I don’t know if I can assuage your concerns but…
- any project like this goes through layers of lawyers on both sides (mit and the brokerage). They are extremely careful about exactly your concern.
- mit has infrastructure to securely hold data. They do a ton of defense work, for example. They take it seriously. In the non-defense context, accidentally exposing certain health data can (iirc) lead to the entire university losing eligibility for NIH funding. At MIT that might be a half billion dollar hit. They don’t mess around with that. (Compare to the private sector where there are effectively no meaningful fines or consequences for data breaches.)
- none of the researchers care about you as an individual enough to try to deidentify you in the data. I work with health data, some of which includes addresses. I have never thought for even one second that I should find out who lives at the address, even when dealing with data which includes the city I live in (so potentially my neighbors, eg.)
- everyone involved in the project also separately promises not to de-identify anyone. Again: I really doubt anyone I have ever met in my field would care identify someone, but we do promise not to.
- any data which is going to be merged with whatever the researchers got from the brokerage will be outlined in great detail in advance.
As another point of comparison, how many breaches of university research data are you aware of? These things happen in the corporate world all the time with extremely sensitive data but I have not heard of university data beaches myself.
Finally, there is generally some scientific benefit to the work that the researchers do. We know something from this paper about panic selling which we didn’t know before. That may be valuable.