The field guide

Everything we know about getting out from under the watching, written down and given away.

122 answers across 21 topics, and nothing to sign up for. Which browser to use and why. What to turn off on your phone tonight. What a VPN actually does, and the three things people wrongly believe it does.

Almost none of it is about us. We recommend Signal, Mullvad, Tor, Bitwarden and GrapheneOS because those are the right answers, and a guide that only ever recommended its own author would not be worth reading.

You do not have to do all of it. Doing three things beats reading all of it and doing none.

21 topics122 answers34 carry a source you can followlast checked August 2026free, no sign-up

Some setupmeans a few minutes and a little patience.Advancedmeans it is genuinely fiddly. Anything unmarked, anyone can do tonight.

Start here

What this is for, and the version you can do tonight.

01

Start here

checked August 2026

You will not become invisible, and you don't need to. The goal is to stop being watched by default and to become more trouble to track than you're worth. Doing three of these beats reading all of them.

The five-minute version

Put uBlock Origin in your browser, move your chats to Signal, switch off your phone's advertising ID, and point your devices at a blocking DNS resolver. That is most of the casual tracking aimed at you, gone, in an evening. Come back for the rest when you can.

What the watching actually looks like

It is rarely a person reading your messages. In 2012 a New York Times reporter documented Target working out that a teenager was pregnant from her shopping, and mailing her baby coupons before she had told her father. That is the shape of it: nothing was hacked, nothing was leaked, and the conclusion was drawn from perfectly ordinary purchases. Twelve years later the same trick runs on your location, your browsing and your car, at a scale no analyst reviews and no human ever sees. Each piece is boring on its own. Together they are a file on you that you never asked for and cannot read.

How to think about it

Decide what you are actually protecting: your location, your messages, your identity, your money. You cannot harden everything at once and you do not need to. Change defaults before you change tools, prefer things that work offline and need no account, and keep a small habit instead of chasing a big one you will abandon.

Convenience is the price, and it is usually small

Most of this costs ten minutes and nothing else. Some of it costs real friction: a search engine with slightly worse results, a group chat that has to move, a smart speaker that becomes a speaker. Decide in advance how much friction you will accept, because the plan you keep beats the perfect one you drop in a week.

A first week, if you want an order

Day one, install a content blocker and change your default search engine. Day two, install Signal and move one conversation to it. Day three, go into your phone's settings, kill the advertising ID, and revoke location from three apps that never needed it. Day four, change your DNS on your phone and your laptop. Day five, install a password manager and move your five most important accounts into it, with a new password for each. Day six, turn on two-factor on your email, because whoever owns your email owns everything else. Day seven, do nothing.

What this guide won't do

It will not make you invisible, and anything that promises that is selling something. It will not protect you from someone who already has your unlocked device, from malware you install yourself, or from a state that has decided you specifically are worth the effort. It also will not stay right forever: tools get bought, defaults change, and good software goes bad. Every topic here carries the date it was last checked. Treat it as a starting point, not as gospel.

The devices you own

The browser, the phone and the computer. This is where most of it happens, and where most of the fix is.

02

Your browser

checked August 2026

Most of the watching happens while you read the web, and this is the cheapest large fix on the whole list. Mostly it is about which browser you open.

Which browser should I use?

There is a tier for everyone. For strong privacy with no fiddling, the Mullvad Browser. If you will maintain a config, a hardened Firefox goes furthest. For the easiest strong default, Brave. And when what you need is anonymity, not privacy, the Tor Browser, which is a different job entirely.

Mullvad Browser
the best everyday pick. Built with the Tor Project to make your fingerprint look like everyone else's. Use it with or without a VPN.
Firefox + arkenfox
the most control, if you're willing to maintain a config.
Brave
the easiest strong default, with blocking built in.
Tor Browser
for real anonymity. Slower, and a different job entirely.

Block the trackers

One good content blocker stops the large majority of tracking. A pile of extensions just makes you more identifiable. Install one and leave it.

uBlock Origin
the one extension worth adding. Free, open, and it just works.

Fingerprinting, and why hardening can backfire

Sites identify you without cookies by measuring your browser: fonts, screen size, canvas rendering, extensions, and dozens of other signals that combine into a fingerprint. The trap is that piling on unique tweaks makes you rarer, and therefore easier to single out. The fix is to look like everyone else, which is exactly what the Mullvad and Tor browsers do for you. Test yourself once, then stop tinkering.

Cover Your Tracks (EFF)
see how unique and trackable your browser is right now.

Cookies, logins, and keeping accounts apartsome setup

Third-party cookies are the classic cross-site tracker, and a good blocker plus a modern browser handles most of them. The harder problem is that staying logged in to a big account lets that company follow you across the web. Keep the accounts that track you hardest in their own container or a separate browser profile, so your logged-in identity does not follow you around everything else you read.

Firefox Multi-Account Containers
keeps a login sealed in its own tab colour, so it can't watch the rest of your browsing.

Fewer extensions is safer, not more

Every extension can read the pages you visit, makes your browser more identifiable, and is something that can be sold to a new owner who quietly turns it into a tracker. This is not hypothetical and it is not rare. Stylish was pulled in 2018 for sending users' full browsing history back to its owner. The Great Suspender, with more than two million users, was removed from the Chrome Web Store in 2021 after being sold and updated with malicious code. Nano Adblocker and Nano Defender went the same way in 2020, weeks after changing hands. In every case the extension had a good reputation right up until the moment it did not. Keep one content blocker, add a password manager if you use one, treat everything else as a cost, and audit the list twice a year.

The padlock means encrypted, not safe

HTTPS means nobody between you and the site can read the traffic. It says nothing about whether the site itself is honest, and phishing pages have padlocks too. Separately, even with HTTPS the name of the site you visit usually still leaks to your network, which is what encrypted DNS addresses. Treat the padlock as the floor.

