(Est. reading time: 7 min)
Google provides some of the best services and apps available anywhere on the Internet. Did you ever wonder why nearly every one of them is free?
Many of the people I know in the tech industries, people who are some of the most sophisticated technologists in the world, use the same Gmail service your grandparents do, rather than something more exotic. Why? Because Gmail is an excellent email processor that could easily command a hefty subscription fee, but it’s free. So are most of Google’s other services and apps, like calendars, spreadsheets, meetings, etc.
The reason they’re free is that Google wants billions of people using them. Subscription fees would pale in comparison to the money they make by using the data you willingly hand over to them in exchange for using those apps.
Every email you write, every spreadsheet you create, every on-line meeting you hold and every entry you make in your Google calendar is sitting on the company’s servers. Selling that data to third parties is how Google’s parent company made a large chunk of its $402 billion gross revenue in 2025, of which $132 billion was pure profit.
Mostly, it’s about advertising. Some years ago, I did a Google search on NASA’s Cassini mission to Saturn. Two days later I started getting ads from Google trying to get me to buy a Saturn car.
Sometime after that, I got an email from Citibank telling me not to worry about informing them of my upcoming travel. They’d make sure my credit card wasn’t automatically flagged if I used it in Europe because they already knew I was going to be there. I never told them that.
Since then, there have been equally spooky occurrences. Just a week ago, my wife asked Google’s Gemini AI about an upcoming race in San Diego. At the end of its reply, it said, “Since you’re a triathlete, maybe you’d like to hear about triathlons in your area?” The race she inquired about was a 5K, not a triathlon. She never mentioned triathlon.
I contacted Citibank about how it knew my travel plans. Fortunately, I had a connection there who explained it to me. I bought a ticket from American Airlines, and paid for it with my Citibank credit card. The bank’s systems picked that up and took it from there.
At first, I was pretty angry and considered raising a ruckus. Then I thought about it for a while and calmed down. I have longstanding relationships with both American Airlines and Citibank and I trust them. And, this turned out to be a pretty valuable service. I’ve had credit cards declined overseas twice because I forgot to inform the bank that I’d be traveling.
I’ve worked in the computer world for nearly all of my adult life. I tend to parcel out my paranoia where it really matters. I’m not that concerned with privacy. I don’t care if someone gets hold of my medical information or knows how often I service my car. (I have never done business with Carvana, have never even logged onto their website, but every month I get messages telling me I’m due for an oil change or a tire rotation, along with an estimate of what my cars are currently worth. It’s scary that they manage to get their hands on my data, and my email address, but the service is valuable so I shrug it off.)
What I do care about is security. If someone manages to figure out my bank balance, I’m not going to get bent out of shape, but if they tamper with my account I’m liable to go ballistic. I also confess to small bits of joy when real estate brokers contact me to ask if I want to sell properties I never heard of but they think I own. (I’ve already accepted half a dozen offers. Just waiting for the checks.)
But all of this leads me to wonder: Just how much do strangers know about me? What kind of data are they collecting? How are they combining information from multiple sources to learn things about me I don’t even know?
Are they possibly making mistakes and putting false and harmful data about me out into cyberspace for all to feast on? How much trouble am I in if someone with malicious intent decides to go after me?
Even worse, how complicit am I in falling into their clutches?
Have you ever taken one of those online quizzes, like “Just how secure are your finances?” or “Is your sex life all it could be?” or “Are your dietary habits killing you?” or “Find out your IQ!”
Nearly all of these kinds of quizzes have no benefit to you whatsoever and have only one purpose: To gather information about you that you probably wouldn’t even tell your therapist, and then sell it to anyone with the money to buy it. And there are a lot of buyers.
I’m going to say a lot more about all of this stuff in a future article, but right now I want to tell you a true story that will illustrate some of the ways digital data can be gathered and exploited.
You might have heard that a consulting firm used illicitly obtained data in service to Donald Trump’s 2016 presidential campaign, but maybe you don’t know the details. They’re as important as they are fascinating, because this episode had a world-shaking impact on social media manipulation and the weaponization of information. And it’s not clear to me that the lessons were well learned.
The following has no political content whatsoever. These are just the facts of what happened.
“This Is Your Digital Life”
That’s the name of a “fun” personality quiz posted on Facebook in 2014 by a Russian academic named Aleksander Kogan. It might have been fun for users who took it, but it was money in the bank for Kogan, who figured out that he could predict, with over 90% accuracy, whether the test taker was a Democrat or a Republican by looking at only five questions. Kogan’s objective was to sell that information to campaign operatives who would pay good money to learn the political persuasions of people active on social media.
Over 270,000 people took the quiz. Knowingly or otherwise, they also gave the quiz program permission to access their full Facebook profiles. This was like striking gold for Kogan, but what happened next was more like getting the keys to Ft. Knox: A security vulnerability in Facebook’s systems allowed Kogan to access the full profiles of all of the quiz-takers’ connections, as well as of all the connections’ connections, and so on.
By the time Facebook found out what he’d done and closed the loophole, Kogan had stolen the personal data of more than 87 million Facebook users, most of them Americans.
He then turned the whole cache over to a campaign consulting firm called Cambridge Analytica. That firm was backed by a number of heavy-hitting conservatives, including Steve Bannon and a huge GOP donor named Robert Mercer. The summer before the 2016 presidential election, Bannon was hired to run the Trump campaign and Cambridge Analytica was brought in to run its digital advertising and voter targeting operations.
Now in possession of a staggering amount of background information on those Facebook users, the company analyzed likes, posts and a ton of other data to create what they called “psychographic profiles” of millions of potential voters.
Armed with these profiles, the company then created hundreds of carefully constructed ads designed to appeal specifically to each of the types of voters they categorized, and serve them up in ways that ensured that every one of those people saw ads targeted for them.
As an example, potential voters characterized as neurotic or fearful saw scary, apocalyptic ads warning of increasing crime, immigration and corruption under Democratic candidate Hillary Clinton. “We targeted their inner demons,” a whistleblower would later testify.
Cambridge Analytica and the Trump campaign didn’t care about the popular vote. They ran ads only in states that would swing the electoral college, which decides presidential elections.
Did it work? There are no studies that definitively answer the question. But Cambridge Analytica ran over 5,000 of these highly customized ads that were seen by more than 1.5 billion people, and while Hillary Clinton won the popular vote by nearly 3 million votes, she lost the electoral college count and therefore the election.
The perpetrators of this scheme didn’t get away scot-free. Cambridge Analytica went bankrupt and its executives were blacklisted from political consulting and faced several legal actions. Facebook paid a record $5 billion fine to the FTC for violating consumer privacy, another $100 million to the SEC for misleading investors (by telling them that data misuse was a “hypothetical risk” after the breach had already occurred), and $725 million more to settle a lawsuit brought by affected users.
The election results were not challenged.
Bear in mind that this is an incident, just one of many, that we happened to find out about.
What else is going on that we have no idea about?
Stay tuned…


