Why bother with privacy at all?
Let's get one thing straight up front: this isn't about becoming a ghost, growing a tinfoil hat, or unplugging the router and moving to a cabin. It's about closing the easy doors. Most of the tracking, profiling and data-hoovering that happens to you online isn't sophisticated - it's just default settings nobody bothered to change. Fix the defaults and you cut out 90% of it.
Here's five steps I run through with anyone who asks me where to start. No paid subscriptions required, no PhD in networking needed - just an afternoon and a willingness to tinker.
1. Ditch the default search engine
Every search you make on Google gets logged against your account (or your IP, if you're not signed in) and quietly builds a profile of what you're into, worried about, shopping for and Googling at 2am. Swapping this out is the single easiest win on this list.
Do this: Switch your default search engine to DuckDuckGo or Startpage (Startpage actually runs Google's results but strips the tracking on the way through, so you keep the search quality). Takes about 30 seconds in your browser settings.
2. Get your phone off the leash
Your phone is the biggest snitch in your life. It knows where you sleep, who you talk to and what apps you open at 3am. You don't need to go full de-Googled overnight, but a few changes make a real dent:
- Turn off ad personalisation in your phone's privacy settings (Settings > Privacy > Ads on both Android and iOS)
- Switch to a private DNS provider like Quad9 or NextDNS - this alone blocks a huge chunk of tracker and ad domains at the network level
- Audit your app permissions and rip out location/microphone access from anything that doesn't genuinely need it
If you want to go further down the rabbit hole, this is where things like GrapheneOS come in - a privacy-hardened Android build with Google Play sandboxed off entirely, paired with something like Aurora Store for grabbing apps anonymously without a Google account attached. That's a whole separate post though - start with the basics above first.
3. Get a password manager and turn on 2FA everywhere
If you're reusing passwords - and statistically, you are - one leaked database anywhere on the internet means every account sharing that password is compromised. A password manager fixes this permanently and is honestly one of the biggest quality-of-life upgrades in computing, privacy aside.
Do this: Grab Bitwarden (free, open source, syncs everywhere) or go fully local with KeePassXC if you don't want anything touching the cloud. Then go through your important accounts - email, banking, socials - and turn on two-factor authentication using an authenticator app, not SMS. SMS 2FA can be SIM-swapped; app-based codes can't.
4. Move your messages to something encrypted
Regular SMS and most default messaging apps aren't end-to-end encrypted, meaning the contents can be read by the carrier, the platform, or anyone who intercepts them. Encrypted messaging fixes that so only you and the person you're talking to can read what's sent.
Do this: Install Signal and start nudging your group chats over to it. It's free, open source, and the gold standard here - even government agencies recommend it. Bonus: it also does encrypted voice and video calls.
5. Lock down your browser
Your browser is leaking data constantly - trackers, fingerprinting scripts, third-party cookies following you from site to site. A few extensions and settings changes shut most of it down.
- Switch to Firefox or Brave if you're still on stock Chrome
- Install uBlock Origin - blocks ads and trackers, and it's one of the few extensions worth fully trusting
- Turn on "Enhanced Tracking Protection" (Firefox) or Brave Shields, set to strict
- Clear cookies on browser close, or run a separate container/profile for anything you're logged into
Bonus tip: website over app, every time
Quick one to bolt onto all five steps above: if a website does the job, use the website. Don't install the app unless you genuinely have to.
Here's why. A website running in your browser is sandboxed - it gets a narrow, temporary slice of access and nothing more. An app you install onto your phone is a different beast entirely. To even get through the app store listing it usually asks for a long list of permissions - contacts, location, camera, microphone, background activity, your device's unique identifiers - and once granted, a lot of that access doesn't stop when you close the app. It keeps checking in, keeps reporting back, keeps building a profile, all quietly in the background.
A browser tab can't do that. Close it and it's gone. It also can't dodge your ad blocker or tracker protection the way an app can - uBlock Origin and friends have no visibility into what an app is sending once it's outside the browser.
Do this: Before you tap "Install," check if the service has a proper mobile website first. Most banks, retailers, airlines, food delivery services and social platforms work perfectly fine in-browser. If you want an app-like shortcut without the app-like data grab, add the site to your home screen instead - both Android and iOS let you save a website as an icon that opens straight into the browser, no app store trip required. You get the convenience without handing over your contacts list to a shopping app that has no business wanting it.
The takeaway
None of this makes you invisible, and that's not really the goal. It's about raising the cost of tracking you until it's not worth the effort for the average data broker or advertiser. Pick one of these five tonight, get it sorted, then come back for the next one. Privacy is a habit, not a setting you flip once.
Got a step you'd add to this list? Drop it in the comments - always keen to hear what other tinkerers are running.