The biggest privacy gain for most people comes from five moves done in order: a password manager with unique passwords, phishing-resistant multi-factor authentication or passkeys on email and banking, prompt software updates, a locked-down home Wi-Fi network, and basic tracker controls in your browser. Layer these together instead of picking one. A VPN can help in specific situations, like public Wi-Fi, but it is not a substitute for any of the steps above. The checklist sections below walk through each piece in order.
TL;DR:
- Ensuring account protection with unique passwords and phishing-resistant MFA is critical because email account takeover enables access to all linked services.
- Securing your home Wi-Fi with strong encryption, changing default credentials, and restricting device access prevents attackers from easily infiltrating your network.
- Using a password manager built on zero-knowledge encryption and enabling hardware security keys significantly reduces the risk of credential theft and phishing.
- Browsers should have third-party cookies blocked, tracker-blocking extensions installed, and permissions reviewed regularly to minimize web tracking and data leakage.
- Regularly updating software, reviewing privacy settings on social media, and choosing encrypted messaging apps protect your personal data from common online threats.
Table of Contents
ToggleCore privacy baseline: prioritized controls to set up first
Start with identity, not gadgets. If someone takes over your email, they can reset passwords on your bank, your social accounts, and nearly everything else you own online, which is why CISA’s cybersecurity guidance and the FTC both put account protection ahead of network or device settings.
- Use a password manager to generate and store unique passwords for every account, cutting off credential stuffing attacks that rely on reused passwords.
- Turn on phishing-resistant MFA or passkeys for email, banking, and any account tied to your identity, so a stolen password alone cannot get an attacker in.
- Install operating system and app updates as soon as they arrive, since most exploited vulnerabilities are ones a patch already fixed.
- Turn on device encryption and a screen lock, and keep a current backup somewhere separate from the device itself.
These four steps cover the paths attackers use most: weak or reused passwords, unpatched software, and unlocked devices. Everything else in this guide builds on top of that foundation.
Secure your home Wi-Fi and router
Your router is the front door to every device in your house, and most people never change the settings it shipped with.
- Replace the default admin username and password on the router, and rename the network so it does not broadcast the make or model.
- Turn on WPA3 encryption, or WPA2 if WPA3 is not available, and make sure WEP or an open network is never in use.
- Set up a separate guest network for visitors and smart-home devices so a compromised camera or speaker cannot reach your laptop.
- Keep router firmware updated and turn off remote administration unless you specifically need it.
- Check whether your router supports encrypted DNS settings, which reduce how much of your browsing activity leaks to outside observers.
Pro Tip: Check your router settings twice a year, since manufacturers push firmware updates that can quietly reset options like remote access back to their defaults.
Account security: passwords, password managers, and phishing-resistant MFA
A password manager solves the problem that unique, complex passwords for dozens of accounts are impossible to remember. It generates and stores them behind one master credential, so reusing a password (the main cause of credential stuffing) stops being necessary. When picking one, look for a zero-knowledge encryption model, independent security audits, and a clear breach history.
- Choose a password manager built on zero-knowledge encryption, so the provider itself cannot read your stored passwords.
- Turn on a passkey or hardware security key wherever the option exists, especially for email and financial accounts.
- Favor authenticator apps over SMS codes for any account that still requires a traditional MFA code.
- Set up account recovery options in advance, using answers or backup methods that are not guessable from public information.
For most users, a passkey or hardware key provides substantially stronger protection against phishing than a password alone, according to NIST’s authentication guidance, which recommends phishing-resistant authenticators for higher-assurance accounts. SMS codes can be intercepted through SIM-swapping, which is why the FTC recommends authenticator apps or security keys over text-message codes whenever an account offers the choice.
Reduce web tracking: browser settings, cookies, and extensions
Browsers track far more than most people realize, and the settings to limit it are usually a few clicks away.
- Block third-party cookies in your browser’s privacy settings and restrict site access to your location and browsing history by default.
- Install a tracker-blocking extension from a reputable developer, and keep it updated rather than installing it once and forgetting it.
- Choose only necessary cookies when a site offers a granular consent banner instead of accepting everything by default.
- Review saved site permissions occasionally, since microphone, camera, and location access tend to accumulate over time.
Private or incognito mode only clears your local browsing history when the window closes. The FTC notes that it does not hide your activity from the websites you visit, your internet provider, or an employer managing the network, so it is not a privacy tool on its own, just a way to avoid leaving local traces on a shared device.
