You have a tab open for a VPN, or a paid service that scrubs your name off the data broker sites, or maybe a privacy-focused phone. Before you enter a card number, give me one unhurried hour.
A digital privacy cleanup is the set of free changes that removes the risks that actually get people hurt: reused passwords, a weakly protected email account, forgotten logins sitting in old databases, and personal details anyone can pull up in a search. None of it costs money. Most of it is dull. All of it matters more than the thing in your cart.
There is a second reason to go in this order. Once your accounts are sorted, you can see which gaps are left, and that tells you what is worth paying for. Buy the tool now and you are guessing. Buy it after and you are solving a problem you can name.
This is not about becoming anonymous or going off-grid. It is maintenance, and if you have never done it, an hour goes a long way. If you have never worked out why the effort is worth it at all, why privacy matters even if you have nothing to hide is worth reading first.
What this digital privacy cleanup does and doesn’t do
Precision matters here, because “private” on its own does not mean anything. Private from a stranger who has your email address is a different claim from private from your internet provider, which is different again from private from a government with a subpoena. This cleanup handles the first kind.
What it protects against:
- Credential stuffing: someone takes a password leaked from one breached site and tries it on your email, your bank, and your shopping accounts. Reused passwords make this easy.
- Email account takeover: your inbox resets everything else, so a weak password or no second factor there is the whole game.
- Fraud through stale accounts: an old account you forgot about still holds your card, your address, and a password from 2015.
- Low-effort exposure: someone types your name into a people-search site and gets your address, phone, relatives, and past cities in seconds.
What it does not do: it will not make you anonymous, it will not stop someone who is specifically targeting you with real resources, and it will not permanently remove you from data brokers, because they re-list. It is also not a substitute for working out who you are actually protecting yourself from, which is what tells you how far past this baseline to go.
Two rules before you touch anything
Rule one: work in order, because email is the master key. Almost every account you own will email a reset link to your inbox if someone asks it to. So the order is not arbitrary. Fix your primary email first, then your password manager, then the account with your phone company (that one is how SIM-swap attacks start), then anything financial, then accounts that store a card, then everything else. Secure your email last and you have spent an hour hardening accounts that a single inbox breach would unlock anyway.
Warning: do not lock yourself out. This is the part people skip and regret. Change one thing at a time and confirm you can still log in before moving to the next. When a site shows you backup codes for two-factor authentication, write them down on paper before you click past that screen. Keep your old email address working until every account that used it points somewhere else. Set aside a real block of time so you are not doing this in a rush. If you have locked yourself out of an account before, go slower than feels necessary.
Phase 1: Inventory your accounts and delete the dead ones
You cannot secure a list of accounts you do not have. Build the list first.
Find every account
Four places to look:
- Your email. Search your inbox for “welcome”, “verify your email”, and “confirm your account”. Years of signups will come back.
- Your browser and password manager. Both keep a list of saved logins. Scroll through it or export it.
- The “Sign in with Google”, “Sign in with Apple”, and “Sign in with Facebook” screens inside each of those accounts. They list every third-party service you connected.
- Have I Been Pwned (haveibeenpwned.com). Enter each email address you use and it shows which breaches included it, which doubles as a reminder of sites you forgot you joined.
Expect the list to be longer than you think. More than a hundred accounts is common for anyone who has been online for a decade.
Delete what you don’t use
Go down the list. For anything you have not used in a year and can picture never using again, delete the account rather than just logging out. Most services bury the option in settings or a privacy page, labeled “delete account” or “close account”, and most make you confirm by email. Deletion is often not instant, and some data can sit in the service’s backups for a while afterward. If there is anything in the account you want, export it first.
Some sites make deletion deliberately hard. A directory like justdeleteme.xyz rates services easy, medium, hard, or impossible and links straight to the right page for a few hundred of them. For accounts you cannot delete, do the next best thing: change the name to junk, wipe the address and phone number, remove any saved payment method, and switch the account email to an alias.
Phase 2: Lock down the keystone accounts
These are the accounts that protect other accounts. Spend most of your hour here.
Passwords, in keystone order
If you do nothing else in this whole list, do this. Open Have I Been Pwned again and note which of your passwords have shown up in a breach. Then get a password manager, so you only have to remember one strong password instead of fifty. Bitwarden has a free tier that stores unlimited passwords and works on your phone and computer, and KeePassXC is free with no account at all, keeping the database as a local file you sync yourself. The tradeoff: a hosted manager syncs everywhere on its own, local means you handle the syncing.
Now change passwords, starting with your email, then the password manager account itself, then financial accounts, then anything with a stored card. Every password unique, every one long. You will not remember them, and that is the point.
