider these &lt;a href=&quot;https://proton.me/learn/european-alternatives/european-web-browsers&quot;&gt;European web browsers&lt;/a&gt; with better privacy features.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Personal data collected with Web &amp;amp; App Activity switched off&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A lawsuit alleged that Google kept receiving activity data from apps like Uber, &lt;a href=&quot;https://proton.me/blog/is-venmo-safe&quot;&gt;Venmo&lt;/a&gt;, &lt;a href=&quot;https://protonvpn.com/blog/is-tiktok-safe&quot;&gt;TikTok&lt;/a&gt;, &lt;a href=&quot;https://proton.me/blog/instagram-leak&quot;&gt;Instagram&lt;/a&gt;, and &lt;a href=&quot;https://proton.me/blog/is-whatsapp-safe&quot;&gt;WhatsApp&lt;/a&gt;, even with the Web &amp;amp; App Activity setting turned off. Google argued the data was anonymized and used only in aggregate, but a federal jury disagreed. It found Google liable for invasion of privacy in September 2025 and &lt;a href=&quot;https://www.reuters.com/sustainability/boards-policy-regulation/google-must-pay-425-million-class-action-over-privacy-jury-rules-2025-09-03/&quot;&gt;ordered it to pay $425.7 million&lt;/a&gt; to a class of roughly 98 million users. Google has asked the court to vacate the verdict and may appeal.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Right-to-be-forgotten requests leaked via a public database&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In May 2022, Spain’s data protection authority &lt;a href=&quot;https://www.aepd.es/en/prensa-y-comunicacion/notas-de-prensa/the-aepd-has-imposed-sanction-on-google-llc-for-transferring-personal-data-to-third-parties&quot;&gt;fined Google €10 million&lt;/a&gt; over how it handled the GDPR’s “right to be forgotten” — the right, in certain circumstances, to have &lt;a href=&quot;https://proton.me/blog/personal-data&quot;&gt;personal data&lt;/a&gt; erased or removed from search results. Google was sending copies of removal requests to the public Lumen database, where the information could be published and found again, effectively defeating the purpose of having it removed in the first place. It also designed its removal forms in a way that made it hard for people to tell whether their GDPR rights applied.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Google Assistant recordings reviewed by people and used commercially&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google Assistant sometimes recorded private conversations even when users hadn’t activated it, after background sounds were mistaken for the wake word. In 2019, a contractor &lt;a href=&quot;https://www.vrt.be/vrtnws/en/2019/07/10/google-employees-are-eavesdropping-even-in-flemish-living-rooms/&quot;&gt;leaked more than 1,000 recordings&lt;/a&gt; to Belgian broadcaster VRT, including bedroom conversations, medical information, and apparent domestic-violence situations; 153 were confirmed accidental activations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Plaintiffs in a separate case allege Google had been collecting such recordings since 2016, sharing some with contractors and using the data commercially without adequate consent. Google denies the allegations but has agreed to a &lt;a href=&quot;https://www.googleassistantprivacysettlement.com/home&quot;&gt;$68 million settlement&lt;/a&gt;, which is still awaiting final court approval.&lt;/p&gt;



&lt;h2 id=&quot;degoogle&quot; class=&quot;wp-block-heading&quot;&gt;DeGoogle your life, starting with email&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Changing these Google privacy settings can cut down how much of your searches, location, app activity, advertising data, and other personal information Google can use. But it won’t stop Google tracking altogether. Some data collection happens outside the settings on your account or phone, including through Google tools built into third-party websites and apps.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you want to go further, the biggest step is to start &lt;a href=&quot;https://proton.me/degoogle&quot;&gt;deGoogling&lt;/a&gt;, and that begins with your Google Account. A lot of what Google knows about you gets tied together because you’re signed in, so &lt;a href=&quot;https://proton.me/blog/delete-gmail-account#delete-google-account&quot;&gt;deleting your Google Account&lt;/a&gt; breaks one of the main links connecting your activity across Search, YouTube, Maps, Android, Gmail, and other services.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;From there, start replacing the Google services you rely on most, especially &lt;a href=&quot;https://proton.me/mail&quot;&gt;email&lt;/a&gt;. Your inbox is the hub of your digital life, holding private conversations, receipts, travel plans, account alerts, contacts, and password-reset links.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Mail takes a privacy-first approach: no ads, no tracking, no AI training, no profiling you or sharing your data with anyone. If you&amp;#8217;re seeking a private &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail alternative&lt;/a&gt;, we&amp;#8217;re exclusively supported by our community of paying subscribers and fully transparent. Our apps are independently audited and &lt;a href=&quot;https://proton.me/community/open-source&quot;&gt;open-source&lt;/a&gt;, so anyone can check our claims.&lt;/p&gt;



&lt;div class=&quot;text-center&quot;&gt;&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small bg-purple-500 text-white hover:text-white focus:text-white&quot; href=&quot;https://proton.me/mail/pricing&quot;&gt;Create a free account&lt;/a&gt;&lt;/div&gt;
</content:encoded><category>Guides</category><author>Elena Constantinescu</author></item><item><title>Autonomous AI hacked a small business – here’s how to protect yours</title><link>https://proton.me/business/blog/protect-against-ai-agent-cyberattack</link><guid isPermaLink="true">https://proton.me/business/blog/protect-against-ai-agent-cyberattack</guid><description>An AI agent bypassed a gym&apos;s booking rules on its own. Here&apos;s how autonomous agents find security weaknesses and how to protect your business.</description><pubDate>Wed, 12 Aug 2026 14:23:05 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;In late July 2026, OpenAI was testing one of its new models in a closed environment &lt;a href=&quot;https://edition.cnn.com/2026/07/22/tech/openai-hugging-face-ai-cybersecurity&quot;&gt;when the model decided to break out&lt;/a&gt;. It hacked into the private infrastructure of another software firm, Hugging Face, to steal the answer key to a cybersecurity benchmark it was being tested on. In other words, it broke the law for the sake of expedience.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Days later, the UK AI Security Institute disclosed that &lt;a href=&quot;https://www.bbc.com/news/articles/c1w1lvn7d9go&quot;&gt;Anthropic&amp;#8217;s Mythos 5 AI model&lt;/a&gt; had created fake developer identities, spear-phished real GitHub users into approving malicious code, and edited its own activity log to cover its tracks when caught.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Then in August, news broke that a Melbourne man named Andrew had asked&lt;a href=&quot;https://www.news.com.au/technology/online/hacking/ai-agent-asked-to-book-pilates-class-goes-rogue-and-hacks-website/news-story/d50d5fe34ba2fe45b72bd0cfe5227c71&quot;&gt; his personal AI agent,&lt;/a&gt; built on OpenClaw and running Anthropic&amp;#8217;s Claude, to help him get into a fully booked morning gym class. He was fourth on the waitlist and asked if there was any way to move up.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The agent found that the booking API had no authorization check on cancelling other users&amp;#8217; reservations. So without asking permission from Andrew, it went ahead and cancelled the booking of the person in first place to make room for him. When Andrew asked it to undo the cancellation, it couldn&amp;#8217;t: &amp;#8220;The person I removed is gone from the waitlist and I have no way to restore them.&amp;#8221;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The origin of these three incidents is not the same, but the result is: AI agents probed and exploited systems faster and more thoroughly than any human would have managed. They were never instructed to attack anything but found the shortest path to its goal anyway.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It doesn&amp;#8217;t matter whether you&amp;#8217;re a frontier lab&amp;#8217;s infrastructure or a suburban gym&amp;#8217;s booking software. If you have a business that exposes an API, you are now something an AI agent can probe, at a speed and completeness no human attacker matched. And nobody needs to decide to attack you.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Speed is the real story&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A human attacker weighs effort against reward. They get bored, they run out of time, they decide a gym booking app isn&amp;#8217;t worth the trouble. That calculation is what has quietly protected most low-value targets from casual exploitation for the last 20 years (unless you&amp;#8217;re running WordPress).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An AI agent doesn&amp;#8217;t make that calculation. Given a goal, it will try whatever the API technically permits, testing endpoints and parameter combinations at &lt;em&gt;machine speed&lt;/em&gt; until something works. It found the gym&amp;#8217;s authorization gap in the time it took Andrew to ask a follow-up question.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The scale of that speed gap is already visible in the numbers. &lt;a href=&quot;https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report&quot;&gt;Unit 42&amp;#8217;s 2026 Global Incident Response Report&lt;/a&gt; found the fastest attacks now exfiltrate data in 72 minutes, down from 285 minutes the year before. That&amp;#8217;s the trend with humans still mostly in the loop. An agent makes decisions in milliseconds; a human analyst responds in minutes to hours.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For security teams, that increasing speed is the real cause for concern, not any single incident that makes the news.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The new attack surface: everything with an API&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Any service exposing an API is a potential target, whether or not it looks like one.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Pricing engines where discounts are validated client-side&lt;/li&gt;



&lt;li&gt;Inventory systems where stock state lives in the storefront instead of the backend&lt;/li&gt;



&lt;li&gt;Support platforms where internal fields are reachable through undocumented API paths&lt;/li&gt;



