Can you actually stay private online? The case for separate digital identities

Reusing the same email, phone number and card everywhere hands data brokers and criminals a ready-made profile. Compartmentalising your identity blunts that.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Multiple digital identities represented as separate user profiles on a computer screen, each with different emails, devices, and payment methods organized in di
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Reusing one email, phone number and payment card across every site lets data brokers and criminals stitch together a full profile of a person's life.
  • Anonyome Labs argues that separate digital identities, each with their own contact details, reduce this correlation and limit fallout from breaches.
  • No US federal privacy law currently forces brokers to stop this linking; enforcement leans on state laws like the California Consumer Privacy Act.
  • Practical steps include email aliases, masked phone numbers and virtual payment cards, tools now offered by mainstream providers.
  • The approach lowers spam, phishing hits and identity theft risk, but doesn't make anyone invisible online.

Sign up for a shopping account with your real email. Book a dentist with the same address. Post on a forum with it. Within months, that single string of characters ties together your medical visits, your spending and your politics, and it sits in databases you've never heard of.

That is the problem a new explainer from privacy firm Anonyome Labs, first covered by BleepingComputer, sets out to describe. The pitch: stop giving every service the same identifiers, and the profile falls apart. Our 14 August story on DecryptAds, a free tool that surfaces hidden trackers inside popular websites, showed how many brokers are already sitting inside the apps most people use daily.

Why does reusing one email or phone number matter so much?

It's the glue. Data brokers buy and sell personal information; they use shared identifiers to link records from different sources into one file on you. Give ten websites the same email, and a broker can merge ten separate slices of your life into a single dossier.

The same trick helps attackers. When a retailer is breached and your email leaks, criminals try that address against your bank, your work login and other accounts. This is credential stuffing: running stolen username and password pairs against other sites to see which ones open.

A phone number is worse. It rarely changes, it's tied to your carrier account, and it's often the fallback for resetting passwords.

What is a "digital identity" in this context?

A digital identity here means a bundle of contact details you use for one purpose only. One email, one phone number, sometimes one payment card, dedicated to shopping. A different bundle for social media. Another for medical and financial accounts.

If a shopping site is breached, the leak touches only that bundle. Your bank login, tied to a different email the retailer never saw, stays clean.

Anonyome sells software that generates these bundles, but the underlying idea isn't proprietary. Apple's Hide My Email, Google's email alias tool and virtual card numbers from banks or services like Privacy.com all do versions of the same thing.

Does the law help?

Only patchily. There's no single US federal privacy statute. The California Consumer Privacy Act, amended by the California Privacy Rights Act, gives Californians the right to ask businesses what personal information they hold and to demand deletion. Similar laws are now in force in Virginia, Colorado and Connecticut.

In Europe, the General Data Protection Regulation (GDPR), the EU's 2018 privacy law, gives residents stronger deletion and access rights and has produced multi-million-euro fines against data brokers and ad-tech firms.

Neither regime stops a company from collecting your email in the first place. They regulate what happens next.

Practical steps for a non-technical reader

Identifier Everyday tool What it does
Email Apple Hide My Email, Gmail aliases, Firefox Relay Generates a throwaway address that forwards to your real inbox
Phone number Google Voice, carrier secondary lines Gives you a second number for signups and deliveries
Payment card Bank virtual cards, Privacy.com Creates single-use or merchant-locked card numbers
Password Any reputable password manager Stops one leaked password unlocking other accounts

Start with the accounts that matter most: bank, primary email, work login. Give each a unique password and, where possible, a unique recovery email. Then work outwards to shopping and social accounts.

Becoming invisible isn't the goal. Becoming harder to profile, and less interesting to the next breach, is.

Common questions

Is using an email alias legal?

Yes. Aliases forward to your real address and don't involve impersonation. Some services ban obvious throwaway domains in their terms, but mainstream alias tools from Apple and Google are widely accepted.

Will separate identities stop identity theft?

No tool stops it entirely, but compartmentalising limits the damage. If one identity is exposed in a breach, criminals can't easily pivot to your bank or medical records because those sit behind different identifiers.

© 2026 Threat Vectr