Your Privacy Was Already Gone Before AI Showed Up (And What You Can Actually Do About It)
A digital marketer's honest take on AI, privacy, and the surveillance economy we already live in.
Artificial intelligence is advancing faster than most of us can refresh a news feed, and it’s dragging along a creeping, legitimate unease: Who has my data? What are they doing with it? And now that machines can sift through it at a scale no caffeinated human ever could, what does that mean for me?
So first, take a breath. Nobody is coming to repossess your personality. I want to talk about this honestly, not to dismiss the concern, not to tell you to relax with a scented candle, and definitely not to gaslight you with corporate talking points about how your privacy is the “top priority.” It isn’t, and we all know it.
I work in digital marketing. My job, in part, is to help clients reach the right people with the right message. I live inside the plumbing of the modern data economy every single day. And I’m here to tell you: the surveillance state you’re worried about AI creating? It’s already here. It’s been here for decades. Most of us, myself included, handed over the keys willingly, in exchange for a grocery discount.
The Kroger Problem (And It’s Not Really About Kroger)
Let me give you a concrete example of how normalized this is.
Kroger, one of the largest grocery chains in the United States (and the parent company of Harris Teeter), makes over a half billion dollars of its revenue not from selling food, but from selling data about the people who buy food. The fuel points. The loyalty discounts. The “Just for U” personalized coupons. That is not a customer rewards program with a data side hustle. That is a data collection program wearing a coupon as a disguise. In 2024, its “precision marketing” arm generated an estimated $527 million. The company’s so-called “alternative profit” ventures now make up more than 35% of its net income.
When you signed up for the grocery card at Kroger or Harris Teeter (or any of its affiliated brands), you consented to a privacy policy. Here is actual language from it:
“We may sell or process for targeted advertising, the following categories of personal data in connection with your enrollment in our loyalty programs: personal identifiers, contact information, transaction and commercial information, account information, online and technical information, usage information, general demographic information, and inferences.”
“Inferences.” That’s the word that should stop you cold. Not just what you bought, but what they concluded about you from what you bought. That you might be pregnant. That you’re probably diabetic. That you have a baby at home, or an aging parent, or a drinking problem you’re trying to solve with kombucha. They can sell those inferences about you to anyone who wants to buy them.
And we said yes. We all said yes. Because we wanted to save a few bucks at the pump and at the register.
This Didn’t Start With AI
Here’s what gets lost in the AI panic: the systematic collection of our personal data is not some new thing AI invented. It’s a decades-long architecture that AI is now being asked to run more efficiently.
Consider what was already true long before anyone was arguing about chatbots:
Loyalty cards have been tracking purchase behavior since the 1990s. Every grocery store, pharmacy, hotel chain, and airline has been building profiles on customers for thirty-plus years.
Search engines have logged every query you’ve ever typed, your fears, your health questions, your 2 a.m. existential spirals, since the late 1990s.
Social media platforms built billion-dollar businesses on the simple premise that if the product is free, you are the product. Every like, every scroll, every half-second pause on a video is behavioral data, packaged and sold.
Credit card companies and banks have known your spending patterns with extraordinary granularity for as long as you’ve carried a card.
Smartphones track your location continuously, along with your contacts, your app usage, and your communication patterns.
None of this required AI. It happened because data is enormously valuable, collection became technically trivial, and most of us have never read a privacy policy in our lives, including me, honestly, until it became part of my job.
AI doesn’t create the surveillance economy. It turbocharges the one we already built and chose to live in.
The Bargain We Keep Making
I want to be careful not to blame the victim here. The “consent” baked into most of these systems is a legal fiction. A 47-page privacy policy written in legalese, requiring clicks to dozens of other internal policies, all of which you must accept to use a service you need, or to claim a discount you depend on in an economy where groceries are genuinely expensive, is not meaningful informed consent. It’s a trap door disguised as a checkbox.
But it’s also true that many of us, handed a real alternative, pick the data extraction anyway.
Privacy-respecting options exist in nearly every category. DuckDuckGo instead of Google. Signal instead of WhatsApp. Proton instead of Gmail. Plenty of grocery stores skip loyalty programs entirely. Yet the convenience, the network effects, the ecosystem lock-in, it all pulls us back toward the services that want our data the most. The value exchange is real, even when the terms are buried.
