Onyx Digital Intelligence.

Your privacy depends on your postcode

This is a piece I have wanted to publish for a long time. I have always had a special place in my heart for this kind of forensic work. As a South African researcher, the recent wave of social media policy changes gave me a reason to dig deeper. Mastodon's policy update, discussed later in this article, became the catalyst.

I hope you enjoy reading it as much as I enjoyed researching and writing it.

Let's walk the yellow brick road together shall we?

Lets start with the thing nobody is telling you

On 16 December 2025, Meta began using your conversations with Meta AI, voice and text, across Facebook, Instagram, Messenger and WhatsApp, to personalise the ads and content you see.

There is no opt out. Meta confirmed that directly. You can adjust ad preferences. You cannot stop the collection.

Three jurisdictions were carved out of the rollout: the United Kingdom, the European Union, and South Korea.

South Africa was not one of them.

That single fact does more work than any list of toggles, because it tells you what the toggles actually are. They are not privacy controls. They are compliance artefacts, and they appear where a regulator can compel them. Where nobody can, you get a default instead.

And we have already been on the wrong side of this exact line. In September 2024 the Information Regulator of South Africa issued an enforcement notice to WhatsApp after a preliminary finding that it applied one set of terms and privacy policies to European users and a different set to everyone else, us included.

Same company. Same pattern. Fourteen months apart.


What is actually on by default

These are verified. Paths change between app versions, so check yours and screenshot it.

LinkedIn Screenshot_20260803_060907_LinkedIn

Setting: Data for Generative AI Improvement. On by default.

Settings, then Data privacy, then How LinkedIn uses your data, then Data for Generative AI Improvement.

While you are there, the second toggle is Social, Economic and Workplace Research. That one is separate.

Turning it off applies going forward only. Anything already in a training run stays there. LinkedIn also runs a separate objection form for AI models that do not generate content, which the toggle does not cover.

Snapchat ![Uploading Screenshot_20260803_014355_Snapchat.jpg...]

Setting: Allow use of Public Content. On by default.

Settings, then My Privacy and Data, then Generative AI Settings.

Snap's own help documentation is unusually clear about this. It covers what you post publicly, meaning Spotlight, Public Stories and Snap Map, and Snap states this may involve both automated and human review. Not an inference. Their words. Screenshot_20260803_012525_Settings

Also from their documentation: if you appear in public content someone else posted, opting out does not remove you from that.

X

Setting: Grok and Third-party Collaborators. Three boxes, all on by default. Screenshot_20260803_011828_X

Settings and privacy, then Privacy and safety, then Grok and Third-party Collaborators.

The three are training and fine-tuning on your public data and Grok interactions, personalisation, and conversation history. Most guides mention one. There are three, and there is a Delete conversation history button on the same screen.

The stronger lever is that a protected account is excluded from Grok training entirely. If you were going to lock down anyway, that does more than the checkboxes.

Adobe

Setting: Content analysis. On by default, for individual accounts.

account.adobe.com, then Privacy and personal data, then Content analysis.

Business, team, school and minor accounts are opted out automatically and will not show the toggle at all.

Read the Adobe section below before you repeat what you have heard about this one.

Samsung

This is the one almost nobody covers, and in this country it matters more than Adobe does.

Galaxy AI runs a hybrid model. Some features process locally, some go to Samsung's servers. Cloud processing is the default state. The switch is off until you turn it on. Screenshot_20260801_232624_Settings Screenshot_20260803_012525_Settings

Settings, then Galaxy AI, then Process data only on device.

Tap the setting name rather than the toggle and it shows you exactly which features survive the change. On newer hardware you keep most of them. On older hardware you lose more, including summarisation and generative photo edits.

Two things to be precise about. This toggle governs Samsung's own AI features only. If you use Gemini or ChatGPT on the same device, their processing is untouched. And on One UI 8.5 there is a separate item called Personal Data Intelligence, which drives Now Brief and Now Nudge, with its own control.


Opt-in, but engineered

Facebook camera roll cloud processing

This is the one almost every version of this article gets wrong, and it is worth getting right, because the error is expensive. Screenshot_20260803_023740_Facebook Screenshot_20260803_023815_Facebook

It is opt-in. Meta says so, repeatedly and on the record, including in its own newsroom announcement for the EU and UK rollout on 16 April 2026. Anyone who publishes "on by default" about this feature has handed Meta a documented rebuttal, and once a company can disprove one claim in a list, the rest of the list stops being read.

Here is the accurate version, which is worse.

