Apple Sold You “Privacy.” The Lawsuit Says Safari Sold You Out.
Apple built an entire brand identity around three words: “Privacy. That’s Apple.” A class action complaint filed in the Northern District of California says that slogan is a marketing weapon aimed at the exact fear it profits from. The case is Simpson v. Apple, Inc., Case No. 5:26-cv-06307, filed June 24, 2026.
The Non-Financial Ledger
The people in this case did the responsible thing. They read the ads. They chose Safari specifically because Apple told them it stops strangers from watching what they read, search, and click. Plaintiff Sarah Simpson bought two new iPhones in 2025 and used Safari because she “values her online privacy” and believed Apple’s word that she would be protected.
What the complaint describes is a quiet betrayal of that trust. A user opens a fresh tab and sees a reassuring “Privacy Report” telling them Safari “prevents trackers from profiling you.” They switch to Private Browsing believing they have gone dark. The suit alleges that during all of this, the same tracking scripts they were told were blocked are running, harvesting the shape of their device and browser, and stitching their movements together across websites.
The harm here is not abstract. A 2025 study cited in the complaint found that fingerprinting can infer a person’s gender, age, income, and race from browser data, and that Hispanic users, non-white users, lower-income users, and older users are the easiest to identify. The people most exposed to this hidden surveillance are the people already targeted most.
Legal Receipts
These are Apple’s own public words, quoted in the complaint, set against the conduct the suit documents.
“Safari comes with industry-leading privacy protection technology built in, including Intelligent Tracking Prevention that identifies trackers and helps prevent them from profiling or following you across the web. And Private Browsing adds even more protections . . . . Online privacy isn’t just something you should hope forβit’s something you should expect.”
- This is the core promise the complaint treats as the express contract: that Safari’s built-in technology identifies trackers and blocks cross-web profiling.
- The suit alleges the reality contradicts every clause, with fingerprinting scripts loading and executing in both default and Private modes.
“advanced fingerprinting protection extending to all browsing by default”
- Apple’s 2025 iOS 26 announcement, quoted with the complaint’s own emphasis on “all browsing by default.”
- The suit alleges default Safari 26 provides “no defenses against canvas fingerprinting” and that users must “affirmatively make changes in Safari’s settings” to turn any protection on.
- This is the gap between “by default” and “only if you find the hidden switch.”
“In Private Browsing, connections are blocked to data collection companies that use advanced fingerprinting techniques and known tracking parameters are removed from all URLs.”
- The Privacy Report’s specific claim about Private Browsing mode.
- The complaint alleges the Adobe script instead “successfully requests WebGL contexts” and gathers user agent, language, time zone, screen dimensions, color depth, and pixel ratio. all standard fingerprinting inputs.
“While some browsers allow this cross-site tracking, Safari works endlessly to keep your data safe.”
- Language displayed inside Safari’s Privacy Report, positioning Safari as morally above rival browsers.
- The suit alleges this creates a “false sense of security” while the browser transmits the very data it claims to protect.
Public Deception: What You Were Told vs. What Was Running
The complaint’s sharpest allegation is that Apple’s own interface contradicts itself on the same screen. The Privacy Report labels a tracker blocked while Safari’s developer tools show that tracker actively loaded.
- Apple told users the Privacy Report shows “cross-site trackers currently prevented from profiling you.” The suit alleges well-known scripts like Adobe do not appear in the Privacy Report at all in default mode, even on sites where the Adobe script is present.
- Apple told users Private Browsing blocks connections to fingerprinting companies. The complaint alleges the Adobe script “executes successfully” and can “identify the individual user across those websites” within the same session.
- Apple told users the report reflects trackers “being blocked.” The suit alleges that when Adobe was listed as blocked in Private Browsing, “the script continued to transmit the user’s identifiable information.”
“When the Privacy Report listed Adobe as blocked in Private Browsing mode, the script continued to transmit the user’s identifiable information.”
