It's true, however, that they don't want to share it. It may even be true that they specifically don't want the NSA etc to steal it from them. And indeed, I recall an unofficial Google response to Snowden's leaks:
> Fuck these guys.
> I've spent the last ten years of my life trying to keep Google's users safe and secure from the many diverse threats Google faces… But after spending all that time helping in my tiny way to protect Google -- one of the greatest things to arise from the internet -- seeing this, well, it's just a little like coming home from War with Sauron, destroying the One Ring, only to discover the NSA is on the front porch of the Shire chopping down the Party Tree and outsourcing all the hobbit farmers with half-orcs and whips.
https://www.theverge.com/2013/11/6/5072924/google-engineers-...
So anyway, DDG arguably gives users some privacy from Google. But neither has a better claim to providing privacy from the NSA etc. Indeed, maybe it's Google that does, given their greater resources.
If you want more than that, use some mix of VPNs and Tor. Or if you're not feeling lucky, stay off the Internet ;)
According to the State of California Department of Justice [0], the last publicly acknowledged data breach from Google was March 9th, 2017. Before that it was August 10th, 2016, and before that March 29th, 2016.
Here's a quote from one of them:
"We recently learned that certain hotel reservations made for Google business travel were among the many reservations affected by a security incident impacting a third-party provider’s electronic reservation system that serves thousands of travel agencies and hotels. This did not affect Google’s systems. However, this incident impacted one of the travel providers used by Googlers, Carlson Wagonlit Travel (CWT)."
Many users are paranoid about ToS and how companies (esp the big guys) make money either by learning your behaviors (search preference, sites you visited) or selling your data to a partner (Foursquare, although they claim to only sell location data which are anonymous). We have a blind-trust with service providers. We let service providers to collect everything about ourselves, but internally they can decide whether to discard "sensitive data" early on or not during data processing (but web logs would have the trace).
Has anyone every inspect the traffic, or reverse the API in <your wearable device> (e.g. Fitbit?) What about file sharing companies? Are they storing your data in a secure way and without reading what's in your file? What about sites that let you compare prices across multiple stores? What about medtech startups? What about when the company is acquired?
Because the giants are more eye-catching, we don't see the smaller guys; but we are willing to give away sensitive and private data to the smaller guys because? If the argument is "well the big guys should have known better and have more resources to do the right thing", then I argue that by 2017 the new startups are doing the right things (not making the same well-known security flaws for example). I have doubt; I doubt many achieve 50% of what is on the imaginary checklist. The claim "we build MVP" is the equivalent of the big guys saying "we know what we are doing, don't worry."
No, we don't know better. No, your MVP should be secure enough so users can trust you. I almost never try a newly launched service because I really don't want to be a lab rat. I am sorry if that sounds cynical, but I don't trust myself doing everything right. If you let me choose between a new file sharing startup vs others, I'd go with either Dropbox, Google Drive or OneDrive (FWIW, Google is replacing Drive with a new service). Why? Because if the big guy is compromised, well, shit, thousands or millions will be affected. The least cynical version is, well, they are too big to do stupid things (of course not true in reality).
Our biases create illusions.
I think it is less about who you should trust to do the right thing and more of how much you trust an individual group to be able and willing to maintain the security of the data they have.
That is to say: it is more about the ratio of <stored data>/<security of stored data> rather than either of those values.
Google stores more data than I personally trust anybody to be able to store. Largely because they make themselves a huge target.
Equifax is a great example of storing WAY too much data. Sure, their practices are to blame, but I'd argue that them storing half the information they do is better than doubling their security (whatever that means). This is due to the compounding effect of being a smaller target.
DDG at least claims to not store as much of that information.
> When was the last time Google leaked your data.
If Google has one major leak, does the historical quantity of leaks matter?
EDIT: more thoughts.
That Google has your search or email data and that they can always sell it, or that the NSA has a direct link to them, those are separate discussions.