Skip to content
Technology & Digital Life

How to Protect Your Online Privacy: The Buhii.net Checklist

Protect your online privacy with a practical checklist: secure your accounts, cut tracking, tighten app permissions, and control what personal data you share.

Glowing blue circuit pattern on a dark screen, representing personal data and online privacy

Protecting your online privacy doesn’t take technical skill or expensive software. It comes down to a set of settings and habits that limit how much of your personal data leaks out, and who can use it. This checklist from Buhii.net walks through the changes that matter most, in the order that gives you the biggest return on your time.

The Buhii.net team built this checklist from official consumer-protection and digital-rights guidance, so every step points to a setting you can actually find on your own devices.

Start With a Quick Privacy Threat Check

Security professionals begin with a simple question: what am I protecting, and from whom? The Electronic Frontier Foundation’s guide to building your own security plan frames it around a few questions, including what you want to protect, who might want it, and how bad the consequences would be if they got it.

For most people, the realistic risks look like this:

RiskWhat it looks likeMain defense
Account takeoverSomeone logs in with a leaked or guessed passwordUnique passwords and multi-factor authentication
Ad tracking and data brokersYour browsing, location and purchases are collected and soldBrowser settings, ad controls, fewer permissions
Scams and phishingMessages that use your personal details to seem legitimateSharing less publicly, verifying before clicking
Identity theftLoans or accounts opened in your nameCredit freezes and account alerts
People you knowAn ex, coworker or relative finding information you didn’t intend to shareAudience settings and location controls

Your top two or three risks show which sections deserve extra attention.

Online Privacy Checklist Part 1: Lock Down Your Accounts

Use unique passwords stored in a password manager

Reused passwords are the easiest way in for attackers, because one breached site hands them the key to others. A password manager generates and remembers a different strong password for every account. If you haven’t set one up yet, our password manager guide explains how to choose one and move your logins over safely.

Turn on multi-factor authentication

Start with your email account, since it can reset every other password you own. Then add banking, cloud storage and social media. Where you have a choice, an authenticator app, a passkey or a hardware security key is stronger than a code sent by text message, but any second factor beats none.

Review connected apps and active sessions

  • Open the security page of your Google, Apple, Microsoft and Meta accounts and look for “third-party apps” or “connected apps.” Remove anything you don’t recognize or no longer use.
  • Check the list of signed-in devices and sign out of old phones, shared computers and browsers you no longer use.
  • Revoke “Sign in with…” access for quizzes, games and one-time tools.

Close accounts you no longer use

Old accounts still hold your name, email, and sometimes payment details. If the service is breached years from now, that data goes with it. Search your inbox for “welcome to” or “confirm your account” to find forgotten sign-ups, then delete the ones you don’t need.

Part 2: Reduce Online Tracking

The Federal Trade Commission explains how websites and apps collect and use your information: cookies and pixels that identify you after you leave a site, device fingerprinting based on your browser’s configuration, and advertising identifiers on your phone. Third-party trackers can follow you across many of the sites you visit.

You can’t stop all of it, but you can cut a lot:

  1. Block third-party cookies in your browser’s privacy settings. Most major browsers offer this option, and some block many trackers by default.
  2. Install one reputable content blocker rather than several overlapping extensions. Every extension can read some of your browsing, so fewer is better.
  3. Limit your phone’s advertising ID. On iPhone, go to Settings > Privacy & Security > Tracking and turn off “Allow Apps to Request to Track.” On recent Android versions, open the Ads section of your privacy settings and delete your advertising ID.
  4. Turn off personalized ads in your Google account’s ad settings and in Meta’s ad preferences. You’ll still see ads, but fewer will be based on your activity.
  5. Clear cookies and site data periodically, or set your browser to delete them when you close it, keeping exceptions for sites you want to stay signed in to.

Part 3: Tighten App and Phone Permissions

Apps often ask for more access than they need, and those permissions tend to stay switched on long after you’ve forgotten about them.

