What to do right now — and what to keep doing — to stay safe in a world that collects everything.
Most people know online privacy matters. Very few people have actually done anything about it.
If you’ve ever Googled your own name and seen your home address listed on some website you’ve never heard of, you already know the problem is real. And if you’ve ever checked a site like HaveIBeenPwned and discovered your email address appeared in a dozen data breaches, you know how quietly this all happens — without any notification to you.

This guide pulls together everything worth doing in one place. It starts with the six most impactful steps you can take today — the ones that do the most work fastest — and then covers the tools, habits, and financial protections that keep you safe over the long term. None of this requires being a tech expert. It just requires knowing where to look.
Why this matters for your money: Identity theft, financial fraud, and account takeovers almost always start with publicly available personal information. Reducing your digital footprint is one of the most effective and underused forms of financial self-defense available.
Quick Navigation
Part 1: The Six Things to Do This Week
These six steps have the highest return on time invested. If you do nothing else in this guide, do these. Most people can complete the first four in a single afternoon.
Step 1: Remove Yourself From People-Search Sites
Data broker sites are the single biggest source of publicly accessible personal information. Sites like Spokeo, Whitepages, and BeenVerified collect your name, home address, phone number, relatives’ names, and sometimes estimated income — and they make it searchable by anyone.
Removing yourself from the main ones takes about ten minutes:
- Spokeo: Search your name > Opt-Out > Submit.
- Whitepages: Find your listing > click Request Removal.
- BeenVerified: Navigate to their opt-out page directly and submit your details.
These three account for the majority of what a stranger can pull up with a quick search. Getting yourself off all three in one sitting makes a meaningful difference immediately.
Want to go further? Services like DeleteMe or Incogni handle ongoing removal requests across dozens of data brokers for you — for a monthly fee. For most people, the manual approach above covers the essentials. If you have a public-facing job or have experienced harassment, a paid service is worth considering.
Step 2: Submit a Google Removal Request
Google has a removal request form that most people have never heard of. If any webpage shows your home address, phone number, or email address in search results, you can request Google remove that result.
Use Google’s removal request form to file a request for any result showing your personal contact details. Google is required to review all requests, and the majority are approved within a few days.
This doesn’t delete the underlying page — but it removes it from Google search results, which is where nearly all searches start. For most practical purposes, that’s effectively the same thing.
Step 3: Hunt Down and Delete Old Accounts
Most people have signed up for hundreds of websites and apps over the years. Almost all of those accounts still exist, still hold your details, and are waiting to be compromised in a future breach.
Here’s the fastest way to find them:
- Open Gmail and search: verify your email
- Every result is an account you created — the verification email is almost always still in your inbox
- Open each site, log in, and look under Settings or Privacy for a Delete Account option
- Prioritize accounts that had your payment details or home address first
Financial tip: Before deleting any account connected to a payment method, make sure you’ve cancelled any active subscriptions or removed your card details first. Some sites make it very difficult to get refunds after account closure.
Step 4: Check Which Passwords Have Already Been Leaked
Go to HaveIBeenPwned.com and enter your email address. The site cross-references your email against known data breaches and shows you every incident your details appeared in. Most people find between 5 and 15 breaches — and most had no idea.
For every breached account:
- Change the password tonight if the account still exists
- If you reused that password elsewhere — especially on banking, email, or shopping sites — change those too. This is the most common path to getting hacked.
- Turn on two-factor authentication wherever it’s offered, especially on financial accounts
Password reuse is the single biggest vulnerability most people carry. One leaked password from a forum you forgot about in 2014 can give someone access to your bank account if you’ve reused it. Fixing this is the highest-impact thing you can do for your financial security online.
Step 5: Clear Google’s Record of Your Activity
Google maintains a log of every search you’ve made, every site you’ve visited while signed in, your location history, and your YouTube watch history. Clearing and disabling this data is straightforward:
- Open Gmail or any Google app > tap your profile picture > Manage your Google Account
- Go to Data & Privacy > History settings > My Activity
- Select Delete > All time to clear the complete history
- Back in History settings, turn off Web & App Activity, Location History, and YouTube History
Turning off these settings doesn’t break anything — Google’s services work fine without logging your history. You just stop contributing to a behavioral profile that’s been building since you created your account.
Step 6: Clean Up Old Social Media Posts
Public posts from years ago are still indexed and searchable — and can contain your old addresses, employer details, family members’ names, or other information useful to anyone building a profile on you. Free tools make cleanup much faster:
- X (Twitter): Use TweetDelete to automatically remove old posts past a date you choose — it can run continuously to keep your history trimmed.
- Reddit: Use Redact which overwrites comment content before deleting — preventing recovery from cached versions.
- Facebook: Go to your Activity Log > filter by year > delete posts in bulk.
- LinkedIn: Review and archive or delete old LinkedIn posts, especially anything with contact details.
You don’t need to delete everything. The goal is removing anything that contains personal details or anything you wouldn’t want a future employer, lender, or stranger to find.
Part 2: The Tools Worth Using
Beyond the one-time cleanup steps, a handful of tools provide ongoing, largely automatic protection. Here’s what’s worth installing and why.
Password Manager
A password manager is the single most impactful security tool most people aren’t using. It generates and stores a unique, complex password for every site, so you never reuse credentials — and it fills them in automatically so there’s no friction.
You only need to remember one master password. Everything else is handled.
| Free Options | Paid Options |
|---|---|
| Bitwarden — fully featured, open-source, excellent free tier | 1Password — ~$3/month, great family plans |
| Apple Keychain (built into iPhone/Mac) | Dashlane — includes a built-in VPN |
| Google Password Manager (built into Chrome/Android) | Keeper — strong business/family options |
Recommendation: Bitwarden is the best free option for most people. 1Password is worth the cost for families or anyone who wants a more polished experience. Avoid LastPass — it suffered a significant data breach in 2022 that exposed encrypted password vaults.
Two-Factor Authentication (2FA)
Two-factor authentication adds a second verification step to your logins — typically a code from an app or text message — so that even if someone has your password, they can’t get into your account without physical access to your phone.
Enable it on every account that offers it, prioritizing:
- Bank and investment accounts
- Email accounts (especially Gmail — this is the master key to everything else)
- Password manager
- Social media accounts
- Shopping accounts with saved payment methods
For the authentication method, authenticator apps are more secure than SMS text codes. SMS codes can be intercepted or hijacked via SIM-swapping attacks. Recommended authenticator apps:
- Google Authenticator (free, simple)
- Authy (free, backs up your codes — useful if you lose your phone)
- Microsoft Authenticator (free, works well across platforms)
Important: When you set up 2FA on any account, save your backup codes somewhere secure — ideally printed and stored physically, or saved in your password manager. Without them, you can lose access to your own account permanently if you lose your phone.
VPN (Virtual Private Network)
A VPN encrypts your internet connection and routes it through a server in a location of your choosing, masking your real IP address and preventing third parties — including your internet service provider — from monitoring your browsing activity.
When a VPN makes the most difference:
- Using public Wi-Fi (airports, coffee shops, hotels) — your traffic is otherwise visible to anyone on the same network
- When you want to prevent your ISP from selling your browsing data
- Traveling internationally and needing access to home services
A VPN does not make you anonymous, and it won’t protect you from phishing or malware. Think of it as one layer of protection, not a complete solution.
| Reputable Paid VPNs | What to Avoid |
|---|---|
| NordVPN (~$3-4/month on annual plan) | Free VPNs that monetize your data |
| Mullvad (flat rate, privacy-focused, no email needed to sign up) | VPNs with no published privacy policy |
| ProtonVPN (Swiss-based, strong privacy record) | VPNs owned by companies in high-surveillance countries |
| ExpressVPN (fast, beginner-friendly) | Browser extensions marketed as free VPNs |
If you only use public Wi-Fi occasionally, a VPN’s value is mostly limited to those situations. If you work remotely or travel frequently, a paid VPN is worth the relatively small cost.
