A comprehensive guide to protecting yourself online in 2026
Your constitutional right to privacy, drawn from the 1st, 4th, 5th, 9th, and 14th Amendments was not designed with the digital age in mind. Courts have largely held it does not apply to data held by third parties, leaving most of your digital data accessible to government without a warrant, and leaving the companies behind most of the digital technology you use daily to freely build highly detailed profiles of nearly every aspect of your personal life and sell that data to anyone willing to pay. This guide helps cover nearly every layer of your digital life and how to significantly improve your overall privacy and security. Each section lists recommended tools, generally starting from the most private and secure first, while some require slightly more complicated setups. The italicized notes typically indicate warnings or caveats. You do not need to adopt everything at once - you can also begin one step at a time with whichever section feels the most relevant to you and go from there. Otherwise the Getting Started section breaks it all down into a manageable 8-week plan, whether you are taking your first steps or hardening an existing setup, there is something here for everyone.
Getting Started
Week 1: Operating System Week 2: Browser, Extensions + Search Week 3: Password Manager + 2FA Week 4: VPN + DNS Week 5: Email + Aliases Week 6: Mobile + Messaging Week 7: Home Network Week 8: Social Media + Hardening
Ongoing
Automate what you can: Enable automatic updates for all devices, sign up for free breach alerts at haveibeenpwned.com/NotifyMe, sign up for free credit alerts with each bureau, let your password manager flag weak or reused passwords, use a data broker removal service, and schedule regular encrypted backups.
Every six months: Test that your backups restore correctly, delete unused accounts, revoke apps connected to your Google or Apple account that you no longer use, review app permissions, confirm your 2FA recovery codes are accessible, and if not using an automated removal service - manually submit data broker opt-outs.
Yearly: Pull your free credit report at annualcreditreport.com.
Your Privacy Level
You don't need to do everything in this guide at once, everyone's experience is different, just find your level below and work from there
Level 0 ~ Start Here If This Feels Like a Lot: New to this, helping an older relative, or you just want the essentials in plain language without the jargon Steps: work through the plain-language companion guide — bigger text, exact menu names, printable checklists, and only the steps that matter most: passwords, two-step sign-in, freezing your credit, spotting scams, and getting your details off people-search sites. Come back here when you want to go further → guide-en-simple.html
Level 1 ~ The Basics: Companies collecting and selling your personal data, advertisers tracking you across the web, and hackers targeting your accounts Steps: turn off your advertising ID, set social medias to private, switch to a safer browser and install an ad blocker, use encrypted email and messaging, turn on two-factor authentication, use a password manager, use a VPN on public WiFi, remove yourself from data broker sites
Level 2 ~ Privacy First: Want protection from your internet provider logging your activity, protection from your location being sold, want to prevent companies from building detailed profiles on you, and or are concerned about mass surveillance Steps: everything in Level 1, plus use an always-on VPN, enable encrypted DNS, secure your home router, use email aliases for different accounts, keep work and personal browsing separate, switch to a privacy-focused browser (Tor or Mullvad), and freeze your credit
Level 3 ~ Personal Exposure: Protection from a specific person targeting you - a stalker, abusive partner, or an employer conducting surveillance on you personally Steps: everything in Levels 1 + 2, plus use separate devices for sensitive activities, switch to a GrapheneOS phone, NitroPhone, or iPhone in Lockdown Mode, use a no-ID phone plan, use encrypted file storage, and strip metadata from photos and files before sharing
Level 4 ~ High Stakes: Journalists, whistleblowers, activists, and lawyers with sensitive cases. Your adversaries have technical expertise, legal tools, and significant resources. Tools alone are not enough Steps: everything in Levels 1 + 2 + 3, plus get in-person security training, harden your physical device security, and use Tails or QubesOS - consult ssd.eff.org, securitylab.amnesty.org, and accessnow.org/help — nation-state spyware like Pegasus and Paragon's Graphite can silently compromise fully updated devices; GrapheneOS and iPhone Lockdown Mode reduce but don't eliminate this risk
Ask yourself: Who is trying to access my data? What do they want? What happens if they get it? Most people are Level 1-2. If your answer is a specific person or organisation with a reason and the means to target you, you are likely Level 3-4
Individual privacy needs change over time - reassess this section anytime your circumstances change significantly. Otherwise don't be afraid to take baby steps one at a time towards achieving a safer digital footprint for yourself
First Steps
Quick and easy steps you can do today with the biggest impact
Turn off your advertising ID - iOS: Settings > Privacy & Security > Tracking > disable "Allow Apps to Request to Track". Android: Settings > Privacy > Ads > Delete advertising ID
Set social media to private - Instagram: Settings > Account Privacy > Private Account. Twitter/X: Settings > Privacy & Safety > Audience > Protect your posts. TikTok: Settings > Privacy > Private Account. Facebook: Settings > Privacy > "Who can see your future posts"
Switch to Signal for messaging - free, end-to-end encrypted, and takes minutes to set up. Available on iOS and Android. Ask the people you message most to do the same - Signal works just like a regular messaging app
Switch your default browser & search engine - replace Chrome and Google with Brave and Brave Search for example. On iOS/Android: browser settings > Search Engine. Check the Browsers and Search Engines sections for more options
Enable Global Privacy Control (GPC) - it legally tells websites not to sell your data. It is on by default in Brave, Librewolf, Tor, and Mullvad Browsers and you must turn it on in Firefox via Settings > Privacy & Security > "Tell websites not to sell or share my data". The uBlock Origin browser extension blocks tracking requests before they reach company servers, so you should consider adding that to your browser as well to compliment it. While using other less private browsers that don't support it, consider using a browser extension such as Privacy Badger to turn on GPC
Review app permissions - revoke location, microphone, and camera access from any app that doesn't genuinely need it. iOS: Settings > Privacy & Security. Android: Settings > Apps > Permissions
Opt out of personalised ads - Google: myaccount.google.com > Data & Privacy > Ad settings > turn off. Meta (Facebook/Instagram): Settings > Ads > Ad preferences > turn off activity-based ads. TikTok: Settings > Privacy > Ads > turn off personalised ads
Limit data sharing in Google/Apple account settings - Google: myaccount.google.com > Data & Privacy > disable "Web & App Activity", "Location History", and "YouTube History". Apple: Settings > Privacy & Security > Apple Advertising > turn off Personalised Ads. Settings > [your name] > iCloud > disable any apps that don't need cloud sync. Or better yet, consider switching away from these ecosystems entirely
Turn on automatic updates - keeps your devices patched against known vulnerabilities. iOS: Settings > General > Software Update > Automatic Updates. Android: Settings > System > Software Update > Auto download. Windows: Settings > Windows Update > turn on. Mac: System Settings > General > Software Update > enable all options. A March 2026 leak of elite iPhone exploits (DarkSword) made state-level attack tools publicly available — updated devices are protected, unpatched ones are not
Essential Security Habits
Pay with cash for sensitive purchases
Use a unique password for every account
Back up data regularly
Be alert to phishing - verify sender email addresses carefully, never click links in unexpected emails or texts, go directly to websites by typing the address. Legitimate organisations never ask for passwords via email
Enable full disk encryption on all devices
Decline non-essential cookies on websites and clear cookies regularly in your browser settings - installing uBlock Origin significantly reduces how often you'll need to do this, as it blocks most tracking requests before cookies are ever set
Delete old unused accounts
Use a VPN on public WiFi
Separate email addresses for work, shopping, and personal
Use a standard account for daily use, keep a separate admin account for system changes
Remove your data from data brokers (every 6 months) - this also removes your data from what law enforcement can legally purchase about you without a warrant - search your name and submit opt-out requests manually using journalist Yael Grauer's free Big-Ass Data Broker Opt-Out List (github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List), or use a paid service like Optery or EasyOptOuts to automate it. Note: most sites repopulate your data over time, so this requires repeating every 6 months or so
At TSA checkpoints you can opt out of facial recognition - say "I'd like to opt out of the facial recognition scan" before handing over your ID, as agents are not required to tell you this option exists. TSA states participation is voluntary for US citizens, though this is policy not law and the TSA Administrator has publicly stated mandatory biometrics are coming. Non-US citizens cannot refuse at CBP international checkpoints. Power off your device before border crossings - border agents can compel biometric unlock (face/fingerprint) but passcodes have stronger legal protection, which is why powering off matters. CBP also uses Cellebrite to extract full device contents including messages and app data during border searches without a warrant. US citizens cannot be denied entry for refusing but may face delays and questioning; non-citizens risk denied entry. You can also opt out of X-ray body scanners (they'll give you a pat-down instead)
Operating Systems
Your OS has access to everything on your device. Most ship with telemetry enabled by default. Linux distributions are free, run on existing hardware, and can be tried from a USB without installing anything
Windows 10 reached end of life in October 2025 - it no longer receives security patches and becomes more vulnerable over time. Switch to Linux - Linux Mint and Fedora are free and run well on most hardware from the last decade
Most accessible
Linux Mint - Most accessible Linux for Windows switchers. No telemetry, no corporate ownership, removes Ubuntu's telemetry components entirely. Cinnamon desktop is the most Windows-like interface available. Free. Note: prioritizes familiarity over security hardening - keep the system updated regularly, and consider Fedora for stronger default protections if you're willing to adapt to a different desktop layout
Fedora - More secure by default than Linux Mint - actively restricts what installed programs are allowed to do even if one is compromised, and receives security patches faster. User-friendly, installs alongside Windows if needed, though the desktop layout is a bigger visual departure from Windows than Mint's. Note: backed by Red Hat (IBM-owned US corporation); telemetry has been proposed but not yet implemented - monitor developments
Maximum hardening (experienced Linux users)
Secureblue - Fedora Atomic-based with aggressive kernel hardening, mandatory access controls, and attack surface reduction - comparable to GrapheneOS-level security. Includes a hardened browser. Note: best suited to experienced Linux users who want maximum hardening
Kicksecure - Hardened Debian base with strong security defaults out of the box: kernel hardening, Tor-routed updates (the update server never sees your IP), dual user accounts to limit malware impact, and brute force protections. Apps come pre-installed with safe defaults. Live Mode available (run from USB before installing). Note: security-focused first, privacy second - not an anonymity OS; no independent audit completed yet
Anonymity-focused
