Blog

How to Take Back Control of Your Data


Your files, photos, notes, and documents are spread across dozens of services, and most of them don't work for you.



There is a quiet transfer of control happening across the software industry. The tools people use every day, for notes, files, photos, communication, and work, are increasingly designed to keep data inside walled gardens, feed it into training pipelines, and make it difficult to leave. Privacy policies have grown longer and harder to parse. Data breaches have become so frequent that they barely register as news. And as AI agents become more prevalent, every service wants deeper access to your personal information.

None of this is inevitable. The choices you make about where your data lives, which tools you use, and what permissions you grant have real consequences. This is a guide to understanding those choices and making better ones.


Why this moment matters

Several trends are converging to make data ownership more important than it has been in years.

AI training is hungry for data. Many services have updated their terms to allow user data to be used for model training, sometimes with opt-out mechanisms buried deep in settings menus, sometimes with no opt-out at all. The line between "using your data to improve the product" and "using your data to train a commercial AI model" has become blurred, often deliberately.

AI agents are proliferating. The next generation of AI tools does not just respond to prompts. These agents act on your behalf: reading your emails, scanning your files, scheduling your meetings, and making decisions with your information. The amount of data an agent needs to be useful is significant. The question of who else can see that data, and what happens to it after the agent processes it, is one that most users have not yet confronted.

Breaches are accelerating. The volume of data exposed through security breaches has increased year over year. Healthcare records, financial data, personal communications, and identity documents are routinely compromised. The more services that hold copies of your data, the larger your exposure surface.

Portability is declining. Many tools make it easy to import your data but difficult to export it. The switching costs are designed to keep you locked in. If you cannot take your files, notes, and history with you when you leave a service, you do not fully own that data.


Audit what services have your data

The first step is knowing where you stand. Most people underestimate how many services hold their personal data. Email providers, cloud storage accounts, note-taking apps, social media platforms, messaging tools, photo services, health trackers, financial apps, and dozens of SaaS products used for work all hold some portion of your digital life.

A practical approach is to go through your email inbox and search for welcome emails, signup confirmations, and password reset messages. This gives you a rough inventory of accounts you have created. Password managers are also useful here, as they tend to accumulate a record of every service you have logged into.

For each service, consider what data it holds, whether you still use it, and whether you can export or delete your data. Many jurisdictions now give you the legal right to request deletion, though enforcement varies and the process is often tedious.

The goal is not to delete everything. It is to have a clear picture of your digital footprint and to make intentional decisions about what stays and what goes.


Understand what you are consenting to

Privacy policies and terms of service are designed to be comprehensive, which in practice means they are designed to be unreadable. Few people read them. Fewer still understand the implications.

A few things worth looking for: whether the service claims a licence to use your content (and for what purposes), whether your data can be shared with third parties, whether it can be used for AI training, what happens to your data if the company is acquired, and what your rights are regarding deletion and export.

Organisations like the Electronic Frontier Foundation and Terms of Service; Didn't Read can help decode the more opaque agreements. Browser extensions that flag changes to privacy policies can also be useful.

The broader principle is that consent should be informed. If a service makes it difficult to understand what you are agreeing to, that is worth treating as a signal about the service's priorities.


Choose tools that let you own your files

Ownership is not just a legal concept. In practical terms, you own your data when you can access it in standard formats, move it between services without friction, store it where you choose, and delete it with confidence that it is gone.

Some tools are built around this principle. Fabric, for example, lets you bring your own storage through connections to Google Drive, Dropbox, and other providers. Your files stay in infrastructure you control. The workspace layer sits on top of your storage rather than replacing it. If you decide to stop using Fabric, your files are still where they were.

This is a different model from services that ingest your data into their own proprietary storage, reformat it, and make it difficult to extract. When evaluating any tool, ask: where does my data physically live, in what format is it stored, and can I get it back in a form I can use elsewhere?


Keep your data portable

Portability is the ability to move your data between services in standard, usable formats. It sounds obvious, but many popular tools fail this test.

Notes stored in proprietary formats that do not export cleanly to Markdown or HTML. Files locked behind sync clients that only work with one service. Project data scattered across a platform's internal database with no bulk export option. These are all forms of lock-in, and they reduce your effective ownership of your own work.

When choosing tools, favour those that use open or standard formats. Markdown for text. Standard image, video, and document formats for media. Open APIs that allow you to build your own integrations or move data programmatically. Fabric's notes and documents use standard formats, and the platform's search works across your existing files rather than requiring you to re-upload everything into a closed system.

Portability is also about structure. If your organisational system, your tags, your folder hierarchy, your metadata, cannot be exported alongside your files, you lose significant value when you move. Tools with smart organisation that works on standard file structures preserve that value better than tools that build organisation into a proprietary layer.


Use encryption where possible

End-to-end encryption means that only you (and the people you choose to share with) can read your data. The service provider cannot access it, which also means it cannot be exposed in a breach of their systems, cannot be handed over in response to a legal request without your involvement, and cannot be used for training purposes.

Not every service offers end-to-end encryption, and for some use cases (like full-text search across encrypted files) it introduces trade-offs. But where it is available, it is worth using. Encrypted messaging (Signal, for example), encrypted email, encrypted file storage, and encrypted backups all reduce your exposure.

For cloud storage and file management, look for services that encrypt data both in transit and at rest, that give you control over encryption keys where possible, and that are transparent about their security architecture. Fabric encrypts your data and provides backup capabilities to ensure your files are protected.