We are not passive victims of a system we had no hand in building. We built this with our choices, and we keep rebuilding it every time we tap “I agree” without reading what we’re agreeing to.
That’s not a moral failing. It’s a systemic one. The design is intentional.
Plot Twist: Some Companies Actually Fight For You
Here’s the part that gets left out of the doom spiral because doom gets more clicks than nuance. Not everyone in tech is racing to vacuum up your life. Some companies have planted a flag on the other side of this, and a couple of them have done it at genuine cost to themselves.
The cleanest example is Apple versus the FBI.
In 2015, after the San Bernardino terror attack, the FBI was left holding the shooter’s locked iPhone and tried to compel Apple to build a special version of iOS that would let investigators brute-force the passcode. Apple could have done it. Apple refused, arguing that a master skeleton key, once it exists, exists for everyone, and that’s too dangerous a thing to make. (The FBI eventually got into the phone another way.)
Then Apple did something that should make you sit up. Instead of just winning the argument, it redesigned the iPhone so it could never have that argument again. By the time of the 2019 Pensacola attack, a Saudi military trainee who killed three U.S. service members and wounded eight, the FBI again demanded Apple unlock the shooter’s iPhones. This time Apple didn’t refuse. Apple was technically incapable of helping. As the Lawfare analysis put it, the engineering is essentially: “To rekey the lock, you must first unlock the lock.” Absent the passcode, the update path is sealed shut, even to Apple.
Now sit with the corporate stakes for a second. There is no publicly traded company on Earth that wants the headline “Tech Giant Stonewalls Terrorism Investigation.” That’s not a press cycle; that’s a board-meeting nightmare, a stock-price event, and a congressional-hearing-shaped migraine all at once. The path of least resistance, and least reputational risk, is obviously to crack the phone, issue a somber statement about cooperation, and move on. Apple walked into the harder headline on purpose, twice, because the alternative was building a tool that would eventually leak, get subpoenaed, or get copied.
And they took it further than PR. Turn on Apple’s Advanced Data Protection and most of your iCloud data becomes end-to-end encrypted, meaning Apple itself does not hold the keys. The flip side is almost comically unforgiving to their own bottom line: if you forget which account you used and lose your recovery key and recovery contact, Apple’s own support page basically says that data is gone, permanently, even for us. They will effectively brick the device and start you over from scratch.
Think about the money they’re leaving on the table. “Pay us $99 and we’ll recover Grandma’s photos” is a business Apple could launch tomorrow and print money with. They don’t because they built the system so they genuinely cannot see your stuff. A company with every financial incentive to hold a copy of your keys deliberately chose not to. That’s not marketing. That’s architecture you can verify.
The takeaway isn’t “Apple is your friend.” It’s that strong privacy is technically possible and commercially survivable. The companies that say they can’t protect you are, more often than not, telling you they’d rather not.
What the Marketing Industry Can and Can’t Do With Your Data
Here’s some insider perspective that usually gets flattened in the panic: the commercial use of your data, specifically in digital marketing, is more tightly regulated than most people realize.
Most marketing agencies are reputable and operate inside a layered legal framework that constrains what can be done with first-party data (data that clients collect directly from their own customers).
The California Consumer Privacy Act (CCPA), strengthened by the California Privacy Rights Act (CPRA), gives California residents broad rights: to know what’s collected about them, to delete it, to opt out of its sale, and to correct inaccuracies. Because California is roughly 15% of the U.S. economy, CCPA compliance has effectively become a national standard for any serious business.
Virginia, Colorado, Connecticut, Utah, Texas, and over a dozen other states have passed their own consumer privacy laws. The patchwork is maddening for compliance teams, but the net effect is a rising floor of consumer protection that didn’t exist a decade ago.
For anything touching European residents, the General Data Protection Regulation (GDPR) is arguably the most comprehensive data protection law in the world. Consent must be freely given, specific, informed, and unambiguous. Users must be able to withdraw it as easily as they gave it. Violations carry fines of up to 4% of global annual revenue, the kind of number that makes executives suddenly very interested in privacy.
CAN-SPAM governs commercial email. TCPA governs texts and calls. These carry per-violation penalties steep enough to make non-compliance an existential risk for any legitimate operation.