The Anatomy of a Fingerprint
Fingerprinting does not need cookies. The complaint explains it combines ordinary browser data into an identifier unique enough to follow you from site to site, even after you close the tab.
Profit-Maximization at All Costs: Apple Cashes the Tracking Check
The complaint frames privacy as Apple’s brand while the tracking economy quietly pays Apple’s bills. The suit alleges Apple “benefits directly from third parties’ advertising business.”
- A 2023 Department of Justice proceeding against Google revealed that Google sends 36% of the advertising revenue it makes on the Safari web browser to Apple, according to the complaint.
- Apple reported 2025 fiscal year revenue of $416 billion, with internet-connected devices accounting for the majority of that revenue. The same devices ship Safari as the default browser.
- The suit alleges fingerprinting is “extremely lucrative,” citing a 2025 study finding that browser fingerprinting “significantly influenced the amount advertisers bid” in header-bidding ad auctions.
- By marketing anti-tracking while collecting a cut of ad revenue tied to that tracking, the complaint alleges Apple sits on both sides of the surveillance market it publicly condemns.
Legal Minimalism: The Letter but Not the Spirit of “By Default”
The complaint’s central technical charge is that Apple satisfied the words of its promise while defeating its purpose. Protection technically exists; it just is not on.
- Apple announced fingerprinting protection “extending to all browsing by default.” The suit alleges that in Safari 26, “users browsing in default mode must affirmatively make changes in Safari’s settings to enable any kind of fingerprinting protection.”
- The purpose of a default setting is to protect people who never touch settings. The complaint notes users must first “find the appropriate settings to change. something that the average consumer is unlikely to know how to do.”
- The Privacy Report satisfies the appearance of transparency. The suit alleges it “does not detect common fingerprinting scripts and does not flag them,” which the complaint says inverts the feature’s stated purpose into a source of false comfort.
Manufactured Consent: “Privacy. That’s Apple.”
The complaint documents a sustained advertising campaign built to convert consumer privacy anxiety into brand loyalty and premium sales.
- Apple made privacy its brand identity, “even going so far as saying: ‘Privacy. That’s Apple.'”
- The suit describes a recent ad campaign with billboards and TV spots stating “Your browsing is being watched. Safari helps stop it.”
- The complaint states Apple’s YouTube Safari ad “had been viewed over 20 million times,” which it uses to establish the “breadth of Apple’s audience” and the uniform exposure of the class.
- The suit alleges this scheme “has been disseminated to United States consumers over many years,” supporting a reasonable inference that the misrepresentations reached all class members.
Societal Impact Mapping
Economic Inequality
The complaint alleges the harm is not evenly distributed; the people least able to defend themselves are the easiest to fingerprint.
- A 2025 study cited in the suit found the “language attribute” leads to “greater ease of fingerprinting of self-identified Hispanic users and non-white users.”
- The same study found “lower income users and older users were found to be more susceptible to fingerprinting overall.”
- The complaint alleges class members paid a “premium for Apple products in the belief that they would be protected from tracking,” meaning consumers paid extra for a protection the suit says was not delivered.
Public Health of the Information Environment
The complaint warns the consequences go beyond targeted ads into targeted manipulation.
- The suit alleges “user demographics, such as gender, age, income level and race, can be inferred from browser attributes commonly used for fingerprinting.”
- It warns that when demographic data is inferred, “users are at risk of targeted information campaigns,” not merely targeted advertising.
- The complaint states fingerprints are “shared by and between third party advertising and data providers, monetizing users’ data and browsing habits without their consent.”
Who Pays? Following the Cost
The complaint describes a transfer of value that runs in Apple’s favor at the consumer’s expense.
- Consumers paid a price premium for Apple devices specifically for privacy protection the suit alleges was illusory, a documented out-of-pocket loss the class seeks to recover.
- The value of users’ identifiable browsing data flowed to third-party advertisers and data brokers “without their consent,” per the complaint.