Tails - Portable USB OS, leaves no trace on the host computer, routes all traffic through Tor. Remove the USB and RAM is wiped instantly. Note: understand its security model before relying on it - not designed for everyday use; keep updated as critical patches are released regularly
Whonix - All traffic routed through Tor; even malware cannot find your real IP. Runs inside a VM alongside your existing OS. Note: requires a hypervisor such as VirtualBox or KVM to run
Advanced
QubesOS - Highest security via full VM compartmentalization - each app runs in an isolated environment so a breach in one can't reach the others. Used by Edward Snowden and the Freedom of the Press Foundation. Note: steep learning curve, requires 16GB RAM recommended (6GB minimum), not suitable for most hardware
Avoid if possible: Windows/macOS (built-in telemetry and tracking), ChromeOS (extensive Google tracking), Ubuntu (Canonical telemetry, snap packages phone home to Canonical servers), plain Debian as a desktop OS (fine as a base for hardened systems like Kicksecure, but out of the box it has older packages and slower security patches)
Not ready to switch yet? On Windows: disable ad tracking and location, run O&O ShutUp10++ to disable telemetry (free, oo-software.com), and enable BitLocker encryption - all in your privacy settings. On macOS: disable analytics, revoke unnecessary mic/camera/location permissions from apps, and enable FileVault encryption - all in your privacy settings
Computers
Most computers ship with closed-source firmware and Intel Management Engine (ME) - a hidden processor with deep system access. Privacy-focused hardware replaces this with auditable coreboot firmware and disables ME
Already own a standard laptop? You don't need to buy new hardware. Install Fedora or Kicksecure on your existing machine - this removes Windows telemetry entirely, costs nothing, and runs well on hardware up to 10 years old with at least 4GB RAM. Full disk encryption is enabled during install. This single step closes most of the privacy gap without spending anything
Laptops
NitroPad V56 / NovaCustom - Dasharo coreboot, ME disabled, Qubes OS certified. NovaCustom adds more options: webcam/mic removal, tamper-evident screws, 7-year firmware and parts. NitroPad includes a Nitrokey USB - a green LED at boot confirms the device hasn't been tampered with. Choose Qubes OS at purchase for maximum security, or Linux Mint for everyday use. Germany/Netherlands-based
ThinkPad T480 (with Libreboot installed) - ME firmware stripped rather than just disabled - the most thorough ME removal on any modern laptop. Buy with Libreboot pre-flashed at minifree.org. USB-C, NVMe, Linux only. US-based
Star Labs StarBook Horizon - Coreboot, ME disabled, hardware WiFi/Bluetooth kill switch, physical webcam cover, factory-fitted privacy screen. Choose Linux Mint, Manjaro or Zorin OS at purchase. UK-based
Framework 13/16 - Every component user-replaceable, open-source EC firmware. Runs Linux or Windows. US-based. Note: EDK2 not coreboot - less open than above, but the most repairable laptop on the market
Desktops
Raptor Blackbird - Only desktop with zero proprietary firmware - IBM POWER9 bypasses Intel ME and AMD PSP entirely. Runs Linux or BSD. US-based. Note: Linux/BSD only, no x86 compatibility, aging hardware. Most discrete GPUs require proprietary blobs - display output via onboard HDMI only for a fully open system
NitroPC Pro 2 - Dasharo coreboot, ME disabled, Qubes OS certified (integrated graphics only), tamper-evident case seals. Choose Qubes OS at purchase for maximum security, or Linux Mint for everyday use. Germany-based
Avoid: Dell, HP, Lenovo (except ThinkPad T480 with Libreboot), Apple, ASUS, Acer, Microsoft Surface - closed firmware, no ME control, built-in telemetry
Before selling or disposing of a computer, enable full disk encryption first before you factory reset it
Browsers
Most browsers collect everything you do online by default. Switching takes minutes and is one of the single highest-impact privacy changes you can make
Tor Browser - Most anonymous; routes traffic through 3 encrypted relays, no tracking, no fingerprinting, the only browser that hides your IP without a VPN (Desktop: Windows/Mac/Linux). For iOS use Onion Browser. Note: slower due to relays, may break some sites; use VPN-Tor to hide Tor usage from your ISP
Mullvad - Co-developed with Tor Project; private mode by default (clears all data on exit), fingerprint resistance, zero telemetry, GPC on by default, works with any VPN (Desktop). Note: fingerprint standardization may trigger CAPTCHAs on some sites; better as a secondary browser for sensitive sessions than a daily driver
Librewolf - Hardened Firefox fork, privacy-focused, uBlock Origin built-in, zero telemetry, GPC on by default, clears data on exit (Desktop: Windows/Mac/Linux). Note: strict defaults may break some sites; auto-updates are off by default - opt in during installation on Windows; manual on macOS; small community team means security patches can lag Firefox by a day or two
Brave - Strong built-in ad and tracker blocking via Brave Shields, GPC on by default, built-in private window with Tor option, encrypted cross-device sync (iOS/Android/Desktop). Note: Chromium-based (Google-developed engine); telemetry is on by default - check Settings → Privacy and Security to disable P3A if the option is available; crypto wallet and Brave Rewards opted in by default; fingerprint randomisation can cause site breakage and extra CAPTCHAs
Enable Global Privacy Control (GPC) - on by default in Brave and Librewolf. Firefox: Settings > Privacy & Security > "Tell websites not to sell or share my data". uBlock Origin is the more reliable protection as it technically blocks tracking before it reaches these companies' servers
Avoid: Chrome, Edge, Opera, UC Browser, Samsung Internet, Puffin (tracking, telemetry, data sold to third parties, or all traffic routed through vendor servers). DuckDuckGo (Relies heavily on Microsoft Bing for search and ad revenue, allowed Microsoft trackers until caught in 2022, weaker fingerprinting, proprietary core, no extension support). Safari (closed-source, Apple telemetry, limited extension support)
If staying with Firefox, Safari, Chrome, or Edge: install uBlock Origin/uBlock Origin Lite and Privacy Badger where supported and turn on GPC in settings if at all possible. DuckDuckGo claims to have better privacy than most of these options, but it has no extension support and has direct links to Microsoft, so you cannot add ad or tracker blocking beyond what's already built in. Note: these steps reduce but do not fully eliminate surveillance
Enable HTTPS-Only Mode and encrypted DNS (DoH) - HTTPS-Only Mode encrypts the content of your connections; DoH hides which sites you are looking up. Both prevent anyone on your network from intercepting your activity and both are needed for full protection. Tor, Mullvad, and Librewolf have both on by default. Firefox, Brave, and Chrome need both enabled manually in settings
Browser Extensions
The right extensions block thousands of trackers and ads automatically, and send legally enforceable opt-out signals via Global Privacy Control (GPC). A small, trusted set does more to protect your privacy than almost anything else. Ad blocking also prevents Real-Time Bidding (RTB) - ads on a page can broadcast your location, device, and browsing history to hundreds of companies in milliseconds, confirmed to be used by US federal agencies including CBP and ICE for warrantless location tracking. The two extensions below handle both automatically
uBlock Origin - Strong ad, tracker, and malware blocking, zero telemetry, fully open source, no monetization, no data collection. Built-in on Librewolf; full version available on Firefox/Brave. Note: Lite version available on Chrome/Edge but has reduced tracker blocking and be wary of fake clones on the Chrome Web Store
Privacy Badger - Sends legally enforceable GPC opt-out signals, learns to block new trackers behaviorally, removes link click tracking on Google and Facebook. Note: essential on Chrome/Edge where GPC is not built-in; unnecessary on Brave and Librewolf where GPC is on by default
A Password Manager - A browser extension for your password manager improves security. See the Password Management section for recommended options. Note: KeePassXC works without a browser extension via auto-type or copy-paste - the only option for Tor/Mullvad where extensions break anonymity
Recommended setups: Tor/Mullvad: Do not add extensions - breaks anonymity Librewolf: No extensions needed - can add a password manager (optional) Brave: add uBlock Origin (Adds superior filter lists on top of built-in Shields, GPC on by default) + password manager (optional)
Haven't switched to a safer browser yet?: Firefox: add uBlock Origin + Privacy Badger + password manager (optional) (enable GPC in Settings > Privacy & Security > "Tell websites not to sell or share my data") DuckDuckGo:No extension support - has built-in tracker blocking and GPC only (makes revenue on and does not block Microsoft Bing ads) Chrome/Edge: add Privacy Badger + uBlock Origin Lite (Optimal mode, plus turn on ads and privacy filter lists) + password manager (optional) Safari: add uBlock Origin Lite (Optimal mode, plus turn on ads and privacy filter lists) + password manager (optional) Note: no GPC options available Opera/Vivaldi: add Privacy Badger + uBlock Origin (full version currently supported, but may lose MV2 support in the future) + password manager (optional)
I recommend sticking to the above setups - every additional extension increases your fingerprint surface. All major browsers - including Chrome, Safari, and Edge - are required by California's Opt Me Out Act to provide built-in Global Privacy Control settings by January 1, 2027
Search Engines
Search history can reveal a surprising amount about you - health concerns, finances, relationships, and beliefs. The alternatives below take seconds to switch and never log your queries
SearXNG - The most private if self-hosted - your queries never leave your own server. Queries blend with other users. Note: advanced - requires self-hosting
Mojeek - Minimal logging (IPs replaced with country codes, aggregate data only, never sold), fully independent index, no third-party dependency. Note: may return sparser results and feels fairly bare bones by default, but benefits from customizing preferences in settings
Brave Search - Fully independent index, no tracking. Note: disable anonymous usage metrics in settings; runs on Amazon CloudFront servers - your queries pass through Amazon's infrastructure, meaning a third party outside Brave's control has visibility over your traffic
Kagi - No ads, no tracking, no search logs, uses cryptographic Privacy Passes so searches are unlinkable to your account, Tor accessible. Note: $5-10/month; uses a mix of its own index and anonymized third-party sources
Avoid: Google, Bing, Yahoo (all collect IP, search terms, location, and cookies for targeted advertising), DuckDuckGo (relies on Microsoft Bing for search results and ad revenue, proprietary core, allowed Microsoft trackers in its browser until caught in 2022)
AI assistants are increasingly used as search engines - apply the same scrutiny; see the Private AI section
Most private search engines are more useful than they appear by default, explore their settings for even better result filtering and privacy settings. Note that a private search engine only protects your query, not what happens once you click a result – pair with a privacy browser and tracker blocker for full coverage (see the Browsers and Browser Extensions section)
Password Management
Hackers don't always break in - sometimes they log in. Reused passwords are why. A password manager fixes this permanently
KeePass Family - Offline database, most secure, open-source, unaffected by server-side attacks (Desktop: KeePassXC for Windows/Mac/Linux | Mobile: KeePassDX for Android, KeePassium for iOS). Note: no master password recovery
Bitwarden - Open source, self-hostable, annually audited. US-based; cloud version is zero-knowledge E2E encrypted, self-hosting offers the strongest trust model
Why use these instead of browser password managers? Most browser managers (Chrome, Firefox, DuckDuckGo, etc.) sync to company servers, work only in that browser, and have limited features. Dedicated password managers use stronger encryption, work everywhere (browsers + apps), and are independently audited.