Beyond the law, clients bring their own contractual requirements. Healthcare clients under HIPAA. Financial clients with SEC and FINRA obligations. Enterprise clients with security reviews more stringent than anything a regulator demands. In my experience, private contracts are frequently more restrictive than state law, because clients are rightly protective of the trust their customers place in them.
I’m not telling you the industry is spotless, or that bad actors don’t exist, they do, and they give everyone else a black eye. But the cartoon of marketing agencies as shadowy data brokers operating with no rules and no accountability is not the reality I work in every day.
Your Actual Toolkit (Small Keys You Can Take Back Today)
You don’t have to move into a Faraday cabin and pay for everything in unmarked bills. You just have to stop volunteering for the program. A few high-impact, low-effort moves:
Messaging: Use Signal. It’s end-to-end encrypted, run by a nonprofit, and collects almost nothing about you; there’s barely anything to hand over even if someone demands it.
Search: Use DuckDuckGo. It doesn’t build a long-term profile of your every 2 a.m. query.
Email: Proton (or another privacy-first provider) keeps your inbox from becoming ad targeting fuel.
Browser: Firefox or Brave, plus a decent tracker/ad blocker, kills most of the invisible following-you-around-the-web machinery.
Passwords and payments: A password manager and, where your bank offers them, single-use virtual card numbers limit the blast radius when (not if) some company gets breached.
And the fun one, the grocery card. Here’s a fun truth that surprises people: there is no law requiring you to give accurate personal information to sign up for a store loyalty program. A loyalty signup is a private marketing arrangement, not a federal form and not sworn testimony. You can pair it with a Google Voice number, a throwaway email, and a name with all the realism of “Seymour Butts.” You still get the fuel points; you just hand the algorithm a worse dataset. The discount is offered to anyone who enrolls, so you’re not defrauding anyone out of anything, you’re declining to narrate your life for free.
Two common-sense caveats, because I’d be a lousy expert otherwise: don’t impersonate a real, specific person, and this trick is strictly for low-stakes discount cards. The moment you’re dealing with credit applications, age-restricted purchases, prescriptions, insurance, or government benefits, honesty is legally required and lying can be a real crime. Fudging your name for cheaper paper towels is not the same universe as fudging it on a loan application. (Specifics vary slightly by state, but none of them compel you to be truthful for a coupon.)
Okay, Here’s the Part Nobody Wants to Say: This Data Can Actually Help You
Deep breath, because this is the unfashionable bit. The same inference engine that creeps you out is also the one that can catch the tumor.
Data is dual-use. The aggregate that lets a retailer guess you’re pregnant is the same kind of aggregate that lets a hospital catch sepsis hours sooner. And when we let AI work on large pools of (often de-identified) data, some of the payoff lands squarely on the people who need it most.
Medicine is the headline. AI that is run over aggregate medical data is already sharpening diagnostics and cutting costs. McKinsey-cited estimates put potential U.S. healthcare savings from AI as high as $360 billion a year. A systematic review in npj Digital Medicine found AI screening for things like diabetic retinopathy and atrial fibrillation can lower the cost per patient while catching disease earlier, imaging models are now flagging early breast cancer and eye disease at, or above, specialist accuracy. Cheaper, earlier, more accurate diagnosis is not a luxury good; it’s the difference between a $40 screening and a $40,000 hospital stay, and that gap matters most to people who don’t have $40,000.
Cheaper prices, especially at the bottom. Better demand forecasting means less spoiled inventory and food waste is a massive hidden cost quietly baked into your grocery bill. Smarter logistics cut delivery costs. Fraud detection trims the “everybody pays for the thieves” tax embedded in every transaction. And AI credit models can extend fair, affordable credit to “thin-file” borrowers, disproportionately lower-income people, whom the old scoring systems simply rejected at the door.
And plenty more. AI-balanced energy grids shave power bills. Precision agriculture makes food cheaper and more reliable. Real-time translation and tutoring widen access to education. Earlier epidemic and disaster warnings save lives and money at once.
So when people argue we should slam the brakes on AI because they’re worried about privacy, or that the real villain is the data center humming away out in the desert, I have to gently push back, with common sense.
Blaming the data center for the surveillance economy is like blaming the parking garage for traffic. The garage didn’t cut you off on the highway; it’s just where the cars sleep. A data center is a warehouse full of math. It doesn’t decide to collect your data or sell your “inferences”; that decision was made years ago, in a boardroom, by people, with a coupon as bait.