The consent is collected inside a Stories flow. You are trying to post something. A prompt appears. You tap to continue doing the thing you were already doing. The pop-up states that media and facial features can be analysed by Meta AI.

That is not a hidden setting. It is a consent moment engineered to be resolved by reflex rather than by reading. The word for that is not default. It is design.

Path: Settings and Privacy, then Settings, then Preferences, then Camera roll sharing suggestions. There are two toggles. The first is basic suggestions using metadata. The second is the cloud processing one.

On training: Meta's position is that camera roll media uploaded by this feature is not used to improve its AI unless you publish the suggestion or edit it with Meta's AI tools. Do not claim otherwise. What you can accurately say is that when The Verge pressed Meta in June 2025, the company would only confirm it was not doing so currently, and declined to rule out future use.

On availability: this launched in the US and Canada, excluding Illinois and Texas, then reached the EU and UK in April 2026. Meta has said more countries follow. If the toggle is not on your phone yet, that is why, and it is not evidence the feature is not real.


The claims that are wrong, and why I am spending words on them

Three claims dominate this topic. All three are false or overstated. Every time one of them circulates, the real findings above get harder to land, because the audience learns to discount the whole category.

"WhatsApp AI can now read your group chats unless you enable Advanced Chat Privacy."

False. This one has done enormous rounds, including from accounts that should know better.

WhatsApp's own help documentation states that Meta AI cannot access your chats and only reads messages people choose to send it, and that this holds whether Advanced Chat Privacy is on or off. The EFF and Snopes both examined it independently and reached the same conclusion.

Advanced Chat Privacy is real and worth using. It blocks chat export, blocks auto-download of media, and prevents Meta AI being invoked in that chat. It is per-chat, not global, and anyone in the chat can switch it off again.

But it is not the shield the viral post claims, because the threat the viral post describes does not exist.

The genuine WhatsApp concern is the ads change at the top of this article, and it applies to what you send Meta AI, not to your private messages.

"Adobe trains its generative AI on your files."

Overstated. Adobe's current content analysis documentation states plainly that it does not analyse your content to train generative AI models unless you submit content to Adobe Stock, and that Firefly was trained on licensed and public domain material.

Content analysis is real, it is on by default, and it feeds product improvement with limited human review under confidentiality conditions. That is worth turning off. It is not Firefly eating your portfolio.

"Google is silently building an index of your Gmail, contacts and media."

Overstated for the setting people usually mean. Personalise using shared data, under Settings, Google, All services, Privacy and security, is a list of sources with individual controls. Nothing is indexed until you permit that source. Google's own support page describes choosing which app data is used.

The legitimate concern in the Google stack is different. Workspace smart features are on by default outside the EEA, the UK, Switzerland and Japan. Two toggle layers, both worth checking. And note that geography split. It is the same shape as the Meta one.


The layer that actually holds

Every in-app toggle above sits inside an app that updates roughly every two weeks. Settings get renamed, moved, reset, or bundled into a new screen with a new default.

The operating system permission does not.

Android

Settings, then Apps, then the app, then Permissions.

Or go by permission instead of by app: Settings, then Security and privacy, then Permission manager.

For photos, choose limited access and select only what an app needs. Do the same pass over Camera, Microphone, Contacts and Location, then Physical activity and Nearby devices, which people skip.

iPhone

Settings, then Privacy and Security, then Photos.

Set apps to Limited rather than None. None sounds stronger and it is, but it breaks normal posting, so nobody keeps it, and a control nobody keeps is not a control.

The general rule: an app that needs your camera roll to post one photo does not need your camera roll. It needs one photo. Both operating systems have supported that distinction for years now.


The South African question

In October 2024 the South African Artificial Intelligence Association submitted a complaint to the Information Regulator over LinkedIn using South African personal information to train generative AI models. The complaint argued the processing failed the lawful processing conditions in Chapter 3 of POPIA and likely amounted to interference with personal information under section 73.

The Regulator confirmed receipt and said it was assessing the complaint.

There is no published outcome. So on 2 August 2026 I wrote to the Information Regulator and asked for one. Three questions. Was the complaint accepted, referred or closed. Was a decision communicated to the parties. Was any finding or enforcement notice issued.

If a reply comes, it goes here. If none comes, that goes here too, with the date.

The Regulator is itself a public body under PAIA, which means the same question can be asked with a statutory clock attached rather than as a courtesy. That is the next step if this one produces nothing.

The point is not that I expect an answer. It is that the question has been open for close to two years while the defaults kept expanding, and while three other jurisdictions got written into an exclusion list that we did not make.

