Be several people at once.
Twenty-five personas with their own interests, devices and browsing hours. The ones that contradict each other deliberately share a cookie jar, so a single identity accumulates beliefs that cannot all be true.
Self-hosted · privacy obfuscation
You cannot get your household out of the data-broker economy by asking nicely. DataChaff takes the other road: a real browser walks through mutually contradictory people — a luxury shopper and a frugal retiree, a gun owner and an environmentalist — loading the same tracking pixels your own browsing does, until the record being sold about you no longer agrees with itself.
Twenty-five personas with their own interests, devices and browsing hours. The ones that contradict each other deliberately share a cookie jar, so a single identity accumulates beliefs that cannot all be true.
A real browser, not a script hitting URLs. Every request is matched against a map of tracking domains, dozens of which belong to the data brokers whose business is knowing you.
A single visit reads as incidental. Audience segments are built from repeat visits with recency, so part of every session returns to pages that persona has already read.
Weekly it reads the profile back — which advertisers get served to a clean browser on the same connection, and which tracker companies hold a cookie for each fake person.
Interactive · nothing leaves your browser
Press the button and a fake person goes browsing. Watch what the broker on the right can still claim about the household. Every name, number and site below is invented for this page — no real profile, no network requests, no connection to a running instance.
Each run picks the persona that least resembles the last one.
Attributes it has inferred, and the segments it would put this household in.
A clean profile. Every attribute agrees with the others.
The running thing
The home screen answers three questions: is it running, what has it fed, and is the profile getting worse for the people buying it. The detailed instrument panel is one click away for when you want tracker categories, session history and per-subsystem landing rates.

How it works
It does not try to defeat bot detection and it does not scrape anything. It browses slowly and deliberately, in the ways that corrupt behavioural targeting: contradictory identities inside one cookie jar, repeat visits, product pages that move an identity into the expensive in-market segments, and junk details submitted to the newsletter forms that sell your address on.
The junk only lands on your profile if it carries your household identity, which brokers key to your connection — so by default the browser runs outside any VPN tunnel. That tradeoff is the whole design, and it is yours to make: the machine doing the browsing is no longer private, and everything else on your network is untouched.
Everything it does is recorded so the claims can be checked: which trackers fired on which page, which contradictions a broker could actually observe, and which of its own subsystems are landing.
Honestly
Nothing here removes a record from a broker's database. The profile stays; it just stops being reliable. If you want deletion, file the requests — this is what you run in addition.
Google and Meta hide inferred interests behind a login, and the industry opt-out tools no longer report per-company cookie presence. The proxies — which advertisers start bidding, which orgs hold a cookie — are the honest substitutes.
Most retailer search pages serve a challenge to anything automated, and search engines do the same to a fresh browser profile. It measures which ones still answer and routes around the rest; it never tries to solve a challenge.
Blocking protects the browsing you do now. This works on the profile that already exists, which blocking cannot reach. Run both.
Impressions served to a fake person are billed to advertisers. The page reports that as a range rather than a boast, and ad clicking is capped hard and off by default in the shipped configuration.
This is single-user software for a machine you own, not a service. It has no multi-tenant story and is not trying to acquire one.
The measurable part does. The weekly readback records which advertisers are served to a clean browser on the same connection, and per-persona ad targeting shows up in the report — beauty ads to the fashion persona, trucks to the gearhead. Whether a specific broker's segment membership flips is not something they will tell you, or me.
No. It browses at human pace with dwell times, session shapes that vary from a bounce to a long sit, and a per-domain cooldown. Roughly a dozen sessions a day, a hundred-odd pages. A single person reading the news makes comparable traffic.
There is a never-touch list of around 190 domains — banks, email, health services, government, anything with a stored payment method — that is never navigated to, never followed into, and never has cookies imported. Checkout is never reached; nothing is ever bought.
No. It never logs into anything of yours. The fake identities use an email domain with no mail server, so the junk signups reach nobody.
A spare Linux machine — mine is a Raspberry Pi 4 running it as a user service, one browser and a few hundred megabytes. There is a web UI on the local network with a password gate.
Yes — it is free software under the GNU AGPL v3 or later. The repository carries the installer, the tracker map, the persona files and the test suite. If you want to talk through the measurement approach or the parts that did not work, get in touch; the failures are the interesting half.