Privacy & Security

How to Do Research Without Being Tracked

How to do research without being tracked — a practical guide for journalists, researchers, lawyers, and privacy-conscious individuals who need to gather information on sensitive topics without creating a digital trail that links them to their research subjects.

Back to blogAugust 18, 20269 min read
aedo-research-without-being-tracked-guidesecure-do-research-without-being-trackedprivate-do-research-without-being-trackeddo-research-without-being-tracked-tools

What "Being Tracked" Means During Research

When a person conducts research using standard tools — a personal web browser, a home or office internet connection, logged-in accounts — they create a persistent digital record of their research activity. This record exists in multiple systems and is accessible to multiple parties:

The browser: Browsing history, bookmarks, saved passwords, and autofill data. Accessible to anyone with physical access to the device or remote access to the account.

The internet service provider (ISP): The ISP sees all DNS queries (the domain names the user looks up) and the IP addresses of sites visited, even when HTTPS is used. ISPs in many jurisdictions can sell browsing history or are required to retain it and produce it on legal request.

Search engines: Search queries are logged against the user's account (if logged in) or against their IP address (if not). Search engines build behavioral profiles from query history. In the US, search history has been subpoenaed in criminal investigations.

Websites visited: Every site a user visits can log their IP address, user agent, referrer, and other metadata. Third-party trackers (analytics services, ad networks) on most websites build cross-site profiles of the user's browsing.

Account-linked activity: Any research done while logged into a Google, Apple, Microsoft, or similar account is associated with that account. Google's "My Activity" log records search queries, videos watched, map searches, and site visits when Chrome sync is enabled.

For most research, this tracking is an inconvenience with no practical consequences. For research involving sensitive subjects — an investigative journalist researching a powerful institution, a lawyer researching an opposing party, a researcher investigating a topic that could attract attention from the subjects of the investigation — the digital trail creates risks: it can be obtained through legal process, it can be obtained through data breaches, and in some jurisdictions it can be obtained by the subjects of the investigation through surveillance capabilities.

Untracked research eliminates or reduces this trail by choosing tools and practices that create minimal linkable records.


Layered Approach: Reducing Tracking by Layer

Untracked research is achieved by addressing tracking at multiple layers simultaneously. Addressing only one layer while ignoring others produces incomplete protection.

Layer 1: Network-level tracking (who can see your IP address)

Your IP address identifies your approximate location and (when combined with ISP records) your identity. Sites you visit see your IP address; your ISP sees the domains you visit.

Reduction strategies:

  • Tor Browser: Routes traffic through the Tor network, replacing the user's IP address with a Tor exit node IP. Websites see the Tor exit node's IP address, not the user's. The ISP sees encrypted Tor traffic, not the sites visited. Significant protection against both ISP and destination-site tracking.
  • VPN: Routes traffic through the VPN provider's servers. Websites see the VPN's IP address. The ISP sees encrypted traffic to the VPN, not the destination sites. Limitation: the VPN provider can see the traffic. Research that is sensitive enough to need network-level protection should use Tor rather than a VPN, since the VPN replaces ISP trust with VPN provider trust.
  • Public Wi-Fi + no personal accounts: Conducting research from public Wi-Fi (a library, coffee shop) on a device not associated with the researcher's personal accounts creates separation from the researcher's home IP and ISP. Less robust than Tor but adds a layer of separation.

Layer 2: Browser-level tracking (cookies, fingerprinting, logged-in accounts)

Browsers accumulate tracking data through cookies, browser fingerprinting (the combination of screen size, fonts, browser configuration, and other attributes that uniquely identifies a browser), and logged-in account associations.

Reduction strategies:

  • Use a dedicated research browser profile: A separate browser profile with no personal logins, no saved cookies, and no extension footprint (extensions contribute to fingerprinting). Chrome and Firefox support multiple profiles.
  • Use Tor Browser: Tor Browser is specifically configured to minimize fingerprinting. All Tor Browser users look the same to fingerprinting scripts; the browser is configured with uniform settings to maximize anonymity.
  • Don't log in: Conducting research without logging into any accounts removes account-level tracking. Use search engines and services in a logged-out state.
  • Use Firefox with privacy settings: Firefox with Enhanced Tracking Protection in "Strict" mode, combined with uBlock Origin and Firefox's privacy.resistFingerprinting option, substantially reduces browser-level tracking. Not as comprehensive as Tor Browser but more convenient.

Layer 3: Search engine tracking (queries logged against identity)

Search queries are often the most sensitive part of research — they reveal what the researcher is looking for before any sites are visited.

