- Stop Uploading Your Life to Strangers: A Practical Guide to Avoiding SaaSS
- What SaaSS Takes From You
- Ten Practical Scenarios Where SaaSS Endangers You
- 1. Political Activity Notes (Google Docs vs. LibreOffice)
- 2. Medical Records and Symptoms Tracker (Notion vs. Local Database)
- 3. Domestic Violence Safety Plan (Evernote vs. Encrypted Local Notes)
- 4. Whistleblower Evidence and Documentation (Dropbox vs. Local Encrypted Storage)
- 5. Immigration and Asylum Application Materials (OneDrive vs. Local Files)
- 6. Union Organizing Communications (Slack vs. Self-Hosted Chat)
- 7. Sexual Assault Support Group Records (Facebook Groups vs. Encrypted Alternatives)
- 8. Financial Records and Tax Documents (Mint/Personal Capital vs. Local Spreadsheet)
- 9. Journalistic Source Communications (Gmail vs. Self-Hosted Email)
- 10. Children's School and Behavioral Records (Google Classroom vs. Local Files)
- How to Check If a Service Is SaaSS
- Practical Steps to Leave SaaSS Behind
- The Bottom Line
Stop Uploading Your Life to Strangers: A Practical Guide to Avoiding SaaSS
Learn exactly which services take control of your computing and how to replace them with free software that keeps your sensitive data on your own devices.
When you use Google Docs, Notion, or similar services, you are not just using a tool. You are handing your computing to someone else’s server. Richard Stallman calls this SaaSS — Service as a Software Substitute. It means the server does your own computing that you could do locally with free software. The harm is not abstract. It is your wife’s political notes, your child’s medical records, and your family’s safety plans sitting on servers you do not control.
SaaSS (Service as a Software Substitute) means using someone else’s server to do your own computing when you could do it locally with free software. Instead of running a program on your own computer where you control it, you send your data to a remote server owned by a company, they process it, and send back results. The problem is not just that they see your data — it is that they control the computing itself. You cannot audit what the server does, you cannot modify it, you cannot share it, and you cannot run it offline. Examples include Google Docs instead of LibreOffice, ChatGPT instead of a local LLM, or Notion instead of local encrypted notes. With SaaSS, you surrender the four essential freedoms of free software: you cannot run the program as you wish, study its code, share copies, or distribute improvements. You are also vulnerable to surveillance, data breaches, account bans, and terms changes. SaaSS treats you as a user of a service, not as an owner of your computing.
What SaaSS Takes From You
Free software gives you four essential freedoms (https://www.gnu.org/philosophy/free-sw.html):
- Run the program as you wish
- Study and change the source code
- Share copies with others
- Distribute your modified versions
SaaSS takes all four. You cannot run the server software. You cannot study it. You cannot share it. You cannot modify it. Worse, the server sees everything you do.
Ten Practical Scenarios Where SaaSS Endangers You
1. Political Activity Notes (Google Docs vs. LibreOffice)
The SaaSS trap: You create a Google Doc called “Community Meeting Notes.” Inside, you write meeting locations for your wife’s housing justice group, contact lists of tenants facing eviction, strategy discussions for rent strikes, and protest plans for city hall.
What actually happens: Google scans every word. Their automated systems flag content. In the United States, this data can be shared with government agencies without your knowledge. If your wife organizes in a country with authoritarian tendencies, this information can lead to arrests, surveillance, travel bans, or worse. Google retains this data indefinitely, even after you “delete” it.
What you do instead:
- Install LibreOffice:
sudo apt install libreofficeon Debian or Ubuntu - Create your document locally in Writer
- Save to an encrypted folder using VeraCrypt or GnuPG
- Share via encrypted email or in-person USB transfer
- For collaborative notes, use CryptPad (self-hosted) or meet locally
Your wife’s political work deserves protection, not exposure.
2. Medical Records and Symptoms Tracker (Notion vs. Local Database)
The SaaSS trap: Your child has a rare disease. You create a Notion page to track daily symptoms, medication dosages, doctor appointments, test results, and insurance correspondence. It is convenient to share with grandparents and specialists.
What actually happens: Notion stores this health data on their servers in the United States. HIPAA does not cover consumer apps like Notion. This means your child’s medical information can be sold to data brokers, used by insurance companies to deny future coverage, or exposed in data breaches. Notion employees can access this data. If Notion changes their terms, you lose access.
