ldstephens weblog

Security versus Privacy

July 21, 2026

I've been thinking about this a lot lately: security and privacy are often discussed as if they're the same thing, or at least on the same team. They're not. They represent two distinct concerns, and I've come to believe one must be addressed before the other.

Any computer — desktop, laptop, tablet, phone, or otherwise — stores your personal information. Security pertains to whether an unauthorized individual can access that information. Privacy, on the other hand, concerns what the company entrusted with your data does with it once they possess it. These are not the same problem, and I believe the order matters: your data must be secure before privacy even becomes a meaningful question. A privacy policy for data that has just been breached is worthless.

So, when I ask myself which one matters more, I consistently arrive at the same answer: security first, then privacy.

I used to be among those who avoided Google services due to privacy concerns, and I understand why. Google's business model relies heavily on knowing a lot about you, and its default settings often favor data collection over restriction. However, by choosing to avoid Google, many people end up using less secure alternatives. They've prioritized the second question while neglecting the first.

Here's where I've landed: I use a few Google services, specifically Gmail and Calendar, because I trust Google's security. Their track record for preventing account breaches, encrypting data, and catching threats before they reach users is difficult to surpass. I've also recently started using Chrome for the same reason: its robust security practices, plus its ease of use. However, I access Gmail and Calendar within the Apple ecosystem, not through Google's native apps. I use Gmail via Apple Mail, not the Gmail app, and Calendar via Apple Calendar, not Google's. This distinction is important. Apple's Mail Privacy Protection strips tracking pixels, App Tracking Transparency limits what any app can gather about me, and most of what my devices do day-to-day happens on-device rather than being sent to a server at all. When Apple does require cloud processing for more intensive tasks, it states that the request is processed on its own hardware and is neither stored nor reviewed.

In this setup, I gain security from one company and privacy from another, layered on top of each other. And it's worth noting: using Google services doesn't lock me into Apple. Google operates across every platform, so this isn't an all-or-nothing ecosystem commitment. I'm choosing to layer them this way; I'm not stuck doing it.

I'm not pretending this comes without a cost. Using Google services means relinquishing some degree of privacy, and that's not a naive tradeoff; it's a conscious one. I'm willing to make it because of the security I gain in return. And where possible, I reclaim some of that privacy by running those services through Apple rather than directly through Google.

That's really the whole point of this post. Not "use Google" or "use Apple," but rather: explicitly identify your tradeoffs, make deliberate choices, and don't let a vague, undefined sense of "privacy" dissuade you from the security you actually need. Figure out who you trust to keep the door locked. Then, figure out who you trust with what's inside.

Next post: