I used to think privacy online was something only paranoid people worried about. Then my email got hacked, my location data ended up in a data broker's database, and I found out my Netflix password was sitting in a leaked credential dump. That's when I realized I'd been doing almost everything wrong.
Here's what I've learned the hard way, and what actually works instead of the security theater most people engage in.
The Passwords Situation Is Worse Than You Think
Let me be direct: if you're using the same password across multiple sites, you're not being careful — you're being reckless. I used to do this. I had maybe three passwords I rotated across everything from banking to social media. When one service got breached (and they all do eventually), hackers didn't just get into that one account. They got into everything. The math here is brutal. There are roughly 700 data breaches per year in India alone, and globally we're talking thousands. Your email address is almost certainly in at least one breach already. You can check right now at haveibeenpwned.com.Use a Password Manager (Not Sticky Notes or Your Brain)
I resisted this for two years. I thought password managers were overcomplicating things. Then I realized my "system" of writing passwords down was infinitely worse. Now I use Bitwarden — it's free, open-source, and syncs across devices. Dashlane and 1Password are solid too if you want more hand-holding, but you'll pay for it. The workflow is simple: you remember one strong master password. Everything else gets genuinely unique, 20+ character nonsense that you never type manually. When a breach happens (and it will), that password is useless everywhere else.Two-Factor Authentication (2FA) Is Non-Negotiable
2FA used to feel like security theater to me. One extra step per login felt ridiculous. Until I realized that step prevented every single account takeover I would have experienced. Now it feels ridiculous NOT to use it. Here's the thing though: SMS-based 2FA is better than nothing, but it's not great. SIM swapping is real. Authenticator apps (Google Authenticator, Authy, Microsoft Authenticator) are genuinely better because they work offline and can't be intercepted over cellular networks. I use Authy specifically because it syncs across devices — lose your phone, and you don't lose access to your accounts. For anything critical (email, banking), use an authenticator app. For everything else, SMS is fine. But don't skip it.Your Browser Is Leaking More Data Than You Realize
I used to think browsing privately meant using incognito mode. That's not privacy. That's theater. Private browsing stops your browser from storing cookies locally. But the websites you visit still see exactly who you are. Your ISP still sees where you're going. Your router logs everything. The ad networks tracking you don't care whether you're in incognito mode.VPN Usage That Actually Protects You
A VPN changes your visible IP address and encrypts your traffic. Your ISP can't see what sites you're visiting anymore. However — and this is critical — your VPN provider can see everything. So choosing which VPN matters enormously. I used to use free VPNs. Then I read the privacy policies and realized they were literally selling my browsing data to advertisers. I switched to Proton VPN's free tier (limited speeds, but genuinely no logging). For actual daily use, I pay for Mullvad or Proton VPN Plus. They're ~$5-10 per month and they actually keep zero logs. Don't fall for marketing. NordVPN and ExpressVPN spent millions on YouTube ads claiming to be privacy-focused. Their privacy policies are fine, but there are better options. And free VPNs? They're not free. You're the product.Browser Extensions and Search Engines That Don't Track
Google Search is convenient. It's also selling profiles on you to advertisers. I switched to DuckDuckGo (totally free, no tracking). You'll lose some convenience — it's not as good at finding hyper-specific Indian news or local results. But the privacy tradeoff is worth it to me. For extensions, uBlock Origin blocks ads and tracking. Privacy Badger stops invisible trackers. I stopped using ad blockers that claim to show "non-intrusive ads" because that defeats the whole point.
Pro Tip: Your browser fingerprint (OS, browser version, screen resolution, fonts installed) can identify you even without cookies. Disabling JavaScript or spoofing your user agent helps, but honestly? Using a VPN + privacy extensions covers 80% of the concern for 10% of the effort.