Browser and Search Engine
Your browser sends data about every website you visit to the browser maker by default. Switching to a privacy-focused browser — or adjusting your current browser’s settings — significantly reduces what gets collected.
Privacy-Focused Browsers
- Brave: Brave blocks ads and trackers by default, is fast, and is compatible with most Chrome extensions. A solid everyday browser.
- Firefox: Firefox is highly configurable with strong privacy defaults when set up properly, and has a large extension library.
- Tor Browser: Tor Browser offers maximum anonymity — routes traffic through multiple servers. Slower but the most private option available.
Privacy-Focused Search Engines
Google collects and stores every search you make, tied to your account and IP address. Alternatives:
- DuckDuckGo: DuckDuckGo — no tracking, no search history stored, delivers decent results for most searches.
- Startpage: Startpage uses actual Google results without the tracking. Good middle ground.
- SearXNG: SearXNG is open-source, community-run, and excellent for technical searches.
You don’t have to commit fully. Using a privacy-focused search engine for general browsing while keeping Google for specific searches where the results matter more is a reasonable approach.
Ad Blocker
Ad blockers do more than remove ads — they block the tracking scripts that follow you across the web, building profiles of your browsing behavior that are sold to advertisers.
- uBlock Origin: uBlock Origin is the most effective and widely used option. Available for all major browsers. Free.
- AdGuard: AdGuard is available for browsers where uBlock isn’t supported (e.g., Safari on iPhone).
Ad blockers also reduce your exposure to malvertising — malicious ads that can install malware or redirect you to phishing sites. This is a meaningful security benefit beyond just privacy.
Encrypted Messaging
Standard SMS text messages travel unencrypted across mobile networks. Your carrier can read them, they can be intercepted, and they’re subpoenaed regularly in legal proceedings.
For sensitive conversations — anything involving finances, health, legal matters, or personal details — end-to-end encrypted messaging apps are worth using:
- Signal: Signal — the gold standard for private messaging. End-to-end encrypted by default, open-source, non-profit.
- Apple iMessage: End-to-end encrypted when both parties use iMessage (blue bubbles). Falls back to SMS when it’s not available (green bubbles).
- WhatsApp: WhatsApp — end-to-end encrypted in private chats but not in group chats by default.
Email Privacy
Gmail is free because Google scans your emails to inform its advertising. If email privacy is a concern, alternatives exist:
- ProtonMail: ProtonMail — Swiss-based, end-to-end encrypted, strong privacy policy. Free tier available.
- Fastmail: Fastmail — strong privacy credentials, paid plans only.
For most people, the bigger email risk isn’t Google scanning content — it’s phishing. See the phishing section below for how to protect yourself from the most common email-based attack.
Part 3: Protecting Your Finances Specifically
Online privacy and financial security overlap significantly. Here’s what to do specifically to protect your money.
Freeze Your Credit — The Most Underused Protection Available
A credit freeze is the single most effective thing you can do to prevent identity theft. When your credit is frozen, lenders cannot access your credit report — which means a thief who has your personal information still cannot open a new credit card, loan, or line of credit in your name. They hit a wall.
Crucially:
- A credit freeze is free at all three bureaus
- It does not affect your credit score
- It does not prevent you from using your existing credit cards
- You can unfreeze temporarily when you need to apply for new credit — usually takes just a few minutes online
You must freeze your credit at all three bureaus separately:
Credit lock vs. credit freeze: The credit bureaus also offer “credit lock” products, sometimes with monthly fees. A credit freeze is legally protected under federal law — it’s the stronger option. A credit lock is just a contractual agreement with the bureau, which is weaker protection. Always use the free freeze.
Monitor Your Accounts and Credit
No protection is perfect. Monitoring catches problems early, before they become catastrophic.
Free Credit Monitoring
- AnnualCreditReport.com — check your free credit report from all three bureaus. Stagger the requests (one bureau every four months) to maintain year-round visibility.
- Most credit cards now include free credit score monitoring — check your card’s app or website.
