“I have nothing to hide”: an argument that deserves more than a comeback
Convenience, advertising and safety: take the objections seriously. What privacy protects even when you are hiding no wrongdoing.

Original AI-generated illustration · SecuFocus
At a glance
Key points
You can lead an ordinary life and still want a say in who knows your searches, movements or conversations. The questions concern how that information is used, what can go wrong and what recourse you have. Convenience and security justify some data collection; they do not by themselves settle how much is appropriate.
Take “I have nothing to hide” seriously
The phrase comes up whenever privacy enters the conversation. You could reply, “Then hand me your unlocked phone.” It makes a point, but rarely moves the discussion forward. The other person probably was not offering to publish their photos, bank statements and messages. They meant: I lead an ordinary life, nothing particularly bad has happened, and these services are useful.
That is an understandable position. Time is limited. A navigation app needs a location to guide a journey. Having your photos available on a replacement phone is convenient. Fraud prevention has value too. Demanding that everyone give up those benefits to achieve perfect privacy would be an unrealistic answer.
You can value a service while objecting to some uses of your data. Giving an address for a parcel delivery, for instance, says nothing about what you accept for advertising. Each use, retention period and recipient should be open to discussion.
Privacy is more than keeping a secret
You might discuss your health with a doctor, your salary with your partner and a career plan with a friend. None of that information has to be shameful. You still choose different recipients, different moments and different words. Privacy gives you room to make those choices.
Closing the curtains is not evidence of a crime. Keeping a draft to yourself does not make its content scandalous. People also need space to try an idea, ask an awkward question and change their mind without defending every unfinished step to an audience.
Legal scholar Daniel Solove examined this objection in a 2007 paper. He argues that reducing privacy to hiding wrongdoing overlooks other problems, including how information is used and how power is distributed. That framework helps explain why an honest person can still have good reasons to restrict access to their data.
The issue is not only what you have said
Consider a fictional example. You research a treatment for a relative, visit a medical district several times and read a forum about a condition. None of those actions establishes that you have the condition. A system trying to classify your interests might still infer that you do. An inference can be sensitive without being correct.
Four things deserve separate attention: an observed data point, an inference, a stored profile and a decision based on that profile. A click is not a belief. An IP address is not a person. A score with three decimal places does not remove the uncertainty in its inputs.
This does not mean every app makes consequential decisions or every insurer buys your browsing history. Those claims would require specific evidence. The broader question is whether information can follow you beyond its original context, and whether you have a practical way to correct a false conclusion.
Combining traces can make them more revealing than they were individually. A regular route, a time and a persistent identifier may reveal more than a single message. The collection of metadata therefore deserves attention alongside the visible content of a conversation.
Removing names does not always create anonymity
In a study published in 2013, de Montjoye and colleagues analysed mobility traces from 1.5 million people. Four points in space and time distinguished 95% of the traces in that dataset. This describes uniqueness in their sample, not the automatic identification of 95% of all present-day users. Connecting a trace to a name requires additional information.
That distinction matters. Removing names from a table does not necessarily remove the patterns that make someone recognisable. Conversely, this study does not show that every aggregate statistic identifies individuals. The level of detail, the safeguards and the opportunities for linkage change the risk.
When a service describes data as “anonymised”, check what it keeps, how detailed it is and whether it can be combined with other information. Removing a person’s name does not by itself explain the protection achieved.
What the documented case shows
On 11 April 2024, the US FTC finalised an order against X-Mode Social and Outlogic. The case concerned sensitive location data which, according to the FTC, could track visits to clinics, places of worship and shelters. The order prohibits certain sales and disclosures of that data.
This US case does not describe every app and is not a Swiss rule. It does show that the chain from location collection to reuse and additional recipients is more than a hypothetical concern. Understanding a service also means examining its partners and the permitted uses of information.
The arguments and what they leave unresolved
These objections raise legitimate questions about cost, security and convenience. The table examines what they justify and what they leave unanswered.
| The argument | What it leaves unresolved |
|---|---|
| “Personalisation is useful to me.” | It can be. The remaining questions are which data it needs, for how long, and whether it could work with less information. |
| “Nobody personally reads my data.” | Automated classification can influence what you see without human reading. Its effects and the ability to challenge it still matter. |
| “Advertising pays for a free service.” | That is a legitimate business model to discuss. It does not by itself justify every form of linkage or every retention period. |
| “We need data to prevent fraud.” | A security purpose can justify targeted collection. Access limits, a demonstrated connection to that purpose and protection against unrelated reuse still matter. |
| “I agreed to the terms.” | Agreement records an authorisation. It does not guarantee that the consequences were understood or that a practical alternative existed. |
| “My data is already everywhere.” | A past leak does not make future conversations, new journeys or current accounts pointless to protect. |
| “Criminals use privacy tools too.” | They do. The same tools protect bank accounts, medical conversations and ordinary people. That fact alone does not settle every use. |
Advertising and convenience: which trade-offs are acceptable?
Someone may knowingly decide that useful recommendations are worth sharing some interests. Someone else may prefer to pay. Both choices can be reasonable. The difficulty begins when the actual price is hard to understand or refusing an optional collection becomes excessively complicated.
“If it is free, you are the product” is not a universal explanation either. Open-source software, a donation-funded service and an advertising platform do not operate in the same way. Even in advertising, targeting an audience does not necessarily mean handing the advertiser a file containing every piece of personal information.
Google says contextual ads remain after personalised ads are turned off. That setting controls personalisation. It does not disable all data processing across other Google services.
Your data also describes other people
Your address book contains people who never installed your app. A photo can show a relative. A conversation has more than one participant. Saying “I do not mind” therefore does not always answer the question for everyone involved.
Privacy also has a collective dimension. If every search, contact and hesitation creates a lasting record, some people may stop asking a question or consulting a resource. We are not measuring that effect here. It is a reason for care, especially around intimate or socially sensitive subjects.
This does not turn every group photo into a crisis. Asking before publishing a sensitive situation, avoiding unnecessary uploads of a complete address book and limiting detail in a shared calendar are already useful steps.
Privacy does not rule out all collection
A credible position recognises legitimate aims: providing a service, securing an account, investigating within a legal framework and producing some statistics. Privacy does not require every piece of information to remain inaccessible in every circumstance.
A useful aim does not automatically justify every means. Ask whether the data is necessary, whether a less intrusive method would work, who reviews access and when the records will be deleted. A specific, limited and accountable measure is easier to defend than general collection “just in case”. These are analytical criteria, not legal advice about a particular system.
Protection also has costs. A more private app that nobody understands may be abandoned. An encrypted backup can become unusable when its key is lost. Good decisions account for those constraints instead of promising a digital life without trade-offs.
Examine a service you already use
Pick a service you use often, such as your email or maps app. The five questions below help you examine what you share with it and compare its terms with another service.
- What information does the feature I use actually need? Does a one-off route require a permanent travel history?
- Who receives it: the provider, contractors or advertising partners? Are those roles explained?
- How long is it retained, and can I change that period?
- What happens if I refuse an option? Can I still use the essential features?
- How can I inspect, correct or delete the information available in my account? What lies outside that interface?
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
- Daniel J. Solove: “I’ve Got Nothing to Hide” and Other Misunderstandings of Privacy (2007) ↗scholarship.law.gwu.edu ·
- de Montjoye et al.: Unique in the Crowd (Scientific Reports, 2013) ↗pmc.ncbi.nlm.nih.gov ·
- Google: manage ads in My Ad Center ↗support.google.com ·
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.