I said the word “Rimowa” out loud at dinner, and three days later, an ad for Rimowa luggage appeared on my phone. I felt the chill. I own Rimowa. I was in Germany, where the brand is everywhere. The ad made perfect sense, and yet my first instinct was still: it heard me.
I’ve fielded this question from friends and family for years. My mom got knee-brace ads after mentioning her knee pain, which made sense because she’d had knee surgery and probably googled it. A friend got fish-tank ads after talking to his trainer, which made sense because they share contacts and he owns fish. Another friend, Michael, saw a Tourettes ad after we discussed a bartender’s tic in a bar. That one felt genuinely impossible to explain.
Everyone has a version of this story. You talk about something, and then the ad arrives. It feels like proof. But the evidence says something else entirely: your phone isn’t secretly recording you for advertising.
The feeling is real, but the culprit isn’t a hidden microphone. It’s the data-broker industry, ad modeling, and cognitive biases that make coincidence feel like surveillance.
Key Takeaways
No secret microphone exists for ad targeting: a Northeastern University study of 9,100 Android apps found no surreptitious audio recording, and a 2020 experiment played 134 hours of TV audio at smart speakers and found no continuous recording.
Ads feel psychic because of data, not eavesdropping: platforms track in-app behavior, advertisers match hashed customer lists, and household or co-location signals can put you in the same target bucket as someone you talked to.
The real privacy threat is the data-broker industry. Location data bought from brokers has revealed visits to sensitive places, and the FTC has sued over it. The microphone is only listening for a wake word.
Table of Contents
The stories that started the myth
The anecdotes are everywhere. A woman talks about something and sees it on TikTok 30 minutes later. A visitor to New York gets an Instagram reel full of New York content. Someone mentions a food, and an app shows it immediately. They all feed the same feeling: the phone is listening.
My own orbit is full of these stories. The fish-tank friend, the knee-brace mom, the Rimowa moment. And then there’s the Tourettes ad, the one that feels most damning. Michael and I were in a bar in LA, late at night, scrolling.
We discussed the bartender’s tic. A day later, an ad for Tourettes awareness appeared on his iPhone. His voice dropped into a tone I rarely hear outside ghost stories.
Even as I say it, I know how razor-thin the reassurance sounds. He signs the receipt, pockets the phone and mutters, “I’m positive that no one will believe me!”
But here’s the thing: these stories are the phenomenon to explain, not the proof. They’re the weakest evidence imaginable, and they’re exactly what the rest of this piece dismantles.
What the evidence actually says
Let’s start with the guy who’s seen the ad machine from the inside. Ari Paparo founded Beeswax DSP, which was acquired by Comcast’s FreeWheel, and led product at AppNexus and DoubleClick. He says 100% of his colleagues agree the phone is not listening. That’s not a casual opinion; it’s the consensus of people who know where the money flows.

The technical argument is simple math. Processing constant ambient audio from billions of phones would be a data firehose that drowns any ad network. It’s not that they wouldn’t want to; it’s that they literally can’t.
Then there’s the empirical testing. David Choffnes led a Northeastern University study that examined 9,100 Android apps and found no surreptitious audio recording. The unexpected finding was screen recordings and image or video uploads to third-party servers. Technically creepy, but not microphone surveillance.
Choffnes also built a fake apartment full of smart devices, cameras, and speakers, rigged to catch devices sending data where they shouldn’t. Nothing did.
He co-authored a 2020 experiment that played 134 hours of TV audio at smart speakers. The result: no 24/7 recording, only occasional false wakes lasting a few seconds. When a device did wake, it typically sent a short clip to the company’s cloud servers. That’s a real data flow, and it’s worth knowing about. But as Choffnes put it, “This was mostly reassuring: we found no evidence of constant recording, just short, triggered clips when a device thought it heard the wake word.”
His bottom line: “For the most part, most consumers shouldn’t be concerned about pervasive listening.”
