August 9, 2026
I Googled Myself and Regretted It Immediately
No hacker needed. No breach. Just a legal industry nobody warned you about — and the exact steps I used to fight back

By Hartarto
6 min read
Hi, I'm Hartarto. I'm passionate about AI, cybersecurity, OSINT, and emerging technologies. I spend a lot of time exploring new tools, testing them myself, and sharing what actually works. If this article helped you learn something new, then it was worth writing. Thanks for stopping by!
Somewhere right now, an AI is running a probability score on you. Not for something you applied for — for a loan you haven't asked for yet, an insurance premium you haven't been quoted, an ad that's about to slide into your feed. And you will never find out it happened.
Sounds like the opening line of a conspiracy channel, I know. But this isn't a theory. It's just… how advertising, lending, and insurance quietly work now. Most people have no idea how far it actually goes, and honestly, neither did I until I started pulling on this thread.
What I found wasn't the "the machine knows everything about you" nightmare some corners of the internet like to sell. It's messier than that, and in some ways more unsettling — because it's boring, automated, and everywhere at once.
Okay, but what does "AI profiling" even mean
Strip away the jargon and it's simple: a system grabs a pile of data points about you — what you browse, what you buy, where you go, how you pay — and uses it to guess something. Will you click this ad? Default on this loan? File a claim? Cancel your subscription next month?
The "AI" bit just means this used to run on fairly dumb statistical rules, and now runs on models that chew through thousands of signals at once and update the guess in real time. Sometimes while the page is still loading.
None of this is new, really. Insurers have been running actuarial tables since before your grandparents were born. What's different is the scale of it, the speed, and — this is the part that actually gets me — how invisible the whole thing has become.
The systems doing this aren't hypothetical
Real-time bidding. Load almost any website with ads on it, and in the background, in a few hundred milliseconds, an auction fires off. Advertisers bid on the chance to show you something, based on everything known about you at that instant — location, browsing history, guessed interests, even your device. There's essentially no major publisher or app that skips this. And here's the part people miss: your data gets broadcast to potentially hundreds of bidding companies in that split second, whether or not any of them actually wins the slot.
Cash-flow underwriting. Your old credit score was one stale number, refreshed monthly. The newer AI lending models — used by fintechs and, increasingly, regular banks — dig into your actual bank transactions and spending rhythm in something close to real time. Sometimes before you've even filled out an application. If you've got thin credit history but steady income, this can genuinely help you. It also means a lot more of your financial life than "did you pay the bill on time" is now feeding a machine.
Insurance underwriting. Some insurers now pull in more than your driving record or medical file — purchase history, lifestyle signals, even things scraped from social media, all folded into a risk score. Two people with identical official records can walk away with wildly different premiums, and neither of them handed over the data that made the difference.
Social platforms. Meta, for one, runs multimodal systems that don't just track what you post — they scan images, video, even audio in the ads shown to you, guessing at income bracket, job status, life events. That's a different animal than "we track your clicks." That's a system watching and listening and drawing conclusions.
Facial and biometric tracking. Retail loss-prevention cameras, some workplace security setups, law enforcement tools — all increasingly capable of recognizing and following the same person across locations and time. A handful of US states have started classifying biometric and neural data as "sensitive" specifically because of this: you can change a password. You can't change your face.
Hiring algorithms. More employers than you'd guess run resumes and even public social activity through scoring systems before a human ever opens the file. You can get filtered out of a job by an algorithm, and in most cases, never learn why.
The part that actually surprised me
Profiling on its own isn't illegal, or even necessarily malicious. The real problem is consent and visibility — most of us technically agreed to some version of this buried in a terms-of-service doc nobody reads, and have almost zero practical way to see what's actually been concluded about us.
That's shifting, slowly. Going into 2026, states like California, Colorado, and Minnesota have widened their privacy laws to cover automated decision-making specifically, which on paper gives you the right to know about — and sometimes opt out of — this kind of processing. The EU AI Act pushes further, demanding formal risk assessments for anything classified "high-risk." But a right on paper only matters if you actually use it.
