What Your Mobile Carrier Knows About You (and What It Sells)
If you have ever typed what does my carrier know into a search bar, the answers tend to be vague reassurance or vague alarm. Neither helps. A mobile network is a machine with several observation points built into its architecture, and each point sees a specific slice of your life. One slice, location, cannot be switched off by any app or setting, because it is how the machine works.
Below: what is collected, why, who buys it, how long it is stored, and which tool shrinks which layer. No panic, no marketing. Just the architecture.
Layer one: identity. The name attached to the number
Most countries now require ID at SIM activation: a passport or ID scanned at sale and stored against the subscriber record. Postpaid contracts add an address, a credit check, and years of payment history.
Even where registration rules are loose, payment does the same job. A card ties the plan to an account that already passed bank KYC, and top-ups leave timestamps and purchase locations. Once the link between a human and an IMSI exists, every layer below stops being telemetry and becomes a named file.
Layer two: the radio. IMSI, IMEI and location around the clock
Two identifiers travel with you everywhere. The IMSI is the subscriber identity inside your SIM profile; the IMEI is the hardware serial of the phone. Every network attach presents both. Swap SIMs in the same phone and the IMEI links the old number to the new one. Move your SIM to a new phone and the IMSI does the linking. The carrier sees both sides of that graph.
Location follows from basic operation. To deliver a call or a packet, the network must know which cell serves you right now, so your phone constantly checks in with nearby towers, even while idle in a pocket. The carrier logs the serving cell and sector; add signal timing measurements such as timing advance, and the estimate tightens well below cell size. In dense urban networks it routinely resolves to a block. The output: a continuous, around-the-clock movement log. That is carrier tracking at its base, a byproduct of routing rather than a product bolted on.
Layer three: traffic. CDRs, DNS and the metadata of everything
Every call and SMS generates a call detail record, a CDR: the number on each end, timestamp, duration, and the serving cell at the time. Data sessions generate their own records: volumes, session times, assigned IPs. The metadata alone maps your social graph, schedule, and habits.
On the internet side, two quieter channels matter. DNS: if your phone uses the carrier's default resolver, the carrier sees every domain you look up. SNI: when a TLS connection opens, the hostname travels in cleartext in the handshake, so the carrier sees which sites you visit even over HTTPS, unless the connection uses Encrypted Client Hello, which is still rare. Volumes and timing round out the picture.
What the carrier does not see is content inside TLS, and it cannot read end-to-end encrypted messengers. Your Signal messages are unreadable in transit; what stays visible is that your device talked to Signal's servers, when, and how much. The physical path of your packets matters too. We traced it in where eSIM traffic routes, and with travel eSIMs it is less local than most people assume.
Roaming: two operators see two halves
Cross a border and the picture splits. The visited network, whose towers you are using, sees the radio and traffic layers in full: IMSI and IMEI, serving cells, data sessions. It does not necessarily know your name, since your contract is not with them.
Your home operator keeps the identity and billing layers and gains a new signal: which country and which partner network you are on, through roaming signaling and wholesale billing. Where data is home-routed, it keeps seeing the traffic layer too. Roaming does not reduce visibility. It duplicates it across two databases in two jurisdictions.
The selling part: 200 million dollars in fines
For years the open question was how far the resale chain went. US carriers sold real-time subscriber location to aggregators such as LocationSmart and Zumigo, who resold it onward. In 2018 it surfaced that Securus, a prison telecom company, was offering location lookups on nearly any US phone to law enforcement without warrants. Days later, a researcher found that LocationSmart's own demo page let anyone locate almost any US phone in real time, to within roughly 100 yards to 1.5 miles.
The regulatory bill arrived in April 2024. The FCC fined the major US carriers nearly 200 million dollars combined for selling access to customers' location information without consent: 80 million for T-Mobile, more than 57 million for AT&T, almost 47 million for Verizon, and more than 12 million for Sprint. The fines were sized partly by how many days each carrier kept selling after being told the practice was unlawful.
A common defense is that sold datasets are anonymized. Location data resists anonymization: where a device sleeps every night and where it spends working hours identifies most people uniquely. Stripping the name from a movement trail does little when the trail is the fingerprint.
How long they keep it
The honest summary on retention: longer than most people expect. The US has no single retention law for wireless records; carriers set their own schedules. An internal FBI reference document published by journalists in 2021 listed call detail records held roughly seven years at AT&T, two years at T-Mobile, and one year at Verizon. The order of magnitude is years, not weeks.
The EU went the other direction. The Data Retention Directive, which forced blanket retention of telecom metadata for six months to two years, was struck down by the Court of Justice in 2014 in Digital Rights Ireland as a disproportionate intrusion on privacy. What replaced it is a patchwork of national laws that courts keep trimming back. In practice, metadata is still retained across much of Europe, under national rules with varying limits.
