The exposure surface of personal data now extends well beyond the web browser. Between AI assistants that ingest conversations, tracking pixels in emails, and mobile permissions granted without reading, protecting your online privacy requires a more granular approach than the usual lists of tips.
Data Leaks to AI Models: A Blind Spot in Online Privacy
Consumer chatbots and AI assistants represent a disclosure vector that most protection guides overlook. The CNIL published its first recommendations on the development of data-respecting AI systems on June 7, 2024. They cover purpose definition, legal basis, data reuse, and privacy by design.
In practice, never transmit identifying data or confidential professional documents to a chatbot. A prompt containing a name, a medical record number, or a contract excerpt potentially feeds a training dataset. The CNIL’s recommendations specify that individuals can exercise their rights over these datasets, but technical deletion solutions are not yet satisfactory in all cases.
We recommend treating every input field of an AI assistant as a public form. If you wouldn’t publish the information on a social network, don’t paste it into a prompt.
This reflex complements best practices on Sorlav com that detail measures to apply daily to limit the exposure of your personal information.
Tracking Pixels in Emails: Neutralizing Invisible Surveillance

Spy pixels embedded in emails constitute an often-underestimated tracking mechanism. A tracking pixel is an invisible image (usually a one-pixel square) loaded from a remote server upon opening the message. This loading transmits to the sender the opening time, IP address, device type, and sometimes approximate geolocation.
The CNIL has initiated a public consultation with a view to final recommendations on these trackers. This is a clear signal: the issue goes beyond simple marketing and touches on the confidentiality of private exchanges.
To neutralize these pixels, three technical levers work:
- Disable automatic loading of remote images in your email client (Thunderbird, Apple Mail, Outlook all offer this option in privacy settings).
- Use an email relay service that removes trackers before receipt, as offered by some privacy-focused email providers.
- On mobile, prefer a mail client that natively blocks remote content rather than the manufacturer’s default app.
This setting takes less than a minute and cuts off a collection channel that most internet users are unaware of.
App Permissions and Account Compartmentalization
Every permission granted to a mobile application is an open door to your personal data. GPS location, access to contacts, the microphone, or the photo gallery should never be validated by default. We observe that most users grant permissions at installation without ever revoking them afterward.
The principle to apply is the least privilege: a note-taking app does not need geolocation, a flashlight has no reason to access the directory. On both Android and iOS, privacy settings now allow for one-time access (a single session) rather than permanent.
Compartmentalizing Your Digital Identities
Using a single email address for all your services creates a universal identifier that can be exploited through cross-referencing. We recommend segmenting into three levels:
- A primary address reserved for banking, administrative, and health services, never shared on a commercial form.
- A secondary address for online purchases, subscriptions, and loyalty programs.
- Disposable aliases (offered by several email providers) for one-time registrations, white paper downloads, or trial periods.
This compartmentalization significantly reduces the impact of a data leak. If the address used for an e-commerce site ends up in a compromised database, your banking and administrative accounts remain isolated.

VPN Connection and Web Browsing Encryption
A VPN encrypts the traffic between your device and an intermediary server, masking your real IP address from visited sites and your internet service provider. The VPN protects the transport channel, not browsing behavior. Connecting to a social network via a VPN does not prevent that network from collecting all your interactions.
The choice of VPN provider is crucial. A free service funded by advertising may monetize connection logs, which negates the benefit of encryption. Check the logging policy (no-log) and the hosting jurisdiction of the provider.
Beyond the VPN, the HTTPS protocol remains the first layer of protection to systematically verify. Modern browsers signal unencrypted sites, but some login forms on older sites still transmit in clear text. No sensitive information should be entered on a page without a padlock in the address bar.
Encrypted DNS: An Often-Neglected Complement
Even with an active VPN, DNS queries (the resolution of the domain name to an IP address) can transit in clear text if the DNS resolver is not encrypted. Activating DNS-over-HTTPS (DoH) or DNS-over-TLS in your operating system’s network settings closes this last gap. Firefox, Chrome, and recent versions of Windows, macOS, Android, and iOS offer this option natively.
Protecting your online privacy relies less on a single tool than on the methodical stacking of defense layers. The most neglected link is often the most exposed: a clear DNS query, an active tracking pixel, or a too-talkative prompt in an AI assistant can compromise months of precautions. Every setting counts, and the most effective ones are rarely the most visible.



