Most people think of push notifications as harmless little alerts. Here is what almost nobody realizes: they do not travel from an app to your phone. They route through Apple’s or Google’s servers first, a kind of digital post office run by two companies, and those two companies keep a record of every notification, which app sent it, when, and to which phone and account it was headed.
In December 2023, Senator Ron Wyden revealed that governments, American and foreign, had been secretly compelling Apple and Google to hand over exactly that data, under a gag order that kept the practice hidden for years. It is no longer hidden. Apple’s own transparency report shows the requests climbing, 277 worldwide in the first half of 2024, up from 158 a year earlier, with the UK and US leading. Investigators called it what it is: a one-stop shop for tracking which apps a person uses.
Push notifications are just the clearest example of a much bigger problem, and it is the one worth drawing out, because it reshapes how you should think about your whole digital life.
Your data feels diverse. It isn’t.
You probably assume your online life is spread across hundreds of separate companies, diverse, decentralized, too scattered for anyone to see as a whole. It is a comforting picture, and it is mostly false. A small number of intermediaries sit at chokepoints that see across nearly all of it.
Push is the obvious one. If an app wants to reliably send you a notification, it has no real choice but to route through Apple’s Push Notification Service or Google’s Firebase Cloud Messaging. There is no third option. So two companies get to see which apps ping your phone and when, tied to your account, even for apps that market themselves as private. The privacy of the app does not matter if the notification pipe belongs to someone else.
The two-factor codes that “secure” your accounts are the same story. The overwhelming majority still arrive by SMS, and the world’s SMS traffic runs through a small handful of messaging aggregators. A few companies therefore see the login activity of a huge slice of the internet, when you sign in, and to what. And these chokepoints are prime targets: when a major aggregator was breached a couple of years ago, the damage rippled straight into the customers of every service that routed through it. On top of that, SMS codes are the weakest form of two-factor anyway, defeated by SIM swaps and old signaling flaws.
Then there is identity itself. Proving you are a real person, know-your-customer verification, funnels through a small set of vendors who end up holding your ID, your selfie, and the link between them. And every “sign in with Google” or “sign in with Apple” button quietly routes another slice of your life through the same few doors.
The pattern is the thing to see. Your data feels spread out, but it converges, and whoever can reach a chokepoint, a government, a hacker, a data buyer, can see across your entire life without ever touching the hundreds of individual apps. It is the same lesson as the carrier and the SIM: centralize the flow and you centralize the surveillance.
You are funneled through them because you have no choice
The reason you cannot simply opt out is that you need these things to work. You need the code to log in. You need the notification to arrive. You need to pass verification to open the account. The bottlenecks are load-bearing for ordinary life, so you are pushed through them whether you like it or not, choosing, every time, the thing working over the exposure you cannot see.
And in fairness, a lot of this machinery exists for real reasons. Platforms genuinely need identity verification and phone checks to fight fraud, spam, bot armies, and abuse. Requiring some proof of a real human is not villainy, it protects everyone from a flood of garbage and scams. The problem is not that verification exists. It is the concentration of it into a few chokepoints, the retention and reuse of the data far beyond the reason it was collected, and the surveillance quietly layered on top of a system built for legitimate purposes.
Protecting your data is not the same as respecting it
Here is the distinction that actually matters, and it is one these companies work hard to blur. They will tell you they protect your data, and to a point they do, mostly because a breach carries severe legal and financial consequences. But protecting data is not respecting it, and it is certainly not respecting you.
Real respect would mean not collecting it in the first place. Not building the profile. Not sitting at a chokepoint logging which apps ping your phone. A company that genuinely respected the person who created that data would not be trying to surveil him at all. “We carefully guard the data we took from you” is compliance driven by liability. “We never took it” is respect. Almost the entire industry offers the first and hopes you will accept it as the second. Once you can tell the two apart, a lot of privacy marketing stops working on you.
So what is the actual threat model?
You asked the right question, because “some company has my data” is too vague to act on. Here, concretely, is what the bottlenecks expose you to.
Cross-app correlation. An intermediary, or anyone who reaches it, can see which apps and services you use and when, and tie them to your identity. That is a behavioral and social map, built without ever reading a message. A push token can link your supposedly anonymous apps back to your name.
One-stop government access. Instead of serving legal demands on a hundred apps, an agency goes to the two or three chokepoints and gets a cross-app view of you, quietly, as the push-notification program demonstrated. And the reassurance that this is “only for serious crimes” reliably erodes, we were told the same about geofence warrants, right before they were used to investigate a wallet theft, and about facial recognition, right before it produced false arrests.
Breach blast radius. A chokepoint is a jackpot. Compromise one push provider or SMS aggregator and you are inside every service that depends on it. It is the same structural flaw that let a foreign intelligence service ransack the phone network through its lawful-intercept system: build a single point everything flows through, and you have built a single point everything can be stolen through.
Account takeover. The SMS codes funneled through the phone-number chokepoint are the weakest link in your logins, and they fail exactly when it matters.
Identity linkage. Forced phone and identity verification stitches together accounts you deliberately kept separate, and the bottleneck sees the stitching.
The unifying threat is simple to state: a few intermediaries you never chose and cannot avoid can see across your entire digital life, and each of them can be compelled, breached, or bought.
What to do about it
You cannot escape the chokepoints entirely, so the goal is to route around the ones you can and to shrink what the rest can see.
Get off the weakest one first. Move your two-factor authentication off SMS and onto an authenticator app or a hardware key, so your logins stop funneling through the SMS aggregators and your accounts stop being hostage to your phone number.
Shrink the push pipe. Fewer apps means fewer push tokens tied to you. A de-Googled phone reduces the dependence on Google’s notification service, some apps can deliver notifications without the duopoly at all, and identifier-free messengers minimize what the pipe can reveal in the first place.
Compartmentalize your identity and your numbers so that any single bottleneck sees a fragment rather than the whole.
And accept the honest limit: some services will still demand SMS, or verification, or the duopoly’s push, and you will use them. This is about reducing exposure and choosing tools that route around the chokepoints where possible, not achieving zero.
This is the side of the line we try to build on. No forced accounts, no pipeline delivering your behavior to us, identifier-free communication, and as little data as possible sitting anywhere it could be compelled, breached, or sold. The goal is not to assemble a well-guarded pile of your information. It is to not hold the pile at all, so there is nothing at a chokepoint with your name on it. That is what respecting the data, and the person who made it, actually looks like.
If you want a phone and a setup built to route around the bottlenecks instead of feeding them, email hello@spicycorp.com, or book a call.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Posts
- Your Phone, Laptop, and TV Are One Profile. Here’s How They Got Linked.
- Your Advertising ID Is a Tracking Number. Here’s How to Actually Kill It.
- Surveillance Capitalism in Plain English (You’re Not the Product, Your Future Is)
- Does iPhone Lockdown Mode Actually Work? (Yes, and Here’s Where It Stops.)
- Your Data Just Leaked. Here’s the First 48 Hours.
Recent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.