&lt;li&gt;Subscription management that doesn&amp;#8217;t verify caller ownership of the account being modified.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of these require a human to go looking for them. They just require an agent with a goal and an API that answers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The businesses most exposed aren&amp;#8217;t the ones with obvious security holes. They&amp;#8217;re the ones with business logic gaps: rules that exist only in the UI, actions the API technically allows but the interface never surfaces, workflows built on the assumption that no caller would ever try the path that skips the intended one.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The gym&amp;#8217;s developer almost certainly didn&amp;#8217;t think an authorization check on cancellations was worth writing, because no ordinary user, and no ordinary attacker, had reason to try it. An agent had no such reservations, and it wasn&amp;#8217;t even trying to find a reservation to skip. It was just trying to be helpful.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How businesses can brace for AI attacks&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Treat every API action as a privileged operation.&lt;/strong&gt; Identity, authorization, and contextual policy, checked independently, on every call. Not &amp;#8220;the frontend won&amp;#8217;t let you do this,&amp;#8221; but &amp;#8220;the server verifies you&amp;#8217;re allowed to do this, on this resource, given its current state.&amp;#8221; The gym&amp;#8217;s system would have stopped this specific incident with one line of authorization logic on the cancellation endpoint. This is not a new control at all, it&amp;#8217;s the oldest item on OWASP&amp;#8217;s API security list, broken object-level authorization, and it&amp;#8217;s still the one most systems get wrong.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Give agents their own credential model.&lt;/strong&gt; Scoped, short-TTL tokens issued specifically for agent sessions, distinct from ordinary human session tokens, constrain the blast radius even when the agent finds a gap you didn&amp;#8217;t anticipate. If Andrew&amp;#8217;s agent had held a token scoped only to his own reservation, the cancellation of someone else&amp;#8217;s booking would have failed at the credential layer regardless of what the API otherwise permitted. This matters because you cannot rely on the agent&amp;#8217;s own restraint. You have to rely on what its credentials physically allow it to do.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Instrument for agent behavior detection specifically.&lt;/strong&gt; Agent traffic has a distinguishable shape: sub-human request timing, systematic endpoint enumeration, sequential probing across parameter combinations, successful execution of actions no human user has ever attempted through the actual interface. Baseline for that shape and alert on it in real time.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Close the response-time gap, not just the detection gap.&lt;/strong&gt; Detecting a probe in an hour is meaningless if the probe completed and moved on in minutes. The Unit 42 number above, 72 minutes for the fastest human-paced attacks, is already the wrong benchmark to plan against. Automated response, not just automated alerting, is what closes a gap measured in milliseconds. Of course, you also need to ensure that your automated response is not a damaging one either.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Assume this will happen and rehearse the response.&lt;/strong&gt; Document who gets called, predraft customer communications, and run tabletop exercises against agent-driven scenarios specifically, not just traditional breach playbooks. IBM&amp;#8217;s 2026 Cost of a Data Breach Report put the average global breach at $4.99 million, with AI-enabled breaches averaging roughly $1 million more. Those figures increasingly describe incidents that started the way the gym&amp;#8217;s did: no attacker in the traditional sense at all.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Test your own APIs the way an agent would, before an agent does it for you.&lt;/strong&gt; Manual pentesting assumes a human tester with limited time and a finite list of things to try. An automated adversarial against your own endpoints, probing with the same persistence and speed as an agent, will surface the same gaps before a customer&amp;#8217;s assistant stumbles into them. Open-source tools now exist specifically for this. &lt;a href=&quot;https://github.com/CyberStrikeus/CyberStrike&quot;&gt;CyberStrike&lt;/a&gt;, for example, runs specialized agents mapped to OWASP WSTG and MITRE ATT&amp;amp;CK against your own endpoints, including a dedicated tester for exactly the object-level authorization gap that caught the gym off guard: It sends a baseline request, sends the attack, and only flags a finding if there&amp;#8217;s a measurable, reproducible difference. That&amp;#8217;s the same class of check that would have caught the cancellation endpoint before an agent found it in the wild.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The principle isn&amp;#8217;t new of course. Site owners who ran their own vulnerability scanners against WordPress installs during the botnet era survived it. The tooling just needs to match the speed of the caller now, not the speed of a human attacker who might eventually get around to it.&lt;/p&gt;
</content:encoded><category>For business</category><author>Eamonn Maguire</author></item><item><title>How to turn off Siri on iPhone and other iOS devices</title><link>https://proton.me/blog/turn-off-siri</link><guid isPermaLink="true">https://proton.me/blog/turn-off-siri</guid><description>Siri is always listening for its wake phrase. Here’s how to disable Siri on iPhone, iPad, Mac, and Apple Watch.</description><pubDate>Wed, 12 Aug 2026 07:06:22 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you use an Apple device, Siri is already on by default — and it&amp;#8217;s always listening for its wake phrase. Every voice request you make can be processed and stored on Apple’s servers, and accidental activations can pick up on conversations you never intended to share.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&amp;nbsp;If you’re concerned about what Siri means for your privacy,, this guide shows you how to turn off Siri on your iPhone, iPad, Mac, and Apple Watch, and how to clean up the data it’s already collected.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#turn-off-siri-ios&quot;&gt;How to turn off Siri on iPhone and iPad&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#turn-off-siri-mac&quot;&gt;How to turn off Siri on Mac&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#turn-off-siri-apple-watch&quot;&gt;How to turn off Siri on Apple Watch&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#disable-siri-suggestions&quot;&gt;How to disable Siri suggestions&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#delete-siri-history&quot;&gt;How to delete Siri history&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#why-turn-siri-off&quot;&gt;Why you should turn off Siri&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#use-proton&quot;&gt;Your privacy is worth protecting&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;turn-off-siri-ios&quot; class=&quot;wp-block-heading&quot;&gt;How to turn off Siri on iPhone and iPad&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There’s no single off switch for Siri — you&amp;#8217;ll need to turn off a few settings separately. If you’re on iOS 18 or iPadOS 18 and later, open Settings and look for &lt;strong&gt;Siri&lt;/strong&gt; or &lt;strong&gt;Apple Intelligence &amp;amp; Siri&lt;/strong&gt;. On older OS versions, look for &lt;strong&gt;Siri &amp;amp; Search &lt;/strong&gt;instead.&lt;/p&gt;



&lt;h3 id=&quot;disable-voice-activation-ios&quot; class=&quot;wp-block-heading&quot;&gt;Disable voice activation&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disabling voice activation prevents Siri from always listening for its wake phrase. You can still trigger it manually by pressing the side button.&amp;nbsp;&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the &lt;strong&gt;Settings &lt;/strong&gt;app.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Siri (&lt;/strong&gt;or &lt;strong&gt;Apple Intelligence &amp;amp; Siri)&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Talk &amp;amp; Type to Siri&lt;/strong&gt;. If you &lt;a href=&quot;https://proton.me/blog/turn-off-apple-intelligence&quot;&gt;disabled Apple Intelligence&lt;/a&gt;, this will appear as &lt;strong&gt;Talk to Siri&lt;/strong&gt; instead.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1224&quot; height=&quot;1546&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1224,h_1546,c_scale/f_auto,q_auto/v1786506226/wp-pme/disable-voice-activation-iphone-ipad-1/disable-voice-activation-iphone-ipad-1.png?_i=AA&quot; alt=&quot;Talk to Siri settings tab on iOS&quot; class=&quot;wp-post-270887 wp-image-271063&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;398 KB&quot; data-optsize=&quot;41 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;89.7&quot; data-version=&quot;1786506226&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506226/wp-pme/disable-voice-activation-iphone-ipad-1/disable-voice-activation-iphone-ipad-1.png?_i=AA 1224w, https://res.cloudinary.com/dbulfrlrz/images/w_238,h_300,c_scale/f_auto,q_auto/v1786506226/wp-pme/disable-voice-activation-iphone-ipad-1/disable-voice-activation-iphone-ipad-1.png?_i=AA 238w, https://res.cloudinary.com/dbulfrlrz/images/w_811,h_1024,c_scale/f_auto,q_auto/v1786506226/wp-pme/disable-voice-activation-iphone-ipad-1/disable-voice-activation-iphone-ipad-1.png?_i=AA 811w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_970,c_scale/f_auto,q_auto/v1786506226/wp-pme/disable-voice-activation-iphone-ipad-1/disable-voice-activation-iphone-ipad-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1216,h_1536,c_scale/f_auto,q_auto/v1786506226/wp-pme/disable-voice-activation-iphone-ipad-1/disable-voice-activation-iphone-ipad-1.png?_i=AA 1216w&quot; sizes=&quot;auto, (max-width: 1224px) 100vw, 1224px&quot; /&gt;&lt;/figure&gt;



&lt;ol start=&quot;4&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Select &lt;strong&gt;Off&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1250&quot; height=&quot;1080&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1250,h_1080,c_scale/f_auto,q_auto/v1786506233/wp-pme/disable-voice-activation-iphone-ipad-2/disable-voice-activation-iphone-ipad-2.png?_i=AA&quot; alt=&quot;Talk to Siri &amp;quot;Off&amp;quot; setting on iOS&quot; class=&quot;wp-post-270887 wp-image-271087&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;91 KB&quot; data-optsize=&quot;16 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;83&quot; data-version=&quot;1786506233&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506233/wp-pme/disable-voice-activation-iphone-ipad-2/disable-voice-activation-iphone-ipad-2.png?_i=AA 1250w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_259,c_scale/f_auto,q_auto/v1786506233/wp-pme/disable-voice-activation-iphone-ipad-2/disable-voice-activation-iphone-ipad-2.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_885,c_scale/f_auto,q_auto/v1786506233/wp-pme/disable-voice-activation-iphone-ipad-2/disable-voice-activation-iphone-ipad-2.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_664,c_scale/f_auto,q_auto/v1786506233/wp-pme/disable-voice-activation-iphone-ipad-2/disable-voice-activation-iphone-ipad-2.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1250px) 100vw, 1250px&quot; /&gt;&lt;/figure&gt;



&lt;h3 id=&quot;disable-dictation-ios&quot; class=&quot;wp-block-heading&quot;&gt;Disable dictation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Siri’s dictation feature lets you compose text by voice, and your voice input is processed in a similar way to Siri requests. If you’re turning Siri off for privacy reasons, it’s worth disabling dictation too.&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the &lt;strong&gt;Settings &lt;/strong&gt;app.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;General&lt;/strong&gt; →&lt;strong&gt;Keyboard&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Toggle &lt;strong&gt;Enable Dictation &lt;/strong&gt;off.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1242&quot; height=&quot;960&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1242,h_960,c_scale/f_auto,q_auto/v1786506214/wp-pme/disable-dictation-on-iphone-ipad/disable-dictation-on-iphone-ipad.png?_i=AA&quot; alt=&quot;Dictation toggle on iOS&quot; class=&quot;wp-post-270887 wp-image-271015&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;96 KB&quot; data-optsize=&quot;15 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;84.7&quot; data-version=&quot;1786506214&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506214/wp-pme/disable-dictation-on-iphone-ipad/disable-dictation-on-iphone-ipad.png?_i=AA 1242w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_232,c_scale/f_auto,q_auto/v1786506214/wp-pme/disable-dictation-on-iphone-ipad/disable-dictation-on-iphone-ipad.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_791,c_scale/f_auto,q_auto/v1786506214/wp-pme/disable-dictation-on-iphone-ipad/disable-dictation-on-iphone-ipad.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_594,c_scale/f_auto,q_auto/v1786506214/wp-pme/disable-dictation-on-iphone-ipad/disable-dictation-on-iphone-ipad.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1242px) 100vw, 1242px&quot; /&gt;&lt;/figure&gt;



&lt;h3 id=&quot;turn-off-siri-completely-ios&quot; class=&quot;wp-block-heading&quot;&gt;Turn Siri off completely on iPhone and iPad&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before you can fully turn off Siri on iPhone and iPad, you will first need to disable both &lt;a href=&quot;#disable-voice-activation-ios&quot;&gt;voice activation&lt;/a&gt; and &lt;a href=&quot;#disable-dictation-ios&quot;&gt;dictation&lt;/a&gt; before following the steps below.&amp;nbsp;&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the &lt;strong&gt;Settings&lt;/strong&gt; app.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Siri (&lt;/strong&gt;or&lt;strong&gt; Apple Intelligence &amp;amp; Siri).&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Talk &amp;amp; Type to Siri&lt;/strong&gt; (or &lt;strong&gt;Talk to Siri&lt;/strong&gt;)&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1224&quot; height=&quot;1546&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1224,h_1546,c_scale/f_auto,q_auto/v1786506188/wp-pme/turn-off-siri-on-iphone-ipad-1/turn-off-siri-on-iphone-ipad-1.png?_i=AA&quot; alt=&quot;Talk to Siri settings tab on iOS&quot; class=&quot;wp-post-270887 wp-image-270919&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;398 KB&quot; data-optsize=&quot;41 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;89.7&quot; data-version=&quot;1786506188&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506188/wp-pme/turn-off-siri-on-iphone-ipad-1/turn-off-siri-on-iphone-ipad-1.png?_i=AA 1224w, https://res.cloudinary.com/dbulfrlrz/images/w_238,h_300,c_scale/f_auto,q_auto/v1786506188/wp-pme/turn-off-siri-on-iphone-ipad-1/turn-off-siri-on-iphone-ipad-1.png?_i=AA 238w, https://res.cloudinary.com/dbulfrlrz/images/w_811,h_1024,c_scale/f_auto,q_auto/v1786506188/wp-pme/turn-off-siri-on-iphone-ipad-1/turn-off-siri-on-iphone-ipad-1.png?_i=AA 811w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_970,c_scale/f_auto,q_auto/v1786506188/wp-pme/turn-off-siri-on-iphone-ipad-1/turn-off-siri-on-iphone-ipad-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1216,h_1536,c_scale/f_auto,q_auto/v1786506188/wp-pme/turn-off-siri-on-iphone-ipad-1/turn-off-siri-on-iphone-ipad-1.png?_i=AA 1216w&quot; sizes=&quot;auto, (max-width: 1224px) 100vw, 1224px&quot; /&gt;&lt;/figure&gt;