Browser sync uploads more than you expectsome setup

Signing into your browser can sync history, open tabs, saved passwords and autofill details to a company's servers. Some of that is encrypted so only you can read it and some is not, depending on the browser and whether you set a passphrase. If you use sync, set the passphrase so it is end-to-end encrypted, and look at what it is uploading before you decide you are happy with it.

A search engine that doesn't profile you

Your default search sees everything you are curious about, which over a year is a more intimate record than your messages. Move it off anything that builds a profile.

DuckDuckGo
the easy switch.
Startpage
Google's results without Google's tracking.
SearXNG
self-hosted, for the technical.
03

Your phone

checked August 2026

The most sensor-packed, most surveilled thing you own, in your pocket all day. If you fix one thing, fix this.

Kill the advertising ID

Your phone hands every app the same identifier, and that is the leash that lets them stitch your behaviour together across apps and sell it as one profile. On Android, reset and then delete it in Settings under Privacy and Ads. On iPhone, turn off Allow Apps to Request to Track. Note what happened when Apple made that prompt mandatory in 2021: an industry that had described this tracking as something users accepted lost most of it overnight, because it turned out almost nobody accepts it when actually asked.

Permissions and apps

Every app is a potential tracker. Revoke location, microphone and camera from anything that does not obviously need them, set location to 'while using' at most, and delete apps you do not use. Prefer a website over an app where you can, since a site cannot sit in the background.

Exodus Privacy
look up an Android app and see the trackers inside it before you install.

Your location history, and how to stop keeping it

Both big phone platforms keep a running map of where you have been, and it is more revealing than people expect: where you sleep, who you visit, which clinic you went to. It is also reachable by others. Google's location store was searched by police through so-called geofence warrants, which ask for everyone who was near a place at a time rather than for a named suspect; Google received thousands of them a year before announcing in late 2023 that Location History would move on-device, which ended the practice by making the data impossible to hand over. Turn off and delete Google's Timeline, and on iPhone clear Significant Locations. Neither is needed for maps to work.

Android, done properlysome setup

Stock Android reports to Google constantly. You can harden it in settings, or go all the way. Install open apps from a store that is not tracking you, and swap the keyboard, which on many phones sends what you type off to be improved.

GrapheneOS
the gold standard. A de-Googled, hardened Android for Pixel phones, without losing security.
F-Droid
a store of open-source apps that don't come with trackers.

iPhone, locked down

You cannot de-Apple an iPhone, but you can shut a lot off: turn on Lockdown Mode if you are a likely target, deny app tracking, turn off ad personalisation and location history, and enable Advanced Data Protection so iCloud is end-to-end encrypted. That last one is the big one, and it is off by default.

The keyboard is reading everything you type

Some phone keyboards send what you type to a server to improve prediction, which means passwords typed in the wrong field, private messages and search terms can leave the device. Check your keyboard's settings for anything about personalisation, cloud prediction or sharing usage data. If you would rather not trust a setting, install an open keyboard with no network permission at all.

Backups: what leaves the phone, and who can read itsome setup

A phone backup usually contains your messages, photos, call history and app data, so where it goes and whether it is encrypted matters more than almost any app setting. On iPhone, Advanced Data Protection makes iCloud backups end-to-end encrypted. On Android, check whether your backup is encrypted with your screen lock. If neither is available, back up locally to a computer and encrypt that instead.

The old phone in the drawer

A retired phone usually still holds photos, messages, saved logins and a signed-in account. Sign out of the account first, then factory reset. Modern phones encrypt storage, so a reset leaves the old data unreadable, not merely deleted. Remove the SIM and any memory card as well, because a reset does not touch those.

The part you can't switch off: your carrieradvanced

A phone is a radio that tells the network where it is, all the time, whether or not you have installed a single app. That record sits with your carrier, is handed to police on request, and in several countries has been sold on: in 2018 and 2019 the four largest US carriers were found selling real-time customer location to aggregators who resold it down a chain that ended with bounty hunters, and the FCC eventually fined them almost 200 million dollars for it. No app setting touches any of this. The only real controls are blunt: leave the phone behind when the location itself is the sensitive part, or power it fully off, and understand that flight mode is a software promise rather than a guarantee.

04

Your computer

checked August 2026

Your laptop reports home more than you would think, and the operating system is the biggest talker. You can quiet most of it.

Windows, quieted down

Windows sends a steady stream of telemetry by default, and Microsoft documents what is in each level, so you can read it instead of taking anyone's word. Turn the diagnostic data down to the minimum in Settings, and a free tool can flip the dozens of switches buried elsewhere, all of it reversible.

O&O ShutUp10++
a free, one-click hardener for Windows telemetry. Every change is reversible.

macOS

Turn off 'share Mac analytics' and 'share with app developers' in settings, and limit ad tracking. It is quieter than Windows out of the box, but it still phones Apple, and those settings cut most of it.

Encrypt the disk, or the rest hardly matters

Every setting on this page assumes nobody can simply pick the machine up and read it. Full-disk encryption is built in and costs you nothing: BitLocker on Windows, FileVault on macOS, LUKS on Linux. Turn it on, and store the recovery key somewhere that is not the same machine.

The camera and the microphone

Cover the webcam you are not using; a sticker is a perfectly good answer to a hard problem. For the microphone, check which apps hold permission and revoke the ones with no reason to listen. Both systems show an indicator when something is recording, so learn what it looks like on your machine.

Two accounts: one to administer, one to live insome setup

Running day to day as an administrator means anything that gets onto the machine inherits that power. Make a second, non-administrator account and use it for normal work, keeping the admin account for installing things. It is the oldest piece of advice in computer security and still one of the most effective, because it turns a full compromise into a limited one.

Updates are a privacy feature, not an interruption

Most real-world compromises use a hole that was fixed months earlier in an update nobody installed. Turn on automatic updates for the operating system and the browser, and treat a device that no longer receives security updates as a device you should not put anything sensitive on.

The sync folder that quietly uploads everything

A cloud drive folder is a copy of your files on somebody else's computer, and people routinely put scans of passports, tax documents and password lists inside one without thinking of it as uploading. Look at what is in yours. Either move the sensitive parts out, or encrypt them before they sync so the provider stores something it cannot read.

