Protecting your privacy online starts with two jobs: securing access to your accounts and reducing unnecessary collection or sharing of your information. Begin with your main email account, then review the permissions and public details attached to the services you use most.
You do not need to change every setting at once. Work through one account or device at a time, recording what changed and checking that recovery still works. None of these steps makes your activity invisible or guarantees that a service will never suffer a breach.
Secure the accounts that unlock other accounts
Your main email account is a practical starting point because other services may send password-reset messages there. Give important accounts different passwords and use a password manager if it helps you maintain them. The Federal Trade Commission's account-security guidance explains why unique passwords and additional authentication matter.
The CorelyUp password generator creates random passwords in your browser. It does not save them or provide account recovery. Store a new password securely before closing the page, and do not reuse an example password from an article. If you are choosing where to store credentials, read the research-based Bitwarden and KeePassXC comparison.
Turn on a second authentication factor
Enable two-factor authentication where a service offers it, starting with email and other high-value accounts. Follow the provider's setup instructions and keep recovery codes somewhere you can access if the phone or device is lost.
The FTC's two-factor authentication guide distinguishes text messages, authenticator apps and security keys. It notes that text codes have vulnerabilities such as phone-number takeover and that an authenticator app or security key can offer stronger protection when available. Do not approve a login request you did not initiate or share a code in response to an unexpected message.
Before changing your recovery phone number, check that you have another working recovery route. Improving a security setting should not accidentally leave you unable to reach your own account.
Review what websites and apps collect
The FTC explains online tracking, including cookies, pixels, device fingerprinting and mobile advertising identifiers. Different controls affect different forms of collection, so switching off one option does not switch off every form of tracking.
Open your browser's privacy settings and the advertising or privacy settings on the device itself. Read what each option changes. Reject optional cookies when that matches your preference, and review account-level ad settings on services you remain signed in to. Expect some choices to apply only to that browser, device or account.
Private browsing is not a general anonymity service. For example, Chrome's Incognito documentation explains that it limits what Chrome saves locally after the session, while websites and an employer, school or internet provider may still observe activity. Downloads and bookmarks can remain after the window closes.
Use a small permission checklist
For each app or site, ask what access it needs for the feature you actually use. Device menus vary, so use the current help page for your operating system when a setting is unclear.
- Check camera and microphone permissions, especially for services you no longer use.
- Review location sharing, including whether a public post contains location details.
- Check who can see your profile, contact details and older posts.
- Remove unnecessary connected apps after confirming what functionality depends on them.
- Keep the browser, operating system and apps updated using their supported update mechanisms.
Do not delete an account solely because it appears unfamiliar. First identify it, check whether it stores something you need and confirm how it connects to your other accounts.
Make the review repeatable
Create a short private record containing the account name, the settings reviewed and a future review reminder. Do not put passwords or recovery codes in that checklist. Repeat the review when you replace a phone, stop using a service or receive a genuine security alert.
A useful first session ends with one secured account and understood settings. The time-blocking guide can help reserve time for that maintenance. If you suspect someone is actively accessing your accounts, follow the affected provider's account-recovery and incident guidance rather than relying on a routine privacy checklist.