Privacy Guides
Privacy that fits your threat: practical guides and in-browser tools, each tagged with a threat level and with what it does not protect against.
Start here: build your threat model36 items shown
Nothing at this level in this topic yet. Pick another level or topic.
Start here
Decide what you protect, from whom, and how much effort it is worth.
Decide what you are protecting, from whom, and how much effort it deserves, before you install anything.
Separate your real-name, professional and sensitive-work activity across distinct accounts, emails, numbers, browsers and devices, so a leak in one persona does not expose the others.
Turn a written threat model into daily discipline: reveal less, keep boring routines, share on a need-to-know basis, assume something is already compromised, and recognise the targeted phishing and social engineering aimed at you.
Devices & OS
Hardened phones and operating systems.
Two short scripts, one for Linux and one for Windows, that report how a handful of important privacy and security settings are configured on your own computer. They only read and report: they change nothing, install nothing and send nothing anywhere.
A short, once-a-year pass through the built-in privacy settings on a normal iPhone or Android phone: a strong lock, sensible app permissions, ad tracking off, and find-my turned on.
Prepare your devices before a trip so that a lost, stolen or inspected phone or laptop exposes as little as possible, and you can recover everything afterwards.
Replace the operating system on a supported Google Pixel with GrapheneOS, a security- and privacy-hardened Android, then verify it and lock it down.
Turn on Apple's optional extreme protection for people who may be personally targeted by sophisticated spyware, and understand what it blocks and what it leaves open.
Start a computer from a USB stick running Tails: everything goes through Tor, and nothing is kept when you shut down unless you choose to save it.
Remove GPS position, camera serial and other metadata from photos, and author, company and editing details from PDF and Office files, before you share them. Runs in your browser; nothing is uploaded.
Encryption
Disks, files and backups that stay unreadable if lost or seized.
Keep three copies of what matters on two kinds of storage with one away from home, encrypt every copy, keep one offline against ransomware, and prove it works by restoring a file.
Make sure a lost or stolen laptop or phone shows only scrambled data to whoever picks it up, and that you can still get your own data back.
Protect specific files, a folder of them, or a cloud-synced folder on their own, so that a lost, synced or seized copy is unreadable without your passphrase or key β a layer on top of full-disk encryption, not a replacement for it.
Move your encryption, signing and login keys onto a hardware security key so the secret never touches the disk, generate the long-term key offline, and protect it with a PIN and a physical touch β with a tested backup so one lost key does not lock you out.
Communications
Messaging and email, compared by what they leak.
Give each service its own address that forwards to your inbox, so a leak, a sale or a spam wave stays contained to one address you can switch off.
Signal encrypts your messages end to end by default. These settings protect the account, the phone screen and your phone number.
Compare Signal, WhatsApp, iMessage, Telegram, Element (Matrix), Threema and SimpleX on what each one's own documentation states: default encryption, the identifier you must give, encrypted backups, open source and protocol.
When a capable adversary is actively interested in you, end-to-end encryption is only the starting point: this goes deeper on verifying keys, starving the device of history, and the discipline both people have to keep.
Browsing & network
Browsers, DNS, VPN and Tor without the marketing.
Turn on the tracking, cookie, HTTPS and DNS protections your browser already has, trim your extensions, and split your browsing into separate profiles.
Lock down your home router and Wi-Fi: a new admin password, current firmware, WPA3 or WPA2 encryption, a guest network for visitors and smart devices, and risky features switched off.
A VPN moves your trust from the local network and ISP to one provider; Tor spreads it across several relays. Pick by the threat you actually face, not by marketing.
Browse anonymously under a serious threat: get Tor Browser from the Tor Project, verify its signature, set the security level to Safest, avoid the behaviours that unmask you, and move to Whonix when an app compromise leaking your real IP would be unacceptable.
See what any website can read about your browser without asking, such as screen, time zone and graphics card, and how to reduce it. Runs in your browser; nothing is sent.
Remove the tags that tell sites and advertisers who clicked a link (utm, fbclid, gclid and others) and see where Google, Facebook or Outlook redirect links really go. Runs in your browser and never opens the link.
Paste the cookies a site stored in your browser and see who sets each one and what it is for (analytics, advertising, login, consent), from the vendor's own documentation. Runs in your browser.
Accounts & identity
Passkeys, hardware keys, password managers and SIM-swap defence.
Pick a password manager by checkable properties, protect it with a strong passphrase and two-factor sign-in, move your browser-saved passwords into it, and use its own checks to replace reused and leaked passwords.
Stop someone from moving your phone number to their SIM, and make sure that even if they do, it does not unlock your accounts.
Replace passwords and text-message codes on your most important accounts with passkeys, which phishing sites cannot steal, and keep a backup so you never lock yourself out.
Review who can see your posts and profile, which apps are connected, how you can be found and what the platform uses for ads, then download a copy of your data and use your GDPR rights.
Close the recovery path so an attacker cannot reset your account around a strong login, by removing text-message recovery, registering more than one strong factor, and planning for lockout.
For a targeted, well-resourced adversary: sign in only with a hardware security key, enrol in your provider's strongest program, and turn on end-to-end encryption for the data your accounts store β accepting that the provider can then no longer recover it for you.
Long random passwords and passphrases generated locally, for the accounts that do not support passkeys yet.
EU / GDPR corner
Your rights under the GDPR, used concretely.
Find out which companies collect and sell your personal data, ask them for a copy, then make them delete it and stop using it for marketing.
What to do when an organisation ignores, refuses or half-answers your GDPR access, erasure or objection request: the deadlines, escalating to the data protection officer, lodging a complaint with a supervisory authority, and your right to go to court.
When your home address, phone number or other personal data is posted to expose or endanger you, use EU rights, search-engine removal forms and platform abuse channels together, and escalate to a supervisory authority, fastest routes first.
Ask an organisation what it holds about you, or have it corrected, deleted, exported or no longer used for marketing. EN, FR or DE letter with the one-month deadline; nothing is uploaded.
How to read the threat levels. Low: Everyday privacy, for anyone. Medium: Elevated exposure: journalists, activists, consultants on sensitive engagements, high-profile staff. High: A hostile, well-resourced adversary. No guide guarantees anonymity: your threat model decides what is enough. Every guide links its official sources and shows when it was last verified. No affiliate links, no sponsors. Educational content for lawful, authorized use only.