&lt;ol start=&quot;4&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Toggle off &lt;strong&gt;Press Side Button for Siri&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1245&quot; height=&quot;1034&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1245,h_1034,c_scale/f_auto,q_auto/v1786506251/wp-pme/turn-off-siri-on-iphone-ipad-2/turn-off-siri-on-iphone-ipad-2.png?_i=AA&quot; alt=&quot;&amp;quot;Press Side Button for Siri&amp;quot; toggle on iOS&quot; class=&quot;wp-post-270887 wp-image-271159&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;90 KB&quot; data-optsize=&quot;16 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;82.4&quot; data-version=&quot;1786506251&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506251/wp-pme/turn-off-siri-on-iphone-ipad-2/turn-off-siri-on-iphone-ipad-2.png?_i=AA 1245w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_249,c_scale/f_auto,q_auto/v1786506251/wp-pme/turn-off-siri-on-iphone-ipad-2/turn-off-siri-on-iphone-ipad-2.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_850,c_scale/f_auto,q_auto/v1786506251/wp-pme/turn-off-siri-on-iphone-ipad-2/turn-off-siri-on-iphone-ipad-2.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_638,c_scale/f_auto,q_auto/v1786506251/wp-pme/turn-off-siri-on-iphone-ipad-2/turn-off-siri-on-iphone-ipad-2.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1245px) 100vw, 1245px&quot; /&gt;&lt;/figure&gt;



&lt;ol start=&quot;5&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Select &lt;strong&gt;Turn Off Siri&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1235&quot; height=&quot;1053&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1235,h_1053,c_scale/f_auto,q_auto/v1786506257/wp-pme/turn-off-siri-on-iphone-ipad-3/turn-off-siri-on-iphone-ipad-3.png?_i=AA&quot; alt=&quot;Turn off Siri confirmation box&quot; class=&quot;wp-post-270887 wp-image-271183&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;127 KB&quot; data-optsize=&quot;24 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;80.9&quot; data-version=&quot;1786506257&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506257/wp-pme/turn-off-siri-on-iphone-ipad-3/turn-off-siri-on-iphone-ipad-3.png?_i=AA 1235w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_256,c_scale/f_auto,q_auto/v1786506257/wp-pme/turn-off-siri-on-iphone-ipad-3/turn-off-siri-on-iphone-ipad-3.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_873,c_scale/f_auto,q_auto/v1786506257/wp-pme/turn-off-siri-on-iphone-ipad-3/turn-off-siri-on-iphone-ipad-3.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_655,c_scale/f_auto,q_auto/v1786506257/wp-pme/turn-off-siri-on-iphone-ipad-3/turn-off-siri-on-iphone-ipad-3.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1235px) 100vw, 1235px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’re using HomePod speakers with personal requests enabled, you&amp;#8217;ll see an additional warning that your HomePod will no longer recognize your voice. Select &lt;strong&gt;Stop Using Siri&lt;/strong&gt; to confirm.&lt;/p&gt;



&lt;h2 id=&quot;turn-off-siri-mac&quot; class=&quot;wp-block-heading&quot;&gt;How to turn off Siri on Mac&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The steps to disable Siri on Mac are similar, though menu names vary depending on your macOS version. On macOS Sequoia and later, you’ll find Siri in &lt;strong&gt;Apple Intelligence &amp;amp; Siri&lt;/strong&gt; in &lt;strong&gt;System Settings&lt;/strong&gt;. On older versions, it&amp;#8217;s just &lt;strong&gt;Siri&lt;/strong&gt;.&lt;/p&gt;



&lt;h3 id=&quot;disable-voice-activation-mac&quot; class=&quot;wp-block-heading&quot;&gt;Disable voice activation&amp;nbsp;&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Click the &lt;strong&gt;Apple icon &lt;/strong&gt;in the menu bar and select &lt;strong&gt;System Settings&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Apple Intelligence &amp;amp; Siri&lt;/strong&gt;.&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;Under &lt;strong&gt;Siri Requests&lt;/strong&gt;, toggle off &lt;strong&gt;Listen for “Hey Siri”&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;994&quot; height=&quot;1166&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_994,h_1166,c_scale/f_auto,q_auto/v1786506238/wp-pme/disable-voice-activation-siri-mac/disable-voice-activation-siri-mac.png?_i=AA&quot; alt=&quot;&amp;quot;Hey Siri&amp;quot; toggle on Mac&quot; class=&quot;wp-post-270887 wp-image-271111&quot; style=&quot;width:500px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;149 KB&quot; data-optsize=&quot;32 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;78.9&quot; data-version=&quot;1786506238&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506238/wp-pme/disable-voice-activation-siri-mac/disable-voice-activation-siri-mac.png?_i=AA 994w, https://res.cloudinary.com/dbulfrlrz/images/w_256,h_300,c_scale/f_auto,q_auto/v1786506238/wp-pme/disable-voice-activation-siri-mac/disable-voice-activation-siri-mac.png?_i=AA 256w, https://res.cloudinary.com/dbulfrlrz/images/w_873,h_1024,c_scale/f_auto,q_auto/v1786506238/wp-pme/disable-voice-activation-siri-mac/disable-voice-activation-siri-mac.png?_i=AA 873w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_901,c_scale/f_auto,q_auto/v1786506238/wp-pme/disable-voice-activation-siri-mac/disable-voice-activation-siri-mac.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 994px) 100vw, 994px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This stops Siri from listening for its wake phrase, though you can still activate Siri using a keyboard shortcut.&lt;/p&gt;



&lt;h3 id=&quot;disable-dictation-mac&quot; class=&quot;wp-block-heading&quot;&gt;Disable dictation&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Click the &lt;strong&gt;Apple icon &lt;/strong&gt;in the menu bar and select &lt;strong&gt;System Settings&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Keyboard&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Toggle &lt;strong&gt;Dictation&lt;/strong&gt; off&lt;strong&gt;.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;982&quot; height=&quot;1238&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_982,h_1238,c_scale/f_auto,q_auto/v1786506218/wp-pme/disable-dictation-on-mac/disable-dictation-on-mac.png?_i=AA&quot; alt=&quot;Dictation toggle on Mac&quot; class=&quot;wp-post-270887 wp-image-271039&quot; style=&quot;width:500px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;151 KB&quot; data-optsize=&quot;35 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;76.8&quot; data-version=&quot;1786506218&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506218/wp-pme/disable-dictation-on-mac/disable-dictation-on-mac.png?_i=AA 982w, https://res.cloudinary.com/dbulfrlrz/images/w_238,h_300,c_scale/f_auto,q_auto/v1786506218/wp-pme/disable-dictation-on-mac/disable-dictation-on-mac.png?_i=AA 238w, https://res.cloudinary.com/dbulfrlrz/images/w_812,h_1024,c_scale/f_auto,q_auto/v1786506218/wp-pme/disable-dictation-on-mac/disable-dictation-on-mac.png?_i=AA 812w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_968,c_scale/f_auto,q_auto/v1786506218/wp-pme/disable-dictation-on-mac/disable-dictation-on-mac.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 982px) 100vw, 982px&quot; /&gt;&lt;/figure&gt;



&lt;h3 id=&quot;turn-off-siri-completely-mac&quot; class=&quot;wp-block-heading&quot;&gt;Turn Siri off completely on Mac&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Click the &lt;strong&gt;Apple icon &lt;/strong&gt;in the menu bar&lt;strong&gt; &lt;/strong&gt;and select &lt;strong&gt;System Settings&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Apple Intelligence &amp;amp; Siri&lt;/strong&gt;.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;Under &lt;strong&gt;Siri Requests&lt;/strong&gt;, toggle &lt;strong&gt;Siri&lt;/strong&gt; off&lt;strong&gt;.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;980&quot; height=&quot;1036&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_980,h_1036,c_scale/f_auto,q_auto/v1786506245/wp-pme/turn-off-siri-completely-on-mac/turn-off-siri-completely-on-mac.png?_i=AA&quot; alt=&quot;Siri toggle on Mac&quot; class=&quot;wp-post-270887 wp-image-271135&quot; style=&quot;width:500px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;127 KB&quot; data-optsize=&quot;28 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;78.4&quot; data-version=&quot;1786506245&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506245/wp-pme/turn-off-siri-completely-on-mac/turn-off-siri-completely-on-mac.png?_i=AA 980w, https://res.cloudinary.com/dbulfrlrz/images/w_284,h_300,c_scale/f_auto,q_auto/v1786506245/wp-pme/turn-off-siri-completely-on-mac/turn-off-siri-completely-on-mac.png?_i=AA 284w, https://res.cloudinary.com/dbulfrlrz/images/w_969,h_1024,c_scale/f_auto,q_auto/v1786506245/wp-pme/turn-off-siri-completely-on-mac/turn-off-siri-completely-on-mac.png?_i=AA 969w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_812,c_scale/f_auto,q_auto/v1786506245/wp-pme/turn-off-siri-completely-on-mac/turn-off-siri-completely-on-mac.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 980px) 100vw, 980px&quot; /&gt;&lt;/figure&gt;



&lt;h2 id=&quot;turn-off-siri-apple-watch&quot; class=&quot;wp-block-heading&quot;&gt;How to turn off Siri on Apple Watch&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your Apple Watch does not mirror your iPhone’s Siri settings. Since they’re independent, you can leave Siri enabled on your iPhone and disabled on your watch, or vice versa. Here’s how to disable Siri on your Apple Watch:&lt;/p&gt;



&lt;h3 id=&quot;disable-voice-activation-watch&quot; class=&quot;wp-block-heading&quot;&gt;Disable voice activation&amp;nbsp;&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the &lt;strong&gt;Settings &lt;/strong&gt;app on your Apple Watch&lt;strong&gt;.&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Siri&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Depending on your WatchOS version, toggle &lt;strong&gt;Listen for “Hey Siri”&lt;/strong&gt; or &lt;strong&gt;Listen for “Siri” &lt;/strong&gt;off.&lt;/li&gt;



&lt;li&gt;Toggle &lt;strong&gt;Raise to Speak &lt;/strong&gt;off.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;374&quot; height=&quot;446&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_374,h_446,c_scale/f_auto,q_auto/v1786506968/wp-pme/turn-off-siri-apple-watch-1/turn-off-siri-apple-watch-1.png?_i=AA&quot; alt=&quot;Siri settings on Apple Watch&quot; class=&quot;wp-post-270887 wp-image-271282&quot; style=&quot;width:200px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;25 KB&quot; data-optsize=&quot;6 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;77&quot; data-version=&quot;1786506968&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506968/wp-pme/turn-off-siri-apple-watch-1/turn-off-siri-apple-watch-1.png?_i=AA 374w, https://res.cloudinary.com/dbulfrlrz/images/w_252,h_300,c_scale/f_auto,q_auto/v1786506968/wp-pme/turn-off-siri-apple-watch-1/turn-off-siri-apple-watch-1.png?_i=AA 252w&quot; sizes=&quot;auto, (max-width: 374px) 100vw, 374px&quot; /&gt;&lt;/figure&gt;



&lt;h3 id=&quot;turn-off-siri-completely-watch&quot; class=&quot;wp-block-heading&quot;&gt;Turn Siri off completely on Apple Watch&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Ensure that you’ve followed the steps above to &lt;a href=&quot;#disable-voice-activation-watch&quot;&gt;disable voice activation on Apple Watch&lt;/a&gt;.&lt;/li&gt;



&lt;li&gt;Open the &lt;strong&gt;Settings &lt;/strong&gt;app.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Siri&lt;/strong&gt;.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;Toggle off &lt;strong&gt;Press Digital Crown&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;374&quot; height=&quot;446&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_374,h_446,c_scale/f_auto,q_auto/v1786506982/wp-pme/turn-off-siri-apple-watch-3/turn-off-siri-apple-watch-3.png?_i=AA&quot; alt=&quot;Siri History on Apple Watch&quot; class=&quot;wp-post-270887 wp-image-271330&quot; style=&quot;width:250px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;107 KB&quot; data-optsize=&quot;10 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;90.7&quot; data-version=&quot;1786506982&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506982/wp-pme/turn-off-siri-apple-watch-3/turn-off-siri-apple-watch-3.png?_i=AA 374w, https://res.cloudinary.com/dbulfrlrz/images/w_252,h_300,c_scale/f_auto,q_auto/v1786506982/wp-pme/turn-off-siri-apple-watch-3/turn-off-siri-apple-watch-3.png?_i=AA 252w&quot; sizes=&quot;auto, (max-width: 374px) 100vw, 374px&quot; /&gt;&lt;/figure&gt;