VPNs: what they protect, what they don’t, and when to use one
A VPN encrypts the connection between your device and the VPN provider’s server, hiding your IP address from the local network you’re connected to. That makes it genuinely useful on coffee shop or airport Wi-Fi, where anyone else on the network could otherwise see unencrypted traffic.
- A VPN hides your browsing from your local network and your internet provider, but the websites you visit can still see session data and use fingerprinting to track you.
- Using a VPN means shifting trust to a new party: Mozilla’s explainer notes that you’re relying on the provider’s own logging policy and jurisdiction, so read those details before signing up.
- HTTPS still matters with a VPN turned on, and a VPN does not replace updates, MFA, or tracker blocking.
Pro Tip: If your main concern is account takeover rather than network snooping, spend your time on MFA and a password manager first. A VPN won’t stop a phished password.
Practical step-by-step checklist you can follow today
Break the work into stages instead of trying to fix everything at once.
- Today: turn on automatic updates, change any reused or weak passwords on email and banking, and enable MFA on those two accounts first.
- This week: install a password manager and populate it with your existing accounts, lock down router settings, and review which apps have access to your contacts, location, or photos.
- Ongoing: review account activity every few months, delete accounts and apps you no longer use, and consider dark web monitoring to catch leaked credentials early.
Each stage builds on the last, so skipping ahead to router settings before securing email leaves the bigger risk unaddressed.
How to evaluate privacy tools and vendors
Not every product labeled “privacy” deserves the name. The FTC’s case against Avast, which paid $16.5 million for selling browsing data collected through privacy-branded software, is a reminder to check practices rather than marketing claims.
- Read the privacy policy for what data is collected, how long it’s kept, and whether it’s shared or sold.
- Favor vendors that publish independent security audits, state a clear jurisdiction, and commit to minimal logging.
- Check for regulator actions or credible reviews before trusting a new privacy product.
- Look for concrete transparency, such as published audit reports or a clear process for requesting your data be deleted.
Email and messaging privacy best practices
Email is usually the master key to your digital life, since it’s the recovery method for nearly every other account you own. Treat it accordingly: use a unique, generated password stored in your password manager, and turn on the strongest MFA option your provider offers, ideally a passkey or security key rather than a text code.
Separate your email addresses by purpose where you can. One for banking and financial accounts, one for shopping and newsletters, and one for anything you sign up for once and never expect to hear from again. This limits the damage if one address ends up in a data breach, since attackers can’t pivot from a leaked shopping account into your bank’s password reset flow.
For messaging, be skeptical of links and attachments even from contacts you recognize, since compromised accounts frequently message your own network to spread further. Check the sender’s actual address rather than just the display name, since spoofing a name is trivial. If a message creates urgency (a locked account, an unpaid invoice, a prize) treat that urgency itself as a warning sign, since it’s a standard pressure tactic in phishing attempts.
Review your email provider’s forwarding rules periodically. Attackers who briefly access an account sometimes set up silent forwarding rules to keep reading your mail after you’ve changed the password, so check that settings page every so often as a habit, not just after a suspected breach.
Managing privacy on social media platforms
Social platforms default to sharing more than most people intend, so a periodic settings review matters more than a one-time setup. Start with who can see your posts, your friends list, and your contact information. Most platforms let you restrict these to a smaller circle without losing the ability to post publicly when you choose to.
Turn off location tagging on posts and photos unless you have a specific reason to share it. Location data attached to a public post can reveal patterns, like when you’re regularly away from home, that are more sensitive in aggregate than any single post suggests.
Review third-party app permissions connected to your social accounts. Games, quizzes, and old apps you signed up for years ago often retain access to your profile data long after you’ve stopped using them, and cleaning that list out periodically closes an easy data leak.
Be deliberate about what you put in bios and public profiles. Birthdates, pet names, and schools attended are common security question answers, which means a public profile can sometimes hand an attacker exactly what they need to bypass an account recovery flow.
Finally, treat friend or connection requests from strangers with the same skepticism as an unexpected email. Fake profiles are a common way to gather information for more targeted phishing attempts later.
Understanding and limiting data shared with apps and services
Every app you install asks for permissions, and most people tap “allow” without reading what’s actually being requested. Before installing, check what the app asks for against what it actually needs to function. A flashlight app that wants access to your contacts and location has no functional reason for either.
Go through your phone’s privacy settings periodically and review which apps have access to your camera, microphone, location, and contacts. Both major mobile operating systems let you revoke individual permissions without uninstalling the app, and many let you grant location access only while the app is actively in use rather than at all times.
Pay attention to what data a service collects beyond what you actively type in, since many apps also gather device information, usage patterns, and sometimes data from other apps on your device. The FTC’s guidance on how websites and apps collect information explains that this data often feeds into advertising profiles that follow you across services, not just within the one app you’re using.
