Start with your threat model.
Privacy is about controlling information, not disappearing from the internet. Before installing anything, decide who you want to protect information from and what would happen if it were exposed.
Who are you protecting against?
These are different problems: advertisers building a profile, a stolen phone, an abusive partner with device access, an unsafe public network, a hostile employer, or a well-resourced government observer.
What must stay safe?
List the actual assets: account access, messages, location, contacts, files, browsing history, financial details, or your identity. Protect the highest-impact items first.
A high-impact quick start.
These steps are intentionally boring. They prevent more real-world account takeovers and data loss than collecting a large stack of privacy apps.
Update everything.
Install pending operating-system, browser, router, and app updates. Turn on automatic updates when you can. Restart devices after security updates finish.
Protect your primary email.
Your email can reset most other accounts. Give it a unique password, enable a passkey or authenticator-based 2FA, review recovery addresses, and sign out unknown sessions.
Use a password manager.
Generate a different random password for every important service. Protect the manager with a strong master passphrase and a recovery method stored offline in a safe place.
Turn on device encryption and a lock screen.
Use a long PIN or passcode rather than an easy pattern. Check that encryption is enabled and that sensitive notification previews are hidden while locked.
Make a recovery plan.
Keep encrypted backups of irreplaceable files. Save recovery codes offline, and decide how a trusted person could help you recover access without receiving your passwords.
Harden devices and accounts.
A private browser or encrypted connection cannot protect a phone with spyware, a reused password, or an account that is still signed in on a stranger’s device.
Reduce physical exposure.
- Use automatic updates, device encryption, and a strong screen lock.
- Review installed apps; remove anything you do not recognize or need.
- Limit camera, microphone, contacts, photos, and location permissions.
- Turn off lock-screen previews for messages and authentication codes.
- Do not connect unknown USB devices or accept unexpected remote-support requests.
Make takeover expensive.
- Use a unique password for email, banking, cloud storage, and social accounts.
- Prefer passkeys or hardware security keys; otherwise use an authenticator app.
- Save one-time recovery codes offline, never in a public notes app.
- Review active sessions, connected apps, forwarding rules, and recovery details.
- Use email aliases when a service does not need your primary address.
Phone number note: SMS codes are better than no second factor, but a phone number can be targeted through SIM-swap or number-porting fraud. Add a carrier account PIN and ask your provider about port-out protection where available.
Protect messages and relationships.
End-to-end encryption helps keep message contents away from the service and network observers. It does not hide who you contact, when you contact them, what is on a compromised phone, or what a recipient chooses to share.
Use encryption by default.
- Use a reputable end-to-end encrypted messenger for sensitive conversations.
- Verify a contact’s safety number or identity through a second trusted channel.
- Set disappearing messages for appropriate chats, but remember screenshots remain possible.
- Disable cloud backups for conversations where an extra copy creates risk.
Share less context.
- Remove location metadata from photos before posting or sending publicly.
- Be cautious with group membership, profile photos, usernames, and public status.
- Do not forward sensitive files without checking document history and hidden data.
- Use a separate public identity only when it does not create safety or legal risk.
Browse with fewer leaks.
Browser privacy is a balance. Stronger anti-tracking settings can break sites, and private browsing windows do not make you anonymous to your network, employer, ISP, or the sites you sign into.
Use a maintained browser.
Keep the browser current and install extensions sparingly. Every extension is software with access to some part of your browsing activity.
Separate contexts.
Use browser profiles for personal, work, and sensitive research. Do not sign into your everyday identity in a session where you need stronger separation.
Control tracking.
Block third-party cookies, review site permissions, clear unused data, and consider a content blocker from a reputable source. Avoid accepting every notification and location prompt.
Understand DNS.
DNS-over-HTTPS or DNS-over-TLS encrypts domain lookups from the local network. It does not hide your IP address, change your country, or protect traffic after it reaches the destination.
When VPN access is restricted.
“Teleporting” to another country usually means making a service see a different network exit point. Each option has limitations, may be blocked, and can be regulated. Use only services and systems you own or are authorized to use.
Choose the option that matches the job.
Do you need private browsing, access to your own files, encrypted name lookups, or a different regional egress? These are separate goals and should not be treated as interchangeable.
Tor Browser
Routes browser traffic through the Tor network. An exit relay may appear to be in another location, but country selection is not guaranteed and many sites block Tor.
Strong separation · slower · site frictionAuthorized remote server
A server or remote desktop you own or are authorized to use abroad can provide a different egress point. Secure it carefully and route only traffic you intend to send.
Flexible · responsibility is yoursEncrypted DNS
DoH or DoT keeps ordinary DNS queries from being read by a local network. It does not change your public IP or make you appear to be elsewhere.
Easy · not a location changerTor, explained carefully.
Download Tor Browser only from the official Tor Project. Keep its default privacy settings, do not add random extensions, and avoid logging into accounts that identify you if you need separation from your normal identity. Tor bridges can help in places where direct access to the Tor network is blocked; use bridges documented by the Tor Project rather than lists from unknown sources.
Remote access, explained carefully.
If you have a legitimate need to access your own work or files from another region, use an account and server you control or have explicit permission to use. Use SSH keys or a strong unique credential, enable multi-factor authentication, patch the server, restrict exposed ports, and disconnect remote access when it is not needed. A remote desktop is not automatically private: the host, provider, and applications can still observe activity.
Download from the source.
Use official project pages, check the domain carefully, and keep software updated. Search ads and third-party download sites are common places to encounter modified installers and fake extensions.
Before installing: confirm the domain, read the project’s installation instructions, verify signatures or checksums when provided, and never disable security software just because an installer asks you to.
If you think something leaked.
Move calmly. Preserve useful evidence before wiping anything, and use a known-clean device for account recovery if you suspect the original device is compromised.
Contain the account.
Change the password from a clean device, revoke active sessions, remove unknown recovery methods, and contact the service through its official support channel.
Protect the important accounts first.
Start with primary email, password manager, banking, cloud storage, and accounts that can reset everything else. Notify financial providers quickly if money or identity details may be exposed.
Check the device.
Look for unknown apps, profiles, accessibility services, forwarding rules, and security changes. If you suspect serious compromise, document what you can and seek qualified local technical or legal help before factory-resetting.
Tell affected people carefully.
Warn contacts through a trusted channel if your account sent messages you did not write. Do not forward suspicious links or share private screenshots while trying to explain what happened.