RAZIBINTERNET INDEX Suggest a resource

Everyday privacy

Build a Personal Privacy Plan You Can Actually Maintain

Choose practical privacy priorities, protect essential accounts and create a small review routine that fits the way you use the internet.

A privacy plan becomes useful when it tells you what to do next. “Be safer online” is too broad to act on. “Make sure I can recover my email without my phone” is a task you can finish and check.

Start with the accounts, files and everyday situations that matter to you. Do not begin by buying several tools or changing every setting at once. A small set of working habits is easier to maintain than a restrictive setup you regularly abandon because it gets in the way.

Choose a few outcomes instead of chasing a perfect score

Write three outcomes in ordinary language. For example: keep family photos out of public view, avoid losing access to essential accounts, and stop sending complete documents when a short excerpt would do. Your priorities may be different.

EFF's security-planning guide recommends considering what you need to protect, the relevant risks, the consequences and the effort you can reasonably sustain. Use that as a way to make choices, not as an exercise in imagining every possible threat.

Be specific about the problem. A lost device, a reused password and an accidentally public file link call for different actions. A tool that helps with one does not automatically address the others.

Keep the written plan private if it reveals sensitive information about your accounts or circumstances. You can record a category such as “primary email” without including the password, recovery code and full account history beside it.

Map the few accounts that support everything else

Identify the accounts used to recover other accounts: your main email, password manager, phone service and any important cloud account. Draw a simple relationship map or make a short list of which account depends on which recovery method.

Look for a circle that could lock you out. For example, the password manager may require email access while the email password and recovery codes exist only inside that manager. Do not remove an existing recovery method until you have established and tested an alternative.

Use the email-recovery checklist, password-manager setup guide and recovery-code storage guide to improve this foundation. Finish one account properly before moving to the next.

Record the date you checked the recovery route and where the instructions are kept. A note saying “done” is less useful than “backup code location confirmed; alternate address still accessible.” Do not put the actual secret into an ordinary checklist.

Build a short first-week plan

Choose a manageable set of tasks and stop when each is complete. This is an example schedule, not a requirement to finish everything in seven days.

Session Task Evidence that it is finished
1 Review main email recovery You can identify a working route without the main phone
2 Improve one reused password The new login works and is stored appropriately
3 Check two-factor authentication A backup method is available and understood
4 Review public profiles Unnecessary visible details have been removed
5 Inspect browser permissions Unneeded permissions are revoked
6 Test one backup restore A sample file opens from the backup
7 Write the remaining priorities Each item has a clear next action

Leave room to resolve problems. If a login change causes trouble, fixing it is the task for that session. Do not keep layering changes onto a setup you no longer understand.

Match the habit to the moment it is needed

A useful privacy habit appears at the point of action. Before sharing a file, check the recipient and the final copy. Before installing an extension, read its purpose and permissions. Before connecting an app, confirm which account and access level are involved.

Keep a few relevant guides bookmarked rather than memorizing every setting. Document redaction, connected-app access and browser permissions are tasks you may revisit when something changes.

Make the default easy. A clearly named private documents folder and a separate sharing folder reduce confusion. A presentation browser window reduces the chance of exposing unrelated tabs. A saved official account link helps you avoid responding through an unexpected message.

Do not turn every ordinary task into a long checklist. Reserve detailed checks for sensitive documents, important accounts and unfamiliar services, and use a lighter routine for low-consequence activity.

Give each tool one clear job

List the tools you already rely on and the problem each solves. A password manager organizes credentials. A backup system helps recovery. A browser setting may limit particular tracking. Avoid treating any one product as a complete privacy package.

Before adding another tool, write the gap it addresses. Compare the new permissions, maintenance and account recovery it introduces with the benefit you expect. A complicated setup can create its own problems if you cannot remember what each component does.

Our Privacy / Security directory and toolset category can help you find relevant resources. Read the provider's current documentation and the listing's review notes before relying on a service. A directory entry is a starting point, not a security guarantee.

Remove tools you no longer use through the proper uninstall or account process. Review associated subscriptions, permissions and connected accounts separately rather than assuming the desktop icon was the whole relationship.

Plan for mistakes and unavailable devices

Choose a simple response to the problems you are most likely to encounter. For a missing phone, know the official finding service and an independent account-recovery route. For an accidentally shared document, know how to revoke the link and contact the recipient.

Use the lost-phone guide and encrypted-backup checklist to make those responses concrete. Test a harmless restore and confirm where the recovery instructions are stored. Do not test destructive actions merely to prove a button exists.

Agree with trusted people on the help they can provide. A family member may need to know where instructions are kept without receiving unrestricted access to every account. The family recovery plan explains that separation.

When a problem affects another person's information, include them in the response appropriately. Privacy is not only about the files you own; it also concerns documents, photographs and messages that other people trusted you to handle.

Review changes, not every setting on every device

Pick a regular review point that fits your routine, then add event-based checks after replacing a device, moving home, changing jobs or starting a new application. Review what changed since the last check rather than repeating an enormous audit without a reason.

A short monthly note might cover new accounts, new permissions, unresolved removal requests and the latest backup test. Keep only useful evidence and close finished items. Move a task you cannot resolve into a clear question for the relevant provider or qualified support person.

For each proposed change, ask whether it helps one of your chosen outcomes and whether you can maintain it. Keep the habits that work, simplify those that do not, and update the plan when your situation changes. The result should be a small, dependable routine rather than a collection of settings you are afraid to touch.

Sources and further reading

  1. EFF: Your Security Plan Consulted 28 September 2026.

Consult the linked documentation for current details. Settings, availability and interface labels may change.

Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.