Never reuse passwords across services
Two-Factor Authentication
Passwords get stolen, leaked, and guessed. A second factor means a stolen password alone is not enough to access your account
Passkeys - Replaces passwords with a device-stored cryptographic key. Phishing-resistant by design. Enable in account security settings wherever supported. Note: use a PIN rather than biometrics to unlock; for highest security, use device-bound passkeys or a hardware security key instead
YubiKey - Physical security key you plug in or tap; most secure option, works everywhere, phishing-resistant
Even imperfect 2FA is far better than none - start with Ente Auth or Aegis, upgrade to YubiKey when ready
Avoid SMS-based 2FA, Authy, and Google Authenticator
VPNs
Your ISP can see every site you visit. A VPN encrypts your traffic and hides it from your provider, employer, and network. Switching takes under 5 minutes - install the app, connect, and your traffic is encrypted from your ISP and network
Mullvad - Most anonymous; no-logs, no email/account (random ID only), cash or anonymous vouchers from partnered retailers accepted, RAM-only servers, quantum-resistant, annually audited. Sweden-based
IVPN - Most rigorously and frequently audited; no-logs, no email/account, cash + Monero accepted, quantum-resistant, open-source, annually audited. Gibraltar-based
Proton VPN - Switzerland-based; no-logs, cash accepted, open-source, audited, Secure Core double-hop routing, legitimately secure free tier. Note: free tier: limited server locations, slower speeds, no server selection
Obscura - Best architecture; double-hop routes traffic through two independent providers (Obscura + Mullvad exit), neither can see both your identity and traffic, no email required, open-source, audited. US-based. Note: macOS and iOS only; newer service with shorter track record
Many free VPNs monetize user data - use paid VPNs or Proton VPN's free tier
Use a VPN on public Wi-Fi, enable kill switch, and consider VPN + Tor for sensitive activities
We suggest using a different provider for your VPN and email. If you use Proton Mail, use Mullvad VPN or IVPN for example - keeping them separate avoids a single point of failure if one provider is ever compromised or subpoenaed
DNS
Before your browser loads any page, it asks a DNS server for directions. By default that server is your ISP - and they log every website you look up. A simple settings change puts you back in control
If you use a VPN this is already handled. For when your VPN is off, switch to an encrypted no-log DNS resolver to prevent your ISP logging every website you visit. Always use DNS over HTTPS (DoH) or TLS (DoT)
Mullvad DNS - No-logs, RAM-only servers, blocks trackers and malware, available to non-Mullvad users
Quad9 - Swiss non-profit, no-logs, built-in malware and phishing blocking. Note: some anonymized data shared for security research
Avoid: Google DNS - core to Google's data collection model; NextDNS - logs queries by default (can be disabled in settings), US-based, not independently audited; your ISP's default DNS - logs everything and sells it
A privacy DNS resolver also blocks Real-Time Bidding (RTB) across all apps and devices on your network - every webpage ad instantly broadcasts your data to thousands of companies simultaneously, including US federal agencies for warrantless tracking. DNS-level blocking covers this network-wide, not just in your browser
Email
Email was not designed with privacy in mind. Most providers scan your inbox for advertising data. Set up your new address, forward existing mail, and update accounts until you've fully switched to a safer email provider
Tuta Mail - E2E encrypted by default including subject lines, quantum-resistant, no-logs, open-source, Germany-based - email addresses and timestamps remain unencrypted; encrypted email to non-Tuta users requires a shared password
Proton Mail - E2E encrypted, independently audited, no-logs, Switzerland-based. Note: subject lines are not encrypted; email from non-Proton users arrives unencrypted in transit - Proton encrypts it at rest
For sensitive users: Use multiple accounts for compartmentalization (personal, work, financial, medical, shopping, activism), use email aliases, and avoid paying for your email with a credit card - your payment data links your real identity to your account and can be obtained via legal order despite jurisdiction. Use the free tier or cash if possible. See Email Aliases below for a practical way to manage multiple identities without multiple inboxes
Email Aliases
Your email address is your primary identity online. Aliases let you interact with services without exposing it. Start by using an alias for new signups - you do not need to change existing accounts all at once
SimpleLogin - Open-source, independently audited, strips trackers from forwarded emails, browser extensions, custom domain support. Integrates with Proton Mail (Cross-platform). France-based, Proton-owned
DuckDuckGo Email Protection - Free, no signup needed, strips trackers, gives you a @duck.com address. US-based. Note: forwarding only, cannot send from this address
Create a unique alias per service - your real email is never exposed, and any spam reveals exactly which company leaked it. Note: your alias provider can see forwarding metadata, so choose a reputable one and use a VPN at signup
Phone
Your phone knows more about you than any other device - location, contacts, messages, camera, and microphone. The options below give you full control over what your phone shares and with whom
GrapheneOS - Most secure; hardened kernel, hardened memory allocator, sandboxed Google Play Services, faster security updates than stock Android. Pixel phones only. Motorola officially partnered with GrapheneOS, first compatible Motorola devices expected 2027. Note: installation requires unlocking the bootloader which voids most warranties - consider NitroPhone for a pre-installed option
NitroPhone - Pixel + GrapheneOS pre-installed, no setup required. Unique option: microphones, cameras, and motion sensors physically removed on request - motion sensors can reconstruct nearby speech, so removal makes eavesdropping physically impossible. Germany-based. Note: European frequency bands may limit 5G on some US carriers; removing mic means calls via headset only
iPhone Lockdown Mode: For high-risk users - disables most attack surfaces including message link previews, wired connections, and complex web features. Enable in Settings > Privacy & Security > Lockdown Mode
Android Advanced Protection (Android 16+): Bundles security hardening into one toggle - disables 2G, forces HTTPS, blocks unknown app installs, auto-reboots after 72hrs idle. EFF-recommended for at-risk users. Security-only - does not limit Google's data collection; incompatible with F-Droid. Settings > Security & Privacy > Advanced Protection
If not switching OS yet: Set location, mic, and camera permissions to "Ask Every Time"; disable Bluetooth and WiFi auto-connect when not in use; enable full disk encryption (verify on Android, on by default on iOS); enable Apple Advanced Data Protection if on iOS (opt-in, off by default)
Cell-site simulators (Stingrays/IMSI catchers): Law enforcement has been using these devices that mimic cell towers to identify protesters, silently capturing device identifiers and location data from all phones in range without a warrant - advanced models can also intercept calls and texts - with no indication you are being targeted. They force phones down to 2G, which lacks mutual authentication and is easily intercepted. Disable 2G to prevent this: On GrapheneOS/Pixels: toggle off "Allow 2G" in network settings; On iPhone: no standalone toggle - enable Lockdown Mode, which disables 2G as part of its protections. For sensitive gatherings or for attending protests it is recommended to store your phone in a Faraday bag or leave it behind entirely
ALPRs and phone tracking: License plate reader cameras are now being upgraded with sensors that passively capture Bluetooth identifiers from your phone, AirPods, and smartwatch, as well as Wi-Fi signals from your phone hotspot or any laptop in the car - linking them to your plate as a persistent electronic fingerprint. Disable both Bluetooth and Wi-Fi when driving for any sensitive trip
Before selling or disposing of a phone, enable full disk encryption first before you factory reset it
Phone Service Providers
Major carriers sell your location history and call metadata to data brokers. Privacy-focused alternatives minimize what is collected
Phreeli (from $25/mo) - ZIP code only signup, no ID, crypto accepted. Separates identity from network activity using zero-knowledge cryptography. Does not sell data. T-Mobile network. Note: new (December 2025), not independently audited
JMP.chat ($4.99/mo) - Open-source phone number for calls and texts via XMPP, no SIM needed. No KYC, accepts Bitcoin and Monero. Works well with GrapheneOS (via Cheogram app). Popular as a private texting number to give out instead of your real number. Note: requires internet connection, cannot call 911, best paired with a real SIM for emergency services. Banks and government services also often block SMS 2FA to VoIP numbers - use an authenticator app if possible
In the US, prepaid physical SIMs can be bought with cash at Walmart, Best Buy, CVS, or carrier stores - no ID required. Abroad, your home SIM exposes your location to the local carrier and government - use a privacy-focused travel eSIM (Airalo, Silent.link) instead. For crypto-paid or no-identity-verification options, Silent.Link and PikaSim work for both domestic and international. In either case the carrier still sees your IMEI and logs IPs - stack with a VPN or Tor for more anonymity. Note: a 2026 FCC proposal would require government ID for all prepaid activations and renewals, eliminating anonymous SIMs in the US - not yet law but worth monitoring if you rely on prepaid for privacy
Avoid: AT&T, T-Mobile, Verizon directly - all monetize customer data, all suffered massive breaches, FCC fined the major US carriers in 2024 for illegally sharing customers' real-time location data with third parties without consent
Mobile Apps
Apps are the primary source of location data sold to data brokers and federal agencies. Using the right settings and safer apps in general can significantly reduce the data that is harvested about you
Location permissions: Turn off location for all apps that don't need it and set all others to "approximate" and "only while using"; disable Background App Refresh. iOS: enable App Tracking Transparency, check App Privacy Report, and clear Significant Locations (Settings > Privacy & Security > Location Services > System Services > Significant Locations > Clear History) - iOS silently logs everywhere you regularly go