Be selective about AI access

AI tools can be remarkably useful, but they come in very different configurations when it comes to data handling. Some process your data locally. Some send it to remote servers for processing but do not retain it. Some retain it for a period. Some use it to train models that serve other users. The differences matter enormously.

Before giving an AI tool access to your files, email, or personal information, find out what happens to the data after processing. Is it stored? For how long? Is it used for training? Can you opt out? Is the processing done on infrastructure you trust?

Fabric's AI assistant works across your files to answer questions and surface relevant information, but your data is not sent elsewhere for model training. AI agents within Fabric operate on your content with the same privacy boundaries. This is a meaningful distinction from AI services that use your inputs to improve models that serve millions of other users.

The convenience of AI does not require you to surrender ownership of your data. It requires you to choose tools that respect the boundary between using your data for you and using your data for themselves.


Consolidate where it makes sense

Part of taking control is reducing the number of places your data lives. Every additional service is another account to secure, another privacy policy to monitor, another potential breach surface.

Consolidation does not mean putting everything in one place with no redundancy. It means being intentional about which tools hold which data, and reducing unnecessary duplication. If you have files spread across five cloud storage services, three note-taking apps, and a dozen project management tools, consolidating into fewer, more capable tools reduces complexity and improves your ability to maintain oversight.

A workspace that can handle files, notes, collaboration, and search in one place reduces the sprawl. Connections to existing storage mean you can bring scattered files together without re-uploading everything. Self-writing documentation can help capture institutional knowledge that might otherwise live only in someone's email or chat history.

The aim is fewer surfaces to protect, fewer terms of service to accept, and a clearer picture of where your data is at any given time.


Think about what you leave behind

Digital data has a tendency to accumulate. Old accounts, abandoned services, forgotten uploads, and outdated backups all persist unless you take active steps to remove them. This residual data is a liability: it can be exposed in breaches, harvested by data brokers, or used in ways you did not anticipate when you first created the account.

Regular housekeeping is worthwhile. Delete accounts you no longer use. Remove data from services you have migrated away from. Review app permissions on your phone and revoke access for apps you no longer trust or use. Check what third-party applications have access to your Google, Microsoft, or Apple account.

This is not about paranoia. It is about maintaining a manageable digital footprint and ensuring that the data that exists about you is data you have chosen to keep in places you have chosen to trust.


A practical framework

Taking control of your data does not require a weekend of purging and restructuring (though that can help). It can be an ongoing practice: a set of habits and criteria that guide your choices over time.

When evaluating a new tool, ask: where does my data go, can I get it back, is it encrypted, and what are the AI training policies? When reviewing existing tools, ask: do I still need this, is my data still there, and does the privacy policy still reflect what I signed up for?

Choose tools built around ownership: standard formats, easy export, bring-your-own-storage, transparent security, and AI that works for you without working against your privacy. Fabric was built with these principles, and you can explore how it compares to alternatives like Dropbox, Google Drive, or Notion.

Your data is a record of your work, your thinking, your creativity, and your life. It is worth treating it with the care that implies.


Frequently asked questions

How do I find out which services have my data?

Search your email for signup confirmations, welcome messages, and password resets. Check your password manager for a list of saved accounts. Review app permissions connected to your Google, Apple, and Microsoft accounts. This gives you a working inventory to audit.

What rights do I have over my personal data?

This depends on your jurisdiction. The GDPR (EU and UK) gives you the right to access, correct, delete, and port your data. The CCPA (California) provides similar rights. Other regions have varying levels of protection. Many services honour deletion requests globally, but the process often requires persistence.

How can I tell if a service uses my data for AI training?

Check the service's terms of service and privacy policy, specifically sections on data usage, model training, and content licences. Look for opt-out settings in your account preferences. If the policy is unclear, that ambiguity is itself informative.

What is "bring your own storage" and why does it matter?

Bring your own storage means a tool works with files stored in a cloud provider you already use (like Google Drive or Dropbox) rather than requiring you to upload everything to the tool's own servers. This preserves your existing file ownership and makes it easier to leave the tool without losing access to your data.

Is end-to-end encryption compatible with AI features?

There are trade-offs. Full end-to-end encryption can limit some AI capabilities (like server-side search or processing). Some tools handle this by processing data locally or by using encryption schemes that allow limited computation on encrypted data. The best approach depends on your priorities.

How often should I audit my digital footprint?

A thorough review once or twice a year is a reasonable starting point. Between audits, apply consistent criteria when signing up for new services: read the data policies, check for export options, and favour tools that respect your ownership.

What makes a file format "portable"?

A portable format is one that can be opened and used by multiple applications without conversion or data loss. Markdown, plain text, PDF, standard image formats (PNG, JPEG), and common document formats (DOCX) are portable. Proprietary database formats, app-specific bundles, and formats without published specifications are not.

Can I use AI tools without giving up data control?

Yes. Look for tools that process data locally where possible, that do not retain your data after processing, that do not use your data for training, and that are transparent about their data handling. Fabric's approach is to let AI work across your files without sending them elsewhere for model training.

What is the risk of having data in too many services?

Each additional service increases your attack surface (more potential breach points), your administrative burden (more accounts to manage), and your exposure to policy changes. Consolidating into fewer, trusted tools with strong security practices reduces all three risks.


Related pages

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.