You cannot toggle your way out of that. You can only know it.


The exception, and what it costs

One place is worth looking at before you decide the whole industry is the same.

On 31 July 2026, Mastodon emailed users of mastodon.social announcing new terms effective 31 August. Thirty-one days notice. Full document published in English and German. Drafting history public on GitHub. Community consultation held in October 2025. Lawyer named. The EFF and Cory Doctorow credited in the announcement.

Compare that to a pop-up while you are trying to post a Story.

Both are consent by continued use. Nobody at scale has invented another mechanism. The difference is that one of them gave you a month, a document you could actually read, and an exit that works.

Now the complication, and it has a deadline.

The terms in force until 31 August contain an explicit ban on scrapers, data mining tools and LLM training. The terms replacing them do not. There is no acceptable use section at all. I checked the Server Rules on the About page in case it had moved there. Six rules, none of them about scraping. The one rule that mentions AI runs the other way: it requires you to disclose generative AI use and bars accounts that only post AI output. It governs what AI puts in, not what AI takes out.

Mastodon says dedicated Service Rules arrive in December 2026. This may be deferral rather than retreat. Today nobody can say which.

But do not mourn it too hard, because it never did what people thought it did. That clause bound registered users. It said you may not run a scraper. A company that never opened an account was never party to it. It was a statement of values with no reach over the thing it was aimed at.

What Mastodon actually has instead is on the same About page, further down. A published list of every server it has limited or suspended, named, with the reason stated. Spam. Harassment. Hate speech. Misinformation. Third-party bots.

That works precisely because it is technical rather than contractual. Defederation does not require the other party to have agreed to anything.

Meta publishes enforcement statistics. X publishes almost nothing. Neither names who they acted against, or why. A small German operation with a handful of staff publishes the lot.

The new licence is blunt in the same direction. It says anything you upload can be pulled through RSS, embedded elsewhere, and indexed into search engines and databases, and that neither Mastodon nor you control that. It says that because the service is federated your posts will probably end up on other people's servers, and deleting them here does not delete them there. It even says that content you delete may survive in backups, and that if they restore from one, your deleted posts come back.

Which is the lesson from everything above. The clause was never the protection. The structure was.

And the structure has a tier in it. Under the new terms, consumers in the EU and EEA can only be sued in the courts of their own country, with their own consumer protections applying regardless of the choice of German law. Everyone else, us included, gets German law and German courts.

That is the most user-first operator in this space, drafting in public, with the EFF in the acknowledgements. And South Africa still lands in the second tier.

Not because anyone chose to exclude us. Because the protections that produce a first tier are written somewhere else, by someone else, for someone else.

That is the whole article in one clause.


Ten minutes, once a quarter

Not once. Once a quarter. App updates undo this work quietly and without notice.

  1. LinkedIn, Data for Generative AI Improvement, off. Research toggle, off.
  2. Snapchat, Generative AI Settings, Allow use of Public Content, off.
  3. X, Grok and Third-party Collaborators, all three boxes, off. Delete conversation history.
  4. Adobe, account.adobe.com, Content analysis, off.
  5. Samsung, Settings, Galaxy AI, Process data only on device, on.
  6. Facebook, Preferences, Camera roll sharing suggestions, both toggles off.
  7. OS permission sweep, photos to limited, then Camera, Microphone, Contacts, Location.

Screenshot each screen when you are done. In four months you will want to know whether it moved, and memory is not evidence.


Method

Tier A means verified against primary documentation or a direct on-the-record company statement. Everything in the on by default and no opt out sections is Tier A. So is every Mastodon claim, which comes from the published terms, the About page and the announcement post.

Tier B means credible but resting on user reports or inference. Claims that Meta camera roll toggles were found pre-enabled are Tier B, which is why they are not in this article as fact.

Tier C is speculation and does not get published.

Where I have found a popular claim to be overstated, I have said so even when the overstatement runs in the direction I would prefer. If something here turns out to be wrong, it gets corrected on this page rather than quietly amended, and the standard does not bend depending on which way the error points.


Sources


Clayton Bax

Published under ONYX Digital Intelligence following the #OnyxAudit methodology.

○𝕏: @onyxaudit ○Email:onyxdigitalintelligence85@protonmail.com ○https://github.com/Baximus855 ○@Onyx_Digital@mastodon.social

"Adjacent to true is not true."

Truth has no flag nor favour, only a standard. And it's heavy"

#ai #dark patterns #popia #privacy #south africa