Delete your advertising ID! This single identifier links all your app activity into a location history purchasable by data brokers and government agencies without a warrant. iPhone: Settings > Privacy & Security > Tracking > turn off "Allow Apps to Request to Track," then Apple Advertising > turn off Personalized Ads. Android: Settings > Google > Ads > Delete advertising ID. Repeat after any factory reset
Privacy & Firewall Tools
Orbot - Routes all app traffic through Tor, open-source, Guardian Project (Android/iOS). Note: slower due to Tor relays; exit nodes can monitor unencrypted HTTP traffic
TrackerControl - Shows and blocks trackers across all apps in real time, local analysis, open-source. Note: F-Droid for full blocking (Android)
NetGuard - Per-app firewall, no root required, open-source. Note: Android-only; fake iOS version exists
App Stores
F-Droid - Open-source app store, no Google account required. Note: Google's mandatory developer registration poses an existential threat to its operation on certified Android devices, with enforcement beginning September 2026 in select countries and globally in 2027 - does NOT affect GrapheneOS/AOSP builds
Accrescent - Private Android app store; signing key pinning verifies installs, signed metadata, automatic updates, no account. Note: alpha, small catalog
Obtainium - Pulls APKs directly from developer-controlled sources (GitHub, GitLab, F-Droid) with no intermediary. Note: you validate the sources - more powerful than F-Droid but less hand-held
TrackerControl and NetGuard use Android's VPN slot - they cannot run alongside each other or a VPN. Use your VPN by default; Orbot when anonymity is the priority; TrackerControl to audit apps; NetGuard to cut apps off from the internet
Avoid: Facebook/Messenger, Instagram, TikTok, Snapchat, LinkedIn, Amazon Alexa, Life360, The Weather Channel, Grindr, Muslim Pro, Uber, Lyft, DoorDash, free coupon apps, Tinder, Tumblr, Candy Crush, Subway Surfers, Words with Friends, free utility apps, free VPN apps. Thousands of legitimate-looking apps also embed hidden tracking SDKs - revoking location permissions is the most effective defence
Photos contain hidden metadata including your exact GPS location. On iOS, tap Options before sharing a photo and disable Location. Note: AI tools can also geolocate photos from architecture and surroundings even without embedded GPS data
Mobile Keyboards
Your keyboard sees every password, message, and search before you send it. Most default keyboards send this data to corporate servers. The keyboards below are fully offline - what you type never leaves your device
HeliBoard - Most private, fully open-source, offline, no internet permission, available on F-Droid (Android)
FUTO Keyboard - Best usability, glide typing, voice input, fully offline, no internet permission (Android/iOS). Note: not fully open-source
Apple Keyboard - Safe default, does not share typing data with third parties (iOS). Note: closed-source
Most keyboards track everything you type including passwords. Avoid: Gboard, SwiftKey, Samsung Keyboard
Messaging & Group Communication
SMS and most chat apps are not private. Your conversations may be stored, scanned, or handed to law enforcement. Switching to an encrypted messenger takes minutes and is free
SimpleX Chat - Most private: no phone number, username, or permanent identifier; messages routed through random relays, audited (Desktop/Mobile)
Briar - P2P encrypted, functions as a mesh network via Bluetooth/WiFi, no internet, no servers, no cell service needed (Android only)
Signal - E2E encrypted, widely used, verify safety numbers, US-based. Note: requires phone number to register; hide it from everyone in Settings > Privacy > Phone Number; use a username to connect without sharing it; location sharing uses Google Maps API
Harden Signal: enable disappearing messages by default, hide phone number from everyone, lock notifications to hide content on lock screen, enable Screen Security (blocks screenshots), and set a Registration Lock PIN to prevent account takeover
Push notifications from all apps including Signal are routed through Apple and Google servers — law enforcement can access them with a court order even if messages are encrypted. Disable "Show Message Content" in Signal's notification settings
Molly - Hardened Signal fork for Android; works with Signal contacts, adds RAM wipe on lock, encrypted local database, and UnifiedPush. Note: not affiliated with Signal; recommended on GrapheneOS
Matrix/Element - Federated, self-hostable, good for large communities. Note: E2E encryption must be manually enabled per room; federated model exposes some metadata
For video calls: Signal supports E2E encrypted calls up to 75 people. For larger groups, use self-hosted Jitsi Meet (no account, no third-party data collection)
Avoid: SMS, WhatsApp, Facebook Messenger, Telegram, Discord, Slack - all store messages, lack full E2EE, or share data with third parties. Note: Instagram removed its opt-in encrypted DMs feature as of May 2026 - Meta can now read and share all DM content with law enforcement. WhatsApp cloud backups to Google Drive or iCloud are not E2EE by default - governments routinely obtain full message histories this way. Facebook Messenger group chats require manually enabling E2EE
Voice notes and calls create a permanent voiceprint - a biometric that cannot be changed if compromised. Treat any audio you send as permanently linkable to your identity, even over E2EE apps
Social Media
Mainstream social media is built on surveillance. Decentralized alternatives have no algorithm, no ads, and no central owner
Nostr - Most private; no email/phone required, identity is a self-generated private key, posts sent through decentralized relays. Note: technical setup, not beginner-friendly
Friendica - Decentralized Facebook alternative, profiles, groups, events, photo albums, private messaging, no ads, no tracking, federates with Mastodon and Pixelfed
Mastodon - Decentralized Twitter/X alternative, no ads, no tracking, chronological feed, open-source. Note: Threads content may appear in federated timelines
Pixelfed - Decentralized Instagram alternative, no ads, no tracking, chronological feed, official iOS/Android apps available
Lemmy - Decentralized Reddit alternative, no ads, no tracking, open-source
PeerTube - Decentralized YouTube alternative, no ads, no tracking, French non-profit Framasoft. Note: disable P2P mode or use a VPN, P2P exposes your IP
All above use decentralized/federated models, no central ownership, no algorithmic manipulation. Federated platforms cannot be acquired, shut down, or compelled to hand over all user data at once, this is why they are recommended over centralized alternatives. Note: the server operator of whichever instance you join can read your posts and messages - choose a trusted instance
If keeping existing accounts: set them to private, opt out of personalised ads in each app's settings, and delete your advertising ID (see Mobile Apps section)
Avoid: Meta (Facebook, Instagram, Threads), X/Twitter, LinkedIn, Snapchat, Pinterest, Reddit, YouTube, Twitch, Truth Social, Gab, Rumble, TikTok, RedNote & Lemon8 (all collect personal data, use algorithmic manipulation, and share extensive data with advertisers and third parties)
Meta: Facebook (extensively tracks non-users via invisible pixels, Cambridge Analytica scandal, sued by dozens of US states for harming teen mental health), Instagram (continuous location tracking, internal documents revealed the company knew Instagram was harmful to teen mental health and prioritised profit over safety), Threads (14 data categories collected). Meta Pixel is an invisible tracker embedded on roughly a third of popular websites including hospitals, banks, and retailers, reporting your activity back to Meta even without a Facebook account, building a shadow profile on you. Use the uBlock Origin extension to block it automatically.
X/Twitter (AI training opt-in without consent, collects biometric and location data), LinkedIn (Microsoft-owned, cross-web tracking), Snapchat (continuous location tracking), Pinterest (cross-web tracking via embedded Save buttons), Reddit (sells data to AI companies), YouTube (extensive Google tracking), Twitch (Amazon-owned, collects personal demographics), Truth Social (shares data with advertising partners, cross-web tracking, no independent audit), Gab (no published privacy protections), Rumble (limited published privacy protections), Tumblr (reported RTB surveillance conduit), TikTok (precise GPS, cross-app tracking, political censorship), RedNote & Lemon8 (extensive data collection, government data access, censorship).
FTC 2024 Surveillance Report: Found that major social media platforms collected data far beyond user expectations including from non-users, purchased users' offline data from data brokers, frequently failed to honor deletion requests, treated teens identically to adults, and deployed tracking pixels and algorithms with no opt-out mechanism. Self-regulation was found to be "failing."
Internet Service Providers
In the US, ISPs can legally collect and monetise your browsing history, app usage, and location data without consent — there is currently no federal law prohibiting this. With widespread HTTPS, ISPs can see which domains you visit but not the content of your browsing. A VPN is the most reliable protection (see VPN section)
Sonic - One of the few ISPs with a strong, publicly documented track record of protecting user privacy and fighting government data requests - historically earned perfect scores from the EFF; does not store browsing data, does not share traffic with third parties. Note: Northern and Central California only
To find ISPs at your address, check broadbandmap.fcc.gov. Log into your ISP account and opt out of data sharing and advertising programs - note that ISP opt-out tools are frequently unreliable in practice. Use your own router rather than the ISP-provided one - ISP routers have weak firmware and rarely receive security updates - and change its default admin password
Avoid if possible: Comcast/Xfinity, AT&T, Verizon, T-Mobile - fined for illegally sharing customers' real-time location data with third parties without consent
Routers
Your router is the most exploited device on home networks. Router security has two layers: hardware and firmware. Open-source firmware removes vendor telemetry and backdoors. Privacy-focused hardware ensures the device itself is trustworthy.
