Home › Guide
Privacy on a phone: what the device remembers
Two entirely separate questions get muddled together here — what your phone keeps, and what the network sees. They have different answers and different fixes, and most advice conflates them into something useless.
Two questions, not one
| The device remembers | The network sees | |
|---|---|---|
| What | History, cache, cookies, autocomplete, saved logins | Which domains you connected to |
| Who can look | Anyone holding the phone | Carrier, wifi owner, IT department |
| Fixed by | A private window | Using your own mobile data |
| Not fixed by | Mobile data | A private window |
That bottom row is the whole point. A private window does nothing about the network, and mobile data does nothing about the browser. If both matter to you, you need both, and neither takes any effort.
What a private window actually covers
More than people assume on the device, and nothing at all beyond it. Within the browser it leaves no history entry, keeps no cache or cookies after you close it, and — the one that actually catches people — does not feed the address bar's autocomplete. That last one is where most accidental discoveries happen: not someone going through a history list, but a URL suggesting itself while somebody else types.
What it does not do: hide anything from the wifi you are on, from your carrier, or from a site you log into. A private window with an account logged in is still an account.
You can use one right now — the rooms work fine in a private window with no account at all.
Notifications are the actual leak
Everything above concerns someone deliberately looking. Notifications hand the information to whoever happens to glance at a lock screen, which is a much more likely event.
This is the strongest argument against installing a cam site app, and it is worth being concrete: a "X is now live" banner on a locked phone, on a table, in a room with other people in it, is the single most plausible way this becomes a conversation you did not want. If you enable notifications at all, turn off content previews on the lock screen — and be aware that an installed app also means an icon, an entry in your app-store history, and an account tied to a device identifier.
Browser notifications from the site cover most of the benefit with none of the icon.
Shared and borrowed devices
The one case where managing the problem is worse than avoiding it. A family tablet, a work phone, a partner's laptop — the honest advice is not to use them for this, not because a private window fails but because everything else on a shared device is stacked against you: saved passwords from a previous session, a synced browser profile pushing history to another machine, an autofill entry, a screenshot in a shared photo library.
Work devices deserve their own sentence. A managed phone or laptop may report far more than a browser history — installed profiles can log domains regardless of private mode, and that record exists whether or not anyone ever reads it. There is no browser setting that solves a managed device.
The rest of the setup, on mobile
- A username that exists nowhere else. Same rule as everywhere; phones just make reusing one more tempting because of autofill.
- A separate email. And do not let the phone's password manager offer it alongside your usual one.
- Prepaid, if you buy tokens. Mobile payment sheets make buying fast and frictionless, which is precisely the problem.
- Camera off. Worth restating on mobile, where the camera is always physically present and a mis-tap is easier than on a desktop.
And the rule that a phone makes too easy: do not screenshot a performer. It violates the terms of every major platform, it is a criminal offence in a growing number of places, and on a phone it is two buttons pressed without thinking — which is exactly how people end up doing something they would not have chosen to do deliberately.
Free to watch in any browser — open the full room list .