The layer nothing can hide
A privacy article owes you this part before recommending anything. While a SIM is active, the network knows which cell serves it. That is not a collection policy a carrier could reverse under pressure; it is the physical requirement for delivering service. No serving cell, no calls, no packets.
So no VPN, browser, or app setting changes what the radio layer sees. The only true off switches are airplane mode and power off, and both mean no connectivity. What you can change is whether that movement log carries your name, and what the traffic beside it reveals.
What reduces which layer
Each tool below shrinks exactly one slice of carrier visibility. None is a general cloak, and they do not substitute for each other.
- A VPN moves the traffic layer out of the carrier's sight: DNS, SNI and destinations collapse into one encrypted tunnel. The carrier still sees the tunnel itself, volumes, timing, and, unchanged, your location.
- End-to-end encrypted messengers protect content and shrink CDR exposure: a Signal call over data creates no classic call record with the other party's number.
- A no-KYC eSIM removes the identity layer. Bought with no name, no ID and crypto, the subscriber database holds a paying customer but not a person. Radio and traffic still exist, just not pre-labeled with you.
- A separate travel device breaks linkability: a different IMEI with a different eSIM does not chain back to your main phone's identifiers.
A no-name eSIM plus a VPN covers two layers at once; we wrote up when you actually need both in do you need a VPN with an eSIM. The full map:
- Data type — Who sees it — How to reduce
- Name, ID, payment — Carrier, if KYC or card was involved — No-KYC eSIM bought with crypto
- IMSI and IMEI — Every network the device attaches to — Separate travel device; cannot be hidden while connected
- Tower-level location, 24/7 — Serving network, continuously — Nothing while the SIM is active; airplane mode only
- Calls and SMS metadata (CDR) — Carrier on both ends — E2E messengers over data instead of calls and SMS
- DNS queries — Carrier, if using its resolver — Encrypted DNS or a VPN
- SNI hostnames over HTTPS — Carrier, per connection — VPN; ECH where supported
- Traffic volume and timing — Carrier and roaming partner — VPN hides destinations, not volume
- Content of HTTPS and E2E chats — Not visible in transit — Already protected by design
- Your carrier does not need to read a single message to know you. Who, when, where, and how much is already a biography. Content is almost beside the point.
Where Cypher eSIM stands
We sell one layer of this fix. Cypher eSIM is a no-KYC travel eSIM for 180 plus countries: no account, no email, paid in crypto (USDT on TRC-20, BEP-20, Arbitrum and Solana, plus BTC, ETH, SOL, USDC, DAI, XMR and TON) through the website with an opaque order token or through the Telegram bot. An order in our system is a plan, an amount, and an ICCID. We do not store connection history, and there is no name field because there is no name.
What that buys you is the identity layer: the movement log and traffic metadata above still exist at the network level, as with any provider, but they are not pre-attached to your passport. What it does not buy you is invisibility. No-KYC is not anonymity, an eSIM is not a VPN, and the radio layer works the same for everyone. That stays true as we add voice and SMS in August 2026: calls will generate call records like calls anywhere, minus the subscriber name.
FAQ
Can my carrier see what I do on HTTPS sites?
It sees which hostnames you connect to, via SNI in the TLS handshake and via DNS if you use its resolver. It cannot see page contents, credentials, or messages inside TLS. A VPN moves even the hostname visibility away from it.
Does a VPN hide my location from my carrier?
No. Location comes from the radio layer: your phone's contact with towers. A VPN encrypts traffic above that layer and changes nothing about it.
Does my carrier listen to my calls or read my texts?
Routine collection is metadata: numbers, timestamps, durations, serving cells. Classic SMS is unencrypted in transit and technically readable by the carrier, one reason to prefer E2E messengers.
Is an anonymous prepaid SIM enough to remove the identity layer?
Where no ID is required, partly. Payment is the usual leak: a card or registered wallet re-links the plan to you. A no-KYC eSIM paid in crypto removes both the ID record and the payment linkage.
Does an eSIM change what the network sees?
No. The radio layer is identical: IMSI, IMEI, serving cells. What a no-KYC eSIM changes is the database entry behind the profile: the trail exists but has no name on it.
So, what does your carrier know? Where your device is at all times, who you call and message, which services your traffic touches, and, depending on jurisdiction and payment, exactly who you are. The first item is physics. The other three are choices, yours to take back layer by layer.
- Take back the identity layer.No KYC, no account, no email. Crypto payment, 180 plus countries, eSIM in minutes.Get an eSIM at cypheresim.com ->Telegram bot: t.me/cypheresim_bot