← All guides

Privacy & your data

Presence signals: what online status, last seen, and typing indicators give away

A green dot looks like a courtesy. Left on for a year it is a log of when you sleep, when you work, and who you answer first. What presence signals actually broadcast, and how to decide what to leave on.

By Sarah LeeUpdated 2026-09-07 min read

Almost every messaging product shows some version of the same three signals: a dot saying you are online, a timestamp saying when you last were, and a flicker saying you are typing. They are presented as conveniences, and individually they are. The problem is that they are not individual. They accumulate.

A single "last seen 14:32" tells someone almost nothing. Nine months of them tells someone when you wake up, when you commute, when you are at your desk, when you go quiet on Sundays, whether you were awake at 03:00 last Tuesday, and — if they compare notes with a mutual contact — whose messages you open first.

None of that is content. All of it is inference. This guide is about what each signal actually leaks, and how to make a deliberate choice rather than inherit a default.

The three signals are not the same thing

They get grouped into one settings screen, which encourages people to treat them as one decision. They are not.

Online status is a live boolean. It answers "is this person reachable right now?" and nothing else. It expires the moment you close the app. Its privacy cost is real but bounded: an observer has to be watching at the time.

Last seen is a stored timestamp, and this is the one that matters. It answers "when was this person last reachable?" and, crucially, it can be sampled. Anyone can check it once an hour for a month with no effort at all. Online status requires attention to exploit; last seen does not. That asymmetry is why last seen is the single most revealing presence signal in any messenger, and why it is the one worth restricting first.

Typing indicators are the narrowest and the most socially loaded. They reveal nothing about your schedule. What they reveal is hesitation: that you started a reply, stopped, started again, and sent something shorter than what you deleted. In a healthy conversation that is invisible texture. In a tense one it is evidence.

What can be inferred, concretely

Presence data is metadata, and metadata is the part of communication that is easiest to analyse at scale precisely because it needs no interpretation. From presence alone, an attentive observer can usually establish:

  • Your sleep window, within about an hour, after a week.
  • Your working pattern — office hours, shift work, freelance, unemployed — after two or three weeks.
  • Your time zone, and therefore roughly where you are, including when you have travelled.
  • Your response hierarchy. If two people compare when you came online against when each of them received a reply, they learn who you prioritise. This is a common flashpoint and it requires no technical skill whatsoever.
  • Deviation. The genuinely sensitive inference is not the pattern, it is the break in it. Being online at an unusual hour, or absent for an unusual stretch, is legible to anyone who has watched long enough to know what usual looks like.

Note that none of this requires the observer to message you, and none of it leaves a trace you can see.

Who is actually looking

For most people the honest answer is: almost nobody, most of the time. Presence is not a mass-surveillance problem. It is a close-range one, and the risk profile is unusual in that the people best positioned to exploit it are the people already in your contact list.

The situations where it genuinely matters:

  • After a relationship ends, where an ex-partner retains visibility into your daily rhythm and uses it as a substitute for contact you have declined to give.
  • In coercive relationships, where being online and not replying becomes something to answer for. Presence turns availability into an obligation, and an obligation into leverage.
  • Under targeted harassment, where a stalker builds a routine map and, occasionally, a physical one from time-zone drift.
  • In employment, where a manager or colleague reads presence as a productivity metric it was never designed to be.
  • In social engineering, where an attacker times a fraudulent message to arrive while you are demonstrably online, active and moving quickly — the state in which people scrutinise least. This is the one most people never think about, and it is the reason presence belongs in a security review and not only a privacy one.

Reciprocity, and why it exists

Many products enforce a rule: if you hide your last seen, you cannot see anyone else's. This regularly reads as a punishment and it is not. It is the only design that resists a specific abuse — one person watching everyone while remaining invisible, which is the exact configuration a stalker wants.

Reciprocity makes presence a mutual disclosure rather than a one-way window. It is worth understanding before you assume a product is being obstructive, and worth checking for, because where it is absent, one-way observation is possible and someone will be doing it.

Read receipts are a different problem

Read receipts often sit on the same settings screen, but the harm they cause is social rather than informational. A read receipt does not tell an observer much about your life. It tells them, unambiguously, that you saw their message and chose not to answer yet.

That removes ambiguity, and ambiguity is load-bearing in human communication. "Maybe they haven't seen it" is a small kindness that lets a delay stay neutral. Delivered-but-unread is a fact that has to be explained.

The same reciprocity rule usually applies, and the same reasoning holds. If you find yourself replying to messages faster than you want to, or opening messages on a lock screen specifically to avoid marking them read, the setting is already costing you something. That is a sufficient reason to turn it off.

A configuration that works for most people

There is no universally correct answer, but there is a sensible default that trades very little convenience for most of the benefit:

  1. Restrict last seen first. Limit it to people you actually know, or turn it off entirely. This removes the sampling attack, which is the only presence signal an observer can exploit passively over months.
  2. Leave online status on if it is useful to you — for coordinating calls, or for people who need to know whether to phone instead. It expires on its own and cannot be mined after the fact.
  3. Treat typing indicators as optional. They add warmth to conversations that are already warm and pressure to ones that are not. Turn them off if any of your conversations are the second kind.
  4. Turn read receipts off if you feel obliged by them. Keep them on if you find the acknowledgement genuinely useful and your correspondents do too.
  5. Do not stop at messaging. Story and post view receipts, "active now" badges in contact lists, and shared-document presence indicators leak the same class of information and are usually configured somewhere else entirely.

Two things to check that people miss

Group chats. Some products apply your presence settings per-audience but expose "active now" inside groups regardless, which means a group of forty people is a wider audience than your own contact list. Check what a group reveals separately from what a direct conversation does.

The settings are usually split. Presence controls tend to be scattered across a privacy screen, a chat screen, and sometimes the operating system's own notification settings. Changing one and assuming the rest followed is the most common mistake here. Verify by asking a friend what they can see.

The point

Presence settings are worth ten minutes once, and then never again. The reason to spend the ten minutes is not that a green dot is dangerous. It is that defaults are set for engagement, they are set for everyone, and they quietly assume that the person watching you means well.

Usually that assumption holds. It costs almost nothing to stop relying on it.

Related guides