The account is half made. The app is already on your phone. And there, above the button that lets you in, sits a gray link that says Privacy Policy — nine thousand words you're supposed to have read, standing between you and dinner.
Here's an admission: we've tapped "agree" unread too, more times than we'd like to count. The realistic alternative to an hour of dutiful reading was never an hour of dutiful reading. It was zero minutes.
So the advice isn't "read the policy." It's this: don't read it — interrogate it. A privacy policy has a small number of load-bearing sentences buried in a large number of defensible ones, and the fastest way to the load-bearing ones is not to start at the top. It's to search. Eight terms, in order, about ten minutes. You'll finish knowing more than a linear skim would have taught you in an hour.
Reading it straight through is playing their game
A privacy policy has two jobs, and only one of them is informing you. The other is protecting the company that published it. Nobody has to be a villain for the second job to win. The document gets drafted by people whose professional duty is to make sure nothing the company might ever do is missing from it, so every possible use gets a clause, every category gets a "such as," and the prose swells to cover the future. The sentence that actually decides what happens to your journal entries ends up sixteen paragraphs deep, dressed exactly like the sentence about cookies.
That's what "written to be defensible, not readable" means in practice. Not deception — coverage. But the effect on a linear reader is the same either way: by paragraph thirty your attention is spent, everything sounds like everything else, and the one sentence you needed slides past unmarked.
Searching flips the economics. The company had lawyers and unlimited words; you have find-in-page and a short list. That's a fairer fight than it sounds, because a policy that does things with your data has to use certain words to do them defensibly. Those words are searchable.
The protocol: setup
Open the policy in a real browser, not the in-app viewer, because you want find-in-page: Ctrl-F on a keyboard, Cmd-F on a Mac, "Find in page" from the menu in most phone browsers. Then run the eight searches below, in order, and read every sentence that contains a hit — the sentence, not the section. If a hit confuses you, widen to its paragraph and stop there.
Two rules while you go. First, silence is a result. What a policy declines to say is a finding, not a blank, so note the terms that return nothing. Second, you're collecting, not verdict-making. Judge at the end, when the eight results sit next to each other.
Searches one through four: how long, and who else
1. "retain." This finds the retention language. A good hit has a number and a trigger — a stated period, tied to an event like closing your account. "As long as necessary for business purposes" is a hit that behaves like silence: a duration with no clock. Before you call it silence, run the plainer clothes this term wears — “keep” and “storage” carry the same commitments. True silence means no retention commitment exists anywhere in the document, and your working assumption becomes indefinitely, because nothing on the page says otherwise.
2. "third." This finds third parties. A good hit tells you who and why: named categories of recipients — payment processors, analytics providers — each attached to a purpose. "Trusted partners" is a who without a why. Silence here isn't cause for celebration yet, because sharing can live under other vocabulary; run "partner" and "service provider" as follow-ups before you conclude that nothing leaves the building.
3. "affiliate." The corporate-family word. A hit means your data can move to parent and sibling companies, and the family can change: an acquisition rewrites who counts as an affiliate without rewriting the sentence. Good looks like affiliates explicitly bound by the same policy you're reading. Silence suggests sharing stops at the company itself — worth confirming, since "we never sell your data" can coexist comfortably with free movement inside a corporate group.
4. "train." The AI-era search. Read any hit twice. You're looking for whether your content — not just your usage patterns — can be used to train models, and whether that's something you consent to, can refuse, or merely get to learn about. Good looks like a plain statement that your content is not used for training, or a genuine choice offered before it happens. Silence, in a product with AI features anywhere in it, is not reassurance; it may only mean the policy predates the feature. Either way it's a question for the company, not an answer from the document.
Searches five through eight: what they do with it, and how you leave
5. "aggregate." The contractual point of aggregating data is that promises about "personal" data stop applying to it. A hit tells you the concept is in play: check what the policy permits itself to do with the aggregated version, and whether it says anything about not re-identifying it. Good looks like a description of how de-identification works, or a commitment not to reverse it. On silence, search "anonym" before concluding the concept is absent — it catches "anonymized" and "anonymous," where the same idea can hide under a different flag.
6. "sell." The blunt one. On a hit, read the whole sentence, because "we do not sell your personal information" is good news with narrow edges: selling is one way data leaves a company, and sharing for "advertising purposes" is another that the no-sale sentence doesn't touch. Silence is worth noticing. That sentence costs nothing to write if it's true.
