How to Use This Site
There are two ways in, depending on what brought you here.
If you want the fastest practical improvement, start with hardening your browser and set an auto-delete window on your main account's activity. Those two changes reduce what is collected and shorten how long it is kept, in about half an hour, without breaking anything you rely on.
If you want to understand what is happening and why most privacy advice disappoints, read the four guides in order. Each stands alone, and together they cover the whole path your data takes: how it leaves your device, what your own settings can do about it, what your phone hands over, and what the law lets you demand once it has already gone.

Two support pages sit alongside the guides: the FAQ, which answers the questions readers send most often in a few sentences each, and support and corrections, which explains how to report a factual error and, just as importantly, what we cannot do for you.
One thing worth doing in the next ten minutes. Open your main platform account's activity controls and set web, app and location history to auto-delete after three months rather than being kept indefinitely. That single setting changes what exists on a server somewhere, which matters far more than any advertisement-preference toggle. Then delete your phone's advertising ID.
Your Digital Footprint, in Two Halves
RAJA89 exists to make one invisible thing visible: the record that ordinary internet use leaves behind. Almost nobody has a clear picture of it, because the record is assembled by companies they never chose, from observations they never saw, and joined together with identifiers designed not to be noticed.
The useful starting distinction is between the two ways data about you comes into existence.
- Active footprint — what you deliberately hand over. A sign-up form, a delivery address, a review, a photo with location data, a support ticket, a comment under your real name. You know these exist, even if you have forgotten most of them.
- Passive footprint — what is observed while you do something else. Page views, click coordinates, how far you scrolled, how long you paused, your IP address, your device model, and the fact that the same browser appeared on three unrelated websites within a minute.
Most advice concentrates on the first category, because it is the part you can see and delete. The observations are the larger part, and they are the part that follows you, because they are the part you never chose and cannot enumerate.
Why this matters in practice
Two consequences are worth holding onto before reading any of the guides.
It is not one database. It is hundreds, held by companies you have never heard of. That is why "delete my data" is never a single action, and why the honest answer to most privacy questions is "less than you would like, but more than nothing".
The join is the real product. Any single observation is mundane. What has commercial value is knowing that the person who read about a medical condition on one site, searched for a symptom on another, and bought a related product on a third is the same person. The identifier is the asset; the observations are the raw material. Almost everything in the tracking guide is about how that join is made.
What Is Actually Collected
Data collection is usually described in the abstract. Concretely, the categories are these.
| Category | Typical source | Why it is valuable |
|---|---|---|
| Identifiers | First-party cookies, advertising IDs, account email addresses, device fingerprints | They make everything else joinable. Without an identifier, observations about different sessions are just noise. |
| Behaviour | Page views, clicks, scroll depth, dwell time, search queries, purchases | Reveals intent, interests and, in aggregate, health, financial and relationship circumstances. |
| Location | GPS, IP address, Wi-Fi network names, Bluetooth proximity | Links online behaviour to the physical world and identifies home and workplace. |
| Device and technical | Model, operating system and version, browser build, installed fonts, screen size, IP address | The basis of fingerprinting, and it survives cookie deletion. |
| Inferred | Anything derived from the above: interests, life stage, income bracket, likely health conditions | Harder to dispute than an observation, because it is rarely shown to you, and inferences are what most rights requests struggle to reach. |
Two of those deserve a second look. Identifiers are the whole game: if a company cannot tell that two visits are the same person, the profile is worthless. Most privacy controls work by attacking the identifier rather than the observation. And inferred data is the category people most often forget to ask about, even though a wrong inference about your health or finances can do more damage than a correct observation.
Who Ends Up Holding It
Data does not stay where you left it. The organisations that end up with it fall into rough groups, and knowing the groups makes a rights request much easier to aim.
- The service you used. Your account provider, your bank, your employer, the shop. First-hand and directly answerable to you.
- Analytics and advertising companies embedded in the pages you visit, often several per page, each with its own identifier and its own retention policy.
- Software development kits inside the apps you installed — analytics, crash reporting, attribution and advertising libraries bundled by the developer. You chose the app; you did not choose these.
- Data brokers that assemble profiles from public records, loyalty schemes, warranty registrations and purchased datasets, then resell access. The ones publishing a subset openly are the people-search sites.
- Institutions with legal access, where disclosure is compelled. Worth understanding, and not the subject of this site.
- Criminals, once any of the above is breached. This is the route by which data you gave a shop in 2014 becomes a credential-stuffing attempt against your email today.
