RAJA89 home RAJA89 official siteOfficial site (opens in a new tab)
Support - Questions and answers

RAJA89 FAQ

Short answers to the questions readers send most often about data privacy: what to fix first, whether incognito helps, whether a VPN makes you anonymous, how to find out what a company holds about you, and how long it has to answer.

Every answer links to the full guide it comes from, so you can check the reasoning rather than taking our word for it.

Last reviewed 8 October 2026Free to read, no sign-up

Visit the official RAJA89 website (opens in a new tab)Opens the official RAJA89 website in a new tab.

Starting Out

These are the questions readers actually send. Each answer is deliberately short; the linked guide has the reasoning.

Is it worth trying to protect my privacy at all?

Yes, and the honest reason is that the effort is not proportional to the reward across the board. A handful of settings reduce a large share of everyday commercial profiling in about half an hour. What does not work is trying to be invisible, which breaks useful services and gets abandoned. Aim to reduce and to shorten retention, not to disappear.

What is the single most effective change I can make?

Set an auto-delete window on your main platform account's web, app and location activity. It is more consequential than any anti-tracking tool because it changes what exists on a server rather than what is displayed to you. Most privacy settings affect what you see; this one affects what is kept.

Do I need to worry about this if I have nothing to hide?

Privacy is not only about hiding something. It is about the accuracy of inferences made about you, the security of data that can be breached, and the asymmetry between what a company knows about you and what you know about it. A profile that mistakenly places you in a health or financial category can affect insurance, credit and employment regardless of whether you did anything wrong.

How much time does this actually take?

About half an hour for the highest-value settings, and roughly fifteen minutes twice a year for a permission audit and a broker opt-out pass. Rights requests run about an hour per organisation. Anything beyond that is optional, and the returns flatten quickly.

Tracking and Cookies

If I block third-party cookies, am I no longer tracked?

You are less tracked by that method, and the method is only part of the picture. First-party cookies still profile your behaviour on a single site, fingerprinting needs no cookie at all, and server-side events never pass through your browser to be blocked. Blocking them is worth doing as a layer, not as a solution.

Does incognito mode hide what I do?

It hides the session from your own device at the end of it, and in Chrome it blocks third-party cookies that ordinary windows allow. It does not hide anything from your network, your internet provider or the sites you visit, and it does not change your browser fingerprint.

Can a website identify me without cookies?

Yes, by fingerprinting. Your screen size, fonts, graphics behaviour, time zone, language settings and dozens of other small details combine into a value that is often unique among ordinary browsers and stable for weeks. It is computed on the server, so there is nothing stored on your device to delete.

Why do links have all those extra characters on the end?

They are tracking parameters - campaign attribution fields such as utm_source or gclid. They tell the destination where you came from, and sometimes hand it an identifier linked to your account elsewhere. Delete everything from the first ? before sharing a link, then check the page still loads.

Settings and Tools

Which browser is the most private?

The one you keep updated and configured deliberately. Safari blocks third-party cookies by default, Firefox partitions them with Total Cookie Protection, Brave blocks far more by default, and Chrome still allows them in ordinary windows while offering partitioning. All of them let you raise tracking protection; none of them stops fingerprinting or server-side tracking.

Does a VPN make me anonymous?

No. It moves your trust from your internet provider to the VPN operator, who then sees every connection you make. It is genuinely useful on untrusted Wi-Fi and for hiding your address from a specific site. It does nothing about cookies, fingerprinting, or the account you are signed into, and a free VPN is a business that needs a revenue model.

Should I clear all my cookies regularly?

It is less useful than it feels. It logs you out everywhere, makes your browser state more distinctive, and does not delete the profile the company already holds. Separating your browsing into profiles or containers prevents the cross-site join from happening at all, which is the more durable approach.

Is a browser extension a privacy risk?

It can be the largest one you have, because extensions usually request access to every page you visit and update themselves automatically. Anyone who can publish an update can change what it does with that access. Keep the list short, re-read permissions after major updates, set site access to on-click where possible, and remove anything you have forgotten about.

Your Data Rights

How do I ask a company what data it holds about me?