See what your machine is actually sayingsome setup

You do not have to take anyone's word for which programs phone home, including ours. A connection monitor shows you every outbound connection and the process behind it, which turns a vague worry into a list you can act on.

Wyrm Sieve
free and open. Names the trackers your machine talks to, and blocks them. Linux and Windows.
Little Snitch
the long-standing paid option on macOS.

The security software that was the leak

Antivirus and 'cleaner' tools sit above everything you do, which makes them worth checking as hard as anything else. Avast spent years collecting its users' browsing history through the antivirus and selling it through a subsidiary called Jumpshot, packaged as market data. The US regulator banned the company from selling browsing data and fined it 16.5 million dollars in 2024. The lesson is not that antivirus is bad; it is that a tool with total visibility deserves the same scepticism as everything else on this list.

The private-by-default option: Linuxadvanced

A Linux desktop does not report to anyone by default, and it is more approachable than it used to be. For the highest stakes, there are systems built entirely around isolation.

Linux Mint / Fedora / Debian
friendly, private desktops with no built-in telemetry.
Qubes OS
security by compartmentalisation, for high-threat users.

What you say

Messages, mail and the platforms in between.

05

Messaging

checked August 2026

What you say, and who you say it to, is worth more to a surveiller than almost anything else you produce. Move it somewhere that cannot read it.

The default: Signal

End-to-end encrypted, run by a non-profit with nothing to sell, and it keeps famously little. That last part is checkable, not claimed: Signal publishes the grand jury subpoenas it receives along with what it was able to hand over, and the answer has repeatedly been the date an account was created and the date it last connected. Nothing else exists to give.

Signal
the one to move your daily messaging to.

Encryption isn't the whole story

End-to-end encryption hides what you said. It does not always hide who you spoke to, when, how often, or for how long, and that pattern alone identifies relationships, routines and sources. This is why the messenger matters beyond the word 'encrypted': ask what it keeps, not only what it hides. A messenger owned by an advertising company keeps the pattern even when it cannot read the words.

The backup that undoes your encryption

An encrypted chat backed up in the clear to a cloud drive is no longer an encrypted chat, and this is the most common way people lose the protection they think they have. Check your messenger's backup setting and either turn it off or make sure the backup itself is encrypted with a key you hold.

Your messages are evidence, and they have been used that way

This is the concrete version of the argument. In 2022 police in Nebraska investigating an abortion obtained a Nebraska teenager's Facebook messages by warrant, and those messages were central to the prosecution that followed. Meta complied, as it was legally required to. Nothing was hacked and nothing leaked; the messages were simply stored somewhere readable by the company that ran the service. Whether or not that law is your law today is not the point. The point is that unencrypted messages are a permanent record held by someone who will hand it over when asked.

Verify the person, not just the appsome setup

Encryption protects the message from everyone except the person on the other end, so the remaining question is whether that person is who you think. Signal and similar apps let you compare a safety number or scan a code in person, which confirms nobody is sitting in the middle. Do it once with the handful of people who matter, and pay attention when the app warns you a key has changed rather than tapping past it.

Group chats leak in every direction

A group is only as private as its least careful member, and everyone in it can screenshot, forward, or add somebody new. Assume anything you write in a group of more than a few people will eventually be read by someone outside it.

Disappearing messages, used properly

Timers reduce how much history sits on a device that could be lost, stolen or searched, which is a real benefit. What they do not do is stop the other person keeping a copy: a screenshot, a photo of the screen, or a second device all defeat them. Use them as hygiene against accumulation, never as a promise about the other person.

When you can't even give a phone numbersome setup

Signal ties to a phone number. When you need to talk with no identifier at all, or in a group of strangers, there are messengers built for exactly that.

SimpleX Chat
no phone number, no account, not even a user ID. It's what the Wyrm room runs on.
Matrix / Element
federated, self-hostable, good for communities.
06

Email

checked August 2026

Old, leaky, and tied to everything you ever signed up for. You cannot fix email, but you can stop it linking your whole life together.

A mailbox that doesn't read you

Move off a provider that scans your mail to one that encrypts it and does not. Both of these are based in privacy-friendly jurisdictions.

Proton Mail
the popular pick, with a full suite around it.
Tuta
encrypted and lean. It's what Wyrm's own mailbox uses.

Aliases: stop one leak becoming ten

Give every website a different address that forwards to you. When one leaks or sells you, you see exactly who did it, and you can cut that alias off without touching the rest of your accounts.

SimpleLogin
unlimited aliases, open source.
addy.io
another strong open-source aliasing service.

What encrypted email still gives awaysome setup

Even at its best, email encryption protects the body of the message and not much else. Subject lines usually travel in the clear, and the headers, who wrote to whom and when, are visible by design because that is how mail gets delivered. If the fact of the conversation is the sensitive part, use a messenger.

Your address is the identifier that links everything

One address used everywhere is the key that lets brokers join your shopping, your politics, your health searches and your job into a single profile, and it is the field breached databases get matched on. That is the real argument for aliases: not secrecy, but breaking the join.

Unsubscribe carefully

For legitimate senders the unsubscribe link is the right thing to use and it works. For obvious spam, clicking anything confirms a human read the message, which makes the address more valuable, so mark it as spam instead. When a sender is somewhere in between, unsubscribe at the company's own website rather than through the emailed link.

Tracking pixels in your inbox

Marketing mail commonly hides a one-pixel image that reports when you opened it, how many times, and roughly where you were. Turning off automatic image loading kills most of it in one setting, and every provider has that switch.

07

Social platforms

checked August 2026

The big platforms are surveillance with a feed attached. You do not have to leave, but you can stop feeding them.

Lock it down, or let it go

Go through each account's privacy settings and turn off ad personalisation, off-platform activity tracking and face recognition, and make your posts private. Then delete the accounts you do not use, because a dormant account is still a profile being sold.