As of March 2026, the FCC banned all new foreign-made consumer routers from US sale unless pre-approved by the Department of Defense (DoD) or DHS. Existing authorized router models are unaffected. Firmware updates for foreign-made routers were originally set to cut off March 2027 but the FCC extended this to at least January 2029. Flashing OpenWrt remains the recommended workaround. Firewall appliances are professional devices not subject to this restriction
Firmware + router (accessible starting point)
OpenWrt (on a used router) - Open-source firmware replacing factory software - removes telemetry, adds WireGuard VPN, VLANs, ad blocking. Check openwrt.org/toh for all compatible devices - step-by-step guides are available for every supported device
Firewall appliances (more private but requires technical setup)
Firewall appliances are wired-only mini PCs running OPNsense - a professional firewall OS. They handle all routing, firewall, VPN, and DNS but have no WiFi radio. Full setup: modem → firewall appliance → OpenWrt router in access point mode (WiFi only)
Protectli Vault + OPNsense - Fanless, US-assembled, open-source coreboot firmware. Intel ME soft-disabled. Multiple models available
NitroWall + OPNsense - Coreboot, Intel ME more thoroughly disabled than Protectli. Requires a separate modem, German firmware and assembly on Chinese-manufactured hardware
Deciso + OPNsense - Coreboot. The highest-trust option: hardware and software made in the Netherlands by the team that founded and maintains OPNsense. Note: Most expensive
Replace consumer routers every 3-5 years - manufacturers stop providing firmware updates, leaving them vulnerable. If keeping your current router: change the default admin password, enable WPA3, update firmware, disable WPS, UPnP, and remote management. ASUS users: disable AiCloud immediately. Firewall appliances running OPNsense receive updates indefinitely and do not have this limitation
Running a VPN on your router protects every device on your network - including smart TVs, consoles, and IoT devices that can't run VPN apps directly. Both Mullvad and IVPN support this via WireGuard on OpenWrt. Also enable encrypted DNS (DNS-over-TLS) on your router - this defeats router-level DNS hijacking attacks even if the router itself is compromised
Avoid entirely: Google WiFi, Eero, Nest, and ISP-provided routers (locked-down firmware with no privacy controls and owned by data-collecting companies). TP-Link: replace or flash OpenWrt immediately - subject to documented security vulnerabilities. D-Link: replace immediately - subject to documented security vulnerabilities. ASUS, Netgear, Linksys, Synology, and GL.iNet: only acceptable with OpenWrt replacing factory firmware
Home Network Security
Every device on a flat home network is a neighbor to every other - a simple network separation prevents any one device from compromising the rest
Accessible (no technical setup)
Firewalla - Plug-in hardware device that monitors all network traffic, blocks ads and trackers across every device, detects intrusions, and alerts you when a device behaves unexpectedly. App-based, no command line needed. Open source, data stays local on the device, no account required, one-time purchase. Note: only push notification text strings sent to cloud - not network data. Purple or Gold models recommended for most home networks
Technical setup (~1 hour, Raspberry Pi required)
AdGuard Home - Blocks ads and trackers across every device on your network without installing anything on them. Native encrypted DNS (DoH/DoT) built in. Note: logs queries by default - disable in settings for full privacy
Pi-hole - Same network-wide blocking as AdGuard Home but requires additional manual configuration for encrypted DNS. More customisable for advanced users
Advanced (requires OPNsense)
Suricata - Open-source network intrusion detection and prevention, blocks known attacks in real time. Built into OPNsense (see Routers section)
CrowdSec - Blocks IPs seen attacking other users across its community network. Note: collaborative by design - when an attack is detected on your network, data about it is sent to CrowdSec's central servers and shared with other users. Opt in knowingly
Put smart TVs, speakers, and IoT devices on a separate Guest Network - if one is compromised, it can't reach your computer or phone. If your router is more than 4-5 years old and no longer receives updates, replace it - the FBI has warned that end-of-life routers are being actively exploited
Ring doorbells: opt out of Axon Community Requests (lets police request footage directly) and disable Familiar Faces facial recognition in the Ring app. Ring's Flock partnership was cancelled in February 2026 after public backlash, but other data-sharing programs remain active
Private AI
Local AI
Local AI models should never be granted system access, web access, or file and tool use capabilities unless you fully understand the risk - an AI agent with OS-level access can read plaintext content before encryption and after decryption, including messages, files, and passwords. The tools below are privacy-first alternatives that don't train on your data
Ollama - Fully offline, no data transmitted, no OS or file system access, no outbound connections by default. Best for technical users
Jan - Zero telemetry, zero tracking, fully open-source and auditable, clean ChatGPT-style desktop interface, actively maintained. Best for everyday users wanting a simple private AI. Windows/Mac/Linux
Both run a local API server with no authentication - never expose them to the internet or other devices on your network. Keep them on your machine only
Cloud AI
Many cloud AI assistants store your conversations for years and may use them to train their models, including targeted advertising, as well as psychologically profiling you via Sentiment Analysis, or identifying you by your typing habits. The tools below are built differently - privacy by design, not as an afterthought
Maple AI - Uses secure enclaves so queries are encrypted in transit and only decrypted inside isolated hardware - not true E2EE but better than standard cloud AI. Zero data retention, open-source, anonymous accounts. Funded and endorsed by the Human Rights Foundation. US-based. Most fully featured of the four - web and mobile, document upload, image analysis, cross-device sync
Brave Leo - Built into Brave Browser, no logs, no account required, conversations deleted after response, not used for training, all models self-hosted by Brave. US-based. Most frictionless - zero setup, already in your browser sidebar. Brave users only
Lumo - Proton-built. Zero-access encryption for saved chats, no server-side logs, Ghost mode, Switzerland-based, GDPR compliant. Note: heavy content filtering on many sensitive topics; runs smaller, less capable models than mainstream AI; "open-source" marketing disputed - Proton runs open-weight models on proprietary infrastructure, meaning privacy claims cannot be independently verified
Duck.ai - No logs, strips metadata before forwarding to model providers, not used for training. US-based. Simplest to use with access to the most capable models - best for quick one-off queries without an account. Daily prompt limits on free tier
Avoid: ChatGPT, Google Gemini, Microsoft Copilot, Siri, Grok, Meta AI, Manus, Perplexity, Poe, DeepSeek, Qwen, Character.AI (store and analyze all your conversations, unclear data usage)
If using mainstream cloud AI I highly recommend using an email alias at signup and disable conversation training in settings first (ChatGPT, Claude, Gemini, and Copilot all have this option) - Meta AI and Grok have no opt-out. No cloud AI is fully private. Even with training opted out, safety-flagged conversations can still be reviewed. Never share sensitive, personal, or work information with cloud AI.
Shopping
Every online purchase is a data point - tied to your name, address, card, and browsing history. Retailers sell this to data brokers. Start with local shops and cash for everyday purchases
Local shops / markets / thrift stores / community - Pay with cash to stay anonymous and support the local economy, zero digital footprint
Ten Thousand Villages - Fair Trade marketplace, pays artisans a living wage, handmade crafts and gifts
Craigslist - No account required, relay email hides your real email, cash only. Note: always meet in public, never accept checks or money orders, no buyer protection
eBay - General marketplace, money-back guarantee, far less data collection than Amazon. Note: account and identity verification required
Buy direct from brand or seller websites where possible - many independent sellers have their own sites. For online purchases use either a virtual card (anonymous except to your bank) or a cash-bought fixed-balance non-reloadable "prepaid Visa/Mastercard gift card" (no bank link, no account, no identity trail) with an email alias.
Avoid loyalty cards and rewards programs, they build purchase profiles sold to data brokers. If a seller demands payment by gift card, wire transfer, or crypto, it is a scam. Meet in public for in-person exchanges
Avoid: Amazon, Facebook Marketplace, PayPal, Temu, AliExpress, Shein (data collection, tracking), loyalty cards and rewards programs (purchase profiles sold to data brokers, frequent breach targets)
Banking
No bank is truly private - all must verify your identity and comply with government requests by law. Big banks actively monetize transaction data for advertising. Local credit unions are member-owned and not-for-profit - consumer trust is tied directly to their survival in a way it isn't for big banks
Local credit unions - Fewest third-party vendors by design – the least data exposure of any option. Member-owned, not profit-driven. The NCUA cannot examine those vendors – less regulatory reach into vendor data, but also less protection if a vendor mishandles it. Find one at mycreditunion.gov or mapping.ncua.gov
Redwood Credit Union (Northern California only) - States it does not share with nonaffiliates for marketing and does not jointly market. A+ financial health, no balance transfer fees, CD rates 3x national average. Voted Most Philanthropic in the North Bay 2025, runs a charitable fund for disaster relief, housing, and financial literacy. Note: $14 opt-in overdraft fee (max 4/day); Direct Access checking has no overdraft fees
Self-Help Federal Credit Union (California, Illinois, Washington, and Wisconsin) - States it has not and will not sell personal information to anyone. Open to anyone with a $5 donation. No overdraft fees. 30,000+ fee-free ATMs via CO-OP. CDFI-certified, focused on economic opportunity for underserved communities; certificates fund eco-friendly and community development projects. Note: savings online with $5 donation; checking requires branch visit
HOPE Credit Union (Alabama, Arkansas, Louisiana, Mississippi, and Tennessee) - States it does not sell or transfer member data to third parties. Basic savings available to anyone with a $10 donation. Competitive APY on checking, 5,000+ shared branches via CO-OP. Green America certified, CDFI. Note: $25 overdraft fee (capped at $125/day)
BECU (Washington, Oregon, and Idaho) - States it does not sell member data to outside companies for their own marketing purposes. 77,000 fee-free ATMs, no fees, free credit score checks, gave community grants in 2025. Full account management available remotely via video call with a BECU consultant. Note: $10 overdraft fee up to 5x/day – opt out to avoid it; joint marketing agreements with other financial companies exist and cannot be opted out of, but this is standard industry practice for larger banks and credit unions
Avoid: Chase, Bank of America, Wells Fargo, Citibank, Capital One - all confirmed to monetize customer transaction data for advertising or have major data breach histories. Note: Visa, Mastercard, and American Express also sell aggregated transaction data to advertisers so considering using cash or prepaid fixed-balance gift cards for sensitive purchases
Your annual privacy notice contains a data-sharing opt-out form (required by federal law, the default is opt-in) - you should submit it or contact them directly to opt out. This opt-out does not cover joint marketing agreements between financial institutions
Visiting your physical credit union or bank is recommended over online banking, but if doing online banking consider use a passkey or an authenticator app for logging in if possible (see the Two-Factor Authentication section). Avoid using SMS text messages for 2FA if possible. SMS codes can be intercepted via SIM swapping (criminals can convince your carrier to transfer your number to their device) or SS7 exploits (a flaw in the global SMS routing protocol), both of which give attackers your bank login codes without ever touching your phone. Never give your bank login to other third-party apps aside from authenticator apps - it may void fraud liability.
Never transfer money to someone claiming to be your bank; hang up immediately - AI voice cloning is a developing issue.
