MarioSMS

How to Sign Up for Apps Without Giving Away Your Identity

Updated · MarioSMS team

Most privacy advice is either paranoid (abandon the internet) or useless (accept all cookies mindfully). This is the middle path: a concrete checklist for signing up for things while leaking as little permanent, linkable data as possible. Each step names what it actually prevents, so you can skip the ones whose threat you don’t care about.

1. Stop reusing one email everywhere

Prevents: cross-site linking and breach correlation.

An email address is a join key, the same way a phone number is. Aliasing services (or the plus-trick your provider may support) give every service its own address that forwards to your real inbox. When one leaks or sells, you know who did it, and you kill that alias without touching anything else.

2. Keep your phone number for people, not databases

Prevents: data-broker linking, spam calls, and SIM-swap blast radius.

Give your real number to your bank, your family, your doctor. For every sign-up form that just wants to send one verification code, rent a number for that verification instead. The service gets its code, the account works, and your permanent identifier stays out of one more database. The reasons this matters compound over years; the full argument is here.

3. Move security off SMS entirely

Prevents: SIM-swap account takeover.

SMS two-factor ties account security to whichever carrier employee answers a fraudster’s call. Wherever a service allows it, switch to an authenticator app (TOTP), store the backup codes, and set a recovery email you control. Then remove your phone number from the account if the service permits it. This step matters double for accounts you verified with a rented number: after it, the number plays no role in the account’s future at all.

Prevents: profile enrichment.

Your birthday, real name, and city are optional on most consumer services, and nothing obliges you to be truthful with a meme app. Where the relationship is legal or financial (banks, government, employers, anything with KYC), accuracy is required and the law applies. Knowing which register you’re in is most of privacy competence. Our own position on that boundary is written up in privacy and the law.

5. Audit permissions like subscriptions

Prevents: ongoing collection after sign-up.

The sign-up is one moment; the app’s contact-list, location, and photo-library permissions run forever. Once a quarter, go through app permissions and revoke what the app doesn’t visibly need. Contact-list access deserves particular hostility: granting it leaks your friends’ numbers, not yours.

The one-minute version

Alias the email, rent the number, put 2FA in an app, give optional fields nothing, revoke permissions quarterly. None of it requires technical skill, all of it survives contact with real life, and each step still works even if you skip the others.