Key Takeaways
- Most privacy risks come from weak passwords, unused app permissions, and default settings left unchanged.
- A focused 30-to-60-minute session is enough to cover passwords, devices, browsers, and social accounts.
- Removing access you no longer need is as important as setting strong passwords in the first place.
- Browser behavior and installed extensions can expose more data than most people realize.
- Running this audit once or twice a year keeps your exposure from quietly growing over time.
Summary
22 items · 30 to 60 minutes
Why a privacy audit matters
Privacy exposure rarely happens all at once. It accumulates: an old app still connected to your Google account, a social media profile set to public years ago, a browser extension that reads everything you type. Each gap is small on its own, but together they form a much larger surface area than most people intend to have.
This checklist treats your digital footprint as something you can actually manage. You do not need technical expertise. You need about an hour, your devices in front of you, and a methodical approach. Work through each section in order, or jump to the areas where you know you have been less careful.
For a deeper look at how websites track you beyond what you can see, the guide to cookies, trackers, and fingerprinting explains the techniques involved and what each one means for your data.
What you will need before you start
Gather the following before you begin so you are not switching contexts mid-audit. Having everything ready also prevents the temptation to skip sections.
Password manager
Stores, generates, and audits your passwords so you can check for weak or reused credentials in one place.
Your primary smartphone
Needed to review installed apps, revoke permissions, and check location and notification settings.
Your primary computer or laptop
Needed to audit browser extensions, saved passwords, and account settings on desktop.
Email account access
Required to check connected third-party apps and review which services have access via your email login.
Authenticator app
Used to set up or verify two-factor authentication on accounts that support it.
The full privacy audit checklist
Work through these groups in order. Check off each item as you complete it. Some items take thirty seconds; others, like reviewing app permissions across your phone, may take ten minutes. The time estimate above accounts for both.
Passwords and account access
App permissions and connected services
Browser and extensions
Social media and public profiles
Device-level settings
For the app permissions section in particular, the practical guide to managing app permissions explains the difference between permissions that are genuinely necessary and those that are not, for both Android and iOS.
Settings most people skip
Default settings on phones, browsers, and social platforms are almost never set in the user's favor. Ad tracking is typically on. Location history is often enabled. Personalization features that collect behavioral data are active unless you turn them off.
Two areas deserve special attention. First, browser extensions: many request access to read and modify all data on every site you visit, which is far broader than their stated function requires. The overview of browser extension permissions explains what those access levels actually mean. Second, social media visibility: profile information set to public is indexed by search engines, which means it persists long after you forget you shared it.
Public profile data is indexed by search engines
Information set to public on social platforms can be crawled and cached by search engines, meaning it may remain findable long after you change the setting on the platform itself. If you find sensitive details in search results, use the platform's data removal tools and, where available, submit a removal request directly to the search engine. Do not assume that changing a setting removes data that has already been indexed.
The guide to overlooked privacy settings covers the specific toggles worth changing on the most common platforms and browsers, with step-by-step instructions for each.
Keeping the audit current
A single audit does not stay valid indefinitely. Apps update their permission requests. Services change their data-sharing terms. You install new software and forget about it. Running through this checklist once every six months is enough for most people to stay on top of these changes without it becoming a burden.
If you also want to apply the same methodical thinking to your financial protections, the household insurance coverage audit uses a similar format to review policies for gaps and overlap.