Your posts give away more than you think

A photo can carry the exact place it was taken, a reflection can show the room, a uniform or a street sign can place you, and posting in real time tells anyone watching where you are right now. In 2018 a fitness app published a global heatmap of its users' activity and, without meaning to, traced the perimeter of secret military bases and the jogging routes of the people staffing them. Every one of those runners had chosen to share. None of them had thought about what the aggregate would show. Post after you leave, check the background, and think about what a stranger could assemble from a month of your posts.

Deleting an account, properlysome setup

Deactivating is not deleting, and on several platforms an account merely deactivated comes back the moment you log in. Download your data first, then use the actual delete option, which is usually buried a few menus deeper than deactivate. Expect a waiting period during which logging in cancels the deletion, so stay out of it. Assume advertising profiles derived from you persist for a while regardless.

Other people's faces, and other people's choices

Posting a photo of a friend, tagging them, or uploading your contacts hands a platform information about people who never agreed to any of it. Contact upload in particular is how platforms build shadow profiles of people who are not members. Ask before you post someone, avoid tagging by default, and decline the prompt to sync your address book.

The data does get sold, including the sensitive kind

Grindr shared its users' location, along with the fact that they were Grindr users, with advertising networks. The Norwegian data protection authority fined it around 65 million kroner in 2021 for doing so without valid consent, noting that in this case the mere fact of use disclosed sexual orientation. In 2024 the US regulator brought a similar case over the app's handling of HIV status. Ordinary ad-tech plumbing, applied to a population for whom exposure is genuinely dangerous.

Alternatives that don't sell yousome setup

If you want the social part without the surveillance, the open, federated networks run on your terms instead of an ad company's.

Mastodon
an open, ad-free alternative to the big timeline.

What you keep

Passwords, backups, and the things hidden inside your own files.

08

Passwords & 2FA

checked August 2026

The biggest breach of your privacy is usually a company losing your data, not a person watching you. Lock the accounts down.

A password manager, and a different password everywhere

Reused passwords are how one leak becomes ten. A manager makes a strong unique password for every account and remembers them so you do not.

Bitwarden
open source, syncs across devices, easy. The default for most people.
KeePassXC
fully local, no cloud at all, if you'll manage the file yourself.

Two-factor that actually helps

Turn on two-factor everywhere, but not by text message. SMS is the weakest kind: the US standards body recommended against it as far back as 2016, and it can be stolen by taking your phone number, no password needed. Use an authenticator app, or a hardware key for the accounts that matter most. Passkeys, where offered, are the easiest strong option and cannot be phished at all.

Aegis Authenticator
a free, open authenticator app for Android.
YubiKey
a hardware key, the strongest second factor there is.

Recovery is the weakest link you own

Attackers rarely break a strong password; they go around it. The way in is usually a recovery email you forgot about, a security question whose answer is on your public profile, or your phone number transferred to someone else's SIM. That last one got common enough that the US telecoms regulator wrote SIM-swap rules for carriers in 2023. Print your backup codes and keep them off the machine, treat security answers as extra passwords, not facts, and ask your carrier for a port-out PIN.

Sign out the sessions you forgot about

Most accounts keep a list of devices and browsers currently signed in, and it usually contains an old phone, a work laptop, or a friend's computer from years ago. Each is a way in that no password change closes unless you also revoke it. Go through the active sessions on your email and your main accounts once, sign out everything you do not recognise, and change the password afterwards so anything revoked cannot reconnect.

Sharing access without sharing a password

Passwords sent by message end up permanently in someone else's chat history, and shared family accounts often expose more than the person expects, including addresses and payment details. Use your password manager's sharing feature, prefer a proper family option where the service offers one, and when someone leaves, change the password rather than trusting them to forget it.

Check what's already out there

See whether your email and passwords are in known breaches, and change the ones that are. Set an alert for the next one, because there will be a next one.

Have I Been Pwned
the breach checker to trust.
09

Backups

checked August 2026

Privacy is worthless if you lose everything to a dead drive or ransomware. Back up, but back up encrypted, so the backup is not a new leak.

Encrypt before it leaves your handssome setup

If you back up to the cloud, encrypt it yourself first so the provider stores nothing it can read. If you back up locally, encrypt the drive. Either way the key stays with you.

Cryptomator
encrypts a folder before it syncs to any cloud. Free and open.
VeraCrypt
encrypts a whole drive or a container, on your machine.
restic
encrypted, versioned backups for the command line.

Three copies, two kinds of media, one somewhere else

The rule that has survived every technology change. A backup that lives next to the computer covers a dead drive and nothing else, and a backup you have never restored from is a guess. Test one restore a year.

Ransomware is why versions mattersome setup

A backup that mirrors your machine will faithfully mirror your files after they have been encrypted by ransomware or deleted by accident, which is how people discover their backup was really just a copy. Use software that keeps versions and history, and keep at least one copy offline or somewhere the machine cannot silently overwrite.

Where the recovery key lives

Disk encryption, encrypted backups and password managers all have one key or phrase that everything else depends on, and losing it means losing the data permanently, with nobody able to help. Write it on paper and keep it somewhere physically safe, ideally in two places. Do not store it as the only copy on the device it unlocks, and do not email it to yourself.

10

Your data & metadata

checked August 2026

What you share carries more than you meant to send. Strip it before it leaves your hands.

Photos carry your location

A photo's hidden data can include exactly where and when it was taken, and the camera's serial number. The canonical demonstration is from 2012, when a magazine published a photo of John McAfee while he was on the run from Belizean police, with the GPS coordinates still embedded in the file. He was located within days. Strip it before you post or send.

mat2
the metadata anonymisation toolkit. Strips it from photos, PDFs and more.
ExifTool
the power tool for reading and removing file metadata.

Documents carry your name

PDFs and office files keep the author, the software, and sometimes the whole edit history. Run them through a stripper, or use the app's own 'inspect document' before you share.

Filenames and folders say plenty on their own

Metadata is not only hidden inside a file. A filename like scan-of-passport.pdf, a folder called clinic, or a photo named after the place it was taken all describe the contents to anyone who sees the listing, including cloud providers, backup indexes and anyone glancing at a shared screen.

