How PROX Recommends Privacy Tools (Without Hype)

Start with your threat model, choose tools for real life, and understand the trade-offs.

Privacy tools are easy to argue about and hard to recommend responsibly. The internet is full of “best VPN” lists, affiliate links, and one-size-fits-all advice.

PROX takes a different approach: we recommend tools based on what you’re trying to protect, how you actually live, and what trade-offs you’re willing to accept.

This post explains our approach. It’s the foundation we’ll use for every future recommendation list on PROX.

1) Start with the threat model (not the tool)

Before you pick a tool, answer these questions:

  • What are you trying to protect? (messages, location, photos, identity, browsing history, accounts)
  • Who are you protecting it from? (advertisers, data brokers, scammers, workplace monitoring, abusive individuals, sophisticated attackers)
  • What’s your tolerance for friction? (minimal effort vs “I’m happy to change habits”)
  • What would be the impact if it went wrong? (annoying vs expensive vs dangerous)

Rule: Better privacy usually means some friction. Good recommendations reduce friction without pretending it doesn’t exist.

2) The PROX criteria: what we look for in tools

When PROX recommends a tool, we evaluate it on a consistent set of criteria:

Security and privacy fundamentals

  • Clear security design and sensible defaults
  • Reasonable history and track record (how they handle incidents matters)
  • Strong authentication support (2FA, passkeys, security keys)
  • Encryption where appropriate — and clarity about what is and isn’t encrypted

Trust and transparency

  • Clear business model (how they make money)
  • Privacy policy that matches the product reality
  • Regular updates and maintenance
  • Independent review/audits where available (helpful, but not magic)

Usability and reliability

  • People will only use tools that work.
  • If a tool is “perfect” but painful, most users abandon it — and that failure matters.

Trade-offs and constraints

  • Cost vs privacy
  • Convenience vs control
  • Cloud vs local storage
  • Compatibility with your devices and your life

3) Avoid the two most common mistakes

Mistake #1: “I installed one tool, so I’m private now”

There is no single tool that fixes privacy. A privacy stack is a few complementary habits and defaults.

Mistake #2: Collecting tools instead of improving outcomes

More tools can mean more complexity, more accounts, and more failure points.

Goal: fewer tools, better setup.

4) A simple “privacy stack” that works for most people

We’ll expand this into full recommendation pages, but a sensible baseline usually includes:

  1. Password manager + strong unique passwords
  2. Two-factor authentication for important accounts
  3. A privacy-respecting browser setup (tracking protection + minimal extensions)
  4. A secure messenger for private conversations
  5. Safer backups that don’t leak more than necessary

Everything else is optional and depends on your threat model.

5) How to read privacy marketing (quick filters)

If a tool’s marketing relies on these, be sceptical:

  • “Military-grade encryption” as the main argument
  • “Anonymous” without explaining what that means
  • Aggressive affiliate marketing everywhere
  • Claims that ignore metadata
  • Fear-based messaging and absolute promises

A good tool’s value can be explained clearly with specific limitations.

How PROX will publish recommendations

You can expect recommendation pages to include:

  • Who it’s for
  • What it protects
  • What it doesn’t protect
  • Setup notes
  • Common pitfalls
  • Alternatives
  • Trade-offs explained

We’ll also separate:

  • “Best for most people”
  • “Best for higher-risk”
  • “Best for specific use cases” (travel, creators, small orgs, etc.)