← All articles

The person's data

Your card number is on your phone, not in their database

Every company promises to protect the data you give them. This is a different promise: not giving it to them at all.

Manah Khalil/

Read enough privacy notices and you notice they all make the same promise. We take your data seriously. We encrypt it. We restrict who can see it. We will tell you if something goes wrong.

Every one of those sentences assumes the same thing, which is that they have your data. The promise is about how carefully they hold it.

There is a different promise available, and it is stranger and simpler: they do not hold it. Your card number, your address, your account details sit on your phone. When something needs one, you are asked, on your own device, and you decide.

What that looks like in practice

Software you use, at work or as a customer, sometimes needs a piece of your information to finish what it is doing. Today it gets that by having stored it earlier, in a database you cannot see, retained for a period you did not choose.

Instead: at the moment it is needed, the request reaches your phone. You see what is being asked and who is asking. You provide it, or you refuse.

Squidder is what sits between the two, so the request travels to you instead of a copy of your details travelling to them.

And then the part that makes this useful rather than exhausting: you decide how widely that answer may be reused. Just this once. Just with this company. Just for this purpose. Or, if it suits you, everywhere in your organisation until you change your mind.

Because if you were asked afresh every single time, you would stop reading the prompts within a week, and a control people stop reading is not a control. Reuse is what makes it a wallet rather than an interrogation.

The difference from what you have now

Nothing is stored where you cannot reach it. Your details are not in a system whose retention policy you have never read; they are on a device in your pocket. Refusing is a normal thing to do — not a support ticket, not an account deletion, just a no to this one request while everything else carries on. And when a value does leave, it leaves for one job: it is used for that action rather than becoming a row in a database, waiting for the next breach notification to make it interesting.

Different information can behave differently, too. Something highly sensitive can be kept for minutes and something routine for longer, and those limits are set once and apply without you having to remember them. What you have given, to whom, and how widely it may be reused is in one place, and you can change your mind there.

Why this is hard, and where it is honest

The convenience has to be real or nobody uses it. Any system that asks people to approve things has to be fast and legible or it gets ignored. That is a design problem, not a security one, and it is the part most attempts get wrong.

Someone still has to be the operator. An organisation sets which information can be requested, by which software, and how long each kind may be kept. You are not on your own, and you are also not in charge of everything. That is the right division and it should be stated rather than glossed.

A phone can be lost. So enrolment, replacement and revocation matter as much as the clever part. Any honest version of this promise includes what happens on the worst day.

It does not fix everything. Information you have already given to a company is still with that company. This changes what happens from here.

Why it is worth doing anyway

Because the current arrangement has an obvious failure mode and we have all seen it run many times. A company collects more than it needs, holds it longer than it should, and eventually publishes it by accident. Then it apologises, offers credit monitoring, and the data stays out forever.

The most reliable protection against that is the oldest one available: do not have the data. Every other control is an attempt to be careful with something that could have stayed where it was.

Your card number is on your phone. That is the whole idea, and it is the only one on this page.