When a service offers a data export or account deletion option, use it for accounts you no longer need rather than letting them sit dormant with your information still stored. Dormant accounts are a common source of breach exposure precisely because nobody is monitoring them anymore.
Use of encrypted communication tools
For conversations you want kept private, end-to-end encrypted messaging apps like Signal offer a meaningfully different guarantee than standard text messages or most chat apps. With true end-to-end encryption, the message content is unreadable to the service provider itself, not just to outside eavesdroppers, which matters if you’re concerned about data requests, breaches on the provider’s servers, or employees having access to message content.

Standard SMS text messages have no such protection. They can be intercepted, and carriers retain metadata about who messaged whom and when, even if the content isn’t stored long-term. Some chat apps advertise encryption but only apply it to messages in transit, not at rest, which is a meaningfully weaker guarantee.
Switching your most sensitive conversations to an encrypted app doesn’t require abandoning the apps you already use for everything else. Many people keep SMS or a mainstream chat app for casual conversation and reserve an encrypted option for anything involving financial details, health information, or anything else they would not want exposed in a data breach.
Check whether disappearing messages or manual message deletion fits your needs, since reducing how long sensitive content sits on a server (yours or theirs) limits what could be exposed if an account is ever compromised down the line.
Basics of ad and tracker blockers
Ad and tracker blockers like uBlock Origin work by comparing the content a page tries to load against lists of known tracking and advertising domains, then blocking those specific requests before they load. This cuts down on cross-site tracking, where a single advertiser can piece together your browsing across dozens of unrelated sites.
![]()
The privacy benefit is separate from the ad-blocking benefit, even though they often come from the same tool. Many trackers load invisibly and serve no ads at all, existing purely to build a profile of your activity for later use, so blocking them helps even on sites where you don’t mind seeing ads.
Install tracker blockers only from the browser’s official extension store, and check the developer’s reputation and update history before adding one. An extension with broad permissions and no clear privacy policy can become a tracker itself, which is the same caution that applies to any tool marketed around privacy.
Keep the extension updated, since tracker lists need regular refreshing to keep up with new tracking domains. A blocker that hasn’t been updated in months is quietly losing effectiveness even though it still appears to be running.
A note on prioritization and tradeoffs
Identity first, then network, then tracking: that order holds up in practice, not just in theory. I resisted a hardware security key for months because a password felt faster, until a friend’s email got taken over through a password reset, which was all the convincing I needed. Adapt this checklist to your own risk, but don’t skip email.
— Mike
LogMeOnce: one way to put this baseline in place
Setting up a password manager and phishing-resistant MFA separately takes time most people don’t have, which is where a single tool covering both saves real effort. LogMeOnce’s Password Manager generates and stores unique passwords, and its Passwordless MFA options let you move past text-code authentication toward stronger sign-in methods on the accounts that matter most.

For readers who also want to know if their credentials have already leaked, dark web monitoring and cloud storage encryption round out the same baseline covered above, all from one account. Compare plans, including the free Premium tier, on the pricing and comparison page and see which fits your setup.
Sources
- CISA cybersecurity awareness guidance
- What is a VPN? — Mozilla VPN
- NIST SP 800-63B authentication guidance
FAQ
How can I make myself unsearchable on the internet?
You can’t make yourself completely unsearchable, but you can significantly reduce your exposure by tightening social media privacy settings, removing your information from data broker sites, and limiting what you share publicly. Reviewing what comes up when you search your own name periodically helps you catch and address new exposures.
Can anybody see what I look at on the internet?
Your internet provider, the websites you visit, and anyone on the same unsecured network can potentially see your browsing activity, and private browsing mode does not prevent this. Using HTTPS, a VPN on untrusted networks, and tracker-blocking extensions reduces how much of that activity is visible to each of those parties.
What are the 7 types of privacy?
Privacy frameworks vary by source, but common categories include information privacy, communications privacy, bodily privacy, territorial or spatial privacy, and behavioral or association privacy, sometimes expanded further depending on the framework used. For everyday internet use, the categories that matter most are information privacy (your data) and communications privacy (your messages and calls).
How do I keep my internet private?
Start with a password manager and phishing-resistant MFA or passkeys on your email and financial accounts, then secure your home Wi-Fi, keep software updated, and add browser tracker controls. A VPN adds protection on public networks but works best as one layer among several, not a standalone fix.




Password Manager
Identity Theft Protection

Team / Business
Enterprise
MSP

