Skip to content
LunoVPN
Guide

How to protect your privacy online

Most privacy advice is a list of everything possible, which is why nobody finishes it. This one is ordered by payoff per minute. Do the first four and you have closed the gaps that actually get exploited; everything after that is refinement.

Run a privacy check
Ranked by payoff First four = one evening Threat model first
Before the list

Decide who you are hiding from

Every control below defends against something specific. Applying all of them is expensive and mostly unnecessary; applying the wrong ones is worse, because it feels like progress.

Advertisers and data brokers are the default adversary for almost everyone. They are passive, automated, and they lose interest the moment tracking becomes unreliable. Cheap defences work well here.

Your network operator — an ISP, an employer, a hotel, a café — sees where your traffic goes even when it cannot see inside. Defeating this needs encryption at the network layer, not browser settings.

The services you use know what you tell them. No amount of network privacy hides your Google searches from Google if you are signed in. The only defence here is giving them less.

A targeted adversary with legal powers or real resources is a different problem entirely. If that is your situation, a consumer VPN is not the answer and any guide that tells you otherwise is selling something. Tor, compartmentalised devices and operational discipline are where that conversation starts.

The four that matter

Start here and most of it is done

These four close the gaps that are actually exploited at scale. Together they take about an evening.

A password manager, and unique passwords everywhere

Credential stuffing — reusing one leaked password across sites — remains the single most common way accounts fall. A manager makes unique passwords free. This is the highest-value item on the list and it is not close.

Two-factor authentication on email first

Your email is the reset path for everything else, so it is the account worth protecting hardest. An authenticator app beats SMS, which can be taken over by a SIM swap. A hardware key beats both.

Encrypt the network layer

A VPN moves DNS and traffic into a tunnel, so your ISP, your employer and the café router see one encrypted connection instead of a list of destinations. It also stops the passive collection that feeds data brokers.

Stop being signed in by default

The single biggest source of profiling is a permanently signed-in browser. Sign in when you need the account and sign out afterwards. This costs almost nothing and removes more linkage than any extension.

The rest

Eight more, with honest ratings

ChangeProtects againstEffortWorth it?
Encrypted DNS (DoH/DoT)ISP domain loggingLowYes
uBlock OriginTrackers, malvertisingLowYes
Privacy-first browserFingerprinting, trackingLowYes
Email aliases per serviceBreach linkage, spamMediumYes
Auto-delete account historyProfile depth over timeLowYes
Review app permissionsLocation and contact leaksMediumYes
Disable ad ID on phoneCross-app trackingLowYes
Full-disk encryptionDevice theftLowYes

A VPN is a network control, not a disguise. It hides your traffic from the network and your IP from sites. It does not log you out of Google, does not stop browser fingerprinting, and does not make you anonymous. Anyone claiming otherwise is selling a subscription.

Diminishing returns

Where the effort stops paying

Extreme fingerprint hardening

Aggressive anti-fingerprinting extensions often make you more identifiable — a browser with a rare configuration stands out. Unless you are using Tor Browser, which normalises everyone, this usually backfires.

Constant IP rotation

Changing server every few minutes breaks sessions and buys almost nothing. Tracking is done with cookies and fingerprints; IP is a weak signal by comparison.

Stacking VPN on VPN

Double-tunnelling doubles latency and adds a second operator who can see your traffic edges. Against a targeted adversary it is not enough; against advertisers it is unnecessary.

Choosing a provider

What to check before trusting a VPN

You are moving your traffic from an ISP you did not choose to a company you did. That only helps if the company is better, so verify rather than assume.

Has the no-logs claim been audited, and is the report public? A marketing page saying “no logs” is a sentence anyone can type. An audit report with named findings is evidence. Read whether the auditor was allowed to inspect running infrastructure or only documentation.

What does signup collect? A provider that demands an email address, then promises anonymity, has already contradicted itself. The strongest position is one where the data does not exist to hand over.

Where is it incorporated, and what does that mean for disclosure? Jurisdiction determines what a court can compel. This matters less than marketing suggests for advertiser-level threats, and more than it suggests for legal ones.

Is the client open source? You are running their code on your machine with network privileges. Published source lets researchers check what it does; closed source asks you to take it on faith.

Is there a warrant canary, and is it current? A stale canary is a signal in itself. A missing one means the question was never asked.

Questions

Straight answers

What single change gives the most privacy?
A password manager with unique passwords. It is not glamorous, but reused credentials cause more real-world account compromise than every tracking technique combined.
Is a VPN enough on its own?
No. It covers the network layer well and nothing else. It does not touch account-level tracking, browser fingerprinting, or what you voluntarily give to services.
Are free VPNs safe?
Running a global server network costs money. If you are not paying, the business model is usually your data or your bandwidth. Some free tiers from paid providers are genuinely fine; standalone free VPNs generally are not.
Does incognito mode protect privacy?
It stops your browser saving local history. Your ISP, your employer and the sites you visit see everything they saw before. It is a shared-computer feature, not a privacy feature.
Should I use Tor instead?
If your adversary is a state or a well-resourced organisation, yes — Tor is designed for that and a VPN is not. For advertisers and network operators, a VPN is faster and sufficient. They solve different problems.
How often should I redo this?
Check permissions and account history settings twice a year. The four core items are one-time changes that keep working.

Privacy is a set of small decisions

LunoVPN covers the network layer: encrypted DNS, no email at signup, a published no-logs audit and open-source clients. The rest of the list is yours — and we would rather you did it than bought a subscription instead of it.