Location

  • Set apps to “While Using” instead of “Always.” Very few apps need your location in the background.
  • Turn off precise location for apps that only need your general area, such as weather or shopping apps. Both iPhone and Android offer this toggle in the app’s location settings.

Camera, microphone, contacts and photos

Open your phone’s privacy settings and review each permission category. Ask whether each app truly needs that access. A photo editor needs your photos; a flashlight app does not need your contacts. Where your phone offers limited photo access, share only selected photos instead of your whole library.

Unused apps

Delete apps you haven’t opened in months. Each one is another company holding your data and another piece of software that needs security updates.

Part 4: Share Less by Default

  • Audit your social profiles. Set older posts to friends-only, and hide your birthday, phone number, email and hometown. These details are common answers to security questions and useful material for impersonation.
  • Strip location from photos. Photos can carry location data. On iPhone, tap “Options” at the top of the share sheet and turn off Location before sending. On any phone, you can turn off location tagging in the camera app.
  • Skip “fun” quizzes that ask for your first car, childhood street or mother’s maiden name.
  • Post trips after you’re home, not while your house is empty.
  • Use email aliases for sign-ups. Services such as iCloud’s Hide My Email or Firefox Relay forward mail to your inbox without revealing your real address.

What you like and comment on also shapes what platforms learn about you. Our explainer on how social media algorithms decide what you see shows how much a feed infers from quiet signals like how long you pause on a post.

Part 5: Protect Your Identity and Money

If your data does leak, these steps limit the damage.

  • Freeze your credit. According to the FTC’s page on credit freezes and fraud alerts, a freeze stops anyone from opening new credit in your name, costs nothing to place or lift, and doesn’t affect your credit score. In the US, you contact each of the three bureaus: Equifax, Experian and TransUnion.
  • Turn on bank and card alerts for every transaction, or for purchases above a small amount, so fraud shows up the same day.
  • Pay online with a credit card or trusted payment service rather than a debit card linked directly to your checking account.
  • Verify unexpected messages independently. Scams often reuse real details about you to seem credible. The same habits that help you spot misinformation online, such as checking the source and not reacting in a rush, work on phishing too.

Your Printable Online Privacy Checklist

Copy this list into your notes app and tick items off as you go:

  • Password manager set up, email and banking passwords changed first
  • Multi-factor authentication on email, banking, cloud storage and social media
  • Unknown connected apps removed and old sessions signed out
  • Unused accounts deleted
  • Third-party cookies blocked and one content blocker installed
  • Phone advertising ID limited or deleted
  • Personalized ads turned off in Google and Meta settings
  • App location set to “While Using” and precise location reviewed
  • Camera, microphone, contacts and photo permissions reviewed
  • Apps you don’t use uninstalled
  • Social profiles audited and personal details hidden
  • Credit frozen at all three bureaus (US)
  • Bank and card alerts switched on

Final Thoughts

Online privacy isn’t a single setting you switch on. It’s a handful of decisions that add up: fewer reused passwords, fewer trackers, fewer permissions, and less personal detail posted in public.

Once the checklist is done, maintenance takes only a few minutes every few months. For more practical help with the devices and apps you use every day, browse our technology and digital life guides, or head back to Buhii.net to explore more of what we publish.

Frequently Asked Questions

Does private or incognito browsing keep me anonymous online?

No. Private browsing mainly stops your browser from keeping history and cookies on your device after the session ends. Websites, your internet provider, and any work or school network can still see your activity.

Do I need a VPN to protect my privacy?

A VPN hides your traffic from the local network and your internet provider, which helps on public Wi-Fi, but it shifts that trust to the VPN company. It does nothing about tracking by sites and apps you sign in to, so treat it as one layer rather than a complete fix.

How often should I review my privacy settings?

A quick review every few months works for most people. It is also worth checking after major app or operating system updates, because updates sometimes add new settings or change the defaults.

Buhii.net Editorial Team

This guide was researched, written and fact-checked by the editorial team at Buhii.net, an independent digital publication that turns complex topics into clear, practical advice. Learn more about oureditorial policy andfact-checking process.