And halting AI because you’re worried about privacy is a bit like refusing to install a smoke detector because you’re mad at the electric company. By all means, stay furious about the bill. But you’d still like to know when the kitchen’s on fire and right now AI is one of the better smoke detectors we’ve got, for everything from tumors to bank fraud.
The problem was never the engine. It’s who’s allowed to fuel it, with what, and whether anyone bothered to ask you first.
What the People Who Worry About AI Are Actually Right About
None of that means the concern is overblown. I want to be direct: data collection being old does not make AI harmless.
What AI genuinely changes is the scale of inference and the speed of action that can be taken on collected data.
Legacy systems could tell Kroger what you bought last Tuesday. AI systems can predict what you’ll buy next Tuesday, model your sensitivity to price changes, spot when you’re under financial stress, infer your emotional state from browsing patterns, and cross-reference all of it against data bought from a dozen other sources… in milliseconds.
The data was always the fuel. AI is just a far more powerful engine.
The surveillance-state worry isn’t paranoid science fiction, either. Authoritarian governments are already deploying AI-powered facial recognition, behavioral scoring, and predictive policing at a scale every democracy should be watching closely. And in the United States, law enforcement has purchased commercial data, the same kind your grocery store sells, to run investigations without a warrant, because buying data is not legally treated the same as conducting a search. That’s a real loophole, and it deserves a real fix.
These are legitimate threats. They deserve serious policy responses, not a shrug.
So What Do We Actually Do About This?
I’ll be honest: there’s no clean, one-click answer, and anyone selling you one is selling you something. But honest framing leads somewhere more useful than panic.
First, separate the threats. Commercial data collection and authoritarian surveillance are related but different problems with different fixes. Consumer privacy law, opt-out rights, and data-sale limits address the commercial side. Constitutional protections, limits on law-enforcement data purchasing, and human-rights standards address the state side. Lumping them together makes both harder to solve.
Second, demand meaningful consent. The current consent architecture is broken by design. Lawmakers should require plain-language disclosures, genuine opt-in for sensitive data, and enforcement with real teeth. GDPR is an imperfect model, but it’s a model.
Third, hold AI developers to the same standards as everyone else. Systems trained on personal data should face the same transparency, access, and deletion requirements as the databases feeding them. “It went into the model” should not be a legal escape hatch from privacy law.
Fourth, don’t kill the cure to spite the disease. The fight is against careless collection, non-consensual sale, and unaccountable use, not against computation existing. Regulate the boardroom decisions, not the warehouse of math. Aim policy at consent and data-selling, and you can keep the cheaper diagnoses and the fraud detection while still going after the creepy stuff.
Fifth, be honest with yourself about your own choices. Skim the policy, or at least a summary, before you tap agree. Accept that “free” has a price. Where a privacy-respecting alternative exists, give it a shot, not as a purity test, but as a market signal that privacy is something you’ll actually pay attention to.
And sixth, keep being concerned. Not panicked. Not paralyzed. Engaged. The decisions being made right now about how AI can use personal data will shape what privacy means, in practice, for decades. Those decisions get made in boardrooms, legislatures, and regulatory comment periods, and the people making them absolutely notice when the public is paying attention.
The Bottom Line
The age of AI did not begin the erosion of personal privacy. The loyalty card did. The search engine did. The smartphone did. The free social network did.
AI is not the start of a surveillance society. It’s an accelerant tossed onto a fire we’ve been building, often willingly, almost always inattentively, for thirty-plus years. But that same accelerant, pointed at the right problems, is also catching cancers earlier and kicking fraud out of your bank account.
That’s not an argument for complacency. It’s an argument for clarity.
If you’re worried about AI and privacy, you’re right to be. The concern is legitimate, the stakes are real, and the moment is consequential. But the fight isn’t new, and you’re not starting from nothing. There are laws. There are advocates. There are engineers who care, the kind who’ll engineer themselves out of being able to read your data and leave money on the table to do it. There are tools you can pick up this afternoon. And there are real, tangible upsides worth protecting while we rein in the abuses.
The people who should be nervous are the ones collecting data carelessly, using it without meaningful consent, and assuming the public will never get around to demanding accountability.
Because they really should know better by now: we get remarkably motivated the moment we realize what we’ve given away.


