Your First 30 Minutes of Privacy

A practical starter checklist you can do today (no paranoia, no perfection required).

Most “privacy advice” fails because it’s either too extreme or too vague. This guide is different: it’s a short, realistic set of steps that materially improves your privacy in about 30 minutes.

You don’t need to do everything. Do what you can, then build from there.

Step 0 (2 minutes): Decide what you’re protecting against

Pick the closest match:

  • Everyday privacy: less tracking, fewer leaks, fewer risky defaults.
  • Higher-risk: activism, sensitive work, stalking/harassment concerns, high-profile identity.
  • Business / organisation: protecting clients, donors, internal documents, accounts.

This matters because the “best” tool or setup depends on your situation.

Step 1 (8 minutes): Lock down your accounts (passwords + 2FA)

If you do only one thing today, do this.

1) Use a password manager

A password manager helps you create unique passwords for every site (so one breach doesn’t cascade across your life).

  • Set it up.
  • Import passwords if you already have them saved in your browser.
  • Generate a new strong password for your email account first (email is the “master key” to everything else).

2) Turn on two-factor authentication (2FA)

Start with:

  • Email
  • Banking
  • Social accounts (X, Instagram, etc.)
  • Any account where losing access would hurt

Best options (in order):

  1. Authenticator app (good balance of security + convenience)
  2. Hardware security key (best, but optional)
  3. SMS (better than nothing, but weakest)

Quick rule: Protect email first, then everything else.

Step 2 (7 minutes): Make your browser leak less

Your browser is the biggest tracking surface in everyday life.

Do these three things:

  1. Enable tracking protection
    Most modern browsers include built-in tracking protection. Turn it on (or set it to “strict” if it doesn’t break your daily sites).
  2. Review extensions
    Extensions can become a privacy risk. Keep only what you truly use.
  • Remove anything you don’t recognise or haven’t used in months.
  1. Separate identities
    Use separate browser profiles for:
  • Personal browsing
  • Work/admin accounts
  • “Research”/random clicking

This reduces cross-site linking and accidental logins.

Step 3 (6 minutes): Fix your messaging habits (without overthinking)

There is no perfect messenger for everyone — choose based on risk level.

Everyday use

  • Use a modern messenger with strong encryption by default.
  • Avoid mixing “public identity” accounts with sensitive conversations.

Higher-risk use

  • Prefer tools with strong security reputation and clear encryption defaults.
  • Be careful with backups (some apps back up message history to the cloud in ways that reduce privacy).

Simple habit: For anything sensitive, assume screenshots exist and metadata matters.

Step 4 (5 minutes): Stop accidental data leaks on your phone

Most privacy losses come from permissions and defaults.

Do a quick permissions sweep

On your phone:

  • Check Location permissions: set most apps to “While using” or “Never”
  • Review Photos/Files access: restrict where possible
  • Disable microphone/camera permissions for apps that don’t need them

Turn off ad tracking options (where available)

Most phones have a setting related to personalised ads or ad measurement.
Turning this off won’t make you invisible, but it reduces needless tracking.

Step 5 (2 minutes): Don’t upload your entire life by default

Backups matter — but so does what you back up.

  • If you use cloud photo backup, know it may include metadata (location/time/device).
  • Consider separating:
    • everyday photos
    • documents
    • sensitive images

Minimum move: Don’t automatically sync private folders or screenshots unless you intend to.

A 30-second “privacy baseline” you can repeat monthly

  • Update your password manager and rotate the most important passwords
  • Check account recovery methods (email/phone)
  • Remove browser extensions you no longer use
  • Review phone permissions (especially location)