Privacy & your data
An annual privacy audit for your online accounts
An hour a year, worked through in order: dormant accounts, connected apps, ad profiles, location history, and the settings that quietly reset themselves after product updates.
Privacy settings are not a one-time task. Accounts accumulate, apps retain permissions long after you stop using them, and product updates introduce new settings that default to sharing. Something configured carefully in 2021 is not configured carefully now.
This is a checklist for an annual pass. It takes about an hour and is worth putting in the calendar — pick a date you will remember, like a birthday or the new year.
Work in this order. It goes from highest to lowest impact.
1. Find the accounts you forgot
Dormant accounts are the largest overlooked risk. They hold real data, they are covered by breaches, and you are not monitoring them.
- Search your email for "welcome", "verify your account", "confirm your email", and "your new account".
- Check your password manager's full list — most people are surprised by the count.
- Check what your browser and platform account have saved.
- Look at the "Sign in with Google/Apple/Facebook" list, covered below.
For each: use it, or close it. Closing an account is more effective than any setting inside it. Where a service makes deletion difficult, a formal request under data protection law usually works — see our guide to data rights.
Also check your addresses against a reputable breach notification service. It tells you which accounts existed and were exposed, which is often how people rediscover forgotten ones.
2. Revoke connected apps
Every "Sign in with…" and every app you granted access to is a standing permission, often broader than you remember, and it persists indefinitely.
Review the connected-apps or third-party-access page on:
- Your Google, Apple, Microsoft accounts
- Facebook, Instagram, X, LinkedIn, TikTok
- GitHub, Slack, Dropbox
- Your bank, if it supports open-banking connections
Revoke everything you do not currently use. Nothing breaks that matters — if you need it again, you re-authorise in one click. Pay attention to anything holding write access, access to contacts, or access to your email content.
Old browser extensions deserve the same treatment. Extensions change ownership, and a popular one can be sold and quietly turned into a data collector. Remove what you do not use, and check the permissions on what remains.
3. Check what is public
Look at your own profiles while signed out, in a private window. This is what a stranger, an employer, or someone targeting you actually sees.
Check specifically:
- Profile photo, banner, and bio for identifying detail.
- Friends and followers lists — often public by default and a rich source for social engineering.
- Old posts. Most platforms have a bulk tool to limit past public posts to friends; it is the fastest way to close years of exposure.
- Tagged photos and whether tagging requires your approval.
- Whether your email or phone number can be used to find your profile. Turn this off; it is how scraped datasets get linked together.
Also search your own name, handles, phone number, and email in a search engine. Check the image results.
4. Location
Location is the most sensitive routine data most people share, and it is easy to leak accidentally.
- Review per-app location permissions. Move everything possible from "always" to "while using", and revoke it entirely from apps with no need — a game or a shopping app does not require your location.
- Turn off precise location for apps that only need approximate.
- Check your platform location history setting and consider turning it off or shortening the retention period. Review what is already stored.
- Check whether photo uploads carry GPS coordinates. Most platforms strip this; files shared directly usually do not.
- Review location sharing with individuals — these get set up for a specific trip and then left on for years.
5. Advertising profiles
Every large platform maintains an inferred profile: your estimated age, income bracket, interests, life events, and sometimes political leaning. Most people have never looked at theirs, and it is worth doing once.
- Find the ad settings or "why am I seeing this" controls on Google, Meta, Amazon, Microsoft, and TikTok.
- Review the inferred interests and remove what is wrong or sensitive.
- Turn off ad personalisation where offered.
- Turn off use of activity from partners and other sites — this is usually the biggest single lever, since it governs off-platform tracking.
- On Meta, check the list of businesses that have uploaded information about you. It is long, and you can remove them.
On mobile, confirm app tracking is restricted at the OS level, and reset your advertising identifier — it breaks the continuity of existing profiles.
6. Data brokers
People-search sites publish home addresses, phone numbers, relatives, and property records. They are the usual source of doxxing material.
- Search your name plus your city and see what appears.
- Use each site's opt-out. They are tedious and they work.
- Where a data protection regime covers you, send a deletion request instead — it is legally binding rather than discretionary.
- Expect to repeat this; brokers re-acquire data from public records. Annually is about right.
7. Security settings
Privacy and security overlap here, and this is the part that prevents the worst outcomes.
- Review active sessions on major accounts and sign out anything unrecognised or stale.
- Check recovery options — old phone numbers and dead email addresses are a genuine risk, since whoever eventually gets that recycled number or address inherits a path to your account.
- Confirm your second factor is still the strongest available, and that you have a backup method enrolled. See our guide to two-factor methods.
- Check your password manager's report for reused and weak passwords, and fix the important ones.
- Confirm backups are encrypted — particularly message backups, which are a common gap.
8. Messaging and sharing defaults
- Who can add you to group chats without permission.
- Whether read receipts, typing indicators, and last-seen are visible, and to whom.
- Who can message you directly, and whether requests from strangers are filtered.
- Whether your posts default to public or to a limited audience — and whether a recent update reset that.
9. Email hygiene
- Check forwarding rules and filters on your primary mailbox. An unrecognised forwarding rule is a serious indicator of compromise, and it is invisible unless you look.
- Review which addresses appear in breach databases.
- Consider separating a recovery-only address that is never given out publicly, used solely for banking and account recovery.
- Unsubscribe properly rather than deleting — under GDPR and similar regimes, an objection to direct marketing is absolute and they must stop.
10. Devices
- Remove devices you no longer own from every account.
- Confirm lock screens, encryption, and automatic updates are on.
- Check microphone and camera permissions per app.
- Look at what is visible on the lock screen — message previews can expose verification codes to anyone holding the phone.
- Review smart-home and voice assistant recordings, and set automatic deletion.
Keeping it manageable
The list is long, but the distribution of value is not even. If you only have twenty minutes, do these four:
- Revoke connected apps and unused browser extensions.
- Check recovery options and active sessions on your email.
- Turn off ad personalisation and partner-activity sharing.
- Close accounts you no longer use.
Those four cover the majority of the practical risk. The rest is refinement, and it will still be there next year.