Serge Egelman, research director at the Berkeley-affiliated ICSI and co-founder of AppCensus, makes the practical argument. A true always-on hot mic would leave fingerprints: battery drain, data usage on phone bills, status-bar indicators. Your phone would be constantly streaming audio… battery would not last very long.
There’s also the legal exposure. The Wiretap Act prohibits intercepting conversations without consent, and many states, like California, require all parties to consent. Covert continuous capture would invite massive legal exposure. It’s not just unethical; it’s illegal in most places.
CNET ran an informal 2019 experiment and found no indication Facebook was listening in on conversations to trigger ads. It’s one media outlet’s test, not definitive proof. But it’s another data point in the heap.
The verdict is a convergence, not a smoking gun. No single test is conclusive. But after years of scrutiny, no one has found the smoking gun. If it were real, someone would have caught it by now.
How ads actually reach you
So if it’s not the microphone, what is it? Let’s walk through the actual trail of that Tourettes ad, because it explains everything.
The likely path starts with Michael’s in-app behavior: past donations, an affinity for mental-health content, and the context of late night in LA while scrolling. The advertiser brought a matched list, a donor or mailing list hashed against platform accounts, and built a lookalike audience from it. A data broker may have added health-interest groups. And co-location signals, both of us on the same network, nudged us both into the same target bucket.
That’s the pipeline. Four players make it work:
- Platforms like Instagram, YouTube, Facebook, and TikTok watch what you do in-app: follows, lingers, saves, searches, taps. They run the auction.
- Advertisers bring goals, budgets, creative, and customer lists. They don’t know your name or address; they know the categories you fit into.
- Identity providers link records across devices without handing names around. They keep identity graphs that say “these devices likely belong to the same person or household.”
- Data brokers like LiveRamp, Acxiom, and TransUnion buy, scrape, and package information, mostly out of sight. They pull from apps, websites, and store loyalty programs and ship ready-made audiences or labels. Privacy policies often call the data “de-identified.”
The machinery works like this. Advertisers scramble emails and phone numbers to match against platform accounts. Hashing is not anonymity; matches are still possible. Then the platform runs an instant auction to decide which ad to show, ranking by price, predicted response, and ad quality.
The model predicts what you’re likely to do next. If it thinks you’re very likely to act, a cheaper ad can win over a pricier one.
Household and proximity signals matter. If you and a friend share a Wi-Fi or household network, both of you may fall into the same target bucket. Being near a TV where a campaign just ran can raise the odds. That’s how the fish-tank ad reached my friend: shared contacts, a pet-owner friend, and a trainer connection.
Budget concentration also plays a role. Money concentrates where the model expects better results, so delivery clusters in time. An ad can simply land the same night a topic came up in conversation. That coincidence feels like surveillance.
Advertisers can set guardrails: city, ZIP, age, schedule windows, and they can exclude people who already bought. That explains the Rimowa ad’s eerie timing. I already own Rimowa and was in Germany. The ad was aimed at luggage shoppers in-country. It read my week, not my conversation.
Meta has a “Why am I seeing this ad?” control that surfaces some targeting reasons in-app. It’s not complete, but it’s a useful debugging tool. Meta’s stated position is that it only uses the microphone if you’ve explicitly given permission for a feature that uses it.
The scale is worth noting. About $1.1 trillion was spent on advertising in 2024. Meta pulled in $162 billion. Amazon’s ad business hit $15.7 billion in Q2 2025, up 22% year over year. That’s a lot of money chasing data.
Why it feels so real
The uncanniness isn’t just what’s in your phone. Your brain deceives you.

Remember the invisible gorilla? In the famous basketball study, people focused on counting passes and completely missed a person in a gorilla suit walking through the scene. That’s inattentional blindness: attention edits reality. You see what you’re looking for.
Most ads stream by, but the one aligned with top-of-mind pops out. You scrolled past the ads for an unrelated airline credit card and Japanese selvedge denim, but you noticed the trip to Cancun, because you just talked about going to Cancun to your best friend.
