Executive Summary

Rejecting a technology is a decision with costs of its own. Privacy concerns deserve examination, but so do the hours, opportunities, and capabilities surrendered through blanket refusal. The practical question is whether a specific tool can advance a worthwhile purpose under acceptable boundaries. Assume you are being watched, control what you share, and evaluate providers by evidence rather than promises.

My mother recently showed a property to a man who brought his high-school daughter. The daughter wanted to become a project manager. When my mother mentioned my project-management work and the growing role of AI, the young woman said she did not want to use AI because it uses water. She was holding an iPhone.

The phone does not settle the environmental question. It exposes a question about consistency: what examination led her to accept one technology and reject another? A resource-use objection should identify the activity, its footprint, and a realistic alternative. Repeating a concern does not explain why every possible use should be rejected.

Technology discussions too often become declarations of allegiance. One camp treats adoption as progress by definition. Another treats refusal as evidence of moral seriousness. Neither position tells a student, an artist, or a business owner what to do with a particular task. The decision requires more than choosing a side.

Privacy requires a practice

My starting principle is simple: assume you are being watched. This is a precaution for deciding what to disclose, not a claim that someone continuously observes every person. Before sharing information, consider what would happen if it reached an unintended audience or remained accessible longer than expected.

I use tools such as ChatGPT, Claude, and Notion to increase my production capacity. I limit access, maintain redundancies, and keep sensitive identity, credit, and health information outside these workflows. The purpose is to gain useful capacity without giving every system everything it could request. That is my operating practice, not proof that any provider is risk-free.

Already using email and social media does not eliminate your right to protect additional information. It does require explaining what makes the next service different. Are you rejecting a capability, a particular provider, or a specific disclosure? Those decisions can lead to different answers. You can decline access to private records while still testing a tool with public or fictional material.

You cannot purchase immunity

Privacy products deserve the same scrutiny as the companies they invite us to distrust. A price tag, a privacy label, or an unfamiliar brand does not establish protection. Ask what information the product can access, who controls it, how long it is retained, and what evidence supports its promises.

In 2024, the Federal Trade Commission finalized an order requiring Avast to pay $16.5 million to settle charges that it sold browsing information after promising to protect consumers from online tracking. The order prohibited selling or licensing browsing data for advertising. This is a documented example of privacy marketing conflicting with alleged business practices, not a claim that every security vendor behaves this way. [1]

Technical failures are a different category. The 2023 TunnelCrack research tested more than 66 VPNs across five platforms and demonstrated attacks that could route traffic outside the protected tunnel. Those historical findings show why implementation and maintenance matter; they do not establish that all current versions remain vulnerable. Escaping a VPN tunnel also does not automatically defeat separate HTTPS encryption. [2]

The FTC explains another limit: a VPN shifts trust toward the VPN provider and does not make the user entirely anonymous. A website can still identify you through information you submit. Logging into a personal account does not stop being identifying because the connection uses a VPN. [3]

An honest privacy provider can acknowledge boundaries. GrapheneOS explains that connecting to a cellular carrier requires identifying the device to the network and leaves cellular tracking possible. Its software protections cannot remove that dependency while the cellular connection remains active. This is an openly documented limit, not evidence that GrapheneOS is deceptive. [4]

These cases establish three separate issues: misleading claims, technical vulnerabilities, and unavoidable limits within a chosen activity. They do not establish equal risk across products. Nor does a large company become trustworthy simply because it discloses data collection. Both familiar platforms and privacy vendors must explain their practices and support their claims.

The cost of refusing capability

I discussed these tools with a seamstress and fashion designer who wanted to expand what she could offer clients. Her reaction changed when the discussion moved from whether AI was supposedly evil to how selected tools might help organize orders, prepare estimates, and track materials.

The opportunity was concrete: less administrative work could leave more time for design and client service. Better organization might also help reduce avoidable material waste. Those are possibilities to test, not results I have measured for her business. Generated measurements or patterns still need verification before anyone cuts fabric.

A business owner has limited hours. Work that consumes those hours has a cost even when no invoice records it. If a tool saves meaningful time after checking and corrections, that capacity can support more clients, rest, or family life. If it creates more errors and supervision than value, reject that use. Measure the outcome.

Purpose before allegiance

My faith gives this work its direction: helping people pursue meaningful goals and relieving burdens that can be delegated responsibly. An artist should be able to spend more time making art without every administrative responsibility consuming the same attention. Technology earns its place through the work it helps accomplish.

Your behavior affects exposure, but providers also control security, retention, and access practices. Responsible use therefore requires both personal boundaries and provider scrutiny. Caution becomes useful when it changes permissions, data selection, verification, or the choice of system. Fear without examination can leave the original burden intact.

A practical way forward

Choose one repetitive task with a clear purpose. Use nonsensitive information or fictional examples for the first test. Set a boundary around what the system can access and what it may do. Preparing an estimate for review is different from authorizing a payment or sending a commitment to a client.

Check the output against the original records. Compare the time saved with the time spent correcting errors, the subscription cost, and the effort required to maintain the workflow. Keep a usable copy of essential records and a fallback if the service becomes unavailable. Expand access only when the result justifies it.

Where confidentiality rules out a cloud service, evaluate whether a properly configured local workflow meets the need. Local processing changes where information travels; it does not remove the need to secure the device, control connections, and verify results.

Before rejecting a technology, ask: am I responding to an identified risk, or to a position someone taught me to repeat? Before purchasing privacy, ask: what protection am I actually buying, and what remains exposed? Before adopting a tool, ask: what worthwhile purpose does this serve?

Assume you are being watched. Share deliberately. Test what helps. Keep control over consequential actions. The same scrutiny belongs on the risk of using a tool and the cost of leaving useful capability unused.

Works Cited

1. FTC, Avast case and final order, June 26, 2024.
https://www.ftc.gov/legal-library/browse/cases-proceedings/2023033-avast

2. KU Leuven, NYU, and NYU Abu Dhabi, TunnelCrack, August 8, 2023.
https://tunnelcrack.mathyvanhoef.com/

3. FTC, In the market for a VPN app?, February 2018.
https://www.ftc.gov/business-guidance/blog/2018/02/market-vpn-app

4. GrapheneOS FAQ, cellular tracking section; accessed October 10, 2026.
https://grapheneos.org/faq#cellular-tracking

Personal encounters and operating practices are the author's account from the October 10 conversation. External findings are identified above.