
Uber Built Secret Tools to Track Cops and Rivals. Now It's the Only One of the Four Telling You How Long It Keeps Your Data.
For years, Uber ran secret software that identified undercover police and served them a fake app so they could never catch a ride. A separate Uber tool tracked Lyft's own drivers. A third remotely wiped company laptops the second police raided a foreign office. All three were built to control what outsiders could see. Uber says the tool for tracking regulators is retired — it pledged in March 2017 to stop using it against law enforcement — but no independent audit has confirmed that nine years later. What's clearly still alive is the underlying instinct: deciding unilaterally what customers get to know about their own data. Read the four leading apps' current privacy policies side by side and only one of them — Uber's — tells you in writing how many years it keeps your location and trip history.

One Company Analyzes Your Voice for Your Bank, Your Insurer, and the SSA. A Federal Court Just Sided With It.
Pindrop's voice-analysis technology already sits inside call centers at seven of the top ten U.S. banks, insurers, and healthcare providers, and, since April 2025, inside the Social Security Administration's own fraud-screening system — where it flagged two likely-fraudulent claims out of more than 110,000 while slowing retirement claims processing 25%. It's not siloed company by company, either: Pindrop pools fraud intelligence across every client that uses it, in a shared network built from more than 5 billion monitored calls. Two lawsuits argued the company was collecting biometric voiceprints without the consent Illinois and California law require. On May 12, 2026, a federal appeals court ended one of them for good: for its bank-authentication work, the Third Circuit ruled, Pindrop counts as a "financial institution" under a federal banking-law carve-out — exempt from Illinois's biometric privacy law, the strongest one in the country, including that law's own 3-year data-destruction clock. The federal law that exemption leans on, unlike BIPA, gives an individual caller no way to sue over it at all — enforcement is regulators-only. A second suit, over Bank of the West's use of the same technology, ended after the named plaintiff's individual claims were dismissed with prejudice.

Cities Are Ditching Flock for Axon. Nothing Stops Axon From Becoming Flock.
Thirty-nine Flock Safety contracts were canceled in just the first five months of 2026 alone -- after Mountain View and Ventura County discovered Flock's own "nationwide" sharing setting had been quietly active, feeding roughly 600,000 unauthorized searches to agencies that never signed a data agreement. Most of those cities are hiring Axon to do the identical job. Axon's contracts genuinely lack Flock's national lookup network -- that part is real. But so far that's a competitive selling point, not a locked-in architecture: Flock proved it can build hard technical guardrails when it wants to (encrypted storage, true data deletion); the one setting that caused two scandals was left as a switch instead of a wall. Axon has already announced plans to build the same kind of interoperable network, and its own leadership overrode its ethics board on a different surveillance product four years ago.

Home Depot Is Being Sued Three Times This Year Over How It Watches You. Its Camera Vendor Has a Playbook for Backlash Like It.
Home Depot faces three separate privacy lawsuits in 2026 across three states. The most serious: a California class action says its Flock Safety license-plate cameras at 233 stores feed a searchable, nationwide police database, with a policy that doesn't meaningfully restrict sharing with ICE or out-of-state agencies. That's not hypothetical -- the same complaint documents two real cases where cities that explicitly disabled nationwide Flock access got it secretly turned back on anyway. Separately -- and not shown to be connected to Home Depot's case specifically -- a leaked Flock coaching guide obtained by 404 Media shows the company has a practiced playbook for handling this kind of backlash generally: don't deny it's mass surveillance, reframe the debate around "accountability," and get to officials before the public can organize against it.

A Bipartisan Bill to Protect Kids Online Would Also Outlaw GrapheneOS's Account-less Design
A federal bill sitting in the Senate Commerce Committee -- introduced by two Democrats and two Republicans -- would require every operating system on every general-purpose computer to gate use behind an account and a declared age. Its text carries no exemption for open-source, nonprofit, or small developers. GrapheneOS, the account-less privacy OS BL:UF profiled after a traveler's duress-wipe feature got him federally charged, has already told the identical state-level requirement it would rather leave a market than build the account system this bill demands.

He Gave Border Agents a Passcode. It Wiped His Phone Instead of Unlocking It. Now He's Facing Federal Charges.
CBP stopped Samuel Tunick at the Atlanta airport in January 2025, saying they suspected child exploitation material on his phone. He gave them a passcode; instead of unlocking the device, GrapheneOS's built-in duress feature wiped it permanently. Federal prosecutors indicted him in November 2025 for destroying property to prevent its seizure — the first known US case charging someone specifically over a phone's duress-wipe feature. His lawyers say the child-exploitation justification doesn't hold up and that the real target was his connection to the "Stop Cop City" activist movement. Neither claim has been ruled on yet.

Police Used License-Plate Cameras to Stalk Their Exes. One of the Officers Who Investigated the First Case Was Caught Doing the Same Thing.
Milwaukee police officer Josue Ayala used the department's Flock license-plate-reader system to look up his romantic partner's location 124 times and her ex's location 55 times. He resigned and pleaded guilty. One of the two detectives assigned to investigate him, Tehrangi Chapman, was later charged with the same kind of misuse — tracking two people himself and secretly planting a GPS tracker on one of their cars. Georgia's state investigators have arrested five more officers this month for the same pattern; two more were fired in South Carolina. An Institute for Justice count puts documented cases like this at two dozen and climbing. And in Norfolk, Virginia — Flock's own backyard for one of the most consequential pending court fights over whether any of this requires a warrant in the first place — the city just voted to add more cameras, not fewer.

Every Privacy Law in America Exempts the Government. That's Exactly Where Your Data Is Moving Fastest.
Three separate government surveillance stories broke this month — a police drone leak, license-plate cameras used to stalk exes, a consumer-safety agency demanding hospital ER records — and they're the same story: agencies are sharing and buying data across walls that used to separate them, almost always without a public vote. The part almost no coverage gets to: every one of America's 20 state privacy laws, and the federal proposals that died before becoming law, explicitly exempts government from the rules that bind companies. Add in the terms-of-service agreements nobody reads — a 2008 study put the reading time at roughly 244 hours a year, popularized since as "76 work days" — and the honest answer is that citizens have a little real recourse against companies and functionally none against the government programs documented here.

San Francisco Police Put Five Drone Feeds Behind a Link With No Password. The Leak Showed How Much the Drones See.
Color video, thermal images, locations and pilot identities were accessible from the open web. The exposure was a security failure—and an accidental window into a surveillance system expanding faster than its safeguards.