Guides

Part of Privacy settings: rules, examples and updates for 2027

Best privacy settings tools 2027: practical details

Privacy checkup tools do one of three jobs: reveal, change, or monitor. Start with the free ones inside your accounts, and know what none of them reach.

A privacy tool does one of three jobs. It shows you something, it changes something, or it watches for something. Almost every disappointment in this area comes from buying the third job while skipping the first two, which are free and which you already have.

What to take away

  • The strongest tools are the ones already inside your accounts, and they cost nothing but an afternoon.
  • A tool that only reports is not protection. Ask what a finding lets you actually do next.
  • Anything sold to you off the back of an alarming email deserves more suspicion than the alarm did.

The three jobs

Reveal. Shows you what is currently true: what a service holds about you, who can see your profile, which apps have permission, where you are signed in. Revealing tools are the ones worth starting with, because you cannot fix an exposure you have not seen and most people are wrong about their own settings.

Change. Actually alters something: closes a permission, restricts an audience, deletes a history, ends a session. The useful ones are built into the service, because only the service can change its own settings.

Monitor. Tells you when something happens later: a new sign-in, a password appearing in a breach corpus, your name showing up somewhere new. Monitoring is genuinely useful and it is also where the sales pressure lives, because a subscription needs a recurring reason to exist.

A good pass through your accounts uses all three in that order. Reveal, then change, then set up monitoring for the parts you cannot control. The regulator's own account of what services collect, which is what the first job is revealing, is the FTC's material on how websites and apps use your information.

The inside of a combination lock, showing brass wheels and levers laid open on a dark surface
Photo: Combination lock insides, Wikimedia Commons, CC BY-SA 3.0.

The tools you already own

Every large service has built some version of these, under names that change every couple of years. Look for the function rather than the label.

  • A data export or archive download. The single most persuasive thing you can do. Reading what one service actually holds about you changes how you use all the others, and it shows you exactly what a breach of that service would expose.
  • An activity or history view. Search history, watch history, location history, and the record of what you have interacted with. Usually paired with a control to delete some of it and to stop collecting more.
  • A permissions or connected-apps list. Everything holding access that does not go through your password.
  • A sign-in and device list. Where your account is currently open, and on what.
  • A public preview. A way to see your own profile as a stranger sees it. Where a service does not offer one, a private browser window signed out of everything does the same job.
  • The ad or interest profile. The categories a service has assigned you. Worth reading once for the shock value, and usually editable.
  • A compromised-password report. Most password managers and browsers will tell you which of your saved passwords are reused, weak, or known to have appeared in a breach. This is the highest value per minute of anything in this list.

None of these are advertised, and none of them are on the first screen. They are usually filed under an account, privacy, or security area, sometimes split across two of them.

Reading the result honestly

Tools report what they can see, which is not the same as what exists.

A breach monitor tells you about corpora it has access to. Silence is not evidence that nothing has leaked. A profile preview shows what the platform shows a signed-out stranger, not what someone with a logged-in account, a mutual contact, or a saved copy from three years ago can see. A permission list shows current grants, not what an app took while it had access.

So treat every green result as "nothing found here", never as "nothing exists". The useful output of a checkup is a short list of things to change, not reassurance.

What no tool reaches

Three categories sit permanently outside all of this, and knowing that saves you money.

Copies already taken by other people are gone from your control the moment they were made. Content other people published about you belongs to their account and their settings, and the fix there is a conversation, not a dashboard. And information you gave to a company that has since been acquired, merged, or wound up now sits with whoever holds the assets, under whatever policy they arrived with.

This is the argument for the point made on privacy settings: the layer that lasts is what you decided not to publish. Tooling manages the rest.

Paying for someone to remove things

There is a real category here: services that submit removal requests on your behalf to sites that compile personal records. There is also a large category of businesses that send you an alarming message about your exposure and then sell you the fix.

Some honest questions before paying anyone:

  • Did you go looking for this service, or did it arrive in a message that frightened you first? The second is the shape of a scam even when the company is real.
  • Can you see exactly which sites it covers, and does the list refresh as new ones appear?
  • What happens when you stop paying? Records that were removed frequently return, which is what makes the subscription work.
  • What personal data does it need from you to do the job, and are you comfortable that a new company now holds a consolidated file on you?

Most of these sites publish their own removal process. It is slow and tedious and it is free, and doing three of them yourself tells you quickly whether paying for the rest is worth it to you. What that industry is and how it assembles its records is described in the Wikipedia article on data brokers.

Making the pass repeatable

A checkup is only useful if it happens again. Keep a plain text note with one line per account: what you changed, what you could not find, and the date. Next time the pass takes twenty minutes instead of an afternoon, and you can see what has drifted.

Run the account-by-account version in the social media privacy audit, do the device layer when you move to a new phone, and if you publish for a living the trade-offs are different and are covered in creator privacy settings.

Common questions

Which checkup should I do first?

The password report in your browser or password manager, then the email account behind everything else. Those two produce more risk reduction per minute than everything else combined, for reasons set out in account security.

Is a free tool worse than a paid one?

Not in this category. The most effective tools here are built into the services themselves and cost nothing, because they are the only things that can actually change a setting. Paid tools mostly do monitoring and paperwork.

A service says my data was found in a breach. What now?

Change that password everywhere you used it, starting with anything financial and your email. Do not use links in the notification to get to those accounts. The finding itself is usually old news; the reuse is the live problem.

Can I check what a stranger sees without making an account?

Yes. Open a private browser window, sign out of everything, and search your own name and your usual handle. That is closer to the real answer than most built-in previews, and it costs nothing.

More in Guides

Guides

Privacy settings: rules, examples and updates for 2027

Privacy settings control reach, not consequences: three layers of exposure, the audiences you are really setting for, and what to do once something is out.

Maintenance

Privacy settings rules 2027: practical details

Creator privacy settings for people who have to be findable: the publishable set, the boundaries around other people, and the account rules behind them.

Rules

Privacy settings checklist: facts, examples and context

A new phone privacy checklist in three passes: what to settle before the switch, which permissions to grant during setup, and how to retire the old device.

Rules

Privacy settings changes 2027: practical details

Privacy settings change under you: what a redesign does to your configuration, how to read a consent prompt, and the two minute test that checks the result.