The Everyday User’s Privacy Checklist: 7 Simple Settings to Secure Your Online Accounts
Read this article in clean Markdown format for LLMs and AI context.You probably think privacy is something only tech geeks worry about, but a single unchecked setting can hand your data to strangers faster than you can say “phishing.” Let’s fix that in a few minutes.
Why a privacy checklist matters today
Every day we log into dozens of services—email, social media, banking, shopping. Each login creates a tiny trail that companies (and sometimes bad actors) can piece together. When you leave default privacy options on, you’re basically leaving the front door wide open and trusting the world not to walk in. A quick checklist can lock that door without turning your life upside down.
1. Turn on Two‑Factor Authentication (2FA)
If a password is the key, 2FA is the deadbolt. Most sites now offer a free authenticator app or SMS code. Open the security settings of your email, Google, Facebook, and any banking app, and turn on 2FA. It adds a second step—usually a six‑digit code—so even if someone steals your password, they still can’t get in. I still get a code on my phone every time I log into my own blog, and it feels oddly satisfying.
Quick tip: Use an authenticator app like Google Authenticator or Authy instead of SMS when you can; it’s harder for attackers to intercept. Need a detailed walk‑through? Check out our guide to enable two‑factor authentication for Gmail.
2. Review App Permissions
When you sign up for a new service, it often asks for permission to read contacts, location, or even your camera. Go to the account’s permission page (Google’s “Third‑party apps with account access” is a good place to start) and revoke anything you don’t recognize. If a weather app wants access to your microphone, say no. Less data shared means less chance of it being misused.
Quick tip: Set a calendar reminder every few months to do a permission audit—it only takes a couple of minutes.
3. Hide Your Activity Feeds
Social platforms love to broadcast what you’re doing—liking a post, following a page, even the fact that you read an article. Look for settings like “Show my activity to friends” or “Public profile.” Switching these off keeps your actions private and stops the platform from building a public scrapbook of your life. I once turned off the “recently watched” list on a streaming service and felt like I finally got my binge‑watching back.
Quick tip: On most platforms, the toggle is under “Privacy” → “Activity Status” or similar.
4. Use Strong, Unique Passwords
A strong password is at least 12 characters, mixes letters, numbers, and symbols, and isn’t a word you’d use elsewhere. Use a password manager to generate and store them; that way you never have to remember anything but one master password. Changing a password once a year isn’t enough—if a breach happens, change it immediately.
Quick tip: If you’re new to password managers, try the free tier of Bitwarden or LastPass; they’re easy to set up and work across devices.
5. Limit Data Sharing with Advertisers
Many sites let you opt out of personalized ads. It won’t stop ads, but it stops them from being built on your browsing history. Look for “Ad preferences” or “Data sharing” sections and toggle off “interest‑based ads.” It’s a small win for privacy and often reduces the creepy “why did you just search for that?” ads that follow you around.
Quick tip: On Facebook, go to Settings → Ads → Ad Settings and turn off “Ads based on data from partners” and “Ads based on your activity on Facebook Company Products that you see elsewhere.”
6. Browse Privately or Use a VPN for Sensitive Sessions
When you’re checking bank statements or logging into a work portal on a shared computer, use the browser’s private/incognito mode. It doesn’t save cookies or history after you close the window. For an extra layer, a reputable VPN encrypts your traffic, making it harder for anyone on the same Wi‑Fi network to snoop. I keep a lightweight VPN app on my phone for those quick coffee‑shop logins.
Quick tip: Choose a VPN with a clear no‑logs policy—ProtonVPN and Mullvad are solid options that offer free tiers for light use.
7. Keep Your Account Recovery Options Secure
Most services let you set a recovery email or phone number. Make sure those recovery contacts are up to date and belong to you—not a friend who might change numbers. Some sites also offer recovery codes—write them down and store them in a safe place. If you ever lose access, these codes are your lifeline, and they keep attackers from hijacking your account through a weak recovery process.
Quick tip: Store recovery codes in a password manager’s secure notes feature or a physical lockbox; never keep them in a plain text file on your desktop.
A Simple Run‑Through
- Turn on 2FA everywhere you can.
- Revoke unused app permissions.
- Hide your activity feeds.
- Use a password manager for unique passwords.
- Opt out of interest‑based ads.
- Browse privately or use a VPN for sensitive logins.
- Keep recovery options current and secure.
Doing these seven things takes less than ten minutes, but the peace of mind lasts much longer. At Secure Steps we believe privacy isn’t a luxury; it’s a habit you build one setting at a time.
Further reading: For a concise step‑by‑step on securing your email, see our article on turning on two‑factor authentication for your email.
- →
- →
- →
- →
- →