The practical point is that the company you dealt with is answerable for what it holds and, in most legal frameworks, for what it passed on. The company you never dealt with is the hard case, and it is where the law has been moving.
Threat Modelling: Deciding What You Protect
Privacy advice fails most often because it is applied uniformly. Hiding everything takes enormous effort, breaks useful services, and usually gets abandoned within a fortnight. Deciding what you are protecting against makes the effort proportional.
Four common goals, and the work each actually implies:
| Goal | What actually helps | What would be wasted effort |
|---|---|---|
| Reduce everyday commercial profiling | Strict tracking protection, a content blocker, partitioned cookies, deleting the advertising ID, auto-delete windows on account activity | A VPN for daily browsing, exotic browser configurations, regularly clearing all cookies |
| Keep your address and phone number off people-search sites | Broker opt-outs and deletion requests, repeated every few months; a credit freeze to defend against impersonation | Abstract "privacy hygiene" that never contacts the brokers holding the data |
| Protect against a specific adversary — an ex-partner, a stalker, a hostile employer | Specialist help first. Then: audit what is publicly discoverable, remove it at source, separate accounts, review app permissions and location sharing. | Trusting that ordinary settings are enough. They are not, and this is not a situation to handle alone. |
| Protect data from a breach you may never hear about | Data minimisation and deletion requests — the only controls that affect data already stored somewhere | Anti-tracking tools, which do nothing about a database sitting on someone else's server |
If you are in danger rather than simply uncomfortable — stalking, harassment, domestic abuse, or a threat connected to your work — general guidance is not enough. The support page names what we cannot do and where to go instead.
A Realistic Order of Work
If you do nothing else, do these, in this order. Each takes minutes rather than hours, and each has a durable effect.
- Set an auto-delete window on your main platform account's web, app and location activity. This changes what exists rather than what is displayed, which is why it outranks every advertisement preference.
- Move tracking protection to its strictest tier and install one reputable content blocker. Learn the per-site exception so a broken login does not make you weaken the global setting.
- Delete your phone's advertising ID or switch off app tracking requests, and review location permissions by category rather than app.
- Stop remote images loading in your mail app. That breaks email open tracking outright, and it costs nothing.
- Keep separate browser profiles for accounts, shopping and ordinary reading, so unrelated activity never shares a cookie jar.
- Point your devices at an encrypted, filtering DNS resolver, at the router if you can, so televisions and consoles are covered too.
- Ask the major data brokers to delete your records, and diary a repeat in three months, because profiles get rebuilt.
- Delete the accounts you no longer use. A dormant account is data you are not watching, in a system you are not checking.
The remaining chapters explain why each of these works, where each one stops, and what the law adds when a setting cannot reach far enough.
The short version
- The identifier is the asset; the observations are raw material. Most controls work by breaking the join.
- Blocking third-party cookies helps and is not sufficient. Fingerprinting needs no cookie, and server-side events never reach your browser.
- Private browsing is local cleanup, not anonymity. Your network and the sites you visit still see you.
- Partitioning beats blocking, because it keeps sites working while severing the cross-site link.
- Revoking a permission stops future collection. Only a rights request reaches what was already sent.
- Decide what you are protecting against first, or you will spend effort where it does not matter.
RAJA89: quick answers
What is RAJA89?
RAJA89 is a free, independent educational resource about data privacy and your digital footprint, published at raja89official.site. It explains how data about you is collected, who ends up holding it, and which settings and legal rights actually change that. It sells nothing, carries no advertising, and asks readers for no personal information.
Where should I start if I only have fifteen minutes?
Open your main account's activity controls and set an auto-delete window of three months on web, app and location history. Then move your browser's tracking protection to its strictest tier, install one reputable content blocker, and delete your phone's advertising ID. Those four changes reduce both what is collected and how long it is kept.
Will any of this make me anonymous?
No, and any site claiming otherwise is selling something. Reducing your footprint lowers how much is gathered and how easily it is linked to you. It does not erase what has already been collected, shared or sold, and no combination of settings defeats fingerprinting or server-side matching completely.
Sources checked for this page
- EUR-Lex - Regulation (EU) 2016/679 (General Data Protection Regulation)
- MDN - Web privacy: cookies, storage, fingerprinting and partitioning
- EFF Cover Your Tracks - test your own browser fingerprint
- California Attorney General - California Consumer Privacy Act
- Apple - App Tracking Transparency
- European Data Protection Board - guidance and national authority contacts
About RAJA89
RAJA89 is an independent educational project written by one person. It is not a company, an agency or a managed editorial team, and it does not pretend to be one. Edi Rahmadani writes these pages, checks them against the primary sources cited on each one, and answers corrections sent to the address on the support page.