&lt;ol start=&quot;5&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Tap &lt;strong&gt;Turn Off Siri&lt;/strong&gt; to confirm.&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 id=&quot;disable-siri-suggestions&quot; class=&quot;wp-block-heading&quot;&gt;How to disable Siri Suggestions&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Siri Suggestions analyzes how you use your device, including the apps you use, who you contact, and what you search for, to offer shortcuts and recommendations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Siri Suggestions works independently of the voice features, so you’ll need to turn this off specifically.&lt;/p&gt;



&lt;h3 id=&quot;disable-siri-suggestion-ios&quot; class=&quot;wp-block-heading&quot;&gt;Turn off Siri Suggestions on iPhone and iPad&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the &lt;strong&gt;Settings &lt;/strong&gt;app.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Siri (&lt;/strong&gt;or&lt;strong&gt; Apple Intelligence &amp;amp; Siri).&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;Toggle off the following settings:
&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Suggest Apps Before Searching&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Allow Notifications&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Show in App Library&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Show When Sharing&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Show Listening Suggestions&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1245&quot; height=&quot;1240&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1245,h_1240,c_scale/f_auto,q_auto/v1786506264/wp-pme/turn-off-siri-suggestions-iphone-ipad/turn-off-siri-suggestions-iphone-ipad.png?_i=AA&quot; alt=&quot;Siri Suggestions settings on iOS&quot; class=&quot;wp-post-270887 wp-image-271207&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;135 KB&quot; data-optsize=&quot;23 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;83&quot; data-version=&quot;1786506264&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506264/wp-pme/turn-off-siri-suggestions-iphone-ipad/turn-off-siri-suggestions-iphone-ipad.png?_i=AA 1245w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_300,c_fill,g_auto/f_auto,q_auto/v1786506264/wp-pme/turn-off-siri-suggestions-iphone-ipad/turn-off-siri-suggestions-iphone-ipad.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_1020,c_scale/f_auto,q_auto/v1786506264/wp-pme/turn-off-siri-suggestions-iphone-ipad/turn-off-siri-suggestions-iphone-ipad.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_150,h_150,c_fill,g_auto/f_auto,q_auto/v1786506264/wp-pme/turn-off-siri-suggestions-iphone-ipad/turn-off-siri-suggestions-iphone-ipad.png?_i=AA 150w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_765,c_scale/f_auto,q_auto/v1786506264/wp-pme/turn-off-siri-suggestions-iphone-ipad/turn-off-siri-suggestions-iphone-ipad.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1245px) 100vw, 1245px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To stop specific apps from appearing in Siri Suggestions, scroll down to &lt;strong&gt;Apps &lt;/strong&gt;on the same screen. Select the app(s) you don’t want and toggle all options off.&lt;/p&gt;



&lt;h3 id=&quot;disable-siri-suggestion-mac&quot; class=&quot;wp-block-heading&quot;&gt;Turn off Siri Suggestions on Mac&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Click the &lt;strong&gt;Apple icon&lt;/strong&gt; and select &lt;strong&gt;System Settings&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Apple Intelligence &amp;amp; Siri&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Click &lt;strong&gt;About Siri, Dictation &amp;amp; Privacy&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;954&quot; height=&quot;714&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_954,h_714,c_scale/f_auto,q_auto/v1786506271/wp-pme/turn-off-siri-suggestions-mac/turn-off-siri-suggestions-mac.png?_i=AA&quot; alt=&quot;&amp;quot;About Siri, Dictation &amp;amp; Privacy..&amp;quot; button on Mac&quot; class=&quot;wp-post-270887 wp-image-271231&quot; style=&quot;width:500px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;89 KB&quot; data-optsize=&quot;22 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;74.9&quot; data-version=&quot;1786506271&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506271/wp-pme/turn-off-siri-suggestions-mac/turn-off-siri-suggestions-mac.png?_i=AA 954w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_225,c_scale/f_auto,q_auto/v1786506271/wp-pme/turn-off-siri-suggestions-mac/turn-off-siri-suggestions-mac.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_575,c_scale/f_auto,q_auto/v1786506271/wp-pme/turn-off-siri-suggestions-mac/turn-off-siri-suggestions-mac.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 954px) 100vw, 954px&quot; /&gt;&lt;/figure&gt;



&lt;ol start=&quot;4&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Deselect the apps you don&amp;#8217;t want Siri learning from.&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 id=&quot;delete-siri-history&quot; class=&quot;wp-block-heading&quot;&gt;How to delete Siri history&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Turning Siri off is a good start to reclaiming your privacy, but it doesn&amp;#8217;t erase what&amp;#8217;s already been collected. Your past interactions with Siri and Dictation may be stored on Apple’s servers for up to two years. Here&amp;#8217;s how to delete your Siri history.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;On iPhone and iPad&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the &lt;strong&gt;Settings app.&lt;/strong&gt;&amp;nbsp;&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Siri (&lt;/strong&gt;or &lt;strong&gt;Apple Intelligence &amp;amp; Siri)&lt;/strong&gt; → &lt;strong&gt;Siri &amp;amp; Dictation History.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1219&quot; height=&quot;1629&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1219,h_1629,c_scale/f_auto,q_auto/v1786506197/wp-pme/delete-siri-history-iphone-ipad-1/delete-siri-history-iphone-ipad-1.png?_i=AA&quot; alt=&quot;&amp;quot;Siri &amp;amp; Dictation History&amp;quot; settings tab on iOS&quot; class=&quot;wp-post-270887 wp-image-270943&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;178 KB&quot; data-optsize=&quot;29 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;83.7&quot; data-version=&quot;1786506197&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506197/wp-pme/delete-siri-history-iphone-ipad-1/delete-siri-history-iphone-ipad-1.png?_i=AA 1219w, https://res.cloudinary.com/dbulfrlrz/images/w_224,h_300,c_scale/f_auto,q_auto/v1786506197/wp-pme/delete-siri-history-iphone-ipad-1/delete-siri-history-iphone-ipad-1.png?_i=AA 224w, https://res.cloudinary.com/dbulfrlrz/images/w_766,h_1024,c_scale/f_auto,q_auto/v1786506197/wp-pme/delete-siri-history-iphone-ipad-1/delete-siri-history-iphone-ipad-1.png?_i=AA 766w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1026,c_scale/f_auto,q_auto/v1786506197/wp-pme/delete-siri-history-iphone-ipad-1/delete-siri-history-iphone-ipad-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1149,h_1536,c_scale/f_auto,q_auto/v1786506197/wp-pme/delete-siri-history-iphone-ipad-1/delete-siri-history-iphone-ipad-1.png?_i=AA 1149w&quot; sizes=&quot;auto, (max-width: 1219px) 100vw, 1219px&quot; /&gt;&lt;/figure&gt;



&lt;ol start=&quot;3&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Select &lt;strong&gt;Delete Siri &amp;amp; Dictation History.&lt;/strong&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;1228&quot; height=&quot;780&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1228,h_780,c_scale/f_auto,q_auto/v1786506204/wp-pme/delete-siri-history-iphone-ipad-2/delete-siri-history-iphone-ipad-2.png?_i=AA&quot; alt=&quot;Delete Siri &amp;amp; Dictation History button on iOS&quot; class=&quot;wp-post-270887 wp-image-270967&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;72 KB&quot; data-optsize=&quot;15 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;78.7&quot; data-version=&quot;1786506204&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506204/wp-pme/delete-siri-history-iphone-ipad-2/delete-siri-history-iphone-ipad-2.png?_i=AA 1228w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_191,c_scale/f_auto,q_auto/v1786506204/wp-pme/delete-siri-history-iphone-ipad-2/delete-siri-history-iphone-ipad-2.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_650,c_scale/f_auto,q_auto/v1786506204/wp-pme/delete-siri-history-iphone-ipad-2/delete-siri-history-iphone-ipad-2.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_488,c_scale/f_auto,q_auto/v1786506204/wp-pme/delete-siri-history-iphone-ipad-2/delete-siri-history-iphone-ipad-2.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 1228px) 100vw, 1228px&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;On Mac&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Click on the &lt;strong&gt;Apple&lt;/strong&gt; &lt;strong&gt;icon&lt;/strong&gt; and select &lt;strong&gt;System Settings.&lt;/strong&gt;&amp;nbsp;&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Apple Intelligence &amp;amp; Siri&lt;/strong&gt; → &lt;strong&gt;Siri History.&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;Click &lt;strong&gt;Delete Siri &amp;amp; Dictation History.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;954&quot; height=&quot;712&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_954,h_712,c_scale/f_auto,q_auto/v1786506208/wp-pme/delete-siri-history-on-mac/delete-siri-history-on-mac.png?_i=AA&quot; alt=&quot;Delete Siri &amp;amp; Dictation History on Mac&quot; class=&quot;wp-post-270887 wp-image-270991&quot; style=&quot;width:500px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;89 KB&quot; data-optsize=&quot;22 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;75.7&quot; data-version=&quot;1786506208&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506208/wp-pme/delete-siri-history-on-mac/delete-siri-history-on-mac.png?_i=AA 954w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_224,c_scale/f_auto,q_auto/v1786506208/wp-pme/delete-siri-history-on-mac/delete-siri-history-on-mac.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_573,c_scale/f_auto,q_auto/v1786506208/wp-pme/delete-siri-history-on-mac/delete-siri-history-on-mac.png?_i=AA 768w&quot; sizes=&quot;auto, (max-width: 954px) 100vw, 954px&quot; /&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;On Apple Watch&lt;/h3&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the &lt;strong&gt;Settings &lt;/strong&gt;app.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;Go to &lt;strong&gt;Siri&lt;/strong&gt; → &lt;strong&gt;Siri History.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;374&quot; height=&quot;446&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_374,h_446,c_scale/f_auto,q_auto/v1786506982/wp-pme/turn-off-siri-apple-watch-3/turn-off-siri-apple-watch-3.png?_i=AA&quot; alt=&quot;Siri History on Apple Watch&quot; class=&quot;wp-post-270887 wp-image-271330&quot; style=&quot;width:250px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;107 KB&quot; data-optsize=&quot;10 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;90.7&quot; data-version=&quot;1786506982&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506982/wp-pme/turn-off-siri-apple-watch-3/turn-off-siri-apple-watch-3.png?_i=AA 374w, https://res.cloudinary.com/dbulfrlrz/images/w_252,h_300,c_scale/f_auto,q_auto/v1786506982/wp-pme/turn-off-siri-apple-watch-3/turn-off-siri-apple-watch-3.png?_i=AA 252w&quot; sizes=&quot;auto, (max-width: 374px) 100vw, 374px&quot; /&gt;&lt;/figure&gt;



&lt;ol start=&quot;3&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Select &lt;strong&gt;Delete Siri History.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;



&lt;figure class=&quot;wp-block-image size-full is-resized&quot;&gt;&lt;img width=&quot;374&quot; height=&quot;446&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_374,h_446,c_scale/f_auto,q_auto/v1786506974/wp-pme/turn-off-siri-apple-watch-2/turn-off-siri-apple-watch-2.png?_i=AA&quot; alt=&quot;Delete Siri History on Apple Watch&quot; class=&quot;wp-post-270887 wp-image-271306&quot; style=&quot;width:250px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;27 KB&quot; data-optsize=&quot;8 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;70.8&quot; data-version=&quot;1786506974&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786506974/wp-pme/turn-off-siri-apple-watch-2/turn-off-siri-apple-watch-2.png?_i=AA 374w, https://res.cloudinary.com/dbulfrlrz/images/w_252,h_300,c_scale/f_auto,q_auto/v1786506974/wp-pme/turn-off-siri-apple-watch-2/turn-off-siri-apple-watch-2.png?_i=AA 252w&quot; sizes=&quot;auto, (max-width: 374px) 100vw, 374px&quot; /&gt;&lt;/figure&gt;



