← Privacy Guides

Start here

Compartmentalise your identities

Separate your real-name, professional and sensitive-work activity across distinct accounts, emails, numbers, browsers and devices, so a leak in one persona does not expose the others.

  • Medium threat
  • Time 1 hour to set up, then an ongoing habit
  • Difficulty Moderate
  • Last verified

What this protects, and what it doesn't

Protects

  • Against one exposed account revealing the rest: if a professional login is breached or a sensitive-work account is identified, it does not hand the attacker your real-name accounts as well.
  • Against an observer stitching your activity across services into a single profile, because each persona has its own accounts, email addresses and phone numbers with nothing in common.
  • Against a single slip tying two personas together: a reused profile photo, username, phone number or recovery email that quietly links accounts you meant to keep apart.

Does not protect

  • It does not make any one persona anonymous. A persona you use carelessly can still be traced back to you; compartmentalisation only stops that exposure from spreading to the others.
  • It does not survive weak discipline. One cross-post, one shared browser session logged into two personas, or one reused recovery email can collapse the walls you built.
  • It does not hide that the personas exist from an adversary with legal power over your provider, or with physical access to an unlocked device where several personas live side by side.

Prerequisites

  • A written threat model: which activities must stay apart, and from whom. See Threat modeling: start here.
  • Time to create fresh accounts, and the honesty to admit which separations you will actually keep up day to day.
  • Optional: a second device or a second phone number, and an authenticator app or hardware security key to protect each compartment on its own.

Step by step

  1. Map your personas and draw the boundaries

    Before creating anything, decide how many compartments you need and what belongs in each. A common split is three: your real-name life (family, friends, admin), your professional life (employer, clients, public profile), and your sensitive-work activity (the reporting, campaigning, consulting or research that would put you or others at risk if it were linked to your name).

    Write down, for each compartment, which accounts, email addresses, phone numbers, devices and people belong to it, and — most importantly — what must never cross between them. Let your threat model set the number: more compartments mean more walls to defend, and a split you cannot maintain is worse than an honest smaller one. EFF's security-planning guidance is blunt about this: "Trying to protect all your data from everything all the time is impractical and exhausting."

    Example: Alice Example keeps alice.example for friends, a professional profile under her real name at Example Corp, and a separate sensitive-work persona with its own name that is never linked to either.

  2. Give each compartment its own accounts and look

    Create fresh, independent accounts per compartment. Do not fork an existing account or "rename" one — reuse is what links personas. EFF's guide to protecting yourself on social networks has a section called Keep Separate Profiles Separate and warns that "For a lot of us, it's critical to keep different account identities separate."

    • Unique photo per persona. EFF advises using "a photo or image that you don't use anywhere else online", and warns that "Photos, in particular, can sneakily link accounts you intend to keep separate." A reverse image search will match a reused one.
    • Different usernames and display names with no shared pattern (not alice.work and alice.news).
    • Separate the registration details. Each account gets its own email address, and you avoid giving a phone number at sign-up where the service allows it — both are common links between accounts.
    • No writing-style or bio tells copied from one persona to another.
  3. Separate the email addresses and phone numbers

    Contact details are the most common thread an observer follows from one persona to the next, so give each compartment its own.

    • A dedicated email address per persona, each with its own password and its own recovery settings. Never let the recovery of a sensitive account point back to a real-name address, or a single password reset reconnects them.
    • A dedicated phone number for the compartments that truly need one, kept apart from your everyday number. A phone number given to one account and reused on another silently links the two. For how to keep a recovery number safe, see Defend against SIM swaps and number theft.
    • Prefer services that let you register and recover without a phone number for your most sensitive persona.
  4. Separate your browsing per persona

    If you sign into two personas in the same browser, shared cookies, logins and site data can tie them together. Keep each compartment in its own browsing space:

    • A separate browser profile for each persona (every major browser supports multiple profiles), or isolated browsing containers, so cookies and logins from one persona are not visible to another. Never have two personas logged in in the same window at the same time.
    • For the sensitive-work persona, use Tor Browser. Its manual, Managing identities and preventing linkability in Tor Browser, explains that it uses a different circuit per site so trackers "will force the content to be served over two different Tor circuits", and that the New Identity option — before switching personas — will "close all your open tabs and windows, clear all private information" and build new circuits. Be aware Tor also warns that logging into an everyday account (such as a bank) over Tor can get that account locked because the connection appears to come from elsewhere — another reason to keep that account out of this compartment.
  5. Decide where devices and the network link you

    Compartments on one phone still share that phone. EFF's The Problem with Mobile Phones sets out how a single device links your activity regardless of which account you are using:

    • Location. The carrier can work out where your phone is, often to about a city block, so two personas carried on one device share a location trail.
    • Hardware identifiers. Wi-Fi and Bluetooth broadcast a hardware (MAC) address that "can be observed in wireless signals even if a device is not actively connected"; turn Wi-Fi and Bluetooth off when you do not need them.
    • Calling patterns. EFF notes that "people's calling patterns tend to be extremely distinctive", so who you contact can re-identify a persona even on a new number.

    For a genuinely high-risk persona, a separate device is the strong move — but EFF is explicit that a second phone only helps if used strictly: "merely swapping SIM cards or moving a SIM card from one device to another offers minimal protection", the phone must not be "associated with a personal credit card or bank account", and you must avoid "reusing either SIM cards or devices" and "carrying different devices together" (switched on, they can be seen moving as a pair). Decide from your threat model whether this effort is warranted.

  6. Lock each compartment independently

    Compartmentalisation limits the blast radius only if one persona's accounts cannot be used to break into another's. Secure each compartment on its own:

    • Phishing-resistant multi-factor authentication where you can. CISA states that "The only widely available phishing-resistant authentication is FIDO/WebAuthn authentication" — which passkeys and hardware security keys use — and that "any MFA is better than no MFA." See Passkeys and hardware security keys.
    • A different, strong password for every account, generated at random. You can keep them in one password manager, but store each persona's entries so you never confuse which login belongs where.
    • No shared recovery. A persona's email, phone number, backup codes and security questions must stay inside that compartment. Cross-wired recovery is the quiet path that reconnects everything.
  7. Keep the discipline and check for leaks

    The walls are only as good as the habit. The routine that keeps them standing:

    • One persona at a time. Never post, reply or react from the wrong account, and never have two personas signed in together. Switch deliberately: close the sessions (Tor's New Identity does this in one step) before you change hats.
    • Audit for accidental links. EFF suggests using a reverse image search to find where a photo has appeared and a username-checking service to find forgotten usernames; use both to catch a persona that has bled into another.
    • Review on a schedule and after any big change — a new job, a public profile, a leak — because that is when boundaries quietly break. If you find a crossover, EFF's advice is to go "step by step" and focus on the specific linking detail rather than trying to erase everything at once.

Common mistakes

  • Reusing a profile photo, username, bio or writing style across personas — the easiest link for anyone to follow, and reverse image search makes a shared photo trivial to find.
  • Pointing a sensitive account’s password recovery at a real-name email or your everyday phone number, so one reset bridges the two.
  • Signing into two personas in the same browser (or the same window), letting shared cookies and logins correlate them.
  • Buying a “burner” phone but carrying it alongside your main phone, or paying for it with your own card — the network and the payment tie it straight back to you.
  • Building more compartments than you can maintain, then slipping, instead of keeping a smaller split you can actually follow.

Going further

Compartmentalisation is a plan you maintain, not a product you install, so revisit it whenever your exposure changes and prune personas you no longer use. If your sensitive work needs a browsing and application environment that is isolated at the operating-system level, read the device and operating-system guides next, and combine this with the communications guides so your messaging identities stay as separated as your accounts. When the stakes are high, walk through the setup with your security team or a digital-rights organisation before you rely on it.