Browser privacy settings worth changing first
A practical browser privacy setup that reduces tracking without breaking everyday browsing, with sensible settings for Chrome, Firefox and Safari.
A browser privacy setup should survive an ordinary week. You should still be able to pay a bill, join a call and open a document without guessing which setting broke the page. The useful changes are the ones you understand well enough to keep.
Start with the browser you already use. Update it, review its built-in tracking controls, and change one group of settings at a time. Adding several privacy extensions before checking the existing controls makes troubleshooting harder and gives more software access to your browsing.
This guide is a baseline for a personally owned device. On a work or school computer, follow the organization's rules instead of trying to override managed settings.
Decide what you want to keep private
Write down the problem in one sentence. Perhaps advertising follows you between shops, websites keep asking to send notifications, or a shared laptop exposes your accounts. These problems need different fixes.
Tracking controls can limit some connections between websites. They do not prevent someone using your unlocked computer from opening a signed-in account. For that, use a separate operating-system account and lock the screen. Likewise, a private window is a temporary browsing session, not a replacement for account security. Our guide to what private browsing actually hides explains that distinction.
A useful first pass covers three things: unnecessary tracking, unnecessary permissions and unnecessary stored data. Leave specialist settings alone until you have a reason to change them. A setup you can maintain is more useful than a long list of switches copied from someone else's screen.
Set a tracking baseline in your browser
In Firefox, open Settings and find Privacy & Security. Start by reviewing Enhanced Tracking Protection rather than installing a second tool that promises the same job. Mozilla describes the available protection levels and site exceptions in its official tracking-protection guide. Use a stricter level only after checking the sites you depend on.
In Safari on a Mac, open Safari settings, then Privacy, and review Prevent cross-site tracking. Apple's Safari documentation explains what this control does. The equivalent controls on an iPhone are in the device's Safari settings, so do not expect the desktop menus to match.
In Chrome, review the third-party cookie controls under Privacy and security. Google documents both blocking and site exceptions in its cookie settings guide. A sign-in or embedded tool that fails is a reason to investigate a specific exception, not immediately turn every protection off.
Record the starting setting before changing it. That small note gives you a clear way back if a payment form or learning platform stops working.
Review permission requests separately
Cookie controls and permissions solve different problems. A site can have little need for third-party cookies while still asking for your location, camera or notifications.
Open the saved site-permission list and remove grants for services you no longer recognize or use. For an active video-call service, keep only the access needed for calls. A weather page may work with a manually entered town instead of precise location. A shop rarely needs permission to interrupt you with desktop notifications.
Do not grant a permission just because a page presents it as the next step. Ask what feature should start working afterward. If the request has no clear connection to your task, dismiss it and continue. The browser-permission checkup gives a more detailed review process, including how to test camera and microphone access without changing unrelated settings.
Reduce the data that follows you between devices
Browser sign-in can be convenient, but decide what should travel with it. Bookmarks may be useful on every device; open tabs from a personal research session may not belong on a shared household computer.
Review synchronization on each device, not only the one in front of you. Check which account is signed in, which data types are selected and whether an old computer still appears in the account's device list. Avoid deleting synced history as a casual cleanup step until you understand whether deletion also reaches other devices.
For a careful approach, use the browser sync privacy guide. A separate browser profile can help organize work and personal sessions, but it is not a locked container. Someone with access to your unlocked computer may be able to switch profiles.
Keep extensions to a short, explainable list
Look at every installed extension and describe its purpose without reading its marketing text. If you cannot explain why it is there, investigate before keeping it.
For each extension, consider whether it needs access on every website or only one service. A tool used to capture a page occasionally should not automatically become a permanent participant in every account session. Remove unused extensions rather than simply hiding their icons.
Avoid installing several blockers with overlapping jobs. When a page fails, you will otherwise have to determine which tool changed the request, removed an element or restricted storage. Our extension review workflow focuses on permissions, publisher checks and a practical removal order.
The Privacy / Security directory can help you find relevant tools, but a listing is a starting point for checking the provider, not proof that an extension deserves access to your browser.
Test ordinary tasks before calling the setup finished
Choose a short set of real tasks: sign in to email, open a frequently used document, play a video, join a test call and reach a checkout page without completing a purchase. Use sites you already know. There is no need to enter sensitive information into a random browser-testing website.
If something breaks, first note which action failed. Try the same task after reversing only the most recent change. A site-specific permission or temporary exception is easier to understand than disabling protection for the entire browser.
Keep a brief record of exceptions with a reason, such as “embedded course videos require this setting.” Review the exception when you stop using that service. An exception without an expiry can outlast the task that justified it.
Give the settings a simple maintenance trigger
You do not need a weekly ritual of changing every switch. Review the setup when you install an extension, add a device, change your main browser or encounter a new permission request.
Keep automatic updates enabled where available and let the browser's normal security features do their job. Privacy is not improved by turning off protective warnings merely to make the interface quieter.
A good stopping point is concrete: you know which account is signed in, which permissions you granted, which extensions can read pages and where any necessary exceptions are recorded. That gives you a usable browser and a small set of choices you can explain, rather than a configuration you are afraid to touch.
Sources and further reading
- Mozilla Support: Enhanced Tracking Protection in Firefox Consulted 28 September 2026.
- Apple Safari User Guide: Prevent cross-site tracking Consulted 28 September 2026.
- Google Chrome Help: Manage third-party cookies Consulted 28 September 2026.
Consult the linked documentation for current details. Settings, availability and interface labels may change.
Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.