You have about 168 online accounts. You probably remember a dozen. The rest are still out there, holding your email, your old address, maybe a credit card.

Ninety-four percent of leaked passwords are reused. That's not a typo. Cybernews analyzed 19 billion passwords from breaches in 2024-2025 and found only 6% were unique.

A full privacy overhaul takes a weekend. But the version that actually matters takes 30 minutes. Here's what to do.

Step 1: Set Google to auto-delete (3 minutes)

Go to myactivity.google.com. Turn on auto-delete for Web & App Activity. Set it to 3 months.

If your account is older than 2020, Google keeps your search history forever by default. Google only changed the default for new accounts. Yours probably still stores everything.

This one setting clears years of accumulated search data -- health questions, financial worries, late-night parenting spirals -- every 90 days instead of never.

Step 2: Get a password manager and turn on 2FA (10 minutes)

Pick one. 1Password, Bitwarden, whatever. Install it and change the passwords on your three most important accounts: email, bank, and whatever cloud storage holds your family photos.

Then turn on two-factor authentication on those same three accounts. Use an authenticator app, not text messages. CISA recommends moving away from SMS-based verification because it's too easy to intercept.

If you have a newer phone, set up passkeys. Five billion are already in use worldwide. They're faster than passwords and can't be phished.

Step 3: Audit your phone permissions (10 minutes)

On iPhone: Settings → Privacy & Security. On Android: Settings → Privacy → Permission Manager.

Set location to "While Using" for everything except maps and ride-sharing. Revoke camera and microphone access from apps that don't record anything. Check which apps have access to your contacts -- many upload your entire address book for "friend finding."

Ten minutes here and you'll probably revoke a dozen permissions you never meant to grant.

Step 4: Lock down family-specific apps (5 minutes)

Location sharing. If you use Life360, know that The Markup found it selling precise family location data to about a dozen data brokers in 2021. A class-action suit followed. Consider switching to Apple Find My or Google Family Link, which have tighter data practices.

School apps. A 2022 study tested 1,357 school apps and found 96% share children's personal data with third parties. Seventy-eight percent share it with advertisers. You can't control this, but you can ask your district which apps they use and whether opt-outs exist.

Baby monitors. Change the default password. Put the monitor on your guest Wi-Fi network. Keep the firmware updated. Security researchers have repeatedly found Wi-Fi monitors hackable through weak default passwords.

Kids' gaming. Set Roblox and Minecraft accounts to the strictest privacy settings. Turn on 2FA. Limit or disable chat for young kids.

Step 5: Set up a digital legacy (2 minutes)

If something happens to you, can your partner access your email, bank accounts, and insurance?

Google has an "Inactive Account Manager" -- you can name up to 10 people who get access to your data after a period of inactivity. Apple has a Legacy Contact. Most password managers have an emergency access feature.

Set up one of these today. It takes two minutes and it matters more than any of the steps above.

One more thing

While you're auditing which apps have your data, check your AI tools too.

Most AI chatbots store your conversations permanently and use them to train their models. Every question you've asked about your health, your finances, your kids -- it's in a database somewhere.

Ask Safely is different. It auto-deletes your conversations in 8 hours. No training on your data. No ads. No history. Add "switch to a private AI" to your cleanup checklist.

Try it free →