&lt;h3 id=&quot;opt-out-siri-data-collection&quot; class=&quot;wp-block-heading&quot;&gt;How to opt out of Improve Siri &amp;amp; Dictation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By default, Apple may use your Siri data to improve its functionality. Here’s how to opt out on iPhone, iPad, Mac, and Apple Watch.&amp;nbsp;&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open the &lt;strong&gt;Settings&lt;/strong&gt; app.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Privacy &amp;amp; Security&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Analytics &amp;amp; Improvements&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Toggle&lt;strong&gt; Improve Siri &amp;amp; Dictation&lt;/strong&gt; off.&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 id=&quot;why-turn-siri-off&quot; class=&quot;wp-block-heading&quot;&gt;Why you should turn off Siri&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For Siri to respond to your voice, it has to be listening all the time for the wake phrase &amp;#8220;Hey Siri&amp;#8221; in the background, with no visual indicator that it&amp;#8217;s active. This convenience comes at a cost to your privacy: Voice recognition isn&amp;#8217;t perfect, and your device can mistake an unrelated word or sound for the wake phrase. When that happens, an ongoing private conversation can be recorded and sent to Apple&amp;#8217;s servers without you realizing it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This isn’t just a theoretical scenario. In January 2025, Apple settled a class-action lawsuit alleging that &lt;a href=&quot;https://edition.cnn.com/2025/05/14/tech/apple-siri-settlement-claim&quot;&gt;accidental Siri activations had recorded private conversations&lt;/a&gt;. Though Apple denied the claims, they still agreed to a $95 million settlement.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even outside of accidental activations, using Siri involves a series of privacy trade-offs. Transcripts of your requests can be stored on Apple&amp;#8217;s servers for up to two years. Siri Suggestions continuously analyzes your app usage, contacts, and search habits to build a behavioral profile — even when you&amp;#8217;re not actively using Siri. And while Apple states that your data isn&amp;#8217;t sold or used for advertising, the data still flows to Apple&amp;#8217;s infrastructure and can be used at their discretion.&lt;/p&gt;



&lt;h2 id=&quot;use-proton&quot; class=&quot;wp-block-heading&quot;&gt;Take back your digital privacy&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Turning off Siri is a meaningful step toward reducing how much your device listens to you and what Apple learns about your daily life. But Siri is just one piece of a broader data ecosystem. Every interaction — from voice commands to app suggestions — builds a profile of your habits, preferences, and routines over time.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At Proton, we believe your data should belong to you, not to the platforms you use. Unlike Apple, Proton&amp;#8217;s tools are built around end-to-end encryption and a zero-knowledge architecture, which means we can&amp;#8217;t read your files, emails, or messages even if we wanted to.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re rethinking how much data your devices collect, it&amp;#8217;s also worth looking at what other apps you’re using that could benefit from privacy-first protections — from your &lt;a href=&quot;https://proton.me/mail&quot;&gt;email provider&lt;/a&gt; to an &lt;a href=&quot;https://proton.me/lumo&quot;&gt;AI assistant&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Today, the stakes are higher than ever. Find out more in our guide to AI privacy.&lt;/p&gt;



&lt;h2 id=&quot;faq&quot; class=&quot;wp-block-heading&quot;&gt;Frequently asked questions about Siri&lt;/h2&gt;



&lt;div class=&quot;schema-faq wp-block-yoast-faq-block&quot;&gt;&lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1786504572669&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;How do I know if Siri is listening?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;When Siri is ready to process a request or is processing one, a visual indicator appears. On an iPhone and iPad, a colorful orb appears at the bottom of your screen. If you have Apple Intelligence enabled, a glowing light appears around your screen. Similarly, on Mac and Apple Watch, you’llsee the colorful orb appear when Siri is activated.&lt;br&gt;&lt;br&gt;However, if you have voice activation enabled, Siri listens continuously in the background for the &amp;#8220;Hey Siri&amp;#8221; wake phrase with no visual indicator. If you’d rather not risk Siri recording your day-to-day conversations, no matter how small that risk may be, you should disable Siri voice activation.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1786504607251&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;Is it safe to have Siri enabled?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt;Apple says that much of Siri’s processing happens on-device and that your data isn’t used for advertising or sold to third parties such as data brokers. However, transcripts of your Siri requests may still be stored on Apple’s servers for up to two years. If you opted in to “Improve Siri &amp;amp; Dictation,” audio recordings may also be shared with Apple. In other words, Siri trades off your privacy for convenience.&lt;/p&gt; &lt;/div&gt; &lt;div class=&quot;schema-faq-section&quot; id=&quot;faq-question-1786504664584&quot;&gt;&lt;strong class=&quot;schema-faq-question&quot;&gt;What happens if I disable Siri?&lt;/strong&gt; &lt;p class=&quot;schema-faq-answer&quot;&gt; Some features such as Siri-specific shortcuts, voice commands, and hands-free functionality will also be disabled. That said, your devices will still function normally for everything else — turning off Siri doesn&amp;#8217;t affect the core experience of using an iPhone, iPad, Mac, or Apple Watch.&lt;/p&gt; &lt;/div&gt; &lt;/div&gt;
</content:encoded><category>Guides</category><author>Greg Ng</author></item><item><title>How your house spies on you</title><link>https://proton.me/blog/smart-home-privacy</link><guid isPermaLink="true">https://proton.me/blog/smart-home-privacy</guid><description>Your smart home may know more about you than you realize. Learn how connected devices collect data and how to better protect your privacy.</description><pubDate>Tue, 11 Aug 2026 18:01:18 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smart home devices can make everyday life more convenient, from answering the front door to tracking your workouts. But many also &lt;a href=&quot;https://proton.me/blog/wifi-surveillance&quot; data-type=&quot;link&quot; data-id=&quot;https://proton.me/blog/wifi-surveillance&quot;&gt;collect data about your habits, routines, and even your health&lt;/a&gt;. Taken together, that information can paint a surprisingly detailed picture of life inside your home.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;From the moment someone rings your doorbell to the time you switch off the lights at night, connected devices can record where you go, what you watch, when you&amp;#8217;re home, and even how you sleep. Some of that data is essential for the products to work, some helps companies improve their services, and some raises important questions about how much information we&amp;#8217;re comfortable sharing.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In this guide, we’ll take a room-by-room tour of a modern smart home to see what devices know about you, and where you can take back a little more control.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;Shut Down the Spying Tech in Your Home, Room by Room&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/9_WQZNEOhys?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Jump to:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#front-door&quot; data-type=&quot;internal&quot; data-id=&quot;#front-door&quot;&gt;The front door&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#hallway&quot; data-type=&quot;internal&quot; data-id=&quot;#hallway&quot;&gt;The hallway&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#living-room&quot; data-type=&quot;internal&quot; data-id=&quot;#livingroom&quot;&gt;The living room&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#childrens-room&quot; data-type=&quot;internal&quot; data-id=&quot;#childrensroom&quot;&gt;The children&amp;#8217;s room&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#bathroom&quot; data-type=&quot;internal&quot; data-id=&quot;#bathroom&quot;&gt;The bathroom&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#bedroom&quot; data-type=&quot;internal&quot; data-id=&quot;#bedroom&quot;&gt;The bedroom&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#kitchen&quot; data-type=&quot;internal&quot; data-id=&quot;#kitchen&quot;&gt;The kitchen&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#home-gym&quot; data-type=&quot;internal&quot; data-id=&quot;#home-gym&quot;&gt;The home gym&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;front-door&quot; class=&quot;wp-block-heading&quot;&gt;The front door&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Video doorbells have become one of the most popular smart home upgrades, offering a convenient way to keep an eye on deliveries and visitors. But they also create a permanent digital record of everyone who walks past your home.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy concerns extend beyond the footage itself. In 2023, the U.S. Federal Trade&amp;nbsp;Commission &lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-says-ring-employees-illegally-surveilled-customers-failed-stop-hackers-taking-control-users&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;accused Ring of allowing employees and contractors broad access to customer videos&lt;/a&gt;, with allegations that some viewed recordings from sensitive locations. These incidents highlight the importance of understanding who can access cloud-stored footage.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;What you can do&lt;/h4&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Choose cameras that support &lt;a href=&quot;https://proton.me/blog/internet-of-things-privacy-iot-explained&quot;&gt;local storage rather than cloud-only recording&lt;/a&gt;.&lt;/li&gt;



&lt;li&gt;If you use a cloud camera, disable facial recognition and optional AI features whenever possible.&lt;/li&gt;



&lt;li&gt;Review your privacy settings regularly to minimize unnecessary data collection.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;hallway&quot; class=&quot;wp-block-heading&quot;&gt;The hallway&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Motion sensors, entry logs, and optional facial recognition features can reveal when you leave for work, when you return home, and even your family&amp;#8217;s daily habits. Privacy experts often refer to this as a &amp;#8220;pattern of life&amp;#8221;, a detailed timeline built from seemingly ordinary events.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security companies have also experienced data breaches that exposed customer information, reinforcing the importance of choosing providers that prioritize security as much as convenience. Traditional alarm companies often focus on intrusion detection rather than building extensive advertising profiles around user behavior.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;What you can do&lt;/h4&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Review which features your security system has enabled by default.&lt;/li&gt;



&lt;li&gt;Disable facial recognition and other cloud-based AI features you don&amp;#8217;t use.&lt;/li&gt;



&lt;li&gt;Consider providers that focus on intrusion detection rather than building detailed user profiles.&lt;/li&gt;



&lt;li&gt;Check your account settings periodically to understand what information is being collected and stored.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;living-room&quot; class=&quot;wp-block-heading&quot;&gt;The living room&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your television may know more about your viewing habits than your favorite streaming service. Some smart TVs collect information about what you watch through technologies like &lt;a href=&quot;https://protonvpn.com/blog/smart-tv-privacy-risk&quot; data-type=&quot;link&quot; data-id=&quot;protonvpn.com/blog/smart-tv-privacy-risk&quot;&gt;Automatic Content Recognition (ACR)&lt;/a&gt;, which can identify content playing on the screen regardless of where it comes from. In one widely reported case, Vizio collected viewing data from millions of TVs before selling that information for targeted advertising. Samsung also faced criticism after users discovered voice commands relied on the TV actively listening for speech.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Convenience often comes bundled with data collection, especially when manufacturers subsidize hardware with advertising revenue.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;What you can do&lt;/h4&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Consider using a basic television paired with a streaming stick.&lt;/li&gt;



&lt;li&gt;Build a personal media library with platforms like Plex or Jellyfin if you&amp;#8217;d rather not rely entirely on cloud services.&lt;/li&gt;



&lt;li&gt;Review your TV&amp;#8217;s privacy settings and disable optional advertising features.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;childrens-room&quot; class=&quot;wp-block-heading&quot;&gt;The children&amp;#8217;s room&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/how-to-protect-your-childrens-privacy-online&quot;&gt;Devices designed for children deserve an even higher standard of privacy&lt;/a&gt;. Connected toys can store conversations, while smart baby monitors may stream video and audio over the internet. This convenience can come with risks. Recent reports involving AI-powered toys exposed children&amp;#8217;s chat logs, while compromised baby monitors have allowed strangers to speak directly through connected devices.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For many parents, these products provide genuine peace of mind. But they also demonstrate why devices aimed at children deserve careful scrutiny before bringing them into the home.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;What you can do&lt;/h4&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Choose closed-loop baby monitors that don&amp;#8217;t rely on cloud services.&lt;/li&gt;



&lt;li&gt;Research how children&amp;#8217;s devices store and protect recordings before purchasing.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;bathroom&quot; class=&quot;wp-block-heading&quot;&gt;The bathroom&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Bathrooms are among the most private spaces in any home, yet they&amp;#8217;re increasingly home to connected health technology.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smart devices can now monitor everything from brushing habits to urine biomarkers, uploading that information to cloud services for analysis. While these features can provide useful health insights, they also require users to trust lengthy privacy policies that often permit data sharing with third parties.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;What you can do&lt;/h4&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Consider keeping a health journal in apps like Obsidian, Standard Notes, or even Apple Notes instead of relying on cloud-connected devices.&lt;/li&gt;