Write to the privacy or data protection officer address in the company's privacy policy, name the right and the instrument - "under Article 15 GDPR" or "under the CCPA" - identify yourself with the account email address, and state the deadline. Keep it in writing. Our data rights guide has a full structure and a template.

How long does a company have to respond?

One month under the GDPR, extendable by two months for complex requests with an explanation. In California, 10 business days to acknowledge and 45 calendar days to respond substantively, extendable once by 45 days, with 15 business days for opt-outs of sale or sharing.

Can a company refuse to delete my data?

Yes, in defined circumstances: legal retention duties, data needed for legal claims, fraud prevention, freedom of expression, or where the record contains another person's data. A refusal should name the provision. A refusal that cites nothing is often a first-line response rather than a considered position.

What are data brokers and can I get off their lists?

Brokers assemble profiles from public records, loyalty schemes and purchased data, and sell access to marketers, employers and investigators. You can request deletion or opt out, sometimes through a central platform such as California's DROP. Expect to repeat it every few months, because profiles get rebuilt from new public records.

RAJA89: 15 questions readers ask

What is the single most effective privacy change I can make?

Set an auto-delete window on your main platform account's web, app and location activity - typically three months instead of indefinite retention. It is more consequential than any anti-tracking tool because it changes what exists on a server rather than what is displayed to you. Advertisement-personalisation toggles are much weaker than people assume.

Will privacy settings make me anonymous?

No. They reduce how much is collected and how easily it is linked to you. They do not erase data already gathered, shared or sold, and nothing available in a browser setting defeats fingerprinting or server-side tracking completely. Treat anonymity and privacy as different goals with different methods.

If I block third-party cookies, am I no longer tracked?

You are less tracked by that method, and the method is only one of several. First-party cookies still profile behaviour within a single site, fingerprinting requires no cookie at all, and server-side events never pass through your browser. Blocking third-party cookies is a worthwhile layer rather than a solution.

Does incognito or private browsing hide what I do?

It keeps the session's cookies and history off your own device and logs you out of existing accounts, and in Chrome it blocks third-party cookies that ordinary windows allow. It does not hide your activity from your network, your internet provider or the sites you visit, and it does not change your fingerprint.

Can a website identify me without using cookies?

Yes, through browser fingerprinting. Screen size, installed fonts, graphics and audio behaviour, time zone, language settings and dozens of other small characteristics combine into a value that is often unique among ordinary browsers and stable for weeks. Because it is computed on the server, there is nothing on your device to delete.

Why do links have extra characters such as utm_source at the end?

Those are tracking parameters used for campaign attribution. They tell the destination where you came from and sometimes carry an identifier linked to your account on another platform. They also travel with any link you copy and share. Delete everything from the first question mark, then confirm the page still loads.

Does a VPN make me anonymous?

No. It moves your trust from your internet provider to the VPN operator, who then sees every connection you make. It is genuinely useful on untrusted Wi-Fi and for hiding your address from a particular site, and it does nothing about cookies, fingerprinting, or the account you are signed into.

Which browser is the most private?

The one you keep updated and configure deliberately. Safari blocks third-party cookies by default, Firefox partitions them with Total Cookie Protection, Brave blocks far more by default, and Chrome still allows them in ordinary windows while offering partitioned cookies. Every major browser lets you raise tracking protection, and none of them defeats fingerprinting.

Should I clear all my cookies regularly?

It is less useful than it feels. It logs you out everywhere, makes your browser state more distinctive, and does not delete the profile the company already holds. Separating your browsing into browser profiles or containers prevents the cross-site join from happening in the first place, which is the more durable fix.

How do I ask a company what data it holds about me?

Write to the privacy or data protection officer address published in the company's privacy policy, name the right and the legal instrument - for example Article 15 of the GDPR or the CCPA - identify yourself with the account email address, state the deadline, and keep everything in writing. Our guide to exercising your data rights sets out the full structure.

How long does a company have to answer a data request?

One month under the GDPR, extendable by two months for complex requests with an explanation. In California, 10 business days to acknowledge and 45 calendar days to respond substantively, extendable once by a further 45 days, with 15 business days for opt-outs of sale or sharing.

