Privacy and telemetry: what I turn off, and what I leave alone
Every privacy toggle costs you something, even if the cost is invisible on day one. Here is where I draw the line on my own machines.
The honest framing
Turning off Windows telemetry does not make you invisible, and any page that implies otherwise is selling something. Your browser, your router, your phone in your pocket and the services you sign into all collect far more than the operating system does. What these settings do is reduce the amount of data your desktop sends about how you use it, and remove a handful of surfaces where the operating system advertises to you.
That is a modest, real benefit. I treat it as tidying rather than defence.
What I turn off on every machine
- Advertising ID. A per-user identifier apps can use to correlate you across experiences. Turning it off costs nothing I have ever noticed.
- Tailored experiences and suggested content. This is the machinery behind app suggestions in Start, tips in Settings and the occasional full-screen "finish setting up your device" prompt.
- Activity history sent to Microsoft. Local timeline features are largely gone anyway; the upload is the part I decline.
- Optional diagnostic data. Reduced to the required minimum. Required diagnostic data cannot be fully disabled on consumer editions, and claims to the contrary usually rely on breaking something.
- The feed, widgets and lock-screen "fun facts". Not privacy exactly, but the same family of noise.
What depends on the machine
| Setting | What you give up | My call |
|---|---|---|
| Location services | Weather by city, Find my device, some map and camera features | Off on desktop, on for laptops that travel |
| Speech and inking personalization | Dictation accuracy improves over time | Off unless you dictate daily |
| App diagnostic access | A few troubleshooting tools stop working | Off |
| Cloud clipboard sync | Copy on one device, paste on another | On for my work laptop only |
| Search highlights / web results in Start | Web answers from the Start menu | Off everywhere, immediately |
What I leave alone
Some things get bundled into "privacy" lists that are really security features wearing a different hat.
Don't disable these in the name of privacy
SmartScreen reputation checks, Windows Security's cloud-delivered protection, and certificate revocation checking all involve a network call, which is why they show up in aggressive scripts. They are also load-bearing. If you disable them, do it because you have a specific replacement in mind, not because a list told you to.
I also leave Windows Update's ability to receive security patches intact. Deferring feature updates is reasonable. Blocking security updates is how a tidy machine becomes an unsafe one.
How to verify anything actually changed
A toggle flipping in an interface proves the interface flipped. Verify at the source.
- Turn on the technical-details view so each setting shows its registry path and current value.
- Spot-check two or three paths in Registry Editor after a restart. Values that revert are a signal: something — group policy, a management agent, or a feature update — is overriding you.
- Re-check after every feature update. Major Windows updates routinely reset a subset of these, and re-importing a saved configuration is far faster than re-walking the list.
That last point is the practical argument for keeping a configuration file rather than a memory of what you clicked. It turns "did that survive the update?" into a two-minute answer.
Written on my own hardware, with my own money, on my own time. Nobody paid for a mention here. If a page ever does contain a paid placement or an affiliate link, it will say so at the top — see the disclaimer.