Social Media and App Permissions Are Privacy Disasters You Can Control
I gave Instagram permission to access my location, my contacts, and my photo library. I don't even remember doing it. I was just tapping "Allow" to get through the setup. Here's what I didn't realize: Instagram was logging my location every few minutes even when I wasn't actively using the app. WhatsApp had my entire contact list synced to Facebook's servers. Apps I installed three years ago were still requesting permissions I'd granted once and forgotten about.Audit Your Permissions Right Now
Go to Settings → Apps on your phone. Pick any app and look at Permissions. You'll probably be shocked. I was. Social media apps especially — they don't need location access. Calendar apps don't need your contacts. The default answer to permission requests should be "No" until you have a specific reason. Here's my rule: if I can't explain why an app needs a specific permission, it doesn't get it. This means some apps become slightly less convenient. I don't care. Convenience isn't worth watching my location get sold to data brokers.Data Brokers and People Search Sites
This one surprised me. There are companies I've never heard of that have compiled detailed profiles on me — where I live, what I earn, my family members, my interests. They buy this data from public records and sell it to marketers, scammers, and insurance companies. Sites like JustDial, Facebook, and Google have public profiles with your information. Opting out is tedious but worth doing. I went through Whitepages, PeopleFinder, and similar sites and requested removal. It took a few hours spread over several weeks. Your mileage varies depending on which countries' data brokers have collected your info.| Privacy Tool/Practice | Effort Level | Protection Level | Cost |
|---|---|---|---|
| Password Manager | Low (one-time setup) | High | Free–$10/month |
| 2FA (Authenticator App) | Low (per account) | High | Free |
| VPN (Paid) | Low (install + forget) | High | $5–12/month |
| Privacy Browser Extensions | Low (install + forget) | Medium-High | Free |
| App Permission Audit | Medium (1-2 hours) | Medium | Free |
| Data Broker Removal | High (tedious) | Medium | Free (or $10–30/month for services) |
Email Is Your Weakest Link (and Your Most Important One)
Your email is the master key to your digital life. Forgot a password? Recovery link goes to email. Want to reset 2FA? Email confirmation. Every service you use can theoretically contact you there. Treat your email like you treat a house key. Because that's what it is. I used to use one email for everything. Then I realized how much tracking happens through email. Promotional emails build profiles on you. Service notifications reveal what you're signed up for. I now use a primary email for things I actually care about, and a secondary for everything else.Email Aliases and Forwarding
I started using SimpleLogin (owned by Proton, €2/month or free tier). It lets you generate unique email addresses on the fly that forward to your real email. So instead of giving my actual address to every newsletter and app, I give them an alias. If one gets sold or spammed, I can disable just that alias without affecting anything else. This is paranoia-level privacy. Honestly? I don't recommend it for everyone. But if you care about not receiving marketing emails, it works. For most people, I'd suggest: use Gmail for real accounts (it's secure), and a separate email for signups and services. Yahoo or Outlook work fine for this.My Take
Here's what surprised me most: most privacy breaches happen not because of sophisticated hacking, but because people reuse passwords and don't use 2FA. The dramatic stuff — encrypted messaging apps, VPNs, browser fingerprinting — those matter less than the boring fundamentals. What disappointed me? That privacy is still this fragmented. You can't just "turn on privacy" on your phone or browser and be done. You have to use different tools, manage different settings, and maintain different practices. It shouldn't be this way. But it is. Who is this actually for? If you're handling sensitive data (freelance work, business operations, medical info), you need everything I've mentioned. If you're just a regular person who doesn't want to be tracked, focus on the password manager, 2FA, and a VPN. That covers 90% of the risk for 10% of the effort. The middle ground is real. You don't need to use every privacy tool available. But you do need the basics. And you need them now, not when you get hacked.Verdict
Online privacy isn't binary. You're not either completely private or completely exposed. You're somewhere on a spectrum, and you get to decide where. Start with a password manager and 2FA (both free or cheap). Add a VPN if you're on public WiFi regularly. Audit your app permissions once. That's your minimum viable privacy. Everything else — privacy search engines, email aliases, data broker removal — those are nice to have. They're not essential unless you have specific reasons to care more deeply. The point isn't perfection. The point is not being the easiest target in the room. And that's achievable without turning into a privacy hermit.Published by Dattatray Dagale • 26 August 2026
0 Comments