Shared documents remember everything

Collaborative documents keep revision history, comments and the names of everyone who touched them, so sharing one can hand over the earlier draft you thought you had deleted along with who changed what and when. Before sharing outside a trusted group, export a flat copy.

Redact so it can't be un-redactedsome setup

A black box drawn over text can often be reversed, and it is reversed regularly by people with no special tools. Paul Manafort's lawyers filed a court document in 2019 with passages blacked out; reporters read the hidden text within minutes by copying it out of the PDF. Actually delete the words or the pixels, do not merely cover them, and flatten the file afterwards. Screenshots need the same care: crop, do not cover, because the pixels under a drawn box are still in the file.

"Anonymised" is a weaker word than it sounds

Stripping names from a dataset is not the same as making it anonymous, and researchers have shown this repeatedly. A 2013 study of fifteen months of mobile phone records found that four approximate time-and-place points were enough to uniquely identify 95 per cent of the people in it. Location is exceptionally identifying because the place a phone spends every night and every weekday names its owner. When a company tells you data is anonymised and sold in aggregate, that is a claim about intent rather than about mathematics.

The places you are

Your home network, your house, your car, the street, and anywhere you travel.

11

Your network

checked August 2026

One change here protects every device in your home at once, including the ones you cannot install anything on.

Block trackers at the DNS layer

Before any connection is made, your device asks a resolver for an address. Point it at one that refuses tracker, ad and malware domains and a lot of the spying simply stops, on every device, with nothing else changed. Use the encrypted form, DNS over HTTPS or DNS over TLS, so the lookups themselves are not readable by the network or your provider.

Mullvad DNS
free, no account, with tracker-blocking variants.
NextDNS
the most configurable, with per-device rules.
Quad9
a simple, non-profit malware-blocking resolver.
Pi-hole
run your own blocker on a Raspberry Pi at home.

Do you actually need a VPN?

A VPN hides your traffic from your internet provider and the network you are on, and moves that trust to the VPN company. It helps on hostile or public networks. It does not make you anonymous. And a free VPN makes its money by watching you: a 2016 study of 283 Android VPN apps found that 38 per cent contained malware, 18 per cent did not encrypt traffic at all, and a number were injecting their own tracking. Facebook ran one called Onavo for years purely to watch which apps its users were spending time in. Pick one that is audited, keeps no logs, takes cash or Monero, and does not need an account.

Mullvad VPN
the honest pick. No account, a flat price, cash or Monero accepted, independently audited, no logs.
IVPN
another audited, no-logs option with the same ethos.
Proton VPN
if you want a free tier to start, from a privacy company.

Router hygienesome setup

Change the default admin password, keep the firmware updated, put smart devices on a separate guest network so they cannot see your phone and laptop, and turn off remote management and UPnP unless you truly need them.

What your internet provider can still see

With HTTPS everywhere, your provider can no longer read the contents of what you do, but it still sees which sites you connect to and when. In several countries it is allowed to sell that, or required to retain it. Encrypted DNS hides the lookups, and a VPN hides the destinations by moving that visibility to the VPN company instead. Choose deliberately which of the two you would rather have holding the record.

Give the smart devices their own networksome setup

Most routers can run a guest network, and this is the single most useful thing that feature is for. Put the TV, the speakers, the plugs and anything else with a cloud account on it, and keep your phones and laptops on the main one. The devices you trust least then cannot see, scan or reach the devices that hold your actual life.

Your phone is shouting its name in every shopsome setup

Phones broadcast Wi-Fi and Bluetooth signals constantly, and that broadcast is what lets shops, airports and city centres count and follow people between visits. Modern phones randomise their hardware address to blunt this, and both platforms now do it by default, but the defence is imperfect and researchers keep finding ways around it. Check that randomisation is switched on; do not assume it. What to do about the shops themselves is in the chapter on being out in the world.

12

Your home

checked August 2026

A smart device is a computer that works for whoever made it. A few are worth it. Most are not.

Audit and cut

Walk around and list everything with a microphone, a camera, or a network connection. Return or unplug anything that needs a cloud account to do its basic job, because if it dies when their servers do, it was never really yours.

Your TV is watching you

Most smart TVs log what you watch and sell it, using a feature called automatic content recognition that samples the screen itself, so it covers anything you play through the TV, not just the TV's own apps. Vizio was caught running it on eleven million televisions without telling anyone, and paid 2.2 million dollars to settle with the US regulator in 2017. The feature did not go away; it became standard, disclosed in a settings screen nobody opens. Turn off viewing data and ACR in its settings, or keep the TV off the internet entirely and feed it from a device you trust.

Voice assistants are microphones with a business model

A smart speaker listens for its wake word constantly and sends what follows to a company. In 2019 it emerged that all three major assistants had human contractors listening to recordings for quality review, including recordings captured by accidental wakes: Bloomberg reported it for Amazon, the Guardian for Apple, and Belgian public broadcaster VRT for Google, whose reporters were able to identify people from the clips. All three changed their policies afterwards. If you keep one, turn off human review, set recordings to auto-delete, and use the physical mute switch when it matters. If you barely use it, unplugging it is the complete fix.

Locks and parcels

A smart lock or a delivery box that reports to an app creates a log of when your home is empty and who came in, held by a company and reachable by anyone who compromises the account. Prefer devices that work without an internet connection, put a strong unique password and two-factor on the account, and keep a physical key that does not depend on anyone's server being up.

Doorbells and cameras point at your neighbours too

A cloud doorbell camera streams your doorstep, and often the pavement and the house opposite, to a company. Amazon's Ring settled with the US regulator for 5.8 million dollars in 2023 over employees and contractors having watched customers' videos, including inside bedrooms and bathrooms, and over security failures that let outsiders in. Ring also spent years handing footage to police through a request tool it eventually withdrew in 2024. If you want a camera, prefer one that records locally to a card or a home recorder with no cloud account, and angle it at your own property.

