Each Facebook user is monitored by thousands of companies
A new study from Consumer Reports and The Markup finds that an average Facebook user is tracked by thousands of companies, largely via Meta’s tracking pixels, data brokers, and real-time ad bidding systems. Commenters describe how even careful use of browser containers, ad blockers, and privacy settings can’t fully prevent data being sent to Meta, including via server-to-server “Conversions API” uploads and “shadow profiles” for non-users. The conversation highlights broader worries about de-anonymization, manipulation, and government or corporate access to this data, alongside calls for stronger regulation and more privacy‑preserving tech.
Access to Facebook Data & Shadow Profiles
- Some users report “no activity” shown in Facebook’s privacy tools and data exports despite long-term use; others (under GDPR) say they saw years of detailed web logs before deletion.
- Multiple comments argue that users never see their full data or the “shadow profiles” built on non‑users from contacts, app SDKs, and other sources.
- It is widely assumed Facebook keeps profiles even for people without accounts or who are banned.
Does Meta “Sell” User Data?
- One side argues Meta doesn’t sell raw data; advertisers get targeting, not user records, and tools like Custom Audiences use hashed identifiers only for matching.
- Others counter that being in an advertiser’s audience, or on a list of companies that “use your activity or information,” is itself monetized data, regardless of hashing or wording.
- There is debate about whether Meta participates in real‑time bidding “bidstream data” sharing like some ad exchanges; some claims are specific to Google and others, not clearly to Meta.
Tracking Tech: Pixels, Cookies, and Server‑Side APIs
- Facebook’s pixel and SDKs are described as main data sources, including on ostensibly privacy‑focused sites.
- Third‑party cookie deprecation is seen as a partial win, but pixels can act as first‑party for logged‑in users, and simple image requests still leak data.
- Facebook’s server‑side “Conversions API” lets sites send events directly, bypassing browser protections and user tools.
Browser Fingerprinting and Client-Side Defenses
- Disagreement over how persistent fingerprinting is: some say fingerprints decay quickly; others say common attributes (screen size, fonts, extensions, OS quirks) remain highly identifying.
- Privacy tools mentioned: containers, private windows, clearing data, DNS‑level blocks, resist-fingerprinting settings, Tor. Several note these help but cannot block server‑side data uploads.
Data Brokers, RTB, and Surveillance
- Commenters highlight real‑time bidding as a major privacy and national‑security risk, with examples of companies de‑anonymizing ad data and profiling billions of devices.
- Strong calls for federal regulation and even campaign‑finance reform to make such regulation politically feasible.
Opting Out, Social Pressure, and Obfuscation
- Some avoid Facebook/Instagram/WhatsApp entirely or use fake identities and heavy blocking; others feel forced to use WhatsApp or Facebook due to schools, gyms, or social groups.
- Several report success persuading friend groups to move to Signal; others find this unrealistic for low‑trust groups (school parents, event chats).
- A subset advocates “noise” tactics—feeding misleading data so profiles become inaccurate.
User Experience and Platform Decline
- Many describe Facebook as cluttered with ads, suggested content, scams, and poor UX (Marketplace, Events), despite Meta’s engineering resources.
- Creepy “People You May Know” suggestions (old flings, brief encounters) are cited as evidence of deep cross‑app/phonebook tracking and an emotionally jarring effect.