- Apple absorbed a documented share of the resulting ad revenue through the alleged 36% Google-Safari revenue arrangement, while consumers absorbed the surveillance.
Impact Scorecard
The documented harms the complaint alleges, grouped by who absorbs them.
The “Cost of a Life” Metric
The complaint places Apple’s scale beside the promise it allegedly broke.
This Is the System Working as Intended
The complaint describes a structure where the company selling privacy also profits from the surveillance it claims to stop. That is not a glitch; the suit alleges it is the business model.
- Apple markets itself as the privacy alternative, yet the complaint alleges it receives 36% of Google’s Safari ad revenue, aligning Apple’s financial interest with the tracking it condemns.
- The suit alleges “fewer than two thirds” of the class are California citizens and the amount in controversy exceeds $5 million, invoking the Class Action Fairness Act because individual damages are too small to litigate alone. The complaint notes it would be “virtually impossible” for consumers to obtain redress individually.
- Without the class mechanism, the complaint warns, “Apple will be permitted to retain the proceeds of its misconduct,” which is precisely the outcome the structure otherwise produces.
What a Legitimate Fix Looks Like
This case exposes a core failure: a privacy claim marketed as automatic while the actual protection is off by default and the reporting tool that is supposed to prove protection instead conceals its absence. The following is editorial analysis, not a finding of the source document.
Regulatory Track
- The FTC should treat “by default” privacy claims as enforceable representations, requiring that any feature advertised as default actually operate without user configuration.
- Regulators should require that in-product privacy dashboards like the Privacy Report be independently audited against the browser’s actual network traffic, since the complaint alleges the two directly contradict each other.
- As a general industry standard, mandate plain-language disclosure of any revenue-sharing arrangement between a browser maker and an advertising firm whose scripts run in that browser.
Legislative Track
- Pass legislation defining browser fingerprinting as a form of tracking that requires opt-in consent, closing the gap the complaint describes where users “cannot completely prevent fingerprinting” without breaking their browser.
- Enact a private right of action for deceptive privacy marketing so consumers are not forced to rely solely on statutes like California’s UCL, FAL, and CLRA that the complaint invokes here.
- Require statutory penalties tied to a company’s revenue from the deceptive product, so a fine cannot be dwarfed by the profit it penalizes.
Corporate Governance Track
- Apple should be required to reconcile marketing claims with engineering reality before launch, with a compliance sign-off documenting that “default” features are actually enabled by default.
- Tie executive compensation partly to verified accuracy of privacy claims, removing the incentive to over-promise protection as a sales driver.
- Establish an independent internal audit of the Privacy Report and similar tools, reporting directly to the board rather than to the marketing organization.
What Now?
The named defendant is Apple, Inc., headquartered in Cupertino, California; the case is being litigated by Lynch Carpenter, LLP in the Northern District of California, San Jose Division.
- Watchlist: the FTC for deceptive advertising and privacy misrepresentation, and the DOJ, whose 2023 Google proceeding surfaced the 36% Safari revenue figure cited in this complaint.
- If you bought an Apple device with Safari pre-installed, preserve your purchase records; the proposed class covers all US purchasers and eligibility depends on documentation.
- Support digital rights organizations pushing for anti-fingerprinting standards and opt-in tracking consent, since the complaint shows individuals cannot self-defend against fingerprinting without breaking the web.
- Organize locally for right-to-repair and privacy literacy workshops so neighbors learn to check browser settings the complaint says “the average consumer is unlikely to know how to do.”
- Demand your representatives back statutory privacy penalties scaled to corporate revenue, so a $416 billion company cannot treat a settlement as a cost of doing business.
The source document for this investigation is attached below.
Explore by category
Product Safety Violations
When companies sell dangerous goods, consumers pay the price.
View Cases →Financial Fraud & Corruption
Lies, scams, and executive impunity that distort markets.
View Cases →