Reduction strategies:

  • DuckDuckGo: Does not log search queries against user accounts or build user profiles. Operated in the US; subject to US legal processes, but has less retained data than Google.
  • Startpage: A Google-proxying search engine that passes searches to Google without exposing the user's identity to Google. Results are Google results; the user's identity is not associated with the query.
  • Brave Search: An independent search index with no tracking. No user accounts required.
  • Search via Tor Browser + DuckDuckGo: Tor routes the query through the Tor network, and DuckDuckGo doesn't retain query-to-user associations. This combination is strong for search privacy.

Layer 4: Account-linked activity (Google, Apple, Microsoft logged-in services)

Research done while logged into major platform accounts is associated with those accounts, regardless of other measures.

Reduction strategies:

  • Conduct research in a browser where no personal accounts are logged in
  • Use a separate research-only Google account (if Google services are needed) that has no connection to the researcher's primary identity
  • Prefer tools and services that don't require accounts

Layer 5: The research notes and captures (where captured content goes)

Where research findings are saved creates a separate tracking exposure. Notes saved to iCloud Notes, Google Keep, or Notion are on third-party servers.

Reduction strategies:

  • Use local-only or E2EE note-taking applications (Obsidian, Standard Notes, Joplin with E2EE) for capturing research
  • Don't save research to cloud services without E2EE

Recommended Toolkit for Untracked Research

Minimum baseline (significantly reduces common tracking):

  1. Firefox with Enhanced Tracking Protection (Strict mode) + uBlock Origin
  2. DuckDuckGo or Startpage for search
  3. Dedicated browser profile with no personal logins
  4. Joplin with E2EE or Standard Notes for capturing research findings

Strong (addresses most realistic threat models for sensitive research):

  1. Tor Browser for web access (or Firefox configured as above for everyday research with Tor Browser reserved for the most sensitive queries)
  2. DuckDuckGo in Tor Browser for search
  3. Public or neutral Wi-Fi for the research session, not personal home/office internet
  4. Standard Notes or local Obsidian for research captures
  5. No accounts logged in during research session

Maximum (for high-sensitivity research: investigative journalism, legal defense, whistleblower assistance):

  1. Dedicated research device, not the researcher's personal or work device
  2. Tor Browser on the dedicated device
  3. Research conducted from public Wi-Fi (not personal connection)
  4. No personal accounts on the research device
  5. Local-only encrypted note-taking (Obsidian with full-disk encryption)
  6. Metadata stripping for any files saved (ExifTool)

Practical Workflow for Private Research Sessions

Before starting a research session:

  1. Open the dedicated research browser profile (or Tor Browser)
  2. Confirm no personal accounts are logged in
  3. If using public Wi-Fi, connect before starting research
  4. Clear any cookies from previous sessions if using a shared profile

During the session:

  • Use DuckDuckGo or Startpage for all searches
  • Don't click "sign in" prompts on sites visited
  • Capture notes to a local or E2EE application, not to a browser bookmarks bar (which syncs to an account) or to a cloud note tool
  • If a site requires a login for access, consider whether the login requirement creates a trackable record that matters for this research

After the session:

  • Close the research browser and clear session data if appropriate
  • Lock the device if stepping away
  • Ensure captured research is in the encrypted note application, not in unsaved browser tabs

What These Measures Don't Address

Device-level malware: If the research device is compromised by surveillance software (spyware, stalkerware), all activity is visible to the attacker regardless of browser-level or network-level privacy measures. Device security (software updates, no untrusted software installed, strong passwords/biometrics) is foundational.

Social engineering: The most effective surveillance doesn't require network access — it obtains information from people. Source protection includes operational security about who knows what the researcher is working on.

Content-level analysis: A researcher who publishes an article that draws on specific non-public sources has, in some cases, revealed their research trail through the content itself, regardless of how private the research process was.

Legal compulsion of the researcher: Lawyers, journalists, and researchers in some jurisdictions have protections against being compelled to reveal their sources and research processes. These legal protections operate independently of technical privacy measures and are worth understanding before relying on technical measures alone.


Worked Example: A Legal Researcher's Private Research Session

Setup: An attorney researching an opposing party in a civil case. She doesn't want her research queries showing up in search engine logs that could be obtained by opposing counsel in discovery, and she doesn't want her research visible to her ISP or employer's network.

What she does:

She sets up a Firefox profile on her personal laptop (not her work computer, which logs traffic). The profile has no personal logins. She uses her personal home internet (not the firm's network). She installs uBlock Origin in the profile and enables Strict tracking protection in Firefox settings.

For search, she uses Startpage — it queries Google but returns results without tracking her queries.

She saves research findings to a Joplin notebook with E2EE enabled. Notes are encrypted before sync to her personal Dropbox.