Which is really the point of this whole piece.
Before you keep scrolling — go check one thing right now. Pull up your phone's ad tracking settings (iOS: Settings → Privacy & Security → Tracking, Android: Settings → Privacy → Ads) and count how many apps have permission to track you across other apps and sites. I'd bet money it's more than you think.
From "this is unsettling" to "I know exactly what's been guessed about me"
Privacy researchers don't just shrug and accept this. They audit their own exposure, and pull the legal levers that already exist. Here's the version of that you can actually do yourself.
Look at what the ad platforms think they know. Google's Ad Settings (myadcenter.google.com) and Meta's Ad Preferences (buried in Facebook/Instagram account settings under "Ads") both show you the interest categories they've built for you. Most people are genuinely rattled by how specific it gets — income brackets, relationship guesses, predicted life events, sitting right there in a dropdown menu.
Actually request your data. If you're in California, Colorado, Virginia, or a growing list of other states, you can legally request a copy of what a company holds on you — including what's been inferred, not just what you typed into a form. Look for "Do Not Sell/Share My Personal Information" on the privacy policy page. In the EU, this is the GDPR Subject Access Request, and it's stronger than most people realize.
Opt out where the option exists. California's expanding automated-decision-making rules increasingly let you refuse certain kinds of profiling — for ads, and in some cases for things that actually affect your wallet, like lending or insurance. It's not universal yet. It's expanding fast enough to be worth checking every so often.
Starve the system a little. These models are only as sharp as what's feeding them:
- Turn on browser-level tracking protection, or add a privacy extension
- Go through your phone and revoke location/contacts permissions from apps that don't need them
- Use a password manager instead of "Sign in with Google" everywhere — that button is quietly stitching your activity together across services
- Reset your advertising ID every so often (both iOS and Android let you do this)
Watch your financial profile directly. Since underwriting increasingly pulls from raw transaction data instead of a static score, check reports from the major bureaus — and any alternative-data platform built on VantageScore 4.0 or similar — at least twice a year. Look for accounts or inquiries you don't recognize.
Make it a habit, not a one-off. Same as with data broker exposure — this isn't a fix-it-once problem. Set a quarterly reminder: recheck the ad dashboards, review app permissions, pull your credit report again. These systems don't sit still, so your defense can't either.
Last thought
The uncomfortable truth here isn't that some shadowy system is out to get you specifically. It's dumber and more pervasive than that — hundreds of companies have quietly built an entire economy around guessing your next move, and until very recently, almost nobody gave you an easy way to see what they'd decided about you. That's starting to change. But only for the people who actually know these tools exist and bother to use them.
Consider this your nudge.
If this shifted how "personalized" your online life actually feels, follow along here — I'm covering this whole space, from OSINT to AI surveillance to practical digital self-defense, as an ongoing series.
Further reading:
- epic.org — Online Advertising and Tracking: https://epic.org/issues/consumer-privacy/online-advertising-and-tracking/
- California AG — CCPA overview: https://oag.ca.gov/privacy/ccpa
- GDPR.eu — Right to Access: https://gdpr.eu/right-to-access/
- FTC — Data Brokers guidance: https://www.ftc.gov/business-guidance/privacy-security/data-brokers
- EU AI Act overview: https://artificialintelligenceact.eu
- Google Ad Settings: https://myadcenter.google.com
- EFF — Privacy issues hub: https://www.eff.org/issues/privacy
- FTC Consumer Advice — Protecting your privacy online: https://www.consumer.ftc.gov/articles/how-protect-your-privacy-online
- IAPP — Consumer privacy resources: https://iapp.org/resources/topics/consumer-privacy/
- secureprivacy.ai — 2026 privacy law roundup: https://secureprivacy.ai/blog/privacy-laws-2026
This piece is for informational purposes, not legal advice. Privacy laws and platform settings shift often and vary by state and country — always double-check current rules directly through official sources.
Medium tags: Cybersecurity, Digital Forensics, Incident Response, Memory Forensics, DFIR, Malware Analysis, Ethical Hacking, IT Security, Threat Hunting, Data Breach