Remember the smaller and more local your credit union, the fewer outside vendors they generally use, and thus less personal data exposure. Also consider using virtual cards for online shopping to limit merchant tracking and to prevent your card info from getting stolen should there ever be a data breach
Virtual Cards
Card transactions build detailed profiles of your life. Virtual cards limit merchant tracking and protect against data breaches from exposing your real card info
Prepaid gift card (cash-bought) - Buy a fixed-balance, non-reloadable Visa/Mastercard gift card with cash at pharmacies, grocery stores, or gas stations. No ID required, no bank link, no account, no identity trail. Do not register it. Fully legal in the USA. Most private option - your bank and card network see nothing
MySudo - All charges appear on your bank statement only as "MySudo Transaction" - your bank cannot see where you spend. Up to 9 virtual cards per plan, each tied to a pseudonym not your real name. Note: virtual cards are iOS only; paid plans only; must disable VPN during initial setup; 2.99% + $0.03 per-transaction fee; KYC required; US only
Privacy.com - Create merchant-locked or single-use virtual cards that protect against merchant data breaches. Never sells customer data, SOC 2 Type II certified. Free tier: up to 12 cards/month. US only. Note: by default shares merchant names with your bank - enable "Private Spend Mode" in settings to hide them. KYC required. Privacy.com still has full knowledge of where you spend
Revolut - Disposable one-time virtual cards with spending limits. International option (US, EU, Australia, Japan). Note: data sharing enabled by default - opt out in privacy settings
Use with an email alias for anonymous online purchases. Standard bank-issued virtual cards only hide your real card number from merchants - your bank and Visa/Mastercard still see every transaction. Only MySudo or cash-bought prepaid cards hide spending from your bank entirely
Financial Privacy
Most of the steps below are one-time actions with lasting protection. See also: Banking and Virtual Cards sections
Freeze all your credit files - Most people freeze only the big three (Equifax, Experian, TransUnion), but several other agencies are checked for different purposes - and each requires a separate freeze. ChexSystems: used by banks for new checking/savings accounts. Innovis: a 4th credit bureau used by some lenders. NCTUE (nctue.com): used by wireless carriers and utilities - freezing Equifax does not cover this separately. LexisNexis (consumer.risk.lexisnexis.com): used by credit card issuers, retailers, and wireless providers - also covers SageStream. All are free. Save your PINs; you'll need them to lift freezes when applying for new accounts or services
IRS Identity Protection PIN - A free 6-digit number that must appear on any federal tax return filed in your name, blocking fraudulent returns. Anyone with an SSN can enroll proactively - you don't need to have been a victim. Get one at irs.gov/ippin. Renews annually
Opt out of prescreened credit offers - Permanently removes you from credit bureau marketing lists at optoutprescreen.com. Stops pre-approved credit card and insurance mailers and reduces your profile being sold to lenders
Check your credit report annually - Free at annualcreditreport.com (the only federally authorized source). Space reports out - one bureau every four months - for year-round monitoring. Look for accounts you didn't open
Navigation & Maps
Your movement patterns reveal where you live, work, worship, shop, who you visit, and where you seek medical care. This data is sold to insurers, data brokers, and law enforcement without your consent. Switching to offline maps takes minutes and immediately stops all location tracking
Physical maps - Zero digital footprint, no tracking possible. Free at visitor centers, libraries, airports, and national parks; most US states mail free road maps on request; AAA members get free detailed maps; gas stations sell road atlases
If you need real-time navigation or live in an area not well covered by print maps, the options below keep your location on your device only
CoMaps - Offline, OpenStreetMap-based, no tracking, open-source, non-profit. Forked from Organic Maps in 2025 over governance concerns (Android/iOS/Linux/macOS)
OsmAnd - Offline, OpenStreetMap-based, highly customizable. Note: generates unique ID sent to OsmAnd servers when downloading maps; disable anonymous data sharing on iOS in settings
Download offline maps in advance - eliminates all data transmission during navigation for maximum privacy
Avoid: Google Maps, Apple Maps, Waze, Bing Maps (track location continuously)
Vehicles
Smart cars collect location, driving behavior, phone contacts, and voice recordings which is then sold to insurers and data brokers. The Mozilla Foundation found no major manufacturer meets basic privacy standards. But vehicle tracking isn't limited just to smart cars - external systems like license plate readers can track any vehicle passing by. Best to check your settings and opt out of everything you can, and be aware and avoid these physical tracking vectors too
vehicleprivacyreport.com - Enter your VIN to see exactly what your car collects and who receives it. Free, no account needed
Opt out - Disable connected services and telematics in your car's settings. Use privacy4cars.com to file opt-out requests with your manufacturer. Note: some collection continues regardless
Delete paired devices - Bluetooth and USB pairing syncs contacts and call logs to the car permanently. Always delete paired devices in rental cars and before selling
Avoid: insurance telematics programs and dongles, connected services opt-ins at the dealership, syncing social media or shopping apps to your infotainment system. Pre-2015 vehicles collect essentially no telematics data, though ALPR tracking still applies
Automated license plate readers (ALPRs) - collect and store timestamped location data every time your plate passes a camera; aggregated over time, this reveals where you live, work, worship, or seek medical care — a June 2026 Supreme Court ruling (Chatrie v. United States) now requires a warrant to access this data, even though no single camera captures the destination itself. EFF and ACLU investigations found California police agencies illegally sharing ALPR data with law enforcement in anti-abortion states in violation of state law. ALPRs are beginning to incorporate additional sensors (SignalTrace) that simultaneously capture RFID signals from key cards, asset tags, and pet microchips; Bluetooth identifiers from mobile phones, watches, fitness trackers, and wireless headphones; Wi-Fi signals from vehicle hotspots, tablets, smartphones, and laptops; and vehicle sensor data from tire-pressure sensors and infotainment systems - linking them all to your license plate as a persistent "electronic fingerprint" that survives a plate change. Mitigation: disable Bluetooth and Wi-Fi while driving; store phones in a Faraday bag; use deflock.me (or maps.deflock.org) or the FlockHopper app to plan routes to avoid known Flock and ALPR cameras entirely. Some choose to remove their tire pressure sensors to eliminate this tracking vector, at the cost of losing the low-pressure warning - check your state's vehicle equipment and inspection laws before doing so
Tire pressure monitoring systems (TPMS) - Tire pressure sensors broadcast a unique fixed radio ID that never changes (mandatory in all cars since 2007 in the US and 2014 in the EU) - trackable by anyone with a cheap receiver from 50+ meters away. Some choose to remove their sensors if their state doesn't require TPMS inspection (most don't) and just check their tire pressure manually instead
Translation
Every sentence you translate is stored and analyzed. On-device translation keeps your words off corporate servers
LibreTranslate - Open-source, self-hostable, no data stored. Access via browser on any device, or through third-party mobile apps. Note: public instances log IP addresses for 2 days; self-hosting is advanced but gives maximum privacy
Firefox Translations - Fully on-device, models downloaded locally, no data transmitted, works offline. Built into Firefox/Librewolf (Desktop only)
Apple Translate - Fully on-device, no data transmitted, 11 languages (iOS/macOS)
TranslateYou - Open-source, supports multiple engines including LibreTranslate, no tracking (Android)
Avoid: Google Translate, Microsoft Translator, Yandex Translate (store and analyze all translations)
File Sharing
Most file sharing services scan your files and store them indefinitely. Encrypted alternatives leave no trace
OnionShare - Most private; shares files over Tor, no central server, no account, file disappears after download. Pre-installed on Tails and QubesOS. Note: large files slow over Tor
Wormhole - E2E encrypted, up to 5GB, link auto-expires after 24 hours, no account needed. Note: files under 5GB transit wormhole.app servers; only the encryption library is open source
Internxt Send - Zero-knowledge, fully open-source, up to 5GB free, password-protected links, no account needed
Dangerzone - Before opening any document received from an untrusted source, run it through Dangerzone (dangerzone.rocks). It converts the file to raw pixels in an isolated sandbox and rebuilds it as a safe PDF, neutralising any embedded malware. Free, open-source, Mac/Windows/Linux
Avoid: Google Drive, WeTransfer, Dropbox (scan files, no E2E encryption)
File Storage & Sync
Files stored in the cloud are accessible to the provider and any government with jurisdiction over them. Encryption ensures only you can read your files
USB / External Drive - Zero network exposure, no cloud, no third-party. Encrypt with VeraCrypt for full protection if lost or stolen
Nextcloud - Self-hosted, most private, full control, open-source. Note: self-host only for maximum privacy, third-party providers defeat the purpose
Syncthing(advanced) - P2P file sync, no cloud server, no third-party involvement, open-source
Borg / restic(advanced) - Open-source encrypted, deduplicating backup tools, command-line, work with local drives or any remote server you control
Cryptomator - Encrypts files client-side before uploading to any cloud; open-source. Use with any cloud provider for added security
Proton Drive - E2E encrypted, open-source, independently audited including mobile apps
NextBox (shop.nitrokey.com, Germany) - Plug-and-play Nextcloud home server appliance, open-source firmware, no cloud dependency, self-hosted from day one
Avoid: Google Drive, Dropbox, OneDrive, iCloud (scan your files, no E2E encryption)
Calendar
Your calendar reveals medical appointments, travel plans, relationships, and daily routine. Safe alternatives below ensure only you can read your schedule
Proton Calendar - E2EE, encrypts event titles, descriptions, locations, and attendees. Audited, Switzerland-based, free tier includes 3 calendars. Note: on Android, Google push notifications leak some event timing metadata to Google
Tuta Calendar - E2EE, quantum-resistant encryption, encrypts more by default than Proton. Open-source, Germany-based. Note: free tier limited to 1 calendar
Avoid: Google Calendar, Apple Calendar, Outlook Calendar (unencrypted, provider can read all event data)
Note-Taking
Your notes contain your most private thoughts. Most mainstream apps scan and analyze everything you write. The options below encrypt your notes so only you can read them
Standard Notes - E2E encrypted, zero-knowledge, independently audited, 2FA hardware token support, Proton-owned (Cross-platform). Note: free tier is limited
Avoid: Google Keep, OneNote, Evernote (scan and analyze your notes)
Audio Transcription
Most popular transcription apps send your audio to remote servers. The good news: fully local, on-device alternatives exist that are free, accurate, and require no account
Whisper Notes (Mac/iOS, $6.99 one-time) - on-device transcription with no server to send data to by design. No analytics, no account. Requires iPhone 12 or later
Whisper (run locally) - open-source transcription model you download and run entirely on your own machine. Free, 99 languages, no telemetry, no account. Requires command line setup and decent processing power. Do not use the Whisper API - that sends audio to OpenAI
Aiko (Mac/iOS, free) - on-device transcription, nothing leaves your device, no analytics, no account required. Drag and drop any audio or video file and receive a transcript. iOS uses a smaller model due to memory limits
oTranscribe (browser, free) - audio playback assistant for typing your own transcripts manually. Audio and transcripts never leave your browser. No account, no server, open source. Used daily by thousands of journalists. Note: does not automatically transcribe - you listen and type yourself. Best for highly sensitive audio where zero automated processing is required
Many doctors and clinics use AI transcription tools that record your appointment and send audio to third-party vendors – often without explicit consent. You have the right to ask your provider if AI transcription is being used and request it be turned off. Some tools also generate voiceprints from your voice, which is biometric data with its own legal risks
Avoid: Otter.ai (faced legal action over consent violations, trains on user data), Fireflies, Fathom, Notion AI, Microsoft Copilot, Zoom transcription
Recording laws vary significantly by jurisdiction. Many US states and countries require all-party consent before recording a conversation. Always check your state laws before recording others
Photo Backup
Cloud photo services use facial recognition and metadata to identify people, places, and events in your photos - often without your knowledge. The options below encrypt your photos before they ever leave your device
Ente Photos - E2E encrypted by default for all photos and metadata, fully open-source, cross-platform, self-hostable, independently audited (iOS/Android/Desktop/Web)
Avoid: Google Photos, iCloud Photos (scan your photos, facial recognition data collected)
Antivirus & Anti-malware
Malware can silently record keystrokes, access your camera, and exfiltrate files. Good habits prevent most infections before they start
ClamAV - Fully open-source, no data collection, maintained by Cisco Talos (Linux/Windows/macOS)
Hypatia - Open-source, real-time malware scanner, ClamAV-based, fully offline, near-zero battery impact (Android). Note: original DivestOS version discontinued December 2024 - community fork available on GitHub and F-Droid
Windows Defender - Built-in baseline protection (Windows only). Note: sends data to Microsoft, last resort option
Good habits beat most AV software - keep everything updated, use uBlock Origin, avoid suspicious downloads, use a standard account (daily use only, keep a separate admin account for system changes). Most AV is closed-source with deep system access, a bad choice is worse than none. Linux and Android have far lower malware exposure than Windows
Avoid: Avast, AVG, Norton, Avira (all Gen Digital; Avast specifically received an FTC fine and settlement for secretly selling user browsing data to more than 100 third parties while marketing itself as a privacy tool), Kaspersky (banned by US government on national security grounds), McAfee (aggressive data collection)
Music & Podcasts
What you listen to reveals your politics, religion, mental state, and interests. The local and open-source alternatives below let you listen freely without building a detailed profile on you that streaming platforms will sell
VLC - Local media player, open-source, plays everything locally, no network calls, no account, cross-platform
Navidrome - Self-hosted music server, streams your own collection, lightweight, open-source. Note: technical setup required
Nuclear - Open-source desktop music player, streams from YouTube/SoundCloud/Bandcamp and local files, no ads, no tracking, no account required (Desktop)
Bandcamp - DRM-free, you own your music, average 82% revenue goes to artists, no AI music. Note: privacy policy uses tracking technologies with Meta, Google, and Reddit ad partners upon consent. Note: acquired by music licensing company Songtradr in 2023
Podcasts: Use RSS-based apps - no account, no tracking. AntennaPod (open-source, F-Droid, supports listening via Tor, Android), gPodder (open-source, desktop/Android)
Avoid: Spotify (shares listening data with advertising and marketing partners, builds detailed behavioral profiles), Apple Music, Apple Podcasts, Amazon Music
If you must use Spotify or similar: use a VPN, sign up with an email alias, never connect via Facebook or Google, disable data sharing in Settings > Privacy, and use a virtual card for payment
TVs & Streaming
Your TV watches you back. The options below let you watch without being watched in return
Jellyfin - Self-hosted, zero telemetry, fully private, free and open-source. Note: technical setup required
Kodi - Local media player, open-source, no telemetry
Apple TV - Best mainstream option, no ACR, apps require tracking permission. Note: disable viewing data in Settings > General > Privacy & Security
Avoid: Roku (advertising-based business model), Netflix, Disney+, Amazon Prime Video (all profile your viewing habits. If you must use them, opt out of data sharing in account settings).
