The Data You Hand Over
What is the safest data to have in a breach?
The idea
Every optional field, permission and connected app widens what is held about you and who holds it.
In the real world
Granting full contact access to an app that only needed a photo.
Going deeper
You cannot control how well a company protects data, and you can control how much of it they hold. Data never provided cannot be leaked, which is the only protection that does not depend on someone else's competence.
The practical surface is optional fields, app permissions and connected accounts. Each is granted once, in a moment where the goal is getting something working, and then persists indefinitely. Reviewing the permissions on one app usually finds several that are unrelated to what it does, and revoking them costs nothing.
Where it stops applying
Some data collection is genuinely necessary for a service to function, and minimalism can degrade the product. The target is the gap between what is needed and what is requested.
Why it matters
You cannot control how well a company protects data you chose not to give it.
Try this today
Review the permissions on one app and remove any it does not need to function.
Test yourself
A service is breached and one user is far less exposed than others with identical accounts. What did they most likely do differently?
Show the answer
Supplied less: skipped optional fields, declined unnecessary permissions, and did not link other accounts. Data never provided cannot leak, which is the only protection that does not depend on the company's security being good.
Learn this in the feed Answering from memory, then again days later, is what makes it stick.