- Credit Karma and Credit Sesame provide free ongoing monitoring with alerts for new accounts or hard inquiries.
Bank and Card Alerts
Enable transaction alerts on every bank account and credit card you have. Most institutions allow you to set a threshold — for example, an alert for any purchase over $25. This means you’ll know about fraudulent transactions within minutes rather than weeks.
Paid Identity Theft Monitoring
If you want more comprehensive protection, paid identity theft monitoring services watch for your information appearing in new contexts — the dark web, new accounts opened in your name, address changes filed with the USPS, and more.
- LifeLock: LifeLock — good mid-range option, widely available, often discounted through insurance providers.
- Aura: Aura — strong feature set, includes credit monitoring across all three bureaus.
- Identity Guard: Identity Guard — solid option, good value for families.
Are paid identity monitoring services worth it? For most people, a credit freeze plus free monitoring covers the essentials. Paid services add value if you’ve already been a victim of identity theft, if you’re a public-facing professional, or if you want the convenience of having everything managed in one place.
Use Credit Cards Instead of Debit for Day-to-Day Spending
This is a simple habit change with significant financial protection benefits.
When your debit card is compromised, the money comes directly out of your checking account — and you’re left waiting while the bank investigates. When a credit card is compromised, the fraudulent charges sit on the card and you dispute them before paying. Your actual cash is never touched.
Federal law gives credit card holders stronger fraud protections than debit card users. Credit card liability for unauthorized charges is capped at $50 — and most major issuers offer zero liability. Debit card liability depends on how quickly you report the fraud.
The practical habit: use a credit card for everyday purchases wherever possible, pay the balance in full each month, and keep your debit card for ATM withdrawals only.
Recognize and Avoid Phishing
Phishing is the most common way people’s financial accounts get compromised. Scammers send emails or texts impersonating your bank, the IRS, PayPal, Amazon, or other trusted institutions — with the goal of getting you to click a link and enter your login credentials on a fake site.
The FTC reported that email was the top method scammers used to contact victims in 2024. Here’s how to protect yourself:
- Never click links in unexpected emails that ask you to verify account details, confirm a payment, or resolve a problem. Go directly to the company’s website by typing the address yourself.
- Hover over links before clicking to see where they actually go. A link that says “paypal.com” in the text might actually point to “paypa1.com” or a completely different domain.
- Legitimate banks and financial institutions will never ask for your password, full Social Security number, or PIN by email or text.
- Be especially suspicious of urgency — “your account will be closed in 24 hours” is a classic pressure tactic designed to bypass your judgment.
- If an email looks legitimate but you’re unsure, call the company directly using a number from their official website — not one provided in the email.
Forward phishing emails to reportphishing@apwg.org and report them to the FTC at ReportFraud.ftc.gov. This helps protect others from the same scam. This helps protect others from the same scam.
Protect Yourself From Tax Identity Theft
Tax identity theft — where someone files a fraudulent tax return in your name to claim your refund — is one of the most disruptive forms of financial fraud. It can take months or years to resolve, and it can delay your legitimate refund indefinitely.
Key protections:
- File your tax return as early in the season as possible. The first return filed with your Social Security number is processed — any subsequent ones are flagged as duplicates.
- Apply for an IRS Identity Protection PIN (IP PIN) at IRS.gov/ippin. This is a six-digit number required on your return, preventing anyone else from filing under your SSN without it.
- Be very careful about where you share your Social Security number. Never send it via email or text.
Part 4: Habits That Keep You Protected Over Time
The one-time cleanup steps and tool installations provide a strong foundation. These ongoing habits maintain that protection.
Keep Software Updated
Most successful cyberattacks exploit known vulnerabilities in outdated software — vulnerabilities that were already patched in a newer version. Keeping your operating system, browser, and apps up to date is one of the highest-leverage security habits you can have. Enable automatic updates wherever possible and don’t ignore system update prompts.