There’s a name for this. The frequency illusion, also known as the Baader-Meinhof phenomenon, causes people to notice things they’ve recently learned about. Once you’re thinking about a car, you see it everywhere. The classic example: buy a 1986 Mercedes-Benz 560SL and suddenly they’re all over the road.
Confirmation bias does the rest. You remember the eerie hit, the ad that appears right after the conversation, but you discard the thousands of misses before that. The self-fulfilling story writes itself: we said it, then saw it, therefore the phone listened.
The availability heuristic makes vivid examples feel more common than they are. And illusory correlation makes you assume two things that happen together are linked. The memorable collision makes you believe the events are connected.
With the sheer volume of data signals, conversations, searches, locations, purchases, and the household’s shared devices, collisions are inevitable. Egelman puts it neatly: What is happening is targeted advertising, and some of it is cognitive biases.
He also points out the cognitive dissonance: “People complain Alexa or Siri don’t understand them, yet believe they can perfectly overhear conversations to target ads.”
That latter belief is the exact subject of our analysis of
Does your phone listen for ads?The myth endures because it’s flattering. It makes our lives feel like the center of someone’s attention, rather than nodes in a statistical model.
When your phone actually listens
Here’s the honest caveat: your phone is listening. But only for a wake word, on-device, with nothing sent until triggered.

Apple’s “Hey Siri” runs a lightweight recognizer that wakes the full system only on the trigger phrase. Google Assistant keeps a few seconds of audio in a local buffer to detect the trigger. If there’s no trigger, nothing is sent or saved. By default, audio recordings aren’t saved to your account. Smart speakers work the same way: they listen for the wake word locally, and nothing is sent until activation.
Amazon says Echo devices detect the wake word locally and don’t store or send audio unless activated. Wake-word engines exist to launch a helper, not to feed ads. Apple and Google both formally state they don’t use assistant audio for ad personalization. Apple says it has never used Siri data for marketing profiles or advertising.
There’s a real caveat: false triggers happen. An occasional wake sends a short clip before canceling, and short clips can sit on vendor servers. Some platforms let you review or delete them. Amazon lets you review and delete voice history, and you can opt out of ad personalization with Alexa.
The incidents that made the myth credible happened in 2019. An Apple contractor revealed workers regularly listened to audio recordings, sometimes including drug deals or sex, as part of a “grading process” to improve Siri recognition. Apple apologized, paused the program, later made it opt-in, and agreed to a 2025 settlement while denying wrongdoing. A Belgian broadcaster revealed Google contractors could hear snippets of Assistant recordings.
Reporting showed Amazon teams listened to some recordings. Facebook paid contractors to transcribe snippets of opt-in voice chats.
And then there was Cox Media Group’s “Active Listening” pitch deck, which touted an ad product targeting ads based on ambient audio. Google dropped CMG from its partner program after coverage. CMG later said the product was discontinued and denied using device microphones.
These were human-review and quality-control failures, not ad surveillance. But they were vivid and mishandled enough to make “always listening” still feel plausible today.
Can the phone listen when it’s off? No. Off means no power, no cell connection, no processing. The mic is hardware that requires power and software state. It’s not magic.
The real privacy threat
I’m not worried about my phone listening in, but something else disturbs me. It’s the shadow I leave behind on the internet.
Eva Galperin, director of cybersecurity for the Electronic Frontier Foundation, puts it plainly: the culprit isn’t a hidden microphone, it’s the data-broker industry. In reality, devices are tracking you in other ways.
The most chilling illustration came in 2021. A Catholic official resigned after his dating-app location data, purchased from a data broker, showed he’d frequented a gay bar and used Grindr. The broker never intended that data to be sensitive. It was used to ruin someone anyway, demonstrating how so-called anonymous trails can be tied back to a real person.
Regulators have warned that location trails can reveal visits to reproductive-health clinics, places of worship, shelters, and recovery centers. That data is bought and sold.