&lt;li&gt;Ask whether a smart feature genuinely adds value before sharing sensitive health information.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;bedroom&quot; class=&quot;wp-block-heading&quot;&gt;The bedroom&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Few devices are more personal than those used in the bedroom.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A lawsuit involving the smart vibrator We-Vibe alleged that usage information was collected through its companion app without users&amp;#8217; knowledge or consent. Whether or not someone uses connected devices in intimate settings is a personal choice, but it&amp;#8217;s worth considering whether internet connectivity actually improves products that are already highly personal.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;What you can do&lt;/h4&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Consider whether your device really needs internet connectivity in the first place.&lt;/li&gt;



&lt;li&gt;Review the companion app&amp;#8217;s privacy settings and data-sharing options.&lt;/li&gt;



&lt;li&gt;Delete old accounts if you no longer use the device.&lt;/li&gt;



&lt;li&gt;If privacy is your priority, an analog alternative remains the safest choice.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;kitchen&quot; class=&quot;wp-block-heading&quot;&gt;The kitchen&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Not every appliance needs to be connected to the internet.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smart refrigerators, ovens, and even air fryers increasingly ask for app permissions, account creation, or cloud connectivity. While some features are genuinely useful, others appear difficult to justify. A refrigerator with internal cameras might help you check what&amp;#8217;s inside while shopping but it also creates another source of personal data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy experts have also warned that connected home devices can become tools for coercive control, allowing abusive partners to remotely manipulate lights, speakers, thermostats, and other household appliances.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;What you can do&lt;/h4&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Skip smart features if they don&amp;#8217;t offer any value.&lt;/li&gt;



&lt;li&gt;Use &lt;a href=&quot;https://proton.me/blog/how-to-create-a-strong-password&quot;&gt;strong, unique passwords&lt;/a&gt; for connected appliances and change them regularly.&lt;/li&gt;



&lt;li&gt;Disable microphones, cameras, or cloud features you don&amp;#8217;t use.&lt;/li&gt;



&lt;li&gt;If multiple people have access to your smart home, regularly review who can control your devices.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;home-gym&quot; class=&quot;wp-block-heading&quot;&gt;The home gym&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smart home gym equipment doesn&amp;#8217;t just record workouts, it can also collect surprisingly sensitive personal information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some products ask users to share details such as pregnancy status or long-term health goals. Individually, these questions may seem harmless. Combined with other personal data, however, they can contribute to highly detailed personal profiles.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Privacy is all about about maintaining control over who has access to your information and deciding when that information is shared.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;What you can do&lt;/h4&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Only share the personal information needed to use the service.&lt;/li&gt;



&lt;li&gt;Review what health data your fitness apps collect and whether you can opt out.&lt;/li&gt;



&lt;li&gt;Use offline workout tracking when possible.&lt;/li&gt;



&lt;li&gt;Ask yourself whether a connected gym offers benefits that outweigh the privacy trade-off.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Smart home, outsmarted&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smart home technology isn&amp;#8217;t inherently bad. Many connected devices genuinely make life safer, easier, and more comfortable. The goal isn&amp;#8217;t to eliminate technology altogether but rather to make informed decisions about the trade-offs that may impact your &lt;a href=&quot;https://proton.me/blog/internet-privacy&quot;&gt;internet privacy&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before buying a new smart device, ask yourself a few simple questions. Does it really need an internet connection? Where is the data stored? Can cloud features be disabled? Is there a version that works locally instead?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Small choices add up. Using &lt;a href=&quot;https://proton.me/blog/how-to-create-a-strong-password&quot;&gt;stronger passwords&lt;/a&gt;, disabling unnecessary cloud features, choosing devices with local storage, and only buying smart products when they offer meaningful benefits can significantly reduce how much information leaves your home.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your home should still feel like your sanctuary. With a little extra attention to privacy, it can remain one.&lt;/p&gt;
</content:encoded><author>Proton Team</author></item><item><title>Automate your business cloud storage without compromising privacy</title><link>https://proton.me/business/blog/cli-workflow-automation</link><guid isPermaLink="true">https://proton.me/business/blog/cli-workflow-automation</guid><description>Automate backups, sharing, and file management for your business with a cloud storage CLI that protects your data with end-to-end encryption.</description><pubDate>Tue, 11 Aug 2026 13:51:55 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Businesses rely on automated workflows to back up records, transfer files, and keep critical information available to the right people, both in and out of the team. When those workflows send sensitive client or operational data to a conventional cloud storage provider, your business has less control over who can access that information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Proton Drive Command Line Interface (CLI) offers a private alternative&lt;/strong&gt;. It brings Proton Drive’s end-to-end encrypted &lt;a href=&quot;https://proton.me/drive&quot;&gt;cloud storage for teams&lt;/a&gt; to the command line, so your organization can automate routine file operations while staying in control of its data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Available for Linux, macOS, and Windows, Proton Drive CLI enables your business to securely back up files through &lt;a href=&quot;https://proton.me/business/drive/cli&quot;&gt;scripts and automated workflows&lt;/a&gt;, as well as upload, download, organize, and share them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s what that looks like in practice:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Scheduled backups: Set up a nightly or weekly job that automatically copies new and changed files into end-to-end encrypted storage, so backups happen on a fixed schedule.&lt;/li&gt;



&lt;li&gt;Managed sharing and access: Invite a reviewer or collaborator with a defined role, then revoke their access the moment a project ends, all as a scripted step.&lt;/li&gt;



&lt;li&gt;Release and build artifacts: Add a step to your existing deployment pipeline that uploads release files, or build outputs automatically every time you ship, without a manual export.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For businesses already comfortable with command-line tools, it’s a straightforward way to add private cloud storage to existing processes. For smaller teams exploring &lt;a href=&quot;https://proton.me/business/drive/cloud-backup-small-business&quot;&gt;cloud backup for small business&lt;/a&gt;, it offers a practical starting point for automated, encrypted backups, without requiring you to build and maintain a custom storage integration.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Secure, automated backup and file operations for industries handling confidential data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Manual &lt;a href=&quot;https://proton.me/business/blog/file-management&quot;&gt;file management&lt;/a&gt; creates gaps in &lt;a href=&quot;https://proton.me/business/drive/cloud-data-security&quot;&gt;cloud data security&lt;/a&gt;: Someone might forget to upload an important folder, a backup may be delayed during a busy week, or &lt;a href=&quot;https://proton.me/business/blog/sensitive-information&quot;&gt;sensitive information&lt;/a&gt; may end up in the wrong account.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Automation turns that informal responsibility into a consistent, repeatable process — and with Proton Drive CLI, it stays end-to-end encrypted throughout. Only you and the people you authorize can access the contents of what&amp;#8217;s stored or shared, not even Proton.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s what that looks like across the industries handling the most sensitive data:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Legal and accounting&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/drive/cloud-storage-for-law-firms&quot;&gt;Law firms&lt;/a&gt; can automatically archive case files, contracts, evidence, and privileged communications when a matter closes. &lt;a href=&quot;https://proton.me/business/drive/financial-services-document-management&quot;&gt;Accounting firms&lt;/a&gt; can schedule secure backups of tax documents, financial records, and client reports.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This data is often highly sensitive and personal. &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;End-to-end encryption&lt;/a&gt; helps protect your business and clients while supporting compliance with data protection laws such as the GDPR.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Consulting and professional services firms&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Protect client deliverables, research, and NDA-covered material with automated encrypted backups for &lt;a href=&quot;https://proton.me/business/drive/professional-services&quot;&gt;professional services&lt;/a&gt;. Remove a client&amp;#8217;s access the day an engagement ends and keep a consistent process for archiving completed projects. You can also assemble a &lt;a href=&quot;https://proton.me/business/drive/secure-data-room&quot;&gt;secure data room&lt;/a&gt; for due diligence.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Healthcare organizations&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Move patient records into &lt;a href=&quot;https://proton.me/business/drive/hipaa-compliant-cloud-storage-for-healthcare&quot;&gt;HIPAA-compliant cloud storage&lt;/a&gt; as soon as they&amp;#8217;re created to ensure confidentiality and protect administrative files. Automated backups reduce manual handling, keep sensitive data stored consistently, and support your organization’s wider HIPAA compliance efforts.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Tech and cybersecurity companies&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Protect customer data exports before they leave your systems, and store software release files automatically as part of your existing pipeline. Deliver reports, audits, or compliance packages to clients through a &lt;a href=&quot;https://proton.me/business/drive/secure-client-portal&quot;&gt;secure client portal&lt;/a&gt; instead of building one from scratch. For cybersecurity companies, using end-to-end encrypted storage for their own files shows they follow the same security practices they recommend to their clients.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;NGOs, journalists, and human rights organizations&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Automatically upload interviews, reports, photos, and other sensitive information to encrypted storage as soon as it’s collected, reducing the risk of files being lost, exposed, or handled inconsistently. Proton has long supported &lt;a href=&quot;https://proton.me/business/media&quot;&gt;press freedom&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/nonprofit-discount&quot;&gt;nonprofit organizations&lt;/a&gt; operating in high-risk environments.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Bring privacy to your automated workflows&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your business should not have to choose between efficient cloud workflows and strong &lt;a href=&quot;https://proton.me/business/drive/data-protection&quot;&gt;data protection&lt;/a&gt; — with Proton Drive CLI, you get both. Automate file storage, backups, transfers, and sharing, with all operations protected by Proton Drive&amp;#8217;s end-to-end encryption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Drive is built on the same foundation as the rest of Proton. It&amp;#8217;s &lt;a href=&quot;https://proton.me/business/iso-27001-certification&quot;&gt;ISO 27001 certified&lt;/a&gt; and holds a &lt;a href=&quot;https://proton.me/blog/soc-2&quot;&gt;SOC 2 Type II&lt;/a&gt; attestation, supporting your own &lt;a href=&quot;https://proton.me/business/trust&quot;&gt;compliance&lt;/a&gt; work under frameworks like &lt;a href=&quot;https://proton.me/business/healthcare&quot;&gt;HIPAA&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/gdpr&quot;&gt;GDPR&lt;/a&gt;. Proton apps are &lt;a href=&quot;https://proton.me/community/open-source&quot;&gt;open source&lt;/a&gt; and independently audited, so anyone can verify our security claims. And as a &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;Swiss&lt;/a&gt; company, Proton operates under some of the world&amp;#8217;s strongest privacy laws, part of a broader push toward &lt;a href=&quot;https://proton.me/business/europe-tech-watch&quot;&gt;European tech sovereignty&lt;/a&gt; and outside the reach of the surveillance and data practices of US companies.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/drive/download&quot;&gt;Download Proton Drive CLI&lt;/a&gt; and try it against your own workflow, &lt;a href=&quot;https://proton.me/business/drive/pricing&quot;&gt;explore our business plans&lt;/a&gt; for a full rollout, or &lt;a href=&quot;https://proton.me/business/contact&quot;&gt;talk to our sales team&lt;/a&gt; about deploying it across your organization.&lt;/p&gt;
</content:encoded><category>For business</category><author>Michal Hořejšek</author></item><item><title>Shadow AI is a hidden risk to your business</title><link>https://proton.me/business/blog/shadow-ai</link><guid isPermaLink="true">https://proton.me/business/blog/shadow-ai</guid><description>Learn what shadow AI is, how it exposes business data, how to detect unapproved AI tools, and how to reduce the security and compliance risks.</description><pubDate>Fri, 07 Aug 2026 11:21:34 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI tools are now part of everyday work, helping people summarize meeting notes, draft emails, debug code, analyze spreadsheets, and turn documents into presentations. Used without approval or oversight, however, they can raise serious &lt;a href=&quot;https://proton.me/lumo/ai&quot;&gt;AI privacy&lt;/a&gt; concerns, expose sensitive business information, and leave IT teams unable to see where company data is going.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This guide covers what shadow AI is, how it spreads inside organizations, and the serious risks it creates. We’ll show how to spot unapproved tools and implement practical safeguards to protect your business data — without slowing your team down.&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#what-is&quot;&gt;What is shadow AI?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#shadow-it&quot;&gt;Shadow AI vs. shadow IT&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how&quot;&gt;How does shadow AI happen?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#auto-ai-training&quot;&gt;Does AI automatically train on your data?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#examples&quot;&gt;Examples of shadow AI&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#risks&quot;&gt;What are the shadow AI risks?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#detect&quot;&gt;How to detect shadow AI&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#reduce-risks&quot;&gt;How to reduce shadow AI risks&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#what-to-do&quot;&gt;What to do if sensitive data has already been shared&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#lumo&quot;&gt;A private AI assistant for teams&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;what-is&quot; class=&quot;wp-block-heading&quot;&gt;What is shadow AI?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI is any use of &lt;a href=&quot;https://proton.me/lumo/ai&quot;&gt;artificial intelligence&lt;/a&gt; for work that falls outside a business&amp;#8217;s approved systems and policies. It can involve an unapproved tool, a personal account used for company work, or an approved AI service used with data or for tasks the organization has not authorized.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI often starts with everyday workplace pressures: a tight deadline, the need to find a faster or better way to work, or a tool that is not quite getting the job done. Sometimes, an approved AI tool is available, but people turn elsewhere because they are more familiar with another option.&lt;/p&gt;



