Data Security for Travelers, Privacy, and Nosy Apps
Would you willingly hand over all your credit cards to a stranger and let them take photos of them? Would you let a stranger read all your e-mails, your search history, and your conversations with an AI tool? Would you give them access to your bank account?
Unfortunately, if you’re not paying attention to data security for travelers, you may be doing all that in a virtual way when you hit the road, with close to zero data privacy.

Considering these sentences I pulled from recent consumer news stories I was reading:
– The new version of Siri is getting rave reviews from tech publications because it is “much better at sifting through phone messages to find links and information buried in your text conversations and emails.”
– By default, OpenAI uses conversations, code, and documents submitted to ChatGPT to train and refine future foundation models. Many employees have accidentally leaked sensitive proprietary code, trade secrets, patient notes, or meeting summaries simply by pasting them into ChatGPT for summarization or debugging.
– Google uses automated parsers to construct an internal, detailed log of your purchases (digital receipts, deliveries, plane tickets, hotel stays) accessible in your Gmail account’s Payments & Subscriptions hub under the guise of “smart features.” It also paid a $391.5 million settlement because even when users turned off “location history” in their settings, Google continued harvesting precise GPS coordinates and Wi-Fi data through a separate, default-enabled setting called “Web & App Activity.”
– Meta feeds publicly shared posts, photos, comments, and captions across Facebook and Instagram into its generative AI training sets. In many jurisdictions outside the EU/UK, opting out is difficult or entirely unavailable.
Don’t those statements feel creepy? Or downright scary?
As a traveler using my phone and laptop constantly while on a variety of networks, I find that it’s harder to lock down what’s private than it used to be. I am having to work harder to keep both giant corporations and basement-dwelling hackers away from my conversations and data. I use AI as little as possible since the last thing I want to do is to give some nefarious robot with questionable guardrails access to my credit card numbers and list of contacts.
Sure, people have figured out that the price we pay to have free Facebook is to let the app listen to our conversations (and everything we write) so they can send us targeted advertising and earn billions. Most people now realize that we are the product they are selling via our attention and clicks. Some have quit the network over this. Others log out when they’re not using it and close the app — or even turn off their phone when discussing something sensitive.
But the other 98% take the easy default route that Meta wants them to take and their life is a very open book, updated hourly.
Protecting your data while traveling comes down to a handful of habits: avoiding risky networks and public equipment, locking down your accounts with strong authentication, and being careful what you type into apps that store or learn from your information. None of this requires becoming a security expert. It just means doing a few things on purpose instead of leaving them to chance.

Cybersecurity risks don’t take a vacation just because you did. Sensitive data becomes far more exposed the moment you step outside your normal routines, connect to networks you don’t control, and rely on devices you can’t easily replace mid-trip.
If you’re at all concerned about maintaining a shred of privacy and keeping identity theft at bay, here are a few suggestions that will keep you from having to swear off the latest tech altogether.
Your Voluntary Bot Training vs. Security
Did you know that every conversation you have with ChatGPT or Google Gemini is a small version of you teaching robots a master class? All those medical questions, info requests, and personal advice queries are recorded. They’re stored and used for training. Every time someone says “ChatGPT knows me better than my friends do,” without a trace of irony or fear in their voice, Sam Altman rubs his hands in glee like Mr. Burns of The Simpsons.
Travel-specific AI apps raise the stakes further, since they often combine chat history with real-time location and reservation details, making the information more sensitive than a typical chatbot conversation. These tools know where you are, where you’re going, and what you’re planning to do there.
On corporate earnings calls, Google, Facebook, Open AI, and others have made no secret of their desire to record anything and everything they can get their hands on to train their models and make them more human. Beyond the energy strain, water use, and job stealing you might be concerned about, these tools are also treating your private thoughts and fears as a currency to get rich off of.
If you want to turn to an AI assistant for answers, then you’re better off using Proton Lumo. It was built by the privacy-obsessed company behind Proton Mail, with a focus on not retaining or using your conversations to train its models. It’s a practical substitute for general AI searches when you’re dealing with anything personal or financial while traveling, without giving up the convenience of AI-assisted answers entirely. Here’s how they explain it:
“All conversations with Lumo are stored with zero-access encryption, so no one (not even Proton) can access them.”
Sure, that’s a little harder than opening the ChatGPT app or using Google’s AI answers that they’ve force on us whether we want them or not, but most security steps are more difficult for a reason. If you just take the easy route, it’s easy because you’re giving up something. If you want better privacy, you have to be active instead of passive.
Limit the Personal Info Collection From Apps

The apps you use to plan and document a trip can quietly collect more than you realize, and some of it sticks around longer than you’d expect. Knowing what Google, Facebook, and Amazon actually retain when you’re logged in, and choosing more private tools for sensitive questions, closes a gap that most travel security advice skips entirely.
Also understand that “going live” while traveling is broadcasting not only where you are, but where you are not — at your empty house. Scheduling posts in advance, disabling geotagging, and tightening who can see your content lets you document a trip without advertising your location live.
Google’s account activity and location history settings can also reveal more than intended if left on their defaults, so it’s worth reviewing them before a trip rather than assuming the defaults are private. “We work hard to protect your privacy” is never a statement you’re going to hear from Meta, Google, Facebook, or OpenAI.
Use a VPN on Public Networks
This should be obvious by now, but a surprising number of people will log into a public network at a hotel or airport and start filling in credit card information like they’re on their secure home network. Never mind that a hundred or more other people are on that same network — which may or may not be the legit one you wanted — and one of those people might be someone who makes a small fortune selling credit card info on the dark web.
Identity theft costs individual Americans somewhere between $10 billion and $16 billion per year and that’s just an estimate based on what is reported or surfaces in investigations. As anyone with an elderly parent who has gotten scammed knows, a lot of theft never gets officially reported. Most people wouldn’t even know who to turn to.
A virtual private network (VPN) adds encryption on top, scrambling your traffic so anyone else on the same network can’t easily see what you’re doing. There are plenty of VPN options out there and some of them are free (like in the Firefox browser now) or are bundled with other purchases like an eSIM plan.
This is cheap insurance though, so it’s worth paying for. The average traveler can get away with something simple like TunnelBear. To step it up, ones that companies use include NordVPN, Surfshark, and MullvadVPN.
Use this for something besides trying to fool a streaming service that you’re in another country or to try to shave $7 off a flight if you look like you’re buying it in Cyprus. Use it to keep your data safe and secure.

Fun fact: cellular networks are actually much more secure than Wi-Fi. So if you do have to make a purchase or share sensitive info while on the move, it’s better for your travel data security to do it from your phone rather than your laptop or tablet.
Then clear your cookies regularly! If you’re using Firefox you can set it to erase them when your browser is closed. With Google-owned Chrome though, they want to spy on you as much as possible and mine your data, so you’ll have to delete them manually there on a regular basis.
Use a Password Manager
Are you using the same password across multiple sites so you can remember it? Or do you have your passwords saved in your browser, where anyone getting access to your laptop can see them? Or in a spreadsheet somewhere?
With so many websites now demanding long and complicated log-ins, a password manager not only keeps you safe, it also gets that info out of your brain and into a stored system. Even if you have a different complicated string of numbers, letters, and symbols for every site, the password manager remembers everything and fills it in automatically.
I’ve been using LastPass on a family plan for more than a decade, but there are others out there like 1Password for instance. There are free plans, but it’s definitely worth paying for, especially if there are two or three of you that can go on one family plan. Also, with the single master password, a loved one can get into your accounts and take care of things without needing to know the specific passwords. Plus you can share access via the password manager with an assistant and he/she never sees your actual log-in information.

Harden Security Before You Depart
While you’re on your secure home network, get everything done that will make your laptop and phone more secure when you’re on the road, especially if you work remotely. Data security for travelers is mostly about making it harder for criminals to compromise your system.
- Set up a password manager if you don’t have one already.
- Update all your apps and software subscriptions to the latest versions.
- Review which apps have access to location services and turn off tracking for anything that doesn’t need it. You want the “only while using the app” setting for rideshare services, map programs, and others that need a location.
- Check that you have anti-virus software on your laptop that roots out malware and has a firewall.
- Set up credit card alerts if you want to be notified when a charge goes through.
- Create back-up systems you can restore from with Apple, Google, Dropbox, or other cloud services. Also upload photos of your passport, driver’s license, and other key documents in case your device is lost or stolen.
- Although it requires leaving location services on, “find my phone” settings will allow you to locate your device and wipe sensitive data remotely.
- If you don’t have it set up already, put fingerprint or facial recognition on your phone in addition to a pin number.
- Install Duck Duck Go and use it for searches instead of Google for more privacy and no saved cookies. You can even make it your default search engine on your phone; I’ve done that for years now.
- Delete apps you downloaded in the past but don’t use anymore. This meaningfully shrinks what’s exposed if any one app has a security issue down the line.