Can a company refuse to delete my data?

Yes, in defined circumstances: statutory retention duties in tax, accounting or employment law; data needed to establish or defend legal claims; fraud prevention; freedom of expression; or where a record contains another person's data. A refusal should name the provision it relies on, and one that cites nothing is often a first-line response rather than a legal position.

What are data brokers, and can I get off their lists?

Brokers assemble profiles from public records, loyalty schemes, warranty registrations and purchased datasets, then sell access to marketers, employers and investigators. You can request deletion or opt out, sometimes through a single platform such as California's DROP. Expect to repeat the exercise every few months, because profiles are rebuilt from new public records.

Is a browser extension a privacy risk?

It can be the largest one you carry. Extensions typically request access to every page you visit and update themselves automatically, so whoever can publish an update can change what it does with that access. Keep the list short, re-read permissions after major updates, set site access to on-click where possible, and remove what you have forgotten.

Does this site collect any personal data?

No. It is a static site with no cookies, no analytics, no trackers, no forms, no advertising and no JavaScript. The only record of a visit is whatever request log the hosting provider keeps by default, under its own policy rather than ours.

Back to top ↑

Sources checked for this page

About RAJA89

RAJA89 is an independent educational project written by one person. It is not a company, an agency or a managed editorial team, and it does not pretend to be one. Edi Rahmadani writes these pages, checks them against the primary sources cited on each one, and answers corrections sent to the address on the support page.

RAJA89 is the name the site publishes under; the name above is the person accountable for what it says. Nothing here is generated and published unread: a claim either traces to a source you can open yourself, or it is marked as the author's own judgement.

How this site is funded

It is not. There is no advertising, no sponsorship, no affiliate link, no paid placement and no product for sale anywhere on this site. No company pays to be mentioned, and no page carries a commission-bearing link. Hosting is paid for out of the author's own pocket, which is the whole of the commercial relationship. If that ever changes, the change will be disclosed on this page before it appears anywhere else.

How to read this site

Editorial standards we hold ourselves to

Dates, and what they mean

The date below is the last time these pages were re-checked against the sources they cite. It is a record of what happened, not a schedule: no page here states a calendar interval for review, because a static site cannot enforce one. Pages are re-checked when something they describe actually changes — a vendor renames a setting, a standard is revised, a regulation is amended, a link breaks — and at least once a year regardless, so that nothing is left unexamined through neglect.

The date moves only when a person has re-opened the cited sources and confirmed the text still matches them. It is not the date a file was last saved. Where a passage has been left standing but is no longer certain, it is marked as uncertain rather than quietly carried forward.

If the date below looks old, that is information, not a fault. It means the pages are due for their next pass. Everything on them links its primary source precisely so you can check the current position yourself rather than relying on our copy of it.

Who is accountable for this page

Published byRAJA89, an independent educational project written and paid for by Edi Rahmadani
Written byEdi Rahmadani — an independent writer, publishing under the RAJA89 name. No employer, qualification or years of experience is claimed here, because this site asserts only what can be checked.
Reviewed byEdi Rahmadani. This site has no separate reviewer, and we do not name one to look better. Every page is self-reviewed against the sources it cites, and that is exactly what the review record below means.
CorrectionsSend a correction — specific reports are checked against a primary source and fixed or answered
First published2026-10-08
Last reviewed2026-10-08 — every page on this site carries the same review date, and each one links the sources it was checked against

Contact

Corrections, factual disputes, reports of a link that now leads somewhere harmful, and notices that a described setting has moved are all welcome at the address below. Edi Rahmadani reads them.

raja89officials@gmail.com

One person, checking messages between other work. Reports that name the passage and the source they disagree with are answered fastest — the support page sets out exactly what to include, and what we cannot help with.

We will never ask you for a password, a one-time code, a recovery code or remote access to your device, and we will never ask you to confirm account details by replying to a message. Any message claiming to come from this site and asking for any of that is not from us.

Scope and limitations

Read this before acting on anything here.

Back to top ↑