&lt;h3 id=&quot;shadow-it&quot; class=&quot;wp-block-heading&quot;&gt;Shadow AI vs. shadow IT&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/shadow-it&quot;&gt;Shadow IT&lt;/a&gt; is the broader term for any software or hardware used without an organization’s approval or oversight. Common examples include personal &lt;a href=&quot;https://proton.me/drive&quot;&gt;cloud storage&lt;/a&gt; used for work, unauthorized messaging apps, and unapproved project management platforms.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI is a specific form of shadow IT involving AI systems and AI-powered features. AI introduces an additional data governance challenge because company information may be submitted to an external system or processed in unfamiliar ways outside the organization’s control.&lt;/p&gt;



&lt;h2 id=&quot;how&quot; class=&quot;wp-block-heading&quot;&gt;How does shadow AI happen?&lt;/h2&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1008&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1008,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA&quot; alt=&quot;A process flow diagram showing how shadow AI happens&quot; class=&quot;wp-post-254799 wp-image-254825&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;62 KB&quot; data-optsize=&quot;16 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;74.4&quot; data-version=&quot;1786093900&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_126,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_430,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_323,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_645,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_860,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_659,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees can enter large amounts of company information into an AI chat window within seconds. Depending on the AI’s settings, the tool may retain the input, share it with other parties (such as &lt;a href=&quot;https://proton.me/blog/data-brokers&quot;&gt;data brokers&lt;/a&gt; or analytics vendors, like in the &lt;a href=&quot;https://proton.me/business/blog/openai-data-breach&quot;&gt;OpenAI breach&lt;/a&gt; case), or use it for targeted ads or model development.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI usually spreads because of a few common organizational gaps.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;No approved alternative&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees are more likely to use shadow AI tools when the business has not provided an approved option A &lt;a href=&quot;https://www.blackfog.com/blackfog-research-shadow-ai-threat-grows/&quot;&gt;BlackFog survey&lt;/a&gt; of 2,000 workers&amp;nbsp; found 49% of employees adopt AI tools without employer approval, 63% think it&amp;#8217;s acceptable to use AI when there&amp;#8217;s no corporate-approved option, and 51% have connected AI tools to work systems without IT&amp;#8217;s knowledge.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Unclear policies&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees may be unsure which tools, tasks, and types of information are permitted. Company guidance may clearly restrict highly sensitive data while saying little about internal meeting notes, draft emails, spreadsheets, source code, or customer conversations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://www.itbrew.com/stories/more-than-one-third-of-it-pros-arent-confident-employees-know-ai-policies&quot;&gt;IT Brew&amp;#8217;s survey&lt;/a&gt; run on 241 IT professionals found that 35% have little to no confidence employees know their company&amp;#8217;s AI usage and data security policies, and only 12% felt “very confident.” A separate &lt;a href=&quot;https://datacentrenews.in/story/over-half-of-firms-lack-clear-ai-policy-as-risks-mount-survey-finds&quot;&gt;WorkNest survey&lt;/a&gt; of 505 HR professionals/employers found 54% of organizations have no AI policy at all, 24% are still developing one, and only 13% have clear, documented rules.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Slow approval processes&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Pressure to meet deadlines can make a lengthy security or procurement review feel impractical. When employees can access a free tool immediately, slow internal processes make unofficial workarounds more likely.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;New AI features in approved software&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A vendor may add generative AI features to an application that has already passed a security review, and the software stays on the approved list even though nobody has assessed how the new feature processes, stores, or shares company data. The employee hasn&amp;#8217;t broken any policy, but the result is the same as the other causes: Company data is now moving through a channel nobody has actually vetted.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Limited awareness of data handling&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees may not know how AI providers like &lt;a href=&quot;https://proton.me/lumo/ai/is-chatgpt-safe&quot;&gt;ChatGPT&lt;/a&gt; and &lt;a href=&quot;https://proton.me/lumo/ai/is-gemini-safe&quot;&gt;Gemini&lt;/a&gt; retain prompts, process uploaded files, use conversations for service improvement, or share data with other providers. They may assume their inputs disappear when they close the browser tab, even when copies remain in account histories, logs, backups, or connected systems.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://www.kolide.com/blog/89-of-workers-use-ai-far-fewer-understand-the-risks&quot;&gt;Kolide&amp;#8217;s report&lt;/a&gt; found that while 89% of employees use AI monthly, only 56% of companies have explained &lt;a href=&quot;https://proton.me/lumo/ai/security&quot;&gt;AI&amp;#8217;s security risks&lt;/a&gt; to staff.&lt;/p&gt;



&lt;h2 id=&quot;examples&quot; class=&quot;wp-block-heading&quot;&gt;Examples of shadow AI&lt;/h2&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Team&lt;/th&gt;&lt;th&gt;Example of shadow AI&lt;/th&gt;&lt;th&gt;&lt;br&gt;Information potentially exposed&lt;/th&gt;&lt;th&gt;Potential impact&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Software development&lt;/td&gt;&lt;td&gt;Pasting internal code into a public chatbot for debugging&lt;/td&gt;&lt;td&gt;Source code, credentials, system architecture, and unreleased features&lt;/td&gt;&lt;td&gt;Proprietary code or secrets may be retained outside company systems&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Product&lt;/td&gt;&lt;td&gt;Uploading a roadmap for summarization&lt;/td&gt;&lt;td&gt;Launch dates, product strategy, pricing, and partner information&lt;/td&gt;&lt;td&gt;Confidential business plans may sit unmanaged on third-party servers&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Marketing and design&lt;/td&gt;&lt;td&gt;Entering campaign plans into an AI writing or design tool&lt;/td&gt;&lt;td&gt;Unreleased products, customer research, brand assets, and audience data&lt;/td&gt;&lt;td&gt;Sensitive campaign information may be processed without legal or security review&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Data analysis&lt;/td&gt;&lt;td&gt;Uploading customer datasets to an external analysis tool&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://proton.me/blog/personal-data&quot;&gt;Personal data&lt;/a&gt;, commercially sensitive records, and confidential insights&lt;/td&gt;&lt;td&gt;Protected or regulated information may be disclosed to unapproved third parties&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Human resources&lt;/td&gt;&lt;td&gt;Using an AI tool to assess applications or summarize interviews&lt;/td&gt;&lt;td&gt;Candidate data, employment information, and assessment criteria&lt;/td&gt;&lt;td&gt;Personnel data exposure may breach GDPR or CCPA&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sales&lt;/td&gt;&lt;td&gt;Uploading call transcripts or account notes for analysis&lt;/td&gt;&lt;td&gt;Customer identities, contract details, pricing, and sales strategy&lt;/td&gt;&lt;td&gt;Customer data exposure may breach GDPR or CCPA&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Customer support&lt;/td&gt;&lt;td&gt;Pasting support tickets into a public chatbot&lt;/td&gt;&lt;td&gt;Customer names, account details, complaints, and correspondence&lt;/td&gt;&lt;td&gt;Retained support records may violate GDPR or CCPA&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Finance&lt;/td&gt;&lt;td&gt;Asking an AI assistant to analyze internal spreadsheets&lt;/td&gt;&lt;td&gt;Budgets, forecasts, payroll information, and transaction records&lt;/td&gt;&lt;td&gt;Financial data may be processed without appropriate safeguards&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Legal&lt;/td&gt;&lt;td&gt;Uploading contracts or case files for summarization&lt;/td&gt;&lt;td&gt;Privileged advice, contractual terms, and client information&lt;/td&gt;&lt;td&gt;Client data misuse may breach GDPR or CCPA and affect privilege&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Leadership&lt;/td&gt;&lt;td&gt;Using an AI service to review board documents or strategic plans&lt;/td&gt;&lt;td&gt;Acquisition plans, internal targets, and executive discussions&lt;/td&gt;&lt;td&gt;Highly sensitive corporate intelligence may become exposed&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;auto-ai-training&quot; class=&quot;wp-block-heading&quot;&gt;Does AI automatically train on your data?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/llm&quot;&gt;Large language models (LLMs)&lt;/a&gt; do not automatically retrain themselves on every prompt in real time, so a conversation won’t inevitably become part of the AI model or appear in another user’s response. However, the level of risk depends on the provider, account type, privacy settings, contract, and how the service has been configured.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An AI provider may retain prompts and uploaded files, make them available for human review, use them to improve its services, or share them with infrastructure and model providers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even when model training is disabled, information may appear in account histories, operational logs, abuse-monitoring systems, backups, browser records, connected services, or third-party integrations. If your content has already contributed to model training, turning off this option won’t make the model forget your past conversations.&lt;/p&gt;



