How to protect your privacy online
Most privacy advice is a list of everything possible, which is why nobody finishes it. This one is ordered by payoff per minute. Do the first four and you have closed the gaps that actually get exploited; everything after that is refinement.
Run a privacy checkDecide who you are hiding from
Every control below defends against something specific. Applying all of them is expensive and mostly unnecessary; applying the wrong ones is worse, because it feels like progress.
Advertisers and data brokers are the default adversary for almost everyone. They are passive, automated, and they lose interest the moment tracking becomes unreliable. Cheap defences work well here.
Your network operator — an ISP, an employer, a hotel, a café — sees where your traffic goes even when it cannot see inside. Defeating this needs encryption at the network layer, not browser settings.
The services you use know what you tell them. No amount of network privacy hides your Google searches from Google if you are signed in. The only defence here is giving them less.
A targeted adversary with legal powers or real resources is a different problem entirely. If that is your situation, a consumer VPN is not the answer and any guide that tells you otherwise is selling something. Tor, compartmentalised devices and operational discipline are where that conversation starts.
Start here and most of it is done
These four close the gaps that are actually exploited at scale. Together they take about an evening.
A password manager, and unique passwords everywhere
Credential stuffing — reusing one leaked password across sites — remains the single most common way accounts fall. A manager makes unique passwords free. This is the highest-value item on the list and it is not close.
Two-factor authentication on email first
Your email is the reset path for everything else, so it is the account worth protecting hardest. An authenticator app beats SMS, which can be taken over by a SIM swap. A hardware key beats both.
Encrypt the network layer
A VPN moves DNS and traffic into a tunnel, so your ISP, your employer and the café router see one encrypted connection instead of a list of destinations. It also stops the passive collection that feeds data brokers.
Stop being signed in by default
The single biggest source of profiling is a permanently signed-in browser. Sign in when you need the account and sign out afterwards. This costs almost nothing and removes more linkage than any extension.
Eight more, with honest ratings
| Change | Protects against | Effort | Worth it? |
|---|---|---|---|
| Encrypted DNS (DoH/DoT) | ISP domain logging | Low | Yes |
| uBlock Origin | Trackers, malvertising | Low | Yes |
| Privacy-first browser | Fingerprinting, tracking | Low | Yes |
| Email aliases per service | Breach linkage, spam | Medium | Yes |
| Auto-delete account history | Profile depth over time | Low | Yes |
| Review app permissions | Location and contact leaks | Medium | Yes |
| Disable ad ID on phone | Cross-app tracking | Low | Yes |
| Full-disk encryption | Device theft | Low | Yes |
A VPN is a network control, not a disguise. It hides your traffic from the network and your IP from sites. It does not log you out of Google, does not stop browser fingerprinting, and does not make you anonymous. Anyone claiming otherwise is selling a subscription.
Where the effort stops paying
Extreme fingerprint hardening
Aggressive anti-fingerprinting extensions often make you more identifiable — a browser with a rare configuration stands out. Unless you are using Tor Browser, which normalises everyone, this usually backfires.
Constant IP rotation
Changing server every few minutes breaks sessions and buys almost nothing. Tracking is done with cookies and fingerprints; IP is a weak signal by comparison.
Stacking VPN on VPN
Double-tunnelling doubles latency and adds a second operator who can see your traffic edges. Against a targeted adversary it is not enough; against advertisers it is unnecessary.
What to check before trusting a VPN
You are moving your traffic from an ISP you did not choose to a company you did. That only helps if the company is better, so verify rather than assume.
Has the no-logs claim been audited, and is the report public? A marketing page saying “no logs” is a sentence anyone can type. An audit report with named findings is evidence. Read whether the auditor was allowed to inspect running infrastructure or only documentation.
What does signup collect? A provider that demands an email address, then promises anonymity, has already contradicted itself. The strongest position is one where the data does not exist to hand over.
Where is it incorporated, and what does that mean for disclosure? Jurisdiction determines what a court can compel. This matters less than marketing suggests for advertiser-level threats, and more than it suggests for legal ones.
Is the client open source? You are running their code on your machine with network privileges. Published source lets researchers check what it does; closed source asks you to take it on faith.
Is there a warrant canary, and is it current? A stale canary is a signal in itself. A missing one means the question was never asked.
Straight answers
What single change gives the most privacy?
Is a VPN enough on its own?
Are free VPNs safe?
Does incognito mode protect privacy?
Should I use Tor instead?
How often should I redo this?
Privacy is a set of small decisions
LunoVPN covers the network layer: encrypted DNS, no email at signup, a published no-logs audit and open-source clients. The rest of the list is yours — and we would rather you did it than bought a subscription instead of it.