You've clicked "I agree" thousands of times. By one well-known estimate from Carnegie Mellon researchers (2008), reading every privacy policy the average American encounters in a year, word for word, would take something like 76 working days — nearly a quarter of the year spent parsing subclause 14(b). Nobody spends that. Everyone clicks agree without reading, and that's not laziness — it's the rational response to a document engineered not to be read. There's a shorter method: don't read the whole thing, hit five specific spots in five minutes. It won't replace a lawyer and it won't give you the full picture — but it gives you enough to know what you're agreeing to before you click.
Why the document is built this way
A privacy policy is almost never written as an explanation for you. It's written by lawyers for lawyers and regulators — a shield against a future lawsuit, not an honest account of what happens to your data. Hence the passive voice ("data may be processed"), the vague qualifiers ("in certain circumstances"), and a structure where the three sentences that actually matter drown in twenty paragraphs of preamble about how much the company "values your privacy."
In the old language, this is Shadow Thoth's work. Thoth is the god of writing and the precise word, the one who weighs phrasing at the Scale. Shadow Thoth is the same tool turned against understanding: not a direct lie, but an excess of words built to bury the three sentences that were actually worth reading. The five-minute method below is a way to take the language back.
The method: five minutes, five searches
Open the policy in your browser — it's almost always a plain web page — and hit Ctrl+F (Cmd+F on Mac). Search for five words in order, reading only the sentence around each hit, not everything around it:
- "sell" — the most direct word. Many companies technically don't "sell" data in the legal sense, but trade it for ad placements instead — worth noting even if the word "sell" never appears.
- "share" / "third party" / "affiliates" — exactly who the data goes to: partners, ad networks, "affiliated companies." At a large company, the affiliate list can run to dozens of businesses you've never heard of.
- "retention" — how long data sits around after you stop using the service or delete your account. "As long as necessary" with no concrete number is a red flag — it means "as long as it's useful to us."
- "delete" — is there an actual button that erases your data, or only "deactivation," after which the data quietly stays on the servers.
- "advertising" / "marketing" — whether your data is used to target ads, and whether you can opt out of that specifically without leaving the service entirely.
Five words, roughly thirty seconds each on an average document, and you have the skeleton of what the document actually does — without wading through the preamble.
Red flags worth noticing at a glance
- "We may share data with partners and affiliates for marketing purposes" — almost always means "we share or sell," just phrased differently.
- "As permitted by applicable law" with no law named — a placeholder phrase that usually means "we'll do the legal minimum, and nothing more."
- A mandatory arbitration clause that waives your right to a class action — not strictly a privacy matter, but it often sits nearby, and it's worth knowing it's there.
- Data retained "indefinitely" or "while your account is active and afterward" — meaning forever, unless you personally trigger deletion.
- No deletion section at all — if the policy says nothing about it, the real option probably doesn't exist, or it's buried in account settings rather than the policy itself.
What to do with what you find
Finding something doesn't obligate a dramatic decision. There are really three paths. Accept it knowingly — sometimes the service is worth the trade, and that's a legitimate choice, as long as it's a choice and not blind agreement. Find the opt-out — ad-personalization opt-outs almost always exist separately from the policy itself, usually under account privacy settings. Or use your legal rights where they apply: in the EU, GDPR gives you the right to delete your data and export it in machine-readable form; in California, CCPA gives you the right to opt out of the sale of your data. Even outside those jurisdictions, many services extend these tools to everyone, because building one interface is cheaper than building two.
> Our record. Consent you gave without reading isn't consent in the sense Ma'at means it. The Scale weighs the Ib, the heart, only when the heart knows what it's placing on the pan. The five-minute scan doesn't make you a lawyer. It makes your consent real — something you gave knowingly, not something extracted from you by sheer volume of text.
Do this today
Open, right now, the privacy policy of any service you use daily — email, a social app, your banking app. Hit Ctrl+F, search for the word "sell," and read the one sentence around it. One word, one sentence, thirty seconds — and you already know more about your own data than nine out of ten people who clicked "I agree" on that exact same screen.