RAJA89 is the name the site publishes under; the name above is the person accountable for what it says. Nothing here is generated and published unread: a claim either traces to a source you can open yourself, or it is marked as the author's own judgement.
How this site is funded
It is not. There is no advertising, no sponsorship, no affiliate link, no paid placement and no product for sale anywhere on this site. No company pays to be mentioned, and no page carries a commission-bearing link. Hosting is paid for out of the author's own pocket, which is the whole of the commercial relationship. If that ever changes, the change will be disclosed on this page before it appears anywhere else.
How to read this site
- Primary sources only. Where a claim can be checked, it links to the standards body, regulator or vendor documentation that supports it — not to another summary of it.
- Limits are stated. Where a control fails, or a setting only partly helps, the page says so in the same breath as the advice.
- Country-specific answers are labelled. Reporting routes, consumer protections and privacy law differ by country, so a passage that applies in only one is marked as such.
- No fear as a sales tool. Scaring a reader into a purchase is the behaviour this site exists to argue against.
Editorial standards we hold ourselves to
- We do not quote a statistic without naming the report and its year.
- We do not name a step-by-step settings path unless the vendor's own documentation still shows it.
- We do not present a product as the answer. Where a category of tool helps, we describe the category and what to look for in it.
- We do not write in the voice of expertise we do not have. When a question needs a lawyer, a doctor or a regulator, the page says so and stops.
- We do not silently rewrite a substantive claim. Material corrections are recorded with a dated note on the page, as described on the support page.
Dates, and what they mean
The date below is the last time these pages were re-checked against the sources they cite. It is a record of what happened, not a schedule: no page here states a calendar interval for review, because a static site cannot enforce one. Pages are re-checked when something they describe actually changes — a vendor renames a setting, a standard is revised, a regulation is amended, a link breaks — and at least once a year regardless, so that nothing is left unexamined through neglect.
The date moves only when a person has re-opened the cited sources and confirmed the text still matches them. It is not the date a file was last saved. Where a passage has been left standing but is no longer certain, it is marked as uncertain rather than quietly carried forward.
If the date below looks old, that is information, not a fault. It means the pages are due for their next pass. Everything on them links its primary source precisely so you can check the current position yourself rather than relying on our copy of it.
Who is accountable for this page
| Published by | RAJA89, an independent educational project written and paid for by Edi Rahmadani |
|---|---|
| Written by | Edi Rahmadani — an independent writer, publishing under the RAJA89 name. No employer, qualification or years of experience is claimed here, because this site asserts only what can be checked. |
| Reviewed by | Edi Rahmadani. This site has no separate reviewer, and we do not name one to look better. Every page is self-reviewed against the sources it cites, and that is exactly what the review record below means. |
| Corrections | Send a correction — specific reports are checked against a primary source and fixed or answered |
| First published | 2026-10-08 |
| Last reviewed | 2026-10-08 — every page on this site carries the same review date, and each one links the sources it was checked against |
Contact
Corrections, factual disputes, reports of a link that now leads somewhere harmful, and notices that a described setting has moved are all welcome at the address below. Edi Rahmadani reads them.
We will never ask you for a password, a one-time code, a recovery code or remote access to your device, and we will never ask you to confirm account details by replying to a message. Any message claiming to come from this site and asking for any of that is not from us.
Scope and limitations
Read this before acting on anything here.
- This is general education, not advice for your situation. It explains how data collection and privacy controls generally work, and which rights a reader may have. It is not legal advice and reading it creates no professional relationship. It is not an assessment of your situation: we do not know your accounts, devices, employer policies or past breaches. And it is not anonymity — reducing a footprint lowers how much is collected and how easily it is linked to you, and it cannot erase what has already been gathered or sold.
- We cannot see your accounts or your devices. We cannot tell you whether a particular message you received is genuine, whether an account has been compromised, or what an organisation holds about you.
- We cannot act on your behalf. We cannot contact a platform, bank, regulator or data protection authority for you, and we cannot investigate anyone. Requests like that have to go to the provider directly.
- Menus move. Settings are renamed, moved and reset by updates. A click path that was accurate on the review date may look different in your version. Treat every step here as a description of what to look for rather than a guarantee of what you will see.
- We can be wrong. Errors get through. If you find one, the support page explains what happens next.