13

Your car

checked August 2026

A modern car is a computer with wheels and a data plan, and it is one of the most invasive things most people own. It is also the one almost nobody thinks to check.

What a connected car collects

In 2023 Mozilla reviewed twenty-five car brands and failed every single one, calling cars the worst product category they had ever looked at for privacy: all twenty-five collected more data than needed, eighty-four per cent said they could share or sell it, and several claimed rights over things like sexual activity and genetic information. Then in 2024 the New York Times reported that General Motors had been sending drivers' individual trip and behaviour data to LexisNexis and Verisk, who sold it on to insurers, with drivers discovering it only when their premiums rose. GM stopped after the story ran. Go into your car's settings and the manufacturer's app and turn off data sharing and connected services you do not use, and look up your exact model before assuming it is harmless.

Privacy Not Included (Mozilla)
look up your exact car, and most other connected products, before you trust them.

The phone you paired, and the car you gave back

Pairing a phone copies contacts and call history into the car, and that data stays there. Before you sell a car, return a rental, or hand back a lease, delete the paired phones and factory reset the infotainment system. A rental you drove for a weekend can otherwise keep your address book and every place you navigated to.

Rentals and courtesy cars

Treat the infotainment system as a public computer. Check the paired device list when you get in and delete the strangers you find. Use a charging cable and skip pairing altogether when you only want power, because plugging into the data port is what triggers the contact copy in the first place.

The insurance box, and what it really scores

Telematics devices and insurer apps offer a discount in exchange for continuous monitoring of speed, braking, cornering, time of day and location, and that data has been used to raise premiums and contest claims later. It can be a fair trade. Make it deliberately: read what is collected, how long it is kept and who else it is shared with, and do not simply accept it because a discount was attached.

14

Out in the world

checked August 2026

Some surveillance you cannot install your way out of, because it is pointed at the street, not at your devices. Knowing how it works is most of the defence.

Find out where the cameras actually are

Automated licence plate readers log every car that passes them: plate, time, place, and often make, model and colour, whether or not anyone is suspected of anything. DeFlock is a community-run map of where those cameras are installed, so you can see what is on your own routes instead of guessing. Coverage is strongest in the United States and Canada, because that is where these networks have spread furthest and where people have been mapping them; in most of Europe the map is thin, which reflects how far the mapping has got, not the absence of cameras. It will not hide you from anything and it is not meant to. It is for knowing.

DeFlock
see where licence plate readers are mapped near you, and add one you have spotted.
Atlas of Surveillance (EFF)
which surveillance technologies a given US police department actually operates.

Cameras, faces and number plates

Public and private cameras increasingly feed software that recognises faces automatically, which turns a passive recording into a searchable record of where a person has been. Clearview AI built a database of billions of face images scraped from social media and sold searches of it to police; European regulators have since ruled the whole thing unlawful, with Italy's Garante, France's CNIL, Greece and the Netherlands each fining the company around twenty million euros, and the UK regulator doing the same. The fines have largely gone uncollected. Your practical controls here are legal ones, not technical: know what your country allows, support the groups challenging it, and treat any place with face-recognition entry as a place that keeps a record of your visit.

Shops that follow your phone around the aisles

Retailers and shopping centres use Wi-Fi and Bluetooth beacons to count visitors, measure how long you stand in front of something, and recognise a returning device. Loyalty apps with location permission do the same more precisely and with your name attached. Turning Wi-Fi and Bluetooth off when you are not using them, and denying location to shop apps, removes most of it.

Travel cards, tolls and number plates

A registered transport card, an electronic toll tag or a parking app builds a detailed record of your movements tied to your identity, and these records are routinely requested by police. Where an anonymous or cash-topped card exists, it is one of the few genuinely private options left in daily life, and preferring it costs you almost nothing.

If you go to a protestsome setup

Treat your phone as the biggest risk you are carrying. Bring a spare or leave it at home if you can. If you bring your own, turn off biometric unlock and use a long passcode: in several jurisdictions courts have treated a face or a fingerprint as something you can be compelled to provide, while a passcode has more protection. Turn on airplane mode when you do not need the network, back up and then remove anything sensitive beforehand, and blur or crop faces before posting photos of other people. The EFF's guide is the one to read before you go.

Attending a Protest (EFF)
the practical checklist, kept current, written by lawyers and technologists.
15

When you travel

checked August 2026

Borders and networks you do not own are where a lot of privacy quietly falls apart. A little preparation goes a long way.

At the bordersome setup

Devices can be searched and sometimes seized at a border, often without the suspicion that would be required anywhere else in the country, and you may be pressured to unlock them. US border device searches have risen year on year and now run to tens of thousands annually. Travel with as little on your devices as you can, power them fully off before a crossing since encryption is strongest from cold, and learn the rules for the border you are actually crossing, because they differ enormously.

Digital Privacy at the U.S. Border (EFF)
the detailed guide, if that is the border you are crossing.

On networks you don't trust

Hotel, airport and cafe Wi-Fi is the exact case a VPN is for: it hides your traffic from the network and everyone else on it. Use one, and for anything sensitive, Tor.

Before you go

Decide what needs to travel with you and leave the rest at home. Sign out of accounts you will not need, remove apps holding sensitive material, and make a full backup before you leave so nothing is lost if a device is seized, stolen or simply drowned. Know the number of one person who can help, on paper, because a locked or missing phone takes your contacts with it.

The room you're sleeping insome setup

Hidden cameras in rentals are rare but not imaginary, and the ones people find are usually cheap network cameras hidden in a smoke detector, a socket or a clock, facing a bed. A sweep costs five minutes: look for lenses facing sleeping areas, check the room's Wi-Fi for camera-shaped devices, and unplug anything you cannot explain.

The rest of your life

The computer you were issued, and the way you pay for things.

16

At work and school

checked August 2026

The most closely monitored computer most people use is the one they were given. The rule is simple: assume the owner can see everything.