7. "delete." Two different things hide under this word: your right to request deletion, and their practice when you do. Good looks like both — a way to ask that doesn't require a lawyer, plus a statement of what's actually removed, with the survivors named specifically (backups on a rotation, records they must keep). A policy that offers deletion only "where required by law" has told you the floor is whatever law applies to you; your local law may add rights beyond what any policy volunteers, and figuring out which ones is a separate errand from these ten minutes. Check “eras” too — erasure is the same promise in formal dress. Silence on both means leaving and being forgotten are two different requests, and only one of them has a button.
8. "export." Can you take a copy with you? Good looks like a self-serve export in a format a machine can read, described as a feature rather than conceded as a support process. Try “portab” and “download” before calling it silence — portability is this promise's legal name. True silence means no commitment exists: you can still ask, but anything you receive is goodwill, and goodwill is not a policy.
The two sentences that matter more than the rest
If the ten minutes ever shrink to two, spend them on the retention sentence and the deletion sentence. Everything else in a policy describes the relationship while it's working. These two describe whether it can end.
Hold them both to one test: could you catch a violation? A retention sentence with a number and a trigger is checkable — there's a date after which keeping your data breaks the promise. A deletion sentence that names what's removed and what survives is checkable the same way. "As long as necessary" and "we may retain certain information" are not, because no state of the world contradicts them.
A useful exercise: rewrite each of the two in your own words, as a promise. They delete my content within ___ of my account closing, except ___. If you can't fill the blanks from the text in front of you, that isn't your reading comprehension failing. That's the finding.
Putting the eight results together
You promised yourself you'd judge at the end. Here's how, and it takes one minute of the ten.
Sort your eight results into three piles. Checkable commitments — sentences with numbers, triggers, named categories, real choices. Vague hits — the term shows up, but inside language that no state of the world can contradict. Silences. Then weigh the piles against what you're about to hand over, because the same results mean different things for different data. A weather app with a mushy retention clause is a shrug. A journal, a health tracker, anything that will hold what you wouldn't read aloud — there, a vague "delete" and a silent "export" mean the exit hasn't been built, and you'd be moving in anyway.
One pattern deserves its own name: when the terms about taking your data ("third," "affiliate," "aggregate") return long, careful hits while the terms about returning it ("delete," "export") return vagueness or nothing. That asymmetry is the document telling you which direction the pipes were built to flow. It isn't proof of bad faith. It's just the clearest thing ten minutes can show you, and it's exactly the kind of thing an hour of linear reading tends to blur.
What a policy can't tell you
Now the honest boundary. A privacy policy is a statement of intent, and there are things a statement of intent cannot tell you no matter how carefully you search it. It can't tell you whether the company enforces its own rules internally, or whether any engineer with a laptop can read what you wrote last night. It can't tell you whether there's been a breach, or how the company behaved in the days after one. And it can't tell you what its promises are worth under the pressures that rewrite promises — an acquisition, a bankruptcy, a pivot. Those answers live in how a company behaves over time, and no document, however honestly drafted, can hand them over in advance. Ten minutes of searching finds red flags, not guarantees; the best result this protocol can return is "nothing alarming," and "nothing alarming" is not the same sentence as "safe."
None of that is a reason to skip the ten minutes. A document that fails a test this quick has told you something valuable early, while leaving is still free.
When the searches turn up questions instead of answers
Some searches end in a shrug: silence on training, a retention clause with no clock, a deletion promise with no specifics. That's your cue to stop reading and start asking, because a company's response to a direct question is a kind of evidence the document can't contain. Earlier in this series we published seven questions to ask any wellness app about your data — the escalation path for exactly this moment. Your search results tell you which of the seven to lead with, and the manner of the reply (specific and prompt, or vague and slow) is itself an answer.
Ten minutes, honestly spent
Eight searches. Maybe thirty sentences read closely, instead of nine thousand words read glazed. At the end you know how long they keep what you give them, who else can see it, whether it teaches their models, and whether leaving is a feature or a favor — which is most of what "informed" was supposed to mean in "informed consent."
If you'd like to point this kind of scrutiny at us, we'd welcome it: our answers live on the trust page, where we'd rather be interrogated than taken on faith.
—
This post describes a reading method. It's educational content, not legal advice.