Government access is a side door. ACLU-obtained records showed DHS components, including CBP and ICE, purchased phone location records from data brokers. The Supreme Court’s Carpenter ruling made warrantless cell-site tracking harder for law enforcement, but the commercial data market remains. Location brokers have marketed their data to government and military buyers, with companies like Babel Street and X-Mode surfacing in reporting, and the military purchases were justified on counter-terrorism grounds.
Everything you do, clicks, searches, locations, purchases, is stitched into a ghost profile that follows you. Once assembled, it’s portable and resold. You didn’t consent to the assembly.
These profiles that serve ads can also shape prices and eligibility. The FTC sued Kochava over selling location data that could identify people in sensitive places. The FTC forced Meta to overhaul its housing-ad targeting over algorithmic discrimination. Regulators have flagged the same risks in employment and credit contexts.
There’s a distinction worth making. Legitimate spyware planted on a device is a real, separate category of threat. It’s a targeted compromise, not the consumer ad pipeline. Conflating the two is how the myth gets weaponized.
How tracking evolved
Cookies started as a convenience. They kept you logged in, held your shopping cart, remembered your language preference. First-party cookies were the good guys.

Then third-party cookies and tracking pixels spread across the web, letting a single network recognize the same browser everywhere. That was the tracking engine. At their peak, third-party cookies sat in more than 80% of web traffic, gathering your searches, the sites you visited, your history.
Regulators moved. GDPR forced explicit consent, which is why you see cookie pop-ups everywhere. Then browsers began phasing out third-party cookies entirely, forcing the industry onto first-party data and consent-driven strategies. The industry’s own attention metric tightened. Google Analytics 4 switched from bounce rate to engagement rate, counted only for sessions lasting more than 10 seconds.
Apps don’t use browser cookies at all. Platforms switched to mobile ad IDs and logged-in universes. Your identity inside the app is the tracking anchor. And a new player emerged: retail media, which ties ads to actual receipts.
Retailers know precisely what you bought and can target on that without ever passing identities around. It’s a powerful workaround.
The industry traded IDs for inference: scores, cohorts, household context, predictive models. Measurement shifted from identity to intent. The tools are now generative. Meta’s Advantage Plus suite generates ad creative. For marketers, this AI-based technology is essential for achieving personalisation at scale.
Google’s Performance Max generates headlines, descriptions, and image or video variants. Amazon’s ad tools turn product photos into lifestyle scenes.
The model in action: a predictive score deciding what you’ll do next. A system scoring “likelihood to donate tonight: 0.62.” The ads feel psychic not because they hear you, but because they can score you better than you expect. Every time the industry loses one tracking mechanism, it builds a better inferential one. None of it needs a microphone.
What actually works
You can’t opt out of the ad economy entirely, but you can meaningfully reduce exposure. Start with the two most direct answers to the myth: turn off the assistant’s mic access and audit which apps have microphone permission.
Assistant controls:
- On iPhone X or newer: Settings ? Accessibility ? Side Button ? set “Press and Hold to Speak” to Off. This disables Siri and the classic voice-initiation control.
- On iPhone 8 or earlier: Settings
- Accessibility
- Home Button
- the same Off setting.
- iPhone microphone permissions: Settings
- Privacy & Security
- Microphone
- toggle per app.
- On a Pixel: Settings
- Search, Assistant and Voice
- toggle “Hey Google” and “While driving.”
- On other Android phones, the exact labels may differ, but the pattern is the same: Settings, find the app, open Permissions, deny the mic. Look for the app-permissions screen rather than hunting for a universal switch.
Browser and app privacy:
Galperin endorses tracker blockers: uBlock Origin plus EFF’s Privacy Badger. Check what your phone already reports. iPhone’s App Privacy Report lives in Settings ? Privacy & Security. Android’s Privacy Dashboard shows timestamped mic, camera, and location use. Do a quick permission audit every few months: revoke mic and camera for anything that doesn’t need them, and delete apps you don’t use. Fewer apps means fewer data collections.