What you do instead:
- Install Joplin:
sudo apt install joplinor download from joplinapp.org - Enable local-only storage (no cloud sync)
- Encrypt your notes with a strong passphrase in Settings → Encryption
- For sharing with doctors, export as PDF and send via encrypted email
- For family access, set up self-hosted Syncthing to sync encrypted notes between trusted devices
Your child’s health information belongs to your family, not to Notion’s investors.
3. Domestic Violence Safety Plan (Evernote vs. Encrypted Local Notes)
The SaaSS trap: A woman escaping abuse stores her safety plan in Evernote: safe house addresses, hidden money locations, lawyer contacts, evidence photos of injuries, and a timeline of abuse incidents.
What actually happens: Evernote can be subpoenaed by the abuser’s lawyer. Account recovery options may notify the abuser if they share devices or phone numbers. Location metadata in photos can reveal the safe house. Evernote’s servers keep deleted items in backups for months.
What you do instead:
- Use Standard Notes with local-only mode enabled
- Or create encrypted text files with GnuPG:
gpg -c safety-plan.txt - Store on a USB drive kept separately from your daily devices
- Use a paper backup stored with a trusted friend
- Never use cloud sync for safety-critical information
Survivors need tools that protect, not expose.
4. Whistleblower Evidence and Documentation (Dropbox vs. Local Encrypted Storage)
The SaaSS trap: An employee discovers corporate fraud. They save internal emails, financial records, and safety violation photos to Dropbox for backup and easy sharing with journalists.
What actually happens: Dropbox scans all files for “policy violations.” They comply with corporate legal demands without notifying users. The company being exposed could subpoena Dropbox to identify the whistleblower before they are ready to go public.
What you do instead:
- Create a VeraCrypt container:
sudo apt install veracrypt - Store evidence inside the encrypted container
- Keep on an external drive disconnected when not in use
- Share via SecureDrop (https://securedrop.org) when ready to publish
- Use Tor for all communications related to the disclosure
Whistleblowers protect the public. Their tools should protect them.
5. Immigration and Asylum Application Materials (OneDrive vs. Local Files)
The SaaSS trap: A refugee family stores asylum documents in OneDrive: persecution evidence, identity papers, witness statements, and country condition reports to share with their immigration lawyer.
What actually happens: Microsoft complies with government data requests. If the family’s home country government requests this data through legal channels, it could endanger relatives still there. Immigration status is extremely sensitive information.
What you do instead:
- Store documents in an encrypted folder with GnuPG
- Share with lawyers via encrypted email (Enigmail for Thunderbird)
- Keep paper copies in a secure physical location
- Use Signal’s disappearing messages for time-sensitive document photos
- Never store asylum materials on servers controlled by US corporations
Migration status should not be data-mined for profit.
6. Union Organizing Communications (Slack vs. Self-Hosted Chat)
The SaaSS trap: Workers create a Slack workspace to coordinate union organizing: wage data, strategy discussions, member contact lists, and documentation of employer violations.
What actually happens: Slack is owned by Salesforce. They can be subpoenaed by the employer. Management could identify organizers before the union goes public, leading to firings, blacklisting, or union-busting retaliation. Slack retains all messages indefinitely.
What you do instead:
- Set up a self-hosted Matrix server (Synapse) with Element client
- Or use Signal groups with disappearing messages enabled
- For in-person coordination, use encrypted offline messaging apps
- Never store member lists or wage data on corporate servers
- Train all organizers on operational security basics
Worker power requires communication the boss cannot see.
7. Sexual Assault Support Group Records (Facebook Groups vs. Encrypted Alternatives)
The SaaSS scenario: Survivors create a private Facebook Group to share stories, therapist recommendations, legal resources, and meeting times.
What actually happens: Facebook scans all content for advertising profiles. Data breaches expose sensitive information. Subpoenas in custody battles or legal cases can reveal group membership. Facebook’s algorithms may recommend the group to others, breaking anonymity.
What you do instead:
- Set up a self-hosted forum with Discourse over Tor
- Or use an encrypted mailing list with PGP signatures
- Meet via Signal groups with member approval required
- Never use real names or identifiable information
- Host support group servers outside the jurisdiction of potential legal threats
Survivors deserve privacy that corporations cannot violate.
8. Financial Records and Tax Documents (Mint/Personal Capital vs. Local Spreadsheet)
The SaaSS trap: You connect all bank accounts, investment records, tax documents, and retirement planning to Mint for “convenient tracking.”
What actually happens: The service builds a complete financial profile sold to advertisers and lenders. Intuit shut down Mint in 2024, leaving users without access to their own financial history. Data breaches expose account numbers and net worth information.
