Here's an uncomfortable truth: the technology you use every day is configured, by default, to collect and share as much information about you as legally permissible. Your phone, your web browser, your smart speaker, your car — they're all quietly broadcasting data about your location, habits, purchases, and preferences. And while younger generations have grown up with this tradeoff, many adults over 40 are only now realizing just how much they've been giving away.
The good news: you can fix most of this in under 30 minutes, with no technical expertise required. These seven settings changes won't make you invisible online — nothing short of going completely offline can do that — but they'll dramatically reduce the amount of data that companies, advertisers, and data brokers can collect about you. We consulted privacy researchers and security professionals to build this checklist, ranked from highest urgency to lowest.
1. Turn Off Ad Tracking on Your Phone (iPhone and Android)
This is the single highest-impact change you can make. Both Apple and Google assign your phone a unique advertising identifier — essentially a tracking number that follows you across every app, every website, and every purchase you make from your device. Turning it off doesn't eliminate tracking entirely, but it sends a "do not track" signal that legally obligates apps to stop using your identifier for targeted advertising.
On iPhone: Settings → Privacy & Security → Tracking → toggle off "Allow Apps to Request to Track." Then go to Apple Advertising (near the bottom of the Privacy page) and toggle off "Personalized Ads." On Android: Settings → Security & Privacy → Privacy → Ads → "Delete advertising ID" and toggle off personalized ads. Total time: 90 seconds.
2. Audit Your Google Account's Data Collection
If you use Gmail, Google Maps, YouTube, or Google Search, Google has built an astonishingly detailed profile of you — your location history going back years, every search you've ever made, every YouTube video you've watched. The company uses this data to target ads, but it's also vulnerable to data breaches and government requests.
Go to myactivity.google.com while logged into your Google account. You'll likely be surprised by what's there. Under "Web & App Activity," "Location History," and "YouTube History," you can pause collection and auto-delete existing data older than three months, 18 months, or 36 months. The "auto-delete after 3 months" option retains enough data for Google services to work well while dramatically limiting your exposure. Total time: 5 minutes.
"Most people have no idea their Google account has been saving their precise GPS location, including timestamps, for years. It's not malicious on Google's part — it's just the default. But the default isn't in your interest." — Bruce Schneier, security technologist and Harvard Kennedy School lecturer
3. Switch Your Browser's Default Search Engine
Google's search engine is excellent. It's also the world's largest data collection operation. Switching to a privacy-respecting alternative doesn't mean sacrificing quality: DuckDuckGo delivers Google-quality results for most queries without tracking your searches or building a profile on you. Brave Search is another strong option that operates its own independent index. Both are free and take 30 seconds to set as your default. In Chrome, go to Settings → Search Engine → Manage Search Engines. In Safari, Settings → Search → Search Engine. Total time: 30 seconds.
4. Disable Smart Speaker Recording Storage
If you have an Amazon Alexa or Google Nest device, it has been recording and storing your voice commands — and occasionally things you didn't intend as commands — for years. Both companies have been caught using these recordings for quality assurance and, in some cases, sharing them with third-party contractors for transcription.
For Alexa: Open the Alexa app → More → Settings → Alexa Privacy → Manage Your Alexa Data → toggle off "Use of Voice Recordings" and enable "Automatically delete recordings" after 3 months. For Google Nest: Open the Google Home app → Settings → Privacy → turn off "Include voice and audio recordings." Total time: 3 minutes.
5. Use a Password Manager — and Turn On Two-Factor Authentication
If you're still reusing passwords across sites, you're playing with fire. Data breaches have made billions of username-password combinations publicly available, and credential-stuffing attacks — where hackers try leaked passwords on other services — are automated, relentless, and often successful. A password manager (Bitwarden is free and excellent; 1Password is $3/month and slightly more polished) generates and stores unique, strong passwords for every account. Pair it with two-factor authentication (2FA) — ideally using an authenticator app like Authy or Google Authenticator rather than SMS codes, which can be intercepted — and you've eliminated the two most common ways accounts get compromised. Total time: 15 minutes to set up; ongoing time is near-zero.
6. Lock Down Your Social Media Profiles
Data brokers scrape public social media profiles for personal information — your full name, location, employer, family members, interests — and package it into profiles they sell to advertisers, insurers, and sometimes employers conducting background checks. On Facebook, Instagram, and LinkedIn, set your default post visibility to "Friends only" or "Connections only" rather than "Public." On Facebook especially, go to Settings → Privacy Checkup and walk through the guided review. It takes five minutes and covers settings most people haven't touched since creating their accounts a decade ago. Total time: 5 minutes per platform.
7. Opt Out of Data Broker Sites
This is the most tedious step, but also one of the most impactful. Companies like Spokeo, Whitepages, BeenVerified, and Intelius compile and sell detailed personal profiles — your address history, phone numbers, relatives, property records, and sometimes even court records. Most are legally required to offer an opt-out mechanism, but finding it is intentionally difficult.
Services like DeleteMe (starting at $10/month) or Optery automate this process, submitting opt-out requests to hundreds of data brokers on your behalf and re-checking periodically to ensure your information stays removed. If you'd rather do it yourself, the Privacy Rights Clearinghouse maintains a free opt-out guide at privacyrights.org. The DIY approach works but typically takes 2–3 hours initially and requires quarterly follow-ups. Total time: 2–3 hours (DIY) or 10 minutes to sign up for a removal service.
The bottom line: None of these steps individually is a silver bullet. But collectively, they create a privacy posture that's dramatically stronger than the average American's — and than the default settings tech companies design to maximize data collection. The first six steps take under 30 minutes total. The seventh is ongoing. Start with number one and work your way down. Your future self — the one whose data isn't floating around dozens of broker databases — will thank you.