Smart TVs use Automatic Content Recognition (ACR) to track everything you watch and sell it to advertisers. Disable it in your TV's privacy settings and check after every update. Disconnect your TV from the internet entirely if possible, or isolate it on a guest network. If keeping your TV connected, consider running a VPN on your router (see Routers section)
Gaming
Gaming platforms collect far more than gameplay - the options below let you game privately without handing over your data
GOG - DRM-free, client optional; no data collection without the Galaxy client
Heroic Games Launcher - Open-source launcher for GOG and Epic games, no telemetry by default (Linux/Windows/Mac). Note: opt-in anonymous analytics
Bottles - Open-source sandboxed Wine manager, runs Windows games on Linux without Steam, NLnet-funded (Linux)
Avoid: Steam, Epic Games, PlayStation Network, Xbox Live, EA, Ubisoft Connect - all collect extensive behavioral data. Keep consoles offline when not in use
Gaming platforms collect playtime, hardware specs, IP, chat, purchase habits, and in-game behaviour - used to build profiles sold to advertisers. DRM locks your library to a platform, DRM-free games can be kept forever. If using PC platforms: VPN, email alias, virtual card, disable telemetry, no real name. Consoles cannot run VPNs directly - use a router-level VPN or share from a PC/Mac
Health & Fitness
Health data is among the most sensitive you generate. The apps below store your data locally so it never leaves your device
wger - Self-hosted workout, nutrition, and weight tracker, open-source, fully offline, F-Droid available (Android)
FitoTrack - Outdoor/cardio tracking, open-source, all data stored locally, no tracking, F-Droid available (Android)
Apple Health - Data stays on-device by default, encrypted, user-controlled app permissions (iOS). Note: closed-source
Period & Cycle Tracking: Period tracking apps are exempt from HIPAA - data can legally be sold to insurers and subpoenaed by law enforcement, though some states (Washington, California, Nevada, Virginia) now have specific reproductive health data protections. Use local-only apps: Drip (open-source, feminist non-profit, no data collection, F-Droid), Euki (local storage, PIN protection, fake screen feature to hide app quickly), or Periodical (simplest, local only)
Avoid: Flo (FTC settlement and subsequent class action for secretly sharing menstrual and pregnancy data with Facebook, Google and others without consent), MyFitnessPal (suffered a major data breach affecting millions of users, shares data with advertisers), Fitbit (Google-owned), Strava (public location data risks), Google Fit, Samsung Health, and consumer EEG/brain-sensing wearables (Muse, Emotiv, NeuroSky) - the majority of neurotechnology companies share brain data with third parties and few encrypt it, and no federal protection exists
Physical Security
Digital privacy can be undone in seconds by physical access. The tools and habits below address each of these risks directly
Screen privacy filters - Polarized film that limits your screen's viewing angle to ~60 degrees, blocking shoulder surfing in cafes, airports, and offices. Available for laptops, phones, and monitors - search your device model + "privacy filter"
RFID/NFC-blocking wallet or sleeve - Prevents contactless skimming of credit cards, passports, and access cards. Any wallet or sleeve labelled RFID-blocking works. Particularly relevant for passports - the US e-passport chip can be read without your knowledge at close range
Try not to leave devices unattended in public - even brief physical access to an unlocked device can be enough for someone to access accounts or install tracking software. Lock your screen before stepping away (Windows: Win+L, Mac: Ctrl+Cmd+Q, iPhone/Android: power button). Enable full-disk encryption so a stolen device cannot be read without your password
Emergency Preparedness
Cell networks, internet, and power grids are often the first things to fail in a disaster and also the first things to be monitored during civil unrest. Being prepared for an emergency means having your own communication and navigation tools ready that work independently of any centralized infrastructure
Go Bag - A pre-packed bag ready to grab at a moment's notice. Privacy and security essentials to include: emergency radio, Faraday bag, offline phone with CoMaps downloaded, backup power bank, waterproof pouch with printed copies of IDs, insurance, contacts and evacuation routes, first aid kit, water, and 72 hours of food. Store in a cool dry place and review contents annually
Emergency Radio - Receives 24/7 emergency alerts even with no internet. Look for one with NOAA SAME (county-specific) alerts, hand crank, solar, and USB charging
Physical Maps / CoMaps - Physical and offline maps that require no internet. With the CoMaps app download all relevant regions before an emergency. See the Navigation and Maps section for more details and other options
MeshCore - Encrypted mesh messaging over LoRa radio. No cell service, internet, account, or identity required. Messages relay over several kilometers. Connects to your phone via Bluetooth. Pacific Northwest residents consider joining CascadiaMesh - the largest MeshCore network in North America, solar-powered and already active. Note: requires hardware setup ahead of time - not a plug-and-play solution
Ham Radio (Amateur Radio) - Most resilient long-range emergency option - works independently of internet, cell, and corporate infrastructure. Range of tens to hundreds of miles. ARES provides organized volunteer emergency networks recognized by FEMA. Note: requires FCC Technician license; transmissions are unencrypted and callsign is publicly registered
Faraday bag - Blocks all wireless signals - cellular, Wi-Fi, GPS, Bluetooth, and RFID - preventing passive location tracking and remote access attempts. Also protects devices against electromagnetic pulses from solar flares or EMP events
Briar - Encrypted P2P messaging over Bluetooth or Wi-Fi Direct. No internet, no account, no phone number. Android only. See Messaging section for full details
Keep a solar charger or power bank in your kit - all these tools need power. Print key contacts, evacuation routes, and copies of important documents and store them in a waterproof bag alongside emergency cash - paper and cash cannot be remotely wiped, tracked, or blocked. Consider a backup offline device with CoMaps and contacts pre-loaded, stored in a Faraday bag
These tools complement but do not replace emergency services. Always call 911 in a life-threatening emergency
Ideas & Recommendations
Things to be aware of
Global Privacy Control (GPC) - a browser signal that legally tells websites not to sell your data, enforced under CCPA and 12+ US state privacy laws. A 2026 independent forensic audit found that Google, Meta, and Microsoft routinely ignore GPC signals despite the legal requirement to honor them - the uBlock Origin browser extension blocks tracking requests technically before they reach these companies' servers, making it the more reliable protection, so you should consider adding that as well on browsers that support it (aside from Tor and Mullvad). California's Opt Me Out Act, effective January 2027, requires all major browsers including Chrome, Safari, and Edge to provide a built-in opt-out preference signal (GPC)
Data brokers - companies that legally purchase, aggregate, and resell your private personal information without your knowledge or consent. They collect from public records, social media, loyalty cards, app data, and other brokers, building highly detailed profiles that include your name, current address, current phone number, relatives, health conditions, income, political views, and location history. This data is openly sold to advertisers, insurance companies, employers, law enforcement, the government, and anyone else willing to pay (including stalkers and abusive partners). You have no say in whether your data is collected, only in requesting its removal - which is why the opt-out steps in Essential Security Habits truly matter
Advertising intelligence (AdInt) - governments and law enforcement have purchased location data generated by your everyday apps through advertising platforms without warrants — though a June 2026 Supreme Court ruling (Chatrie v. United States) now requires a warrant to access location data revealing physical movements. One company was reported to collect billions of location signals daily from hundreds of millions of devices, selling access to DHS, DEA, and FBI. Ad blocking and revoking location permissions from apps cuts off the data at the source - opting out of data broker databases alone is not sufficient, and keep devices updated — in April 2026 ICE confirmed domestic use of Paragon's Graphite spyware, which can silently compromise a phone and read encrypted apps including Signal without any user action
Automated license plate readers (ALPRs) - devices that collect and store vehicle location data about drivers are beginning to incorporate tracking technology such as SignalTrace to detect all Wi-Fi, Bluetooth, and vehicle sensor data to link passengers to vehicles directly. Solution: disable Bluetooth and Wi-Fi while driving; store phones in a Faraday bag; use deflock.me (or maps.deflock.org) or the FlockHopper app to plan routes avoiding known Flock and ALPR cameras entirely. Some choose to remove their tire pressure sensors to eliminate this tracking vector, at the cost of losing the low-pressure warning - check your state's vehicle equipment and inspection laws before doing so
Smart home devices (voice assistants, smart TVs, doorbells, thermostats, locks, plugs, bulbs) - almost all send usage data to manufacturer servers regardless of their privacy claims, creating detailed profiles of your daily routines, home occupancy, and behaviour. "Local-only" claims are frequently misleading. Amazon Echo and Ring carry additional risks covered separately below. The only fully private smart home hub is Home Assistant - an open-source, fully local alternative to Alexa and Google Home. For everything else, consider carefully whether the convenience is worth the trade-off. If you do use smart devices, consider putting every single one on a separate guest network