What you do instead:
- Install GnuCash:
sudo apt install gnucash - Import transactions directly from bank CSV exports
- Store files in an encrypted folder
- Backup to external drive weekly
- For tax documents, use local PDF storage with encrypted backup
Your financial life is not a product to be sold.
9. Journalistic Source Communications (Gmail vs. Self-Hosted Email)
The SaaSS trap: A journalist communicates with confidential sources about corruption investigations via Gmail.
What actually happens: Google scans all emails. Governments request records with gag orders preventing notification. Source identities can be revealed through metadata even when content is encrypted. Google retains deleted emails in backups.
What you do instead:
- Set up a self-hosted mail server with encryption
- Use PGP for all source communications (GnuPG)
- For anonymous submissions, use SecureDrop
- Never discuss source identities over email
- Use Signal for time-sensitive coordination
Protecting sources is journalism’s foundation. Gmail cannot protect them.
10. Children’s School and Behavioral Records (Google Classroom vs. Local Files)
The SaaSS trap: Parents store children’s IEP documents, behavioral assessments, therapist notes, and school communications in Google Classroom and Drive.
What actually happens: Google builds permanent profiles on minors. Data persists indefinitely and can follow children into adulthood, affecting college admissions, employment background checks, or insurance. COPPA protections are minimal and easily bypassed.
What you do instead:
- Store documents in encrypted local folders
- Share with schools via encrypted email when required
- Keep paper copies of all official documents
- Request deletion of school-held digital records when possible
- Never consent to third-party educational technology without reading privacy policies
Children cannot consent to lifelong surveillance. Parents must protect them.
How to Check If a Service Is SaaSS
Use this checklist before uploading anything:
| Question | If Yes, It Is SaaSS |
|---|---|
| Does the computing happen on their server? | You do not control it |
| Can you download and run the software locally? | If no, you cannot audit it |
| Do they retain your data after deletion? | You cannot truly delete |
| Can they read your content? | Privacy is impossible |
| Can they share data with third parties? | You are the product |
| Does it require an account? | You can be deplatformed |
| Can terms change without consent? | Your rights are temporary |
Practical Steps to Leave SaaSS Behind
Step 1: Audit Your Current Services
Make a list of every service where you upload personal data:
- Cloud storage (Google Drive, Dropbox, OneDrive)
- Note-taking (Notion, Evernote, OneNote)
- Email (Gmail, Outlook.com, Yahoo)
- Documents (Google Docs, Microsoft 365)
- Photos (Google Photos, iCloud)
- Messaging (WhatsApp, Facebook Messenger, Telegram)
Step 2: Prioritize by Sensitivity
Start with the most dangerous data first:
- Political or activist information
- Medical and health records
- Legal documents and cases
- Financial records
- Children’s information
- Work documents with confidential information
Step 3: Install Free Software Alternatives
On Debian or Ubuntu, run:
# Office suite instead of Google Docs
sudo apt install libreoffice
# Email client instead of Gmail
sudo apt install thunderbird
# File manager with encryption support
sudo apt install thunar veracrypt
# Note-taking without cloud
sudo apt install joplin
# Password manager
sudo apt install keepassxc
# File sync without servers
sudo apt install syncthing
Step 4: Set Up Encryption
# Install GnuPG
sudo apt install gnupg
# Generate your key
gpg --gen-key
# Encrypt a file
gpg -c sensitive-document.pdf
# Decrypt when needed
gpg sensitive-document.pdf.gpg
Step 5: Migrate Your Data
- Download all your data from SaaSS services (use Google Takeout, etc.)
- Store locally in encrypted folders
- Delete from cloud services after confirming local backup
- Inform contacts of your new secure communication methods
Step 6: Join the Free Software Community
You are not alone. Connect with others at https://lists.gnu.org/ where free software users and developers work in public. Ask questions, share your migration experience, or contribute to projects you use.
The Bottom Line
SaaSS is not just “using a website.” It is letting someone else’s server do your own computing — computing that you could do locally with free software. The harm is not just privacy. It is the loss of sovereignty over your own digital life.
When you upload your wife’s political notes to Google, your child’s medical records to Notion, or your family’s safety plan to Evernote, you are trusting corporations with information that could endanger lives. These corporations answer to investors, not to you. They comply with governments, not with your rights.
Free software gives you control. You can run it, study it, change it, and share it. Your data stays on your devices. Your computing happens on your terms.
Read more about why this matters: https://www.gnu.org/philosophy/free-sw.html
Read about SaaSS specifically: https://www.gnu.org/philosophy/who-does-that-server-really-serve.html
Jean Louis, Free Software Supporter since 1999