How to Sign Up for Apps Without Giving Away Your Identity
Most privacy advice is either paranoid (abandon the internet) or useless (accept all cookies mindfully). This is the middle path: a concrete checklist for signing up for things while leaking as little permanent, linkable data as possible. Each step names what it actually prevents, so you can skip the ones whose threat you don’t care about.
1. Stop reusing one email everywhere
Prevents: cross-site linking and breach correlation.
An email address is a join key, the same way a phone number is. Aliasing services (or the plus-trick your provider may support) give every service its own address that forwards to your real inbox. When one leaks or sells, you know who did it, and you kill that alias without touching anything else.
2. Keep your phone number for people, not databases
Prevents: data-broker linking, spam calls, and SIM-swap blast radius.
Give your real number to your bank, your family, your doctor. For every sign-up form that just wants to send one verification code, rent a number for that verification instead. The service gets its code, the account works, and your permanent identifier stays out of one more database. The reasons this matters compound over years; the full argument is here.
3. Move security off SMS entirely
Prevents: SIM-swap account takeover.
SMS two-factor ties account security to whichever carrier employee answers a fraudster’s call. Wherever a service allows it, switch to an authenticator app (TOTP), store the backup codes, and set a recovery email you control. Then remove your phone number from the account if the service permits it. This step matters double for accounts you verified with a rented number: after it, the number plays no role in the account’s future at all.
4. Lie where lying is legal, and only there
Prevents: profile enrichment.
Your birthday, real name, and city are optional on most consumer services, and nothing obliges you to be truthful with a meme app. Where the relationship is legal or financial (banks, government, employers, anything with KYC), accuracy is required and the law applies. Knowing which register you’re in is most of privacy competence. Our own position on that boundary is written up in privacy and the law.
5. Audit permissions like subscriptions
Prevents: ongoing collection after sign-up.
The sign-up is one moment; the app’s contact-list, location, and photo-library permissions run forever. Once a quarter, go through app permissions and revoke what the app doesn’t visibly need. Contact-list access deserves particular hostility: granting it leaks your friends’ numbers, not yours.
The one-minute version
Alias the email, rent the number, put 2FA in an app, give optional fields nothing, revoke permissions quarterly. None of it requires technical skill, all of it survives contact with real life, and each step still works even if you skip the others.