A practical starter checklist you can do today (no paranoia, no perfection required).
Most “privacy advice” fails because it’s either too extreme or too vague. This guide is different: it’s a short, realistic set of steps that materially improves your privacy in about 30 minutes.
You don’t need to do everything. Do what you can, then build from there.
Step 0 (2 minutes): Decide what you’re protecting against
Pick the closest match:
- Everyday privacy: less tracking, fewer leaks, fewer risky defaults.
- Higher-risk: activism, sensitive work, stalking/harassment concerns, high-profile identity.
- Business / organisation: protecting clients, donors, internal documents, accounts.
This matters because the “best” tool or setup depends on your situation.
Step 1 (8 minutes): Lock down your accounts (passwords + 2FA)
If you do only one thing today, do this.
1) Use a password manager
A password manager helps you create unique passwords for every site (so one breach doesn’t cascade across your life).
- Set it up.
- Import passwords if you already have them saved in your browser.
- Generate a new strong password for your email account first (email is the “master key” to everything else).
2) Turn on two-factor authentication (2FA)
Start with:
- Banking
- Social accounts (X, Instagram, etc.)
- Any account where losing access would hurt
Best options (in order):
- Authenticator app (good balance of security + convenience)
- Hardware security key (best, but optional)
- SMS (better than nothing, but weakest)
Quick rule: Protect email first, then everything else.
Step 2 (7 minutes): Make your browser leak less
Your browser is the biggest tracking surface in everyday life.
Do these three things:
- Enable tracking protection
Most modern browsers include built-in tracking protection. Turn it on (or set it to “strict” if it doesn’t break your daily sites). - Review extensions
Extensions can become a privacy risk. Keep only what you truly use.
- Remove anything you don’t recognise or haven’t used in months.
- Separate identities
Use separate browser profiles for:
- Personal browsing
- Work/admin accounts
- “Research”/random clicking
This reduces cross-site linking and accidental logins.
Step 3 (6 minutes): Fix your messaging habits (without overthinking)
There is no perfect messenger for everyone — choose based on risk level.
Everyday use
- Use a modern messenger with strong encryption by default.
- Avoid mixing “public identity” accounts with sensitive conversations.
Higher-risk use
- Prefer tools with strong security reputation and clear encryption defaults.
- Be careful with backups (some apps back up message history to the cloud in ways that reduce privacy).
Simple habit: For anything sensitive, assume screenshots exist and metadata matters.
Step 4 (5 minutes): Stop accidental data leaks on your phone
Most privacy losses come from permissions and defaults.
Do a quick permissions sweep
On your phone:
- Check Location permissions: set most apps to “While using” or “Never”
- Review Photos/Files access: restrict where possible
- Disable microphone/camera permissions for apps that don’t need them
Turn off ad tracking options (where available)
Most phones have a setting related to personalised ads or ad measurement.
Turning this off won’t make you invisible, but it reduces needless tracking.
Step 5 (2 minutes): Don’t upload your entire life by default
Backups matter — but so does what you back up.
- If you use cloud photo backup, know it may include metadata (location/time/device).
- Consider separating:
- everyday photos
- documents
- sensitive images
Minimum move: Don’t automatically sync private folders or screenshots unless you intend to.
A 30-second “privacy baseline” you can repeat monthly
- Update your password manager and rotate the most important passwords
- Check account recovery methods (email/phone)
- Remove browser extensions you no longer use
- Review phone permissions (especially location)