Assume the work laptop is watched

Employer and school devices commonly carry management software that can log browsing, read files, capture the screen and inventory installed apps, and in most countries this is legal when disclosed. None of it is defeated by a private browsing window. Keep personal accounts, personal messaging and anything you would not want read entirely off that machine.

Your own phone on their network

Enrolling a personal phone in a workplace system hands real control to the organisation: the ability to enforce policy, see some app and network activity, and remotely wipe the device. If you can avoid enrolling your own phone, do. If you cannot, keep work in a separate work profile so the two sides stay apart, and understand what the organisation can see before you agree.

Personal accounts on a work machine

Logging into personal email, messaging or cloud storage on a managed device can put that content within reach of the organisation's monitoring, and it survives you leaving. It also works the other way: personal accounts signed in on a work profile can pull work data somewhere it should not be.

What monitoring usually looks likesome setup

In most places the employer must tell you monitoring exists, often in a policy you signed on your first day, so the honest first step is to read it. On a managed device you can usually see the management profile in settings, along with the certificates that let network traffic be inspected. Knowing what is in place beats guessing, and it tells you exactly where the line is.

School software watches children more than parents realise

School-issued devices and learning platforms routinely include monitoring that scans documents, messages and searches, sometimes flagging pupils to staff or police, and it typically follows the device home. Human Rights Watch reviewed 164 education products endorsed by governments during the pandemic and found that 146 of them appeared to surveil children or were capable of it, most often by handing data to advertising technology. In Europe this has run into the law repeatedly, with Dutch and German authorities forcing changes to how school platforms handle pupil data. If you are a parent, ask the school what its devices and platforms collect, who receives it, and how long it is kept. You are entitled to an answer.

17

Your money

checked August 2026

How you pay is a running log of where you were and what you wanted. Some of it you can take back.

The private options

Cash is still the most private way to pay and it leaves no trail at all. Online, note that Bitcoin is a fully public ledger and so is not private by default; Monero is. A masked card number keeps a purchase from being linked to the rest of your spending.

Monero
private digital cash, unlike Bitcoin's public ledger. It's what Wyrm takes for donations.
privacy.com
single-use and masked card numbers (US).

Crypto is not automatically privateadvanced

Bitcoin and most other coins publish every transaction on a permanent public ledger. Once one address is tied to your identity, and buying through an exchange with identity checks does exactly that, the entire history connected to it becomes traceable forever, backwards as well as forwards. This is not theoretical: chain analysis is an industry, and it is how a great many prosecutions have been built. The US authorities traced and seized around 3.6 billion dollars of bitcoin from the 2016 Bitfinex hack six years after the fact, by following the chain. Monero is designed so amounts, senders and recipients are hidden by default. Treat any coin as public unless privacy is a designed-in property rather than a habit you maintain.

Holding crypto yourself, on a hardware walletadvanced

If you hold any crypto, the exchange you bought it on holds the keys, which means it holds the coins and knows exactly who owns what. A hardware wallet moves those keys onto a small dedicated device that never exposes them to your computer: you confirm each transaction by physically pressing a button, so malware on your laptop cannot quietly move funds. Be honest with yourself about the difficulty first. You become the bank, your recovery phrase is the only way back in, nobody can reset it for you, and writing it down badly or storing it in a photo is how most people lose everything. Two things are worth knowing before you buy. Ledger's customer database was breached in 2020, exposing the names and home addresses of around 270,000 buyers of a device that advertises holding wealth, and some of those people were later threatened in person. And in 2023 Ledger announced an opt-in key-recovery service, which demonstrated that the device could be made to export key material in firmware; a lot of people lost trust over it. If that matters to you, look at the fully open-source alternatives, and buy any hardware wallet new and direct from the maker rather than second hand.

Trezor
fully open-source firmware, if being able to audit it is the point.
Ledger
the best known, and genuinely well built. Read the two caveats above first.

Loyalty cards are the point of the discount

A supermarket loyalty scheme exists to attach a name to a basket. The discount is real, and so is the trade. If you want to keep it, at least keep it dumb: give a throwaway email and an alias, and do not link it to anything else.

Open banking, and the apps you gave your statements to

Budgeting and lending apps often ask to connect to your bank account, which hands over a categorised history of everything you have bought, where and when. Check which services still have access in your bank's connected-apps screen and revoke the ones you no longer use, because access usually persists silently after you stop opening the app.

Going further

Anonymity, the law, the myths that stop people acting, and what Wyrm builds.

18

Anonymity

checked August 2026

Most people need privacy, not anonymity. If you are a journalist, an activist, or you truly need to be unlinkable, this is where the bar sits.

Privacy is not anonymity

Privacy means what you do is not watched. Anonymity means what you do cannot be traced back to you. They are different jobs needing different tools. A VPN gives you privacy. It does not give you anonymity.

Tor, used safelysome setup

Tor routes you through several relays so no single one knows both who you are and what you are doing. Use the Tor Browser as it ships: do not log into your real accounts, do not resize the window, do not add extensions, and do not torrent over it.

Tor Browser
the way to actually be anonymous online.

A computer that forgetsadvanced

For the highest stakes, run a whole operating system from a USB stick that leaves no trace and routes everything through Tor.

Tails
an amnesic OS on a stick, for when nothing can be left behind.

How anonymity usually breaksadvanced

Almost never by breaking the cryptography. It breaks because the same account, phrase, photo or habit appears on both sides of the wall. The textbook case is Ross Ulbricht, whose Silk Road identity was tied back to him partly through an early forum post advertising the site from an account carrying his own Gmail address, made months before anyone was looking. Years of operational discipline afterwards did not undo one post. If you need to be unlinkable, keep the identities completely separate, never cross them once, and assume any single mistake is permanent.

Compartmentalise, and never cross overadvanced

Anonymity is maintained by keeping identities in sealed boxes: separate browser, separate accounts, separate email, ideally a separate device or operating system, and no habit shared between them. Decide the boundary before you need it, and make it physical where you can.

