Social Media Privacy Settings: A Practical 20-Minute Checklist
Privacy settings cannot make a social account risk-free. They can reduce unnecessary exposure, limit who can contact or tag you, and make account takeover harder. The highest-value review is short and repeatable: secure the account, reduce default visibility, inspect connected access, and remove data you no longer need.
Menu names change, so this guide describes decisions rather than one platform’s current button labels. Use the provider’s official help centre for the exact path.
Minute 0–3: Secure Sign-In
- Use a unique password stored in a password manager, or a passkey where supported.
- Turn on multi-factor authentication. Prefer a passkey, security key, or authenticator app over SMS when the service offers the choice.
- Save recovery codes somewhere separate from the signed-in device.
- Confirm recovery email and phone, then remove old ones.
- Review active sessions and sign out devices you do not recognise.
The US Cybersecurity and Infrastructure Security Agency explains password managers, strong authentication, and phishing in its Secure Our World resources. Security protects control of the account; privacy controls what a legitimate session may reveal.
Minute 3–6: Set the Audience
Review the default audience for new posts, stories, activity status, friends or followers, and profile fields. “Public” means content can travel outside the original platform through search, screenshots, embeds, archives, and data brokers.
Use the narrowest audience that fits the purpose. A public professional profile may need a role and portfolio while keeping personal contacts, birthday, family links, and live activity private. Check old posts separately; changing the default may not change history.
Preview the profile as a stranger if the platform supports it. Search for your name while logged out. The result often reveals forgotten bios, old usernames, comments, and tagged media.
Minute 6–9: Contact, Tags, and Discovery
Choose who can:
- send direct messages or requests;
- find you by phone number or email;
- tag or mention you;
- add posts to your profile;
- invite you to groups, events, or calls;
- see online or read status;
- download or remix your content.
Enable tag review before tagged content appears. Limit message requests if the account receives abuse or mass outreach. Hiding read status is a boundary choice, not dishonesty.
If an app offers contact syncing, ask whether the core feature works without uploading an address book. Disable continuous syncing if it is unnecessary, and use the provider’s deletion control for contacts already uploaded.
Minute 9–12: Location, Camera, and Microphone
At the operating-system level, review permissions for location, precise location, photos, camera, microphone, Bluetooth, and local network. Choose “while using” or one-time access where sufficient. Remove permission from features you no longer use.
A photo can reveal location through visible landmarks, routines, or embedded metadata. Some platforms strip metadata on upload; do not assume every destination does. Share after leaving a sensitive location rather than broadcasting a routine.
Use the fuller location-sharing privacy guide for live sharing, maps, check-ins, and emergency access.
Minute 12–15: Apps, Advertisers, and Data Sharing
Review connected apps, “log in with” grants, browser extensions, games, quizzes, and automation tools. Revoke anything unused. A third-party token can retain access even after you stop opening the app.
Inspect advertising and personalization controls. Turning off personalized ads may reduce use for targeting without eliminating all collection or ads. Read what the control actually promises.
Apple notes that App Store privacy labels are supplied by developers in its privacy-label overview. Google Play similarly requires a Data safety disclosure. These summaries help comparison, but the provider’s policy, permissions, and actual product behavior still matter.
Minute 15–17: Safety Controls
Locate block, mute, restrict, report, comment filters, and hidden-word settings before you need them. Blocking should not require a confrontation. Save evidence before reporting only when it is safe and necessary; do not keep harmful content indefinitely by default.
For impersonation, document the profile URL and report through the platform’s identity path. A generic “verified” badge is not a safety guarantee; read what identity verification proves.
If a threat may be immediate, use local emergency or specialist resources rather than relying only on an in-app report queue.
Minute 17–20: Retention and Recovery
Download an account export so you know what categories exist. Delete old posts, drafts, searches, location history, or messages that no longer serve a purpose, while understanding that recipients may retain their copies.
Check deactivation versus deletion, the cancellation window, backup-retention language, and what remains for fraud or legal obligations. Set a calendar reminder to repeat this review after major product changes or every few months.
Create a recovery note for a trusted person if the account has business or safety importance. Do not share the password; use official legacy, delegate, or emergency-access tools where available.
Threat-Based Defaults
A creator, job seeker, activist, teenager, executive, and abuse survivor need different settings. Start with the harm that matters:
- Unwanted discovery: restrict email/phone lookup and contact syncing.
- Harassment: narrow messaging, enable filters, and prepare report/block controls.
- Account takeover: strengthen sign-in, recovery, and session review.
- Location exposure: remove precise/background access and delayed-post routines.
- Professional boundary: separate public work facts from personal network and activity.
- Data accumulation: revoke apps and delete stale content on a schedule.
For dating products, combine settings with the broader controls in Private Dating Apps: What “Private” Should Mean.
Final Check
After saving, open the profile from a logged-out browser or a test account. Confirm that the visible result matches your intention. Privacy settings are only useful when the observed surface agrees with the label.
Twenty minutes will not erase every copy or prevent every misuse. It can remove avoidable exposure and establish a review habit. That is a concrete improvement you can repeat.