Two-factor, app not text
Turn on two-factor authentication for the same accounts in the same order. When you get to choose the method, pick a passkey or an authenticator app over text-message codes. Text codes can be stolen with a SIM swap, where someone talks your carrier into moving your number to their SIM, and then your second factor is arriving on their phone. Text is still better than nothing, so treat it as the fallback, not the default. The US standards body NIST, in its 2025 identity guidelines, classifies SMS codes as a restricted method for this reason. Save the backup codes each site gives you somewhere offline.
Your primary email specifically
Your inbox deserves its own pass. Open the settings and check the forwarding rules and filters. A common move after an account is broken into is to add a quiet rule that forwards a copy of everything, or one that auto-deletes password-reset emails so you never notice. Delete anything you did not create. Then find the list of connected apps and third-party services with access to the account, and revoke everything you do not recognize or no longer use. Last, confirm the recovery email and recovery phone number on the account are still yours and still reachable.
Phase 3: Cut off the side doors
Revoke connected apps and extensions
Every major account (Google, Apple, Microsoft, Facebook, GitHub, X) has a page listing the apps and websites you have granted access to. Some of those grants are years old, from a quiz or a photo site you used once. Each one is a way into your data that does not go through your password. Open each list and remove everything you are not actively using.
Do the same for browser extensions. An extension can usually read everything on every page you visit, which is a lot of trust to place in a tool you installed to convert PDFs. Remove the ones you do not use every week.
Clean your phone and browser
On your phone, delete apps you have not opened in months. For the ones you keep, go through their permissions and turn off anything they do not need to function: location, contacts, microphone, camera, photo library. A flashlight app does not need your location.
In your browser, install uBlock Origin, a free content blocker that stops most trackers and ads. Set the browser to block third-party cookies. If you moved your passwords into a manager, clear the ones still saved in the browser itself.
Phase 4: Claw back what’s already public
This phase has the worst effort-to-result ratio of the whole cleanup, and it is still worth doing. Set your expectations low and keep going.
Remove personal info from search results
Google has a tool called “Results about you” that scans Google Search for pages showing your phone number, home address, or email, and lets you request their removal from results. As of early 2026 it also covers government ID numbers. Know the limit: it removes the result from Google Search only. The page still exists, it still shows up on other search engines, and the data broker behind it still has your file.
Data brokers and a self-search
You can opt out of the big people-search sites yourself, for free. The catch is that you do it one broker at a time, each has its own process, the removals expire, and they re-list you when they refresh their data. Budget an evening, start with the largest ones, and put a reminder in your calendar to check again in six months.
While you are there, search your own name a few ways: with your city, with your employer, with old usernames you used to post under. Tighten the public fields on your social accounts, especially birthday, phone number, hometown, and employer. If there is an old resume or a dead blog with your home address on it, take it down.
Phase 5: Free financial locks (US)
If you are in the United States, freeze your credit. It is free by federal law, it stops someone opening a loan or card in your name because lenders cannot pull a frozen report, and you can lift it for a few days whenever you actually need credit. You have to do it separately at all three bureaus: Equifax, TransUnion, and Experian. Each has to place the freeze within one business day of an online or phone request.
Outside the US, look up your country’s equivalent. Many have a credit-notification or protective-registration scheme.
Separately, log into the shops and services where you have saved a card “for convenience” and remove the ones you rarely use. A card that is not stored cannot leak from that vendor.
Confirm it worked, then keep it that way
Spend five minutes checking the work. Run your email addresses through Have I Been Pwned again so you know your current exposure. Log out of a keystone account and back in, and confirm it actually asks for the second factor. Look at the connected-apps list again and make sure it is short. Try to get into two or three accounts you touched, to be sure you did not lock yourself out. Over the next few weeks, search your name again and watch the people-search results thin out, slowly.
Then put it on a schedule. Once a quarter, spend half an hour: skim for new accounts you created and stopped using, redo the data broker opt-outs that have lapsed, and glance through the app permissions on your phone. The cleanup is not a one-time event, because you keep making new accounts and the brokers keep re-listing you. A small recurring pass beats a big cleanup you do once and never repeat.
Now decide what’s worth paying for
With the free work done, look at what is left. Maybe the data broker opt-outs are too much to keep up with by hand, and a paid removal service earns its fee. Maybe you want your search and email off a company that sells ads, so a private email provider makes sense. Maybe you use hotel and airport wifi a lot, and a VPN is worth it for that specific reason. Those are now real decisions with a visible gap behind them, not a purchase you made because a review site told you to be afraid. The cleanup protects your accounts, and it also turns “I should probably buy something” into a question you can answer.