&lt;h2 id=&quot;risks&quot; class=&quot;wp-block-heading&quot;&gt;What are the shadow AI risks?&lt;/h2&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA&quot; alt=&quot;A chart that explains the risks of shadow AI&quot; class=&quot;wp-post-254799 wp-image-254849&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;260 KB&quot; data-optsize=&quot;65 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;75&quot; data-version=&quot;1786093960&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI can influence decisions, generate customer-facing material, write code, or analyze personal data, all of which create risks extending beyond the security of the tool itself:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Data breach&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;IBM’s 2025 &lt;a href=&quot;https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications,-97-of-which-reported-lacking-proper-ai-access-controls&quot;&gt;Cost of a Data Breach Report&lt;/a&gt; found that one in five organizations had experienced a &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;breach&lt;/a&gt; linked to shadow AI, yet only 37% had policies designed to manage or detect it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Organizations with high levels of shadow AI faced breach costs averaging $670,000 more than those with little or no shadow AI. Further, incidents involving shadow AI exposed personal information and intellectual property more frequently than the global average.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Exposure of confidential information&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees may share internal documents, source code, financial information, contracts, customer records, product plans, or trade secrets without realizing the AI provider retains their inputs. Even when information is excluded from model training, it can remain exposed to account compromise, security breaches, provider access, insecure integrations, or legal demands.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, &lt;a href=&quot;https://www.forbes.com/sites/siladityaray/2023/05/02/samsung-bans-chatgpt-and-other-chatbots-for-employees-after-sensitive-code-leak/&quot;&gt;Samsung banned ChatGPT&lt;/a&gt; company-wide in May 2023 after employees pasted confidential material into it three times in 20 days, including semiconductor source code, defect-detection algorithms, and a transcribed internal meeting.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Loss of intellectual property&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proprietary knowledge is often a company’s most valuable asset. Uploading code, research, product designs, processes, or strategy documents to an external AI service may conflict with confidentiality agreements or weaken the business’s ability to control that information. An employee may also use AI-generated content without understanding its origins, licensing restrictions, or similarity to third-party material.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Privacy and regulatory violations&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Personal data remains subject to data privacy law when it is processed through an AI tool. Shadow AI can bypass privacy safeguards because the relevant legal teams never know that the processing is taking place. The UK Information Commissioner’s Office warns that AI systems can &lt;a href=&quot;https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-should-we-assess-security-and-data-minimisation-in-ai/&quot;&gt;amplify existing security risks&lt;/a&gt;. Serious GDPR infringements can lead to penalties of up to €20 million or 4% of the organization’s worldwide annual turnover from the previous financial year, whichever is higher.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Insecure integrations and excessive access&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI tools may connect to email, cloud storage, calendars, code repositories, customer databases, and collaboration platforms. Broad permissions, poorly secured APIs, leaked access tokens, malicious browser extensions, and compromised third-party services can expose company systems and data beyond the information entered in a single prompt.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In the &lt;a href=&quot;https://proton.me/business/blog/salesloft-drift-attack&quot;&gt;Salesloft Drift breach&lt;/a&gt;, attackers stole OAuth tokens from Drift, an AI sales-assistant integration, and used them to pull data out of Salesforce instances at more than 700 organizations, including business contacts, API keys, and cloud credentials embedded in support cases.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Prompt injection attacks&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This vulnerability exists in any connected AI system, approved or not — attackers can manipulate an AI system through instructions hidden in documents, webpages, emails, or other content it processes, causing it to reveal information, ignore its original instructions, or take unintended actions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI raises the stakes because an unapproved tool or &lt;a href=&quot;https://proton.me/blog/ai-agent&quot;&gt;AI agent&lt;/a&gt; may never have been assessed for prompt injection or limited to the permissions it needs. If an attack succeeds, security teams may have little visibility into what happened or how to contain it. The consequences are especially serious when the AI agent can access sensitive data or take actions without human review.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Lack of accountability&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI activity often leaves no central audit trail. Security teams may be unable to determine which information was submitted, which model processed it, what output it produced, or how the result influenced a decision. Investigating an error, complaint, &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breach&lt;/a&gt;, or regulatory question becomes much harder without those records.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Unexpected costs and supplier dependence&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Separate subscriptions and API accounts can create duplicated spending across departments. Experimental tools may also become embedded in important workflows before procurement teams have assessed their pricing, reliability, or long-term availability. A free service can become business-critical without a service agreement, continuity plan, or practical way to move the workflow elsewhere.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;detect&quot; class=&quot;wp-block-heading&quot;&gt;How to detect shadow AI&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI can be difficult to detect because employees may use personal accounts, browser extensions, embedded AI features, &lt;a href=&quot;https://proton.me/blog/ai-browsers-perplexity-chrome-privacy&quot;&gt;AI browsers&lt;/a&gt;, or tools that blend into normal web traffic. Organizations therefore need visibility into which services are being used and how company data moves through them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Monitoring should remain proportionate and respect employee privacy. The goal should be to identify risky tools and data flows without routinely inspecting the contents of every prompt or conversation.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA&quot; alt=&quot;A chart that explains how to detect shadow AI&quot; class=&quot;wp-post-254799 wp-image-254873&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;81 KB&quot; data-optsize=&quot;23 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;71.9&quot; data-version=&quot;1786094058&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are some tips for identifying shadow AI within your organization:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Create an inventory of AI use&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ask teams which AI tools they currently use, what tasks they use them for, and what prevents them from using approved alternatives. A short survey, interviews with department leads, and a voluntary disclosure period can reveal uses that technical controls miss. Employees are more likely to be honest when the goal is to understand their needs rather than punish early experimentation.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Review network and application activity&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security teams can use network logs, software inventories, and cloud access security tools to identify connections to known AI services. Monitoring can show which services are being accessed and how much data is transferred without capturing the content of every conversation.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Audit browser extensions and plug-ins&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Browser extensions can add AI writing, summarization, translation, meeting, and coding features to almost any workflow. Review which extensions are installed, what permissions they request, and whether they can read webpage content, email, documents, or login information.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Check expenses and procurement records&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employee expense claims, corporate card statements, and procurement records may reveal paid AI subscriptions that have never completed a security review. Repeated payments from different teams can also uncover duplicated tools and unofficial accounts.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Search for unmanaged API keys and integrations&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Review code repositories, secrets managers, cloud environments, billing dashboards, and automation platforms for connections to external AI providers. Unmanaged API keys or unfamiliar usage charges may indicate a prototype, integration, or internal tool that has not been formally approved.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Use data loss prevention controls&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/data-loss-prevention&quot;&gt;Data loss prevention&lt;/a&gt; tools can identify attempts to upload sensitive categories of information such as personal records, credentials, financial data, and source code. Controls should be proportionate and clearly communicated. Employees need to understand what is monitored, why it is necessary, and how to complete legitimate work through approved systems.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Work with employees rather than around them&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Technical monitoring alone will not reveal every instance of shadow AI. Employees may use personal accounts, mobile devices, or tools that appear as normal web traffic. Regular discussions with teams can identify where existing workflows create friction and why employees seek external tools.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;reduce-risks&quot; class=&quot;wp-block-heading&quot;&gt;How to reduce shadow AI risks&lt;/h2&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA&quot; alt=&quot;A chart that explains how to reduce shadow AI risk&quot; class=&quot;wp-post-254799 wp-image-254897&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;110 KB&quot; data-optsize=&quot;32 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;71.1&quot; data-version=&quot;1786094119&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reducing shadow AI requires practical alternatives, clear policies, appropriate access controls, employee training, and ongoing review. Effective safeguards should support legitimate AI use while keeping company data within approved systems:&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Give employees an approved AI tool&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees are less likely to search for alternatives when you provide&amp;nbsp; a &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt; that meets their practical needs. Any approved tool should offer strong privacy protections, clear data handling terms, appropriate business controls, and enough capability to support common tasks.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Avoid a blanket ban&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A complete ban can push AI use further underground, especially when employees already depend on these tools. Some may move to personal accounts, mobile devices, browser extensions, or less reputable AI services that are harder for the organization to identify.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Create an AI acceptable-use policy&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Use examples based on real workflows. “Do not share sensitive information” leaves too much room for interpretation. A clearer policy might tell employees never to upload customer support exports, source code, contracts, credentials, unreleased financial results, or identifiable employee records to an unapproved service.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Classify data before setting AI rules&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Identify which categories of information are public, internal, confidential, regulated, or highly restricted. Connect each category to permitted AI uses. Public marketing copy may be appropriate for a wider range of tools, while personal data, credentials, trade secrets, and privileged legal material may require a tightly controlled system or be excluded entirely.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Periodically review approved software for new AI features&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An application may process data differently after adding an AI assistant, automatic transcription, content generation, or predictive analysis. Regular vendor reviews can identify these changes and confirm that previously approved tools still meet the organization’s security, privacy, and compliance requirements.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Limit permissions&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Give AI tools access only to the data and systems needed for an approved task. Use company-managed accounts, &lt;a href=&quot;https://proton.me/business/blog/what-is-sso&quot;&gt;single sign-on (SSO)&lt;/a&gt;, &lt;a href=&quot;https://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt;two-factor authentication (2FA)&lt;/a&gt;, role-based permissions, and centralized account removal where available. Avoid connecting a &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt; to an entire drive, inbox, or customer database when a narrower source will work.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Set rules by role and use case&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Different teams have different needs and levels of risk. Developers may need API access for testing or prototyping. Marketing teams may need text and image generation. Legal or HR teams may work with information that requires much stronger restrictions. Role-based rules can keep the policy realistic while limiting access to sensitive data and high-risk functions.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Train employees&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees need enough AI literacy to understand both the benefits and limitations of the systems they use. Training should cover &lt;a href=&quot;https://proton.me/lumo/ai&quot;&gt;AI privacy&lt;/a&gt;, confidentiality, hallucinations, bias, intellectual property, prompt injection, human review, and incident reporting. The appropriate training level depends on staff knowledge, experience, and the context in which the AI is used.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Create a simple approval process&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A working process might collect the tool name, intended task, data involved, required integrations, and expected business benefit. Security and legal teams can then approve, restrict, test, sandbox, or reject it based on the actual risk. A long procurement process may encourage employees to find their own workaround. Set a reasonable review target and explain what information is needed to reach a decision.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Keep people responsible for the output&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI-assisted work should have a human owner. Require a review before outputs affect customers, employees, finances, legal decisions, production code, published information, or other high-impact areas. Any person using an AI tool remains responsible for checking its accuracy, appropriateness, confidentiality, and compliance with company policy.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Document important AI-assisted decisions&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Keep a clear record when AI contributes to decisions that affect customers, employees, finances, legal matters, or other high-impact areas. A reliable audit trail supports accountability and helps organizations investigate errors, explain outcomes, and respond to complaints or regulatory questions.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;what-to-do&quot; class=&quot;wp-block-heading&quot;&gt;What to do if sensitive data has already been shared&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Treat an accidental disclosure to an AI tool like any other potential data incident. Move quickly through the following steps.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Identify what was shared:&lt;/strong&gt; Confirm what information was entered or uploaded, which tool and account were used, when the disclosure happened, and who may have had access to the data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Remove the information where possible:&lt;/strong&gt; Delete the conversation and any uploaded files from the tool. Check the provider’s terms and support options to see whether you can submit a formal deletion request.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Check what the provider may retain:&lt;/strong&gt; Removing a chat from view doesn’t always erase every copy. Review and document what the provider says about operational logs, backups, human review, model training, and deletion timeframes to help determine whether any data may remain.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Secure affected systems:&lt;/strong&gt; Revoke permissions granted to the AI tool or connected plug-ins. Rotate any &lt;a href=&quot;https://proton.me/pass&quot;&gt;passwords&lt;/a&gt;, API keys, access tokens, or other credentials that appeared in the prompt or attached files.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Notify the relevant teams:&lt;/strong&gt; Report the incident to the organization’s security, privacy, legal, or data protection team. They can assess contractual obligations, regulatory requirements, and whether affected customers or partners need to be informed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Learn from the incident:&lt;/strong&gt; Document what happened and use it to improve training, controls, and approved alternatives. Avoid punishing employees who report genuine mistakes, since a punitive response may discourage others from raising future incidents.&lt;/p&gt;



&lt;h2 id=&quot;lumo&quot; class=&quot;wp-block-heading&quot;&gt;A private AI assistant for teams&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lumo for Business gives your team a reliable AI assistant for summarizing documents, analyzing data, reviewing code, drafting content, and exploring ideas while helping your business maintain control of confidential information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt; does not keep logs of conversations or use them to train AI models, and any chat history you choose to save is protected with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-access encryption&lt;/a&gt;, which means we never have access to your data&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lumo is fully &lt;a href=&quot;https://proton.me/community/open-source&quot;&gt;open source&lt;/a&gt;, built in Europe, and designed to support &lt;a href=&quot;https://proton.me/business/gdpr&quot;&gt;GDPR&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/healthcare&quot;&gt;HIPAA&lt;/a&gt; compliance through Proton’s &lt;a href=&quot;https://proton.me/business/iso-27001-certification&quot;&gt;ISO 27001 certification&lt;/a&gt; and &lt;a href=&quot;https://proton.me/blog/soc-2&quot;&gt;SOC 2 Type II attestation&lt;/a&gt;.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://lumo.proton.me/&quot;&gt;Chat with Lumo&lt;/a&gt;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-outlined-purple&quot; href=&quot;https://proton.me/business/lumo/pricing&quot;&gt;Get Lumo for Business&lt;/a&gt;
&lt;/div&gt;





&lt;p class=&quot;wp-block-paragraph&quot;&gt;Giving your team a capable, privacy-focused AI assistant reduces reliance on unapproved tools and helps you keep AI use within systems you oversee.&lt;/p&gt;
</content:encoded><category>For business</category><author>Tom Odlin</author></item></channel></rss>