
When most people hear the phrase “privacy controls,” they picture toggles: an Incognito window in Chrome, a Global Privacy Control signal broadcasting “do not sell my data,” an Android permissions screen, or the account checkup buried in a Google settings menu. These tools matter, and a lot of people use them. Keyword data shows “privacy settings” draws roughly 74,000 searches a month in the United States alone, more than four times the volume for “identity theft” at 18,100. People are actively looking for ways to lock down their digital footprint.
But there is a category of personal information these controls were never built to reach: the public record. Deeds, mortgages, liens, and property filings sit in county databases that predate the modern internet, and no browser extension, app permission, or opt-out signal can touch them. That gap is exactly what Public Records Safety was created to address, and it is worth understanding before you assume your privacy settings have you fully covered.
This is not a small or rare category of data. Property records exist for nearly every homeowner, and county portals were designed decades before anyone anticipated automated bots pulling records at machine speed. Understanding where consumer privacy controls end, and where a separate set of protections needs to begin, is the first step toward closing that gap.
Consumer privacy tools have matured quickly over the past few years, and most of them fall into a few familiar categories:
Each of these does something real. GPC reduces the burden of manually opting out of data sales one site at a time. Device permission reviews limit what apps can quietly collect in the background. But every one of them governs data that lives inside a private company’s ecosystem: your browser, your phone’s operating system, or a platform account. None of them reach the recorder’s office down at the county courthouse.
Public record systems were built on a different premise entirely: transparency. County recorders, clerks, and assessors maintain property and legal filings specifically so that real estate transactions, lending decisions, and legal processes can happen in the open. That openness is valuable, but it also means there has never been a “privacy setting” for a deed.
A single property filing can include:
No toggle in Chrome, Firefox, Safari, or Android settings governs any of it, because none of that data is held by Google, Apple, or a browser vendor. It sits across roughly 3,000 individual county governments in the United States, each running its own portal, with wildly inconsistent protections. That patchwork is precisely the environment automated systems have learned to exploit.

Digitization made county property records easier to access, which was the point. But it also created a vulnerability that public records laws never anticipated: bots, scrapers, and AI systems can now pull enormous volumes of this data at a speed no human clerk could match. Public Records Safety’s research points to Solove and Hartzog’s 2025 paper, “The Great Scrape,” as an early marker of this shift, arguing that mass scraping runs directly against core privacy principles like consent, purpose limitation, and data minimization.
The numbers behind this shift are hard to dismiss:
County-originated records don’t stay in county hands, either. Commercial pipelines such as ATTOM, CoreLogic, BatchData, and DataTree routinely absorb public filings through bulk sales, open APIs, and vendor agreements, feeding that information into national data products with little downstream oversight. A record that started as a routine deed filing can end up several steps removed from the county that created it, with no way to trace where it went.
The consequences of this gap are not evenly distributed. Some groups face outsized risk:
This is also why “data broker opt out” and “personal information removal” have become searches in their own right, drawing hundreds of monthly queries from people trying to claw back control after the fact. By the time someone searches for removal help, the data has often already been aggregated and resold.
The response is starting to catch up with the problem, on two tracks at once. On the policy side, states are experimenting with filing alerts, suspicious-document holds, photo ID requirements, and title-freeze style protections. On the technical side, counties can take concrete steps that function like a public-records version of Global Privacy Control: a documented, standardized way to say “do not scrape this.”
Public Records Safety’s own recommended framework breaks this into five steps counties can move through in order:
Practical tools already exist to support this, including sample robots.txt language that blocks known AI crawlers while still allowing legitimate search engines, and sample Terms of Use language prohibiting automated scraping without written authorization. Public Records Safety also publishes a Research Briefing, a County Action Guide, and a one-page Fact Sheet so county officials, IT staff, and concerned residents have sourced material ready for board meetings and policy discussions, along with a county lookup tool to check where a specific county currently stands.

None of this is an argument against GPC, browser tracking protections, or locking down your app permissions. Those remain the fastest, most direct way to reduce your exposure to commercial tracking, and they take only a few minutes to set up. But real privacy control, in 2026, has to account for data that lives outside any app or browser entirely.
Public records were built for transparency, not for automated, industrial-scale extraction, and the tools that protect your search history won’t do anything to protect a deed filed decades ago. Closing that second gap depends less on personal settings and more on counties, vendors, and abstractors adopting the same instinct that browsers already have: give people, and their local governments, a real way to say no to bulk automated access.
The most effective privacy strategy right now treats these as two separate but connected tasks. Keep using GPC, browser tracking protections, and device permission reviews to manage what companies collect about your behavior online. Then look one layer deeper, at the records your county already holds, and ask whether anyone is actively protecting them. Until bulk scraping protections become standard practice everywhere, checking where your own county stands is one of the few privacy controls left that actually reaches this part of your data.
The most effective approach layers several tools at once: turn on Global Privacy Control in a supported browser, use the tracking protections built into Chrome, Firefox, Safari, or Brave, and periodically review account and device permissions on Android and iOS. This is also the single most-searched privacy question online, drawing roughly 450,000 U.S. searches a month. What it won’t do is touch data that a government agency, rather than a company, already holds — including county property and court filings.
A data broker is a company that collects personal information from public and commercial sources and compiles it into profiles it can sell. County-originated property records are one major source: pipelines such as ATTOM, CoreLogic, BatchData, and DataTree routinely absorb public filings through bulk sales, open APIs, and vendor agreements, then feed that information into national data products.
GPC is a browser-level signal, drawing about 210 monthly searches, that automatically tells participating websites not to sell or share your data. It only works on commercial sites built to recognize it, though. County recorder and assessor portals are government systems, not commercial websites, so a GPC signal has no effect on a deed or mortgage filing already sitting in a public database.
Generally, no. Property and deed records are public by law, specifically so real estate transactions, lending, and legal processes can happen transparently, and most counties don’t offer an individual removal option the way a data broker does. The more realistic path is pushing counties to restrict bulk, automated access to that data rather than trying to erase any single record, which is the operational middle ground Public Records Safety’s resources are built around.
Title fraud happens when someone uses stolen identity or ownership information to forge a deed transfer or fraudulently claim a property. A 2025 NAR survey found 63% of real estate professionals were aware of title fraud in the prior 12 months, rising to 92% in the Northeast. Bulk-scraped ownership, mortgage, and signature data gives bad actors the raw material to attempt exactly this kind of fraud at a larger scale than manual research ever allowed.
Enter a county name to check its protection status