A personal privacy checklist: decide in advance
A practical privacy baseline for people whose work, money, and personal life all run through the same devices.
Most personal privacy checklists begin with someone targeting you personally. Most privacy failures do not. They begin with a small default that stays in place for years: the app that has access to your contacts, the old account that still has a password you reused once, the laptop full of work files with no recovery plan.
That is why I think of privacy less as a feature you switch on and more as a few decisions you make before you need them.
The useful goal is not to disappear from the internet. Most of us want the convenience of online banking, shared calendars, maps, cloud storage, and software that works across devices. The goal is to decide what information each service actually needs, protect the accounts and devices that hold the most sensitive material, and make a breach or lost laptop less likely to become a full-blown mess.
Start with the things that unlock everything else
Your email account is usually the master key. It receives password resets, invoices, travel confirmations, tax documents, and every "new sign-in" alert that matters. A compromised email inbox is often more serious than a compromised social account because it gives someone a route into the rest of your life.
Use a unique password for it, turn on multi-factor authentication, and keep the recovery method somewhere you can access if you lose your phone. CISA's basic guidance is still the right starting point: use strong passwords, enable MFA, recognize phishing, and update software.
A password manager makes this much easier than trying to remember clever variations. Its job is not to make passwords memorable. Its job is to make them different.
I would also put banking, the Apple or Google account tied to your devices, your domain registrar, and any work account with access to customer data in this category. These are the accounts worth checking first when you have half an hour to improve your setup.
Make a small permission audit part of setup
Every new app asks for something. Notifications are usually harmless enough. Access to your microphone, camera, location, files, contacts, photos, or accessibility controls deserves a reason.
On a Mac, you can review these controls in Privacy & Security settings. Apple documents the permission categories, FileVault disk encryption, and the higher-risk Lockdown Mode option in its Mac security guide. Most people do not need Lockdown Mode. Most people do benefit from checking which apps can see their screen, read files in important folders, or use the microphone.
The practical rule is simple: if you cannot explain why an app needs a permission, do not grant it yet. You can always add it later when a feature actually requires it.
This matters more as AI tools become normal parts of work. A transcription app, browser extension, meeting bot, or assistant can be useful while still receiving far more context than it needs. Before connecting one to email, a drive, a calendar, or a code repository, check what it can read, whether it keeps that data, and how to revoke access later. I wrote about the value of giving AI systems durable context in my piece on agent memory. That same principle has a privacy side: useful context should be intentional, scoped, and easy to remove. It is one small way to stop living in reactive mode.
Secure the device that holds the evidence
A good account setup can still be undone by an unlocked or unencrypted laptop.
Use a real login password. Turn on automatic updates. Encrypt the drive. Keep a current backup. Those are boring measures, which is exactly why they work. They reduce the damage from a stolen device, a failed drive, or malware that arrives through a convincing attachment.
For Mac users, FileVault encrypts the startup disk, and Apple explains how the recovery process works in its FileVault documentation. The recovery key is important enough to store somewhere deliberate. Losing both the account credentials and recovery options can turn security into a lockout.
Security software can be another layer, especially if you download files from many sources, share machines with other people, or work on public Wi-Fi. Moonlock says its Mac product includes real-time malware scanning, a scanner for suspicious files, a VPN, and tools that review Mac security settings. Those are product claims from Moonlock, not an independent test or a guarantee that a Mac cannot be compromised. Compare the product with the protections you already use and decide whether the extra layer fits your risk and habits.
The order matters. No security app can fix a reused password, a fake login page you hand your credentials to, or a recovery key that is gone forever.
Reduce what you give away by default
Privacy is often presented as a giant philosophical question. In practice, it shows up in small forms:
- use an email alias when a store does not need your primary address;
- deny location access to apps that work without it;
- remove old browser extensions and connected apps;
- review who can see shared folders, calendars, and photo libraries;
- turn off data sharing you do not use;
- delete accounts that you no longer need.
There is a trade-off in every one of these choices. Location history can make maps more useful. Cloud storage makes collaboration easier. A calendar connection can save an hour a week. The question is whether the benefit is worth the access, and whether you would notice if that access kept expanding over time.
This is similar to building a work system. The tools that help are the tools you can explain. I have found that good systems look excessive until they fail, but the point is not to turn your personal setup into a security hobby. It is to make the safer option the default before you are rushed, tired, or reacting to an alert.
A reasonable baseline
If you have not looked at this in a while, do these five things this week:
- Secure your primary email account with a unique password and MFA.
- Turn on automatic updates and disk encryption on your computer.
- Confirm that you have a backup and that you know how to restore it.
- Remove one old app, browser extension, or connected service that no longer needs access.
- Review camera, microphone, location, file, and screen-recording permissions on your main devices.
That will not make you anonymous, and it will not make a device invincible. It will make it harder for one weak default to expose everything connected to it.
The best privacy setup is usually the one you can maintain. Start there.