Location discipline:
Galperin’s top recommendation is to turn off location services unless you genuinely need them. When you do grant access, prefer “While Using the App” and, where possible, “Approximate” rather than “Precise.”
Reduce the data diet:
Give apps the minimum access they need. Skip “contact upload” and “Find Friends” prompts. Avoid using one identity or sign-in across everything; compartmentalizing fragments the profile. Use dedicated email aliases for newsletters and loyalty programs so those profiles don’t fuse with your main identity.
Know what they hold and clear what you can:
- Choffnes’s advice: only install and use the apps you actually need, and when you do use them, enter as little data as possible. The Instagram example is instructive. The account’s own data export, in profile menu
- Accounts Center
- Your information and permissions, includes activity Meta tracked outside the app: online purchases and info you submitted to advertisers, plus categories like “engaged shopper,” “household income,” and “travel plans.” Seeing it is a shock. It’s the clearest proof of who they think you are.
Data-removal services like Easy Opt Out and Optery file opt-out requests on your behalf across brokers. The honest caveat: brokers constantly refresh their data, so this is not a one-time fix. Galperin calls it a constant cat-and-mouse. It reduces exposure; it doesn’t erase the industry.
General security hygiene helps here too: use trusted antivirus, like Avira’s free Android scanner which includes camera and mic protection, or Avira’s iOS app with a VPN and protection features. Only install from official stores, use a VPN on unsecured networks, and keep the OS updated.
Delete stored voice recordings. Use long unique passwords plus two-factor authentication.
Why individual effort isn’t enough
Here’s the structural problem. No one even knows how many data brokers exist in the US. Estimates run into the thousands. California maintains a public registry where you can start seeing who’s out there. The industry’s size is itself the problem.
An individual can audit permissions and file opt-outs, but the industry collects on every side of your life: the broker who bought your loyalty-program data, the retailer who knows your receipts, the app that logged your location. You are never at just one site. You’re a profile assembled across hundreds.
Data-subject access requests exist. They can return hundreds of pages, and they prove the industry’s reach. But as Choffnes’s own request showed, the data is also riddled with errors. His 300-page report claimed he owned an Xbox and was planning a cruise. Neither was true.
The system that scores you doesn’t even need to get your specifics right. The statistical model works on the aggregate of what it holds.
The meaningful answers are structural. Choffnes’s call is to push lawmakers for consumer-favorable rules, because individual vigilance cannot match an industry built on assemblage. Christo Wilson, who also worked on the 2018 study, puts it bluntly:
No individual can win against an ecosystem built to surveil you.
The enforcement actions exist. The FTC’s suit against Kochava. The FTC forcing Meta to overhaul housing ads. Regulators flagging employment and credit risks. They prove regulators can act. They’re still the exception, not the floor.
The myth says the industry is secretly listening to your conversations. The reality is more unsettling: it doesn’t need to hear you, because it has assembled a model of you that is often wrong and still powerful. That’s what deserves your attention and your lawmakers’ attention. That’s where the fight actually is.
Frequently Asked Questions
How do ads know what I’m talking about?
Ads reach you through a pipeline of data: platforms track your in-app behavior, advertisers use hashed customer lists and lookalike audiences, and data brokers add interest categories. Co-location signals, like sharing a Wi-Fi network, can also put you in the same target bucket as someone you talk to. This makes ads feel psychic without needing a microphone.
Why do I see ads for things I just mentioned?
This is the frequency illusion, also known as the Baader-Meinhof phenomenon, combined with confirmation bias. You notice ads that match recent conversations and forget the many that don’t. With the sheer volume of data signals and targeted advertising, coincidental collisions are inevitable, making it feel like surveillance.
What is the real privacy threat if it’s not the microphone?
The real threat is the data-broker industry, which buys, scrapes, and packages your location data, purchase history, and online activity into detailed profiles. This data can reveal sensitive information like visits to clinics or places of worship, and it’s sold to advertisers and even government agencies, often without your meaningful consent.