Minimize What You Share
Every time you sign up for a new app or service, you create another potential point of exposure. Before signing up:
- Ask whether you actually need this account
- Use a unique email address or email alias for signups (services like SimpleLogin or Apple’s Hide My Email create disposable forwarding addresses)
- Don’t connect apps to each other unless there’s a clear benefit — “sign in with Google/Facebook” is convenient but shares your data between services
- Review and revoke app permissions periodically — especially location access, microphone, and contacts
Use Strong, Unique Passwords for Everything
If you’re using a password manager, this is automatic. If not, the minimum standard is: at least 12 characters, mixing uppercase, lowercase, numbers, and symbols, with no reuse across sites. The key rule is uniqueness — a weak unique password is still better than a strong reused one, because a breach on one site doesn’t cascade into all your other accounts.
Be Careful on Public Wi-Fi
Public Wi-Fi networks at coffee shops, airports, and hotels are fundamentally untrustworthy. Anyone on the same network can potentially intercept unencrypted traffic. The practical rules:
- Don’t access bank accounts or make purchases on public Wi-Fi without a VPN
- Prefer your phone’s mobile data over unknown Wi-Fi networks for sensitive activities
- If you must use public Wi-Fi, confirm you’re connecting to the actual network (not a lookalike set up by someone nearby)
Review Privacy Settings Annually
Apps and platforms change their privacy settings — sometimes quietly, as part of terms of service updates you didn’t read. Set a reminder once a year to:
- Review what information is public on your social media accounts
- Check which apps have access to your location, camera, microphone, and contacts on your phone
- Verify your Google and Facebook ad settings
- Run a new HaveIBeenPwned check to see if you’ve appeared in any new breaches
Secure Your Home Network
Your home router is the gateway for all your internet traffic. A few simple steps:
- Change your router’s default admin username and password from the factory defaults — these are publicly known and are the first thing an attacker tries
- Use WPA3 encryption if your router supports it (WPA2 is acceptable, WEP is outdated and insecure)
- Keep your router’s firmware updated — most modern routers do this automatically, but it’s worth checking
- Create a separate guest network for smart home devices, visitors, and IoT devices like smart TVs and thermostats — this keeps them isolated from your main devices
Quick-Reference Checklist
Use this as a starting point. Check off what you’ve done, and tackle the rest in order of priority.
Do This Week
- Remove yourself from Spokeo, Whitepages, and BeenVerified
- File a Google removal request for any results showing your address or phone number
- Search Gmail for “verify your email” and delete forgotten accounts
- Check HaveIBeenPwned and change passwords for any breached accounts
- Clear Google activity history and disable Web & App Activity, Location History
- Delete old social media posts containing personal details
Set Up (One-Time)
- Install a password manager and start using it for new logins
- Enable two-factor authentication on email, banking, and social accounts
- Freeze your credit at Equifax, Experian, and TransUnion
- Apply for an IRS Identity Protection PIN
- Install uBlock Origin in your browser
- Enable transaction alerts on every bank account and credit card
Ongoing
- Keep software and apps updated
- Use credit cards instead of debit for everyday spending
- Avoid clicking links in unexpected emails — go directly to sites instead
- Review privacy settings on apps and social media once a year
- Run a new HaveIBeenPwned check periodically
- File taxes early each year to beat fraudulent returns
The Bottom Line
You don’t have to do all of this at once. The six steps in Part 1 alone will put you ahead of the vast majority of internet users in terms of how well your personal information is protected. Add a password manager and a credit freeze, and you’ve closed the two biggest doors that identity thieves walk through.
The rest of this guide is a toolkit — use the parts that make sense for how you use the internet and what level of protection feels right for your situation. Privacy online isn’t about paranoia; it’s about making informed choices about who gets access to your information and what they can do with it.
The people who steal identities and drain bank accounts aren’t usually doing anything sophisticated. They’re walking through doors that were left open. These steps close those doors.
Disclosure: This post may contain affiliate links. We may be compensated if you sign up for a service through our links, at no additional cost to you. All tool recommendations are based on general research and editorial judgment. This content is for informational purposes only and does not constitute financial or legal advice. Please consult a qualified professional for advice specific to your situation.





Share Your Thoughts: