Can you actually stay private online? The case for separate digital identities

Reusing the same email, phone number and card everywhere hands data brokers and criminals a ready-made profile. Compartmentalising your identity blunts that.

ThreatVectr Newsdesk· 4 min read
A computer screen displaying a warning message about data breach, in an office environment, with student loan documents scattered on a desk in the foreground
Share

Key points

  • Reusing one email, phone number and payment card across every site lets data brokers and criminals stitch together a full profile of a person's life.
  • Anonyome Labs argues that separate digital identities, each with their own contact details, reduce this correlation and limit fallout from breaches.
  • No US federal privacy law currently forces brokers to stop this linking; enforcement leans on state laws like the California Consumer Privacy Act.
  • Practical steps include email aliases, masked phone numbers and virtual payment cards, tools now offered by mainstream providers.
  • The approach lowers spam, phishing hits and identity theft risk, but does not make anyone invisible online.

Sign up for a shopping account with your real email. Book a dentist with the same address. Post on a forum with it. Buy a plane ticket. Within months, that single string of characters ties together your medical visits, your politics, your travel and your spending, and it sits in databases you have never heard of.

That is the problem a new explainer from privacy firm Anonyome Labs, first covered by BleepingComputer, sets out to describe. The pitch: stop giving every service the same identifiers, and the profile falls apart.

Why does reusing one email or phone number matter so much?

Because it is the glue. Data brokers, companies that buy and sell personal information, use shared identifiers to link records from different sources into one file on you. Give ten websites the same email, and a broker can merge ten separate slices of your life into a single dossier.

The same trick helps attackers. When a retailer gets breached and your email leaks, criminals try that email, and any password tied to it, against your bank, your streaming service and your work login. This is called credential stuffing: running stolen username and password pairs against other sites to see which ones open.

A phone number is worse. It rarely changes, it is tied to your carrier account, and it is often the fallback for resetting passwords.

What is a "digital identity" in this context?

A digital identity here means a bundle of contact details you use for one purpose only. One email, one phone number, sometimes one payment card, dedicated to shopping. A different bundle for social media. Another for medical and financial accounts.

If a shopping site is breached, the leak touches only the shopping bundle. Your bank login, tied to a different email the retailer never saw, stays clean.

Anonyome sells software that generates these bundles, but the underlying idea is not proprietary. Apple's Hide My Email, Google's email aliases, and virtual card numbers from banks and services like Privacy.com all do versions of the same thing.

Does the law help?

Only patchily. There is no single US federal privacy statute. The California Consumer Privacy Act, amended by the California Privacy Rights Act, gives Californians the right to ask businesses what personal information they hold and to demand deletion. Similar laws are now in force in Virginia, Colorado, Connecticut and a growing list of states.

In Europe, the General Data Protection Regulation (GDPR), the EU's 2018 privacy law, gives residents stronger deletion and access rights and has produced multi-million-euro fines against data brokers and ad-tech firms.

None of these regimes stop a company from collecting your email in the first place. They regulate what happens next.

Practical steps for a non-technical reader

Identifier Everyday tool What it does
Email Apple Hide My Email, Gmail aliases, Firefox Relay Generates a throwaway address that forwards to your real inbox
Phone number Google Voice, carrier secondary lines Gives you a second number for signups and deliveries
Payment card Bank virtual cards, Privacy.com Creates single-use or merchant-locked card numbers
Password Any reputable password manager Stops one leaked password unlocking other accounts

Start with the accounts that matter most: bank, primary email, work login. Give each a unique password and, where possible, a unique recovery email. Then work outwards to shopping and social accounts.

You will not become invisible. You will, however, become much harder to profile, and much less interesting to the next breach.

Common questions

Is using an email alias legal?

Yes. Aliases forward to your real address and do not involve impersonation. Some services ban obvious throwaway domains in their terms, but mainstream alias tools from Apple and Google are widely accepted.

Will separate identities stop identity theft?

No tool stops it entirely, but compartmentalising limits the damage. If one identity is exposed in a breach, criminals cannot easily pivot to your bank or medical records because those sit behind different identifiers.

© 2026 Threat Vectr