The way you write gives you awayadvanced

Distinctive phrasing, spelling, punctuation habits and the hours you post can identify an author across accounts, and the software to do it is neither exotic nor expensive. Research on stylometry has repeatedly shown authors being picked out of pools of thousands from a few thousand words of text. If you genuinely need to be unlinkable, write differently from how you normally write, and do not post on the schedule your other identity keeps.

Threat modeling

Write down your real threat: who might come after this, and how far they would go. Guarding against an ad network and guarding against a state are very different jobs. Do not over-build a fortress you will not keep, and do not under-build against a real adversary.

19

Your rights

checked August 2026

Privacy law is on your side more than most people realise, and almost nobody uses it. In the EU and a growing list of places, exercising these costs nothing.

Get your data, and delete it

You can ask any company what data they hold on you and get a copy, demand they delete it, and object to it being used for advertising or profiling. They are legally required to answer, and under the GDPR that means without undue delay, and within one month.

How to actually send one

It does not need a lawyer or a template service. Email the company's privacy or data protection address, say plainly that you are making a request under the GDPR or your local law, state whether you want a copy of your data, its deletion, or both, and give enough detail to identify your account. Keep the date you sent it. If a month passes with no meaningful answer, that silence is itself grounds for a complaint.

Object to profiling, not just collection

Alongside asking for a copy or a deletion, you can object specifically to your data being used for direct marketing, and that objection has to be honoured with no argument and no balancing test. You can also object to purely automated decisions that significantly affect you, such as credit or insurance scoring, and ask for a human to look instead. These are the least-used and most useful rights in the whole framework.

Children's data

Children get stronger protection almost everywhere: services aimed at them face stricter limits, consent thresholds are higher, and schools are constrained in what they may collect and share. As a parent you can make these same requests on a child's behalf. It is also worth asking a school what its devices and learning platforms actually collect, because the answer is frequently more than anyone assumed.

Data brokers, and complaining

Data brokers are covered too, and many have an opt-out; removal services automate the long list. If a company ignores you, complain to your data-protection authority. It is free, and in the EU it has teeth. In Italy that is the Garante.

Garante per la protezione dei dati personali
the Italian data protection authority, where a complaint goes.
20

Things that aren't true

checked August 2026

These do more damage than any single tracker, because each one talks somebody out of a change that would have worked.

"Private browsing makes me private"

An incognito window forgets your history on that machine when you close it. That is all it does. Your internet provider, your employer, the network you are on and every site you visit see exactly what they would have seen anyway. Google spent four years defending a lawsuit over precisely this misunderstanding and settled in 2024 by agreeing to delete billions of records of Incognito browsing it had collected, and to rewrite the disclaimer. It is a tool for keeping a surprise off the family computer, not a privacy measure.

"A VPN makes me anonymous"

A VPN moves your trust from your internet provider to the VPN company, which is a real gain on a hostile network and no gain at all against the sites you log into. It does not stop cookies, fingerprinting, or an account that already knows your name. Anonymity is a different job and it needs Tor.

"I have nothing to hide"

Everyone has something to protect, which is not the same as something to hide: a medical search, a salary, an address after leaving someone, a religion in the wrong country, a draft you never sent. You also cannot know today which of those becomes dangerous later, under a different employer, insurer or government. The Nebraska prosecution in the messaging chapter is what that looks like when the law changes underneath data that was collected while it was harmless. Privacy is not about guilt, it is about who gets to decide what is known about you.

"Only criminals use Tor"

Tor was built with US government funding, at the Naval Research Laboratory, and is used daily by journalists protecting sources, people living under censorship, domestic abuse survivors, researchers and ordinary people who would rather not be profiled. Crime exists on it as it exists on the ordinary internet and on cash. Avoiding a tool because of who else uses it is how a protection ends up used only by the people who stand out most, which makes it weaker for everyone.

"I'm not important enough to track"

Nobody is watching you personally, and that is precisely the point: this is automated, and it costs a company nothing to include you. You are not a target, you are a row. The profile is built whether or not anyone ever looks at it, and it gets used when you apply for something, get priced for something, or become interesting later for a reason you cannot predict today.

"It's too late, everything is already out there"

Some of it is, and none of that makes the next ten years inevitable. Profiles decay when the flow stops: an advertising ID you reset breaks the chain, a blocked tracker stops adding to the file, a deleted account stops growing it. You are not trying to erase a past. You are trying to stop paying into it.

21

Wyrm's own tools

checked August 2026

Wyrm builds two of these. They are listed here alongside everything else, not above it.

Sieve and Miragesome setup

Sieve is a desktop app that lists every server your computer talks to, names the trackers among them and blocks those; note that it cannot name anything if you have taken this guide's advice on encrypted DNS, which is a real conflict and the DNS advice is the more important of the two. Mirage is an Android app that sets your reported GPS location somewhere else and holds it there. Both are free and AGPLv3. If neither is the right tool for you, the rest of this guide stands on its own.

Wyrm Sieve
see and cut what your computer says behind your back.
Wyrm Mirage
stop apps knowing where you actually are.
+

Where to go next

This guide is a starting point, not the last word. These people do it full time, and do it better.

Surveillance Self-Defense
The EFF's step-by-step guides, kept current. The best free place to go deeper.
Privacy Guides
Community-vetted, non-commercial tool recommendations, updated constantly.
Electronic Frontier Foundation
Ongoing news and the legal fights over surveillance and digital rights.
The Markup
Investigative journalism on exactly how technology watches people.
Exodus Privacy
Look up any Android app and see the trackers baked into it before you install.
Privacy Not Included
Mozilla's reviews of how badly a given product, car or gadget behaves.
Have I Been Pwned
Check whether your accounts are in a known breach, and get told about the next one.
Atlas of Surveillance
Which surveillance technologies a given US police department actually operates.
DeFlock
A community-run map of automated licence plate readers. Strongest in the US and Canada; thin elsewhere.

Every answer that asserts something carries a link and a date, so you can go and check it for yourself. Found something wrong, or out of date? Say so and it gets fixed. That is the whole review process, and you are welcome to be part of it. Reach us at iamwyrm@tutamail.com.