How platforms collect your data, and the microphone question¶
You mention something to a friend, and the ad shows up the next day. The experience is common enough that "my phone is listening" has become the default explanation.
This page does two things. It points to the canonical account of how third-party tracking actually works, and it addresses the microphone question directly, because that one is asked constantly and answered badly. Metadata your own communications and files carry is a separate topic, covered in metadata; this page is about what platforms actively collect.
We point outward on the mechanics
EFF's Behind the One-Way Mirror is the reference for how corporate tracking works: invisible tracking pixels, browser fingerprinting, social widgets, mobile SDKs, and the data-broker ecosystem behind them. It reports that the average web page shares data with dozens of third parties, and that mobile apps do the same, many collecting location and call records even when not in use. We don't reproduce that work.
Why targeted ads feel like eavesdropping¶
The inference does not need your voice. A few of the mechanisms that produce the "it heard me" effect:
- Lookalike audiences. An advertiser uploads a customer list and the platform finds people with similar behavior. You may never have expressed interest in anything; you simply resemble people who bought.
- The social graph. A friend searched for it, a friend bought it, or a friend's device sat on the same Wi-Fi as yours. The association doesn't have to originate with you.
- Co-location. Two devices repeatedly in the same place at the same time is itself a commercially valuable relationship.
- Shared triggers. You and your friend discussed the thing because you both saw the same news, event, or seasonal prompt. The ad system reacted to the same trigger, which reads as if it overheard the conversation.
- Behavioral signals you don't think of as signals. Dwell time on a post you didn't like, scroll-back, typing you deleted before sending, screenshots, and the hours you open the app.
None of that requires a microphone.
What the evidence on microphones actually says¶
Human review of voice assistants is real, and narrower than the rumor. Apple's August 2019 statement acknowledged that its Siri quality-evaluation process, which it calls grading, had contractors review under 0.2 percent of Siri request audio, including recordings produced by accidental activations. Apple suspended grading after the reporting, then made it opt-in, limited to Apple employees, with inadvertent-trigger recordings deleted1. Amazon and Google ran comparable review programs in the same period. This is a real privacy failure, and it concerns a feature you deliberately authorized to listen for a wake word. It is not evidence that social apps record you continuously.
Large-scale testing found no covert audio recording. A 2018 study published in PETS instrumented 17,260 Android apps and looked for exactly this: apps enabling the microphone and exfiltrating audio without the user's knowledge. It found no evidence of that. What it did find was several apps recording the user's screen and sending the video to third parties, a behavior that required no permission on Android at the time2.
That second finding is the useful one. The collection that is genuinely happening does not need the microphone, and triggers no permission prompt.
"No evidence found" is not "proven absent." That study sampled Android in 2018 and its coverage of encrypted traffic was limited. In August 2024, 404 Media obtained a pitch deck from the US advertiser Cox Media Group claiming its "Active Listening" product could capture conversations through smart-device microphones for ad targeting, naming Facebook, Google, and Amazon as partners. Google dropped the company from its partner program when asked, and the company denied listening to conversations4. What that establishes is that someone is selling the concept, not that the technique operates at scale.
You can check for yourself. On iOS 14 and later, an orange dot in the status bar means an app is using the microphone and a green dot means the camera5; swipe down from Control Center to see which app. Android 12 and later shows the equivalent indicators plus a Privacy Dashboard listing microphone and camera access over the past 24 hours. If you suspect a specific app, watching the indicator for a few days beats speculating.
The regional angle¶
The tracking mechanics are global. What differs across Sinophone Asia-Pacific is how directly the collected profile resolves to a legal person.
- Real-name registration closes the gap. Where SIM cards and major platform accounts are bound to identity documents by law, an advertising profile is not a pseudonymous blob; it attaches to a named individual whom local authorities can query. See metadata for the same point about communication records.
- The data can be compelled, not just sold. In the commercial-surveillance frame that most English-language guidance assumes, the worst case is a data broker. Where platforms operate under local data-localization and disclosure obligations, the same profile is reachable by legal process.
- Contact upload spreads exposure to people who never consented. Your phone number can already sit in a platform's graph because someone else uploaded their address book, which matters more where a number maps to an identity document.
Mainland Chinese platforms add a further layer¶
WeChat, Douyin, Xiaohongshu, and Weibo differ from the global platforms above in three ways, and this applies to diaspora users of those apps too.
The account resolves to a legal person. Accounts bind to a phone number and the number to an identity document, with the national Cyberspace ID added on top since July 2025. An ad profile that is a pseudonymous blob elsewhere is a named individual here.