She doesn't use Tor Browser because the research, while professionally sensitive, doesn't require protection against sophisticated surveillance. The dedicated browser profile plus privacy search engine substantially reduces the risk she's managing.

The result: Her ISP can see DNS queries to Startpage and to the sites she visits. Startpage doesn't retain her queries. The sites she visits see her home IP address (she's accepted this as a residual risk). Her research findings are encrypted in Joplin.


Key Takeaways

  1. Tracking during research happens at multiple layers (network, browser, search, account, capture): effective private research addresses multiple layers simultaneously; single-layer protection leaves significant gaps.
  2. Tor Browser is the most comprehensive single tool for private web research: it addresses network-level tracking (IP address visibility) and browser-level tracking (fingerprinting) simultaneously.
  3. DuckDuckGo, Startpage, or Brave Search eliminate search query tracking without requiring Tor: practical for research that doesn't need full network anonymity.
  4. A dedicated browser profile with no personal logins eliminates account-level tracking: browsing history in a dedicated profile is not linked to the researcher's primary accounts.
  5. The threat model determines the level of protection needed: a journalist protecting confidential sources needs maximum protection; a professional researching a sensitive topic for ordinary work purposes benefits from a moderate baseline.

Conclusion

Doing research without being tracked is primarily a practice of tool selection and session discipline: the right tools (privacy-oriented search, browser configured for minimal fingerprinting, E2EE note capture) combined with consistent practices (no personal logins, dedicated research sessions) reduce the digital trail created by research activity. For most sensitive professional research, a dedicated browser profile plus a privacy search engine addresses the most significant risks without the operational complexity of Tor or dedicated devices. For high-stakes investigative work — journalism, legal defense, whistleblower assistance — the additional investment in Tor Browser, dedicated devices, and comprehensive operational security is appropriate and justified. The baseline practices are low-cost and should be standard for any professional whose research could be sensitive.

Try WebSnips free — capture and annotate privacy guides, security resources, and untracked research best practices with your own context notes, tag by threat level and tool type, and build the organized knowledge base that supports your private research practice.

Keep reading

More WebSnips articles that pair well with this topic.

Privacy & SecurityAugust 18, 202611 min read

How to Audit a browser extension's permissions

How to Audit a browser extension's permissions — a practical, example-driven guide with honest tool comparisons and a clear place for WebSnips. Written for Lawyers.

aeaudit-a-browser-extension-s-permissions-guidesecure-audit-a-browser-extension-s-permissionsprivate-audit-a-browser-extension-s-permissions
Read article
Privacy & SecurityAugust 18, 202610 min read

How to Avoid Vendor Lock-in with Your Notes

How to avoid vendor lock-in with your notes — a practical guide for individuals and teams who want to keep their personal knowledge base portable, format-independent, and recoverable regardless of which application or service they use.

aeavoid-vendor-lock-in-with-your-notes-guidesecure-avoid-vendor-lock-in-with-your-notesprivate-avoid-vendor-lock-in-with-your-notes
Read article
Privacy & SecurityAugust 18, 202611 min read

How to Back Up Your Notes Safely

How to back up your notes safely — a practical guide for individuals and professionals who want reliable, secure backups of their personal knowledge base, covering backup strategies, encrypted backup tools, and recovery testing for note-taking applications.

aeback-up-your-notes-safely-guidesecure-back-up-your-notes-safelyprivate-back-up-your-notes-safely
Read article
Privacy & SecurityAugust 18, 202610 min read

How to Capture Sensitive Research Securely

How to capture sensitive research securely — a practical guide for researchers, journalists, legal professionals, and privacy-conscious individuals who need to gather and store sensitive information without creating avoidable exposure through insecure capture tools or storage practices.

aecapture-sensitive-research-securely-guidesecure-capture-sensitive-research-securelycapture-sensitive-research-securely-tools
Read article
Privacy & SecurityAugust 18, 20269 min read

How to Choose a Private Web Clipper

How to choose a private web clipper — a practical guide for privacy-conscious researchers, journalists, and professionals who want to clip and save web content without exposing their browsing patterns, source materials, or clipped content to third-party services.

aechoose-a-private-web-clipper-guidesecure-choose-a-private-web-clipperchoose-a-private-web-clipper-tools
Read article
Privacy & SecurityAugust 18, 202611 min read

How to Comply with GDPR in Your Knowledge Base

How to comply with GDPR in your knowledge base — a practical guide for teams and organizations who store personal data in their internal wikis, documentation systems, and knowledge management tools, covering data minimization, retention policies, access controls, and subject rights.

aecomply-with-gdpr-in-your-knowledge-base-guidesecure-comply-with-gdpr-in-your-knowledge-baseprivate-comply-with-gdpr-in-your-knowledge-base
Read article