Amazon Echo devices (Echo, Echo Dot, Echo Show, Echo Studio) - always-on microphones that record and send audio to Amazon's servers. As of March 2025, Amazon removed the option to prevent voice recordings from being uploaded - all interactions are now sent by default with no opt-out. Amazon complies with law enforcement requests for recordings under legal order. Ring doorbells and cameras carry additional risks: in 2025 Ring reintroduced police footage requests via the Neighbors app (Community Requests) - sharing remains voluntary but critics warn it normalizes surveillance, launched facial recognition that captures biometrics of anyone who appears on camera without their consent, and has a documented history of sharing footage with law enforcement without user knowledge. EFF has called Ring a grave threat to civil liberties. If you own these devices: mute microphones when not in use, disable facial recognition, place on a separate guest network, and consider whether the risks outweigh the convenience
AI voice cloning - scammers replicate voices of family members from social media audio to fake emergencies and demand money. Agree on a family code word. Always call back on a known number before acting
QR code phishing (quishing) - fake QR codes placed over real ones in public spaces link to phishing sites; the URL is hidden until scanned. Preview the destination URL before proceeding and treat public QR codes like unsolicited links
SIM swapping - criminals impersonate you with your carrier to hijack your phone number, intercepting SMS codes and resetting passwords. Ask your carrier to add a SIM lock or port freeze requiring in-person verification
Bluetooth trackers (AirTags, Tiles etc.) can be hidden on your person or in your vehicle. Both iOS and Android alert you to unknown trackers nearby - if you receive an alert, check your belongings carefully and use the app to play a sound to locate it. You can disable or hand it to police as evidence
Public USB charging ports - carry your own charger and use AC outlets; public USB ports can deliver malware alongside power
Bluetooth passive scanning - nearby devices can identify and track your hardware even without pairing. Turn Bluetooth off when not in use
AI smart glasses (Meta Ray-Ban etc.) - bystanders can be recorded without consent in public. Be mindful of sensitive conversations in public spaces and assume audio and video recording is possible at close range
Windows 11 Recall - continuously screenshots your screen; do not enable it
Gait recognition - camera networks can identify you by your walking pattern alone without needing to see your face. No direct countermeasure exists beyond avoiding predictable routes in high-surveillance areas
Forensic linguistics (writeprinting) - your writing style, vocabulary, sentence length, and punctuation patterns can be analysed to link anonymous accounts or posts to your real identity. If writing anonymously, use a translation tool (write in English, translate to another language, translate back, then edit) to disrupt identifiable patterns
MAC address tracking - your device's Wi-Fi and Bluetooth hardware identifiers can track your location even when not connected to a network. Phones randomise these by default but laptops often do not. On Linux enable MAC randomisation in NetworkManager settings; on Windows enable in network adapter privacy settings
Rogue Wi-Fi access points (evil twin attacks) - criminals create fake hotspots mimicking legitimate ones (e.g. "Airport_Free_WiFi") to intercept traffic. Always use a VPN on public Wi-Fi and verify the exact network name with staff before connecting
Motion sensor attacks - your phone's accelerometer and gyroscope require no permission and give no notification when accessed by apps or websites. Researchers have demonstrated they can reconstruct speech from your speaker, infer PINs from screen vibrations, track your location without GPS, and fingerprint your device in a way that survives a factory reset. The same applies to smartwatches. Mitigations: GrapheneOS users can block all sensor access via the Sensors permission toggle; Tor Browser blocks in-browser sensor access; avoid placing your phone near a keyboard when entering passwords; physical sensor removal via a device like the NitroPhone is the only complete countermeasure
DOGE data consolidation - in June 2026 the House passed two bills that would permanently expand warrantless government access to IRS, Social Security, and Treasury records by stripping the procedural safeguards currently required before agencies can share your data — now in the Senate
Reality Check
This guide protects against: Mass surveillance, corporate data collection, data brokers, advertising tracking, account breaches, and opportunistic hackers.
State-level targeting: Traffic analysis can defeat VPNs, hardware may have backdoors, metadata is powerful even without content. True protection requires operational security beyond technology - for high-risk individuals consult ssd.eff.org, securitylab.amnesty.org, and accessnow.org/help.
Intelligence-sharing alliances between the US and other countries can be used to compel companies to hand over your data, but a verified no-logs policy matters more than jurisdiction alone.
The human factor: Most breaches are social, not technical. Phishing and manipulation are how most people get compromised. No tool protects against being deceived into giving up your credentials.
ACR - Automatic Content Recognition (smart TV tracking of everything you watch)
AOSP - Android Open Source Project (the open-source base of Android that privacy-focused mobile OSes are built on)
CCPA - California Consumer Privacy Act (California privacy rights law)
COPPA - Children's Online Privacy Protection Act (US law protecting under-13s online)
DNS - Domain Name System (converts website names to IP addresses)
DoH/DoT - DNS over HTTPS / DNS over TLS (encrypted DNS protocols)
DRM - Digital Rights Management (locks content to a platform or device)
E2E/E2EE - End-to-End Encryption (only sender and receiver can read)
EFF - Electronic Frontier Foundation (non-profit digital rights organisation that defends civil liberties online, produces widely used privacy tools and guides)
FIDO2 - Phishing-resistant hardware authentication standard (used by YubiKey etc.)
GDPR - General Data Protection Regulation (EU privacy law)
GPC - Global Privacy Control (browser signal telling websites not to sell your data, legally enforced in 12 US states, recommended by Senator Wyden as a direct defence against government ad-tech surveillance)
GPG - GNU Privacy Guard (open-source encryption tool used to sign and encrypt emails and files)
HIPAA - Health Insurance Portability and Accountability Act (US health data law - does not cover most apps)
HTTPS - HyperText Transfer Protocol Secure (encrypted connection between your browser and a website - look for the padlock icon)
IMEI - International Mobile Equipment Identity (unique hardware ID assigned to your phone - can be used to track a device even if the SIM is changed)
IMSI - International Mobile Subscriber Identity (unique identifier tied to your SIM card, distinct from your IMEI - used by carriers and can be intercepted by IMSI catchers)
IP - Internet Protocol address (your device's unique online identifier)
ISP - Internet Service Provider (your internet company)
KYC - Know Your Customer (legal identity verification requirement imposed on financial services companies)
NFC - Near Field Communication (short-range wireless technology used in contactless payments and access cards - can be skimmed without contact)
OpSec - Operational Security (practices to protect sensitive information beyond technology)
OS - Operating System (e.g. Windows, macOS, Linux, Android, iOS)
P2P - Peer-to-Peer (direct connection between users, no central server)
RFID - Radio Frequency Identification (wireless technology in cards and passports - readable at close range without your knowledge)
RTB - Real-Time Bidding (every ad on a webpage instantly broadcasts your data to thousands of companies simultaneously - blocked by uBlock Origin)
SDK - Software Development Kit (code libraries embedded in apps, often used for hidden tracking)
SMS - Short Message Service (standard text messaging - insecure for 2FA as messages can be intercepted or redirected via SIM swapping)
SSN - Social Security Number (US government identity number - highly sensitive, used in identity theft and financial fraud)
TLS - Transport Layer Security (encryption protocol that secures data in transit, used in HTTPS and encrypted DNS)
TOTP - Time-based One-Time Password (rotating 6-digit codes for 2FA)
VM - Virtual Machine (software that emulates a separate computer inside your existing one, used for isolation and privacy)
VPN - Virtual Private Network (encrypts and hides your internet traffic)
WPA3 - Wi-Fi Protected Access 3 (current Wi-Fi encryption standard - more secure than WPA2, should be enabled on your router)
XMPP - Extensible Messaging and Presence Protocol (open, decentralised messaging standard used by some privacy-focused chat apps)
Resources
haveibeenpwned.com - Check if your email or passwords have been in a data breach. Sign up for breach notifications at haveibeenpwned.com/NotifyMe - free, automatic email alerts whenever your address appears in a new data breach
coveryourtracks.eff.org - EFF tool that shows how uniquely your browser can be fingerprinted by trackers - test your browser setup
The Hitchhiker's Guide to Online Anonymity - anonymousplanet.org - exhaustive open-source OpSec and anonymity guide, no ads or affiliates, community-maintained
privacyguides.org - community-driven tool recommendations, no ads or sponsorships
epic.org - Electronic Privacy Information Center, privacy law and policy research
securitylab.amnesty.org - Amnesty International Security Lab, digital security resources for all users
guardianproject.info - Builds open-source privacy and security tools for journalists, activists, and high-risk users
accessnow.org/help - Access Now's free 24/7 Digital Security Helpline - emergency technical support for journalists, activists, and anyone facing targeted surveillance or account compromise
Why Privacy Matters
Recognized internationally as a fundamental human right in the UN Declaration of Human Rights and enshrined in the Amendments to the Constitution, privacy underpins and strengthens nearly every one of our freedoms. Every tool in this guide is meant to support those inherent freedoms and bring back as much of your online privacy and security as possible. The end goal is not perfection, it is to make surveillance a lot harder, way more expensive, and much less complete. So that with enough effort we can build a safer future together, because privacy, just like freedom, should never be all or nothing. Every layer you add to protect yourself and the privacy of others truly matters. You are not powerless, you are just getting started.