The data sits in-jurisdiction and is reachable by legal process. For global platforms the worst case is usually a data broker. For mainland platforms the data is held domestically and is also within scope of lawful access requests. That is a difference in kind, not degree.
The content is simultaneously censored. Citizen Lab's WeChat research found that keyword filtering is enabled only for accounts registered with a mainland phone number and persists after relinking to an international one, that images are filtered by both OCR and visual-similarity matching, and that blocking is invisible to the sender. Content between non-mainland accounts is analyzed as well, and has been used to train the censorship system3.
The practical consequence: turning off the advertising identifier and refusing tracking does much less here, because the problem is not in the ad-tracking layer. Account layering is similarly limited — the methods in maintaining multiple online identities assume services outside the mainland, and the real-name chain cancels most of the benefit. What still works is behavioral separation: not reusing one account across purposes, and not cross-referencing between them. Full context in posting on mainland Chinese platforms.
Quitting is not an option for most people. If you keep using them, these adjustments are cheap and their effect is certain: restrict who can see your posts and history, revoke contacts and location permissions, reduce your visibility inside group chats (member lists, nickname, avatar are visible to strangers, and groups carry administrator liability), and keep sensitive matters off the platform entirely, including arranging when and what to discuss.
What actually helps¶
- Turn off the advertising identifier. On iPhone, Settings → Privacy & Security → Tracking, then switch off "Allow Apps to Request to Track"; apps that ask are then denied the IDFA6. On Android 12 and later you can delete the advertising ID outright, after which apps receive a string of zeros7.
- Turn off contact upload. This one protects your contacts, who never agreed to be uploaded.
- Turn off precise location where an approximate one will do, and review which apps hold microphone, camera, location, and contacts permissions.
- Separate browsing contexts, block third-party cookies and trackers, and avoid federated "sign in with" buttons, which join two records together.
- Separate accounts for genuinely distinct purposes, covered in maintaining multiple online identities.
See what a platform actually holds on you¶
Opening your own file beats trusting any explanation. Most platforms are required to offer data export and ad-preference pages:
- Inferred ad interests: Google's My Ad Center and Meta's ad preferences both list the topics the system thinks you care about. Reading that list usually lands harder than any description of the mechanism.
- Data export: Google Takeout, and "download your information" on Meta and Instagram, cover posts, searches, location, and ad interactions.
- Login and device history: most security settings include a list of devices and locations that have signed in.
The export itself is highly sensitive personal data. Store it encrypted, and keep it out of your downloads folder and cloud sync.
Note what this list does not claim: none of it stops behavioral profiling inside a platform you use, and revoking microphone access changes none of the mechanisms in the first section. It also assumes your jurisdiction does not restrict these tools; Tor cannot be reached directly from inside mainland China, and using circumvention carries its own risk there.
This page will age¶
Platform settings and policies change every few months. The mechanisms are durable; the menu paths are not. Verify against each platform's current privacy settings before relying on a specific step, and tell us via the Community page if something here no longer matches reality.
Where to go from here¶
- Metadata, and why it matters — the communication-side counterpart to platform-side collection
- Threat modeling — where "platform business model" sits as an adversary, and what it's worth spending to counter it
- Maintaining multiple online identities — separating contexts so one profile doesn't absorb everything
- Using AI at work without leaking data — the same question applied to AI assistants: where the text goes, and who keeps it
- Privacy Guides — maintained tool recommendations, which we don't duplicate
-
Improving Siri's privacy protections — Apple Newsroom, August 2019, on the grading program, the sampling rate, its suspension, and the move to opt-in. ↩
-
Panoptispy: Characterizing Audio and Video Exfiltration from Android Applications — Proceedings on Privacy Enhancing Technologies 2018; Pan, Ren, Lindorfer, Wilson, and Choffnes (Northeastern University and UC Santa Barbara), an automated analysis of 17,260 Android apps. ↩
-
One App, Two Systems, How WeChat Filters Images for One Billion Users, and We Chat, They Watch — The Citizen Lab. ↩
-
Here's the Pitch Deck for 'Active Listening' Ad Targeting — 404 Media, August 2024, on the Cox Media Group pitch deck. Verified 2026-08. ↩
-
About the orange and green indicators in your iPhone status bar — Apple Support. ↩
-
If an app asks to track your activity — Apple Support. ↩
-
Advertising ID — Google Play Help; deletable from Android 12, after which apps receive zeros. ↩