Reviews
Part of Privacy settings: rules, examples and updates for 2027
Privacy settings guide explained for 2027
A social media privacy audit in eight passes: who sees your posts, who can find you, who can reach you, and what your account has accumulated.
Menus move, labels get renamed, and settings pages are reorganized every year. What does not change is the small set of things you are actually deciding. This audit is written around those decisions, so it still works when the buttons are somewhere else.
Set aside about an hour, do one account at a time, and use a computer if you can: the full settings are often only exposed there. Work through the eight groups below and note what you changed, because it makes the next pass much faster.
What to take away
- Message requests from people you do not follow.
- What does not change is the small set of things you are actually deciding.
- Set aside about an hour, do one account at a time, and use a computer if you can: the full settings are often only exposed there.
1. Who can see what you post
- Default audience for new posts. Whatever this is set to is what you will publish under when you are distracted. Set it to the narrowest option you can live with.
- Past posts. Look for the bulk control that limits everything you have already published. Years of posts made under an older, more open default are the largest single exposure on most accounts.
- Profile fields. Birthday, phone number, email, employer, school, relationship status, family links, home town. Each is separately visible and each is a building block for account recovery questions and for a convincing impersonation.
- Your photo albums, including the ones you have forgotten: profile picture history and cover photo history are often public regardless of everything else.
- Stories and short-form posts. These usually have their own audience setting that ignores your main one.
- Who can see your friend or follower list. Hide it. A visible list is the raw material for a cloned account that messages everybody you know.
2. Who can find you
- Search by phone number and by email address. These reverse lookups link the identity you use publicly to the number on your bank account. Restrict them.
- Whether search engines may link to your profile. A separate switch on most platforms.
- Contact upload and friend suggestions. Check whether the app has your address book and whether it is using it to suggest you to people. Withdraw the upload if you can; it is what surfaces you to people you deliberately do not talk to.
- Suggested-account visibility. Some platforms let you exclude yourself from being recommended to others.
- The username and handle itself. A handle you reuse everywhere ties your accounts together for anyone looking.
3. Who can reach you
- Message requests from people you do not follow. Most unwanted first contact (scams, catfishing approaches, extortion openers), arrives here. Filter or close it.
- Group and channel invitations. Restrict who can add you without asking.
- Comments and replies. Choose who may comment, and keep the keyword filter if the platform has one.
- Tags and mentions. Turn on review before a tag appears on your profile, and control who may tag you at all.
- Blocking and restricting. Learn where both live before you need them. Restricting is quieter than blocking and does not tell the other person.
- Reporting routes. Find the impersonation report, which is usually separate from ordinary abuse reporting and usually faster.
4. What is reused
- Ad topics and interest categories. Read the list the platform holds about you. It is longer and more specific than most people expect, and it can be edited.
- Off-platform activity. Data collected about you elsewhere and linked to your account, usually with a control to disconnect or clear it.
- Advertiser and partner data. Where offered, opt out of the lists uploaded by businesses you have interacted with.
- Your content used to train models. Where the platform gives a choice, make it deliberately rather than by default.
- Public content reuse. Anything public can be copied, and profile photos in particular are used to build fake accounts. This is an argument for a narrower default rather than for a warning label.
5. The history you have accumulated
- Location history. Whether it is being collected, what is stored, and how to delete what exists.
- Search and watch history inside the app.
- Old check-ins and tagged locations, especially anything that maps your home, your workplace, or a routine.
- Photo metadata. Most platforms strip location data on upload, but files you send directly (as an email attachment, a chat file, a cloud link), usually keep it.
- Your data export. Download the archive once. Reading what the platform actually holds is the most persuasive part of this whole exercise, and it shows you what would be exposed in a breach.
- Deleted content. Check the trash or recently-deleted area, which often retains items for a while after you thought they were gone.
6. Connected apps and third-party logins
- The list of connected apps. Remove everything you do not currently use. Quizzes, old games, defunct scheduling tools, and abandoned analytics services keep whatever access they were granted.
- What each remaining app can do, not just that it is connected. Read access and post-on-your-behalf access are very different things.
- Sites you signed into using this account. Convenient, and it means a compromise of this one account reaches all of them. Move the important ones to their own credentials.
7. Devices, sessions, and sign-in
- Active sessions. Sign out anything you do not recognize, and anything on a device you no longer own.
- Login alerts. Turn them on so a new sign-in tells you.
- Two-factor method. Prefer a passkey, a security key, or an authenticator app over text codes.
- Recovery email and phone. Confirm both are current and that you still control them. A stale recovery address is a permanent open door.
- Backup codes. Generate them and store them somewhere that is not the account they protect.
8. Shared and delegated access
- Page, group, and business roles. Remove people who have left, and reduce anyone who has more access than their job needs.
- Shared devices and saved logins. A family tablet with your session still signed in is an access route.
- Family and child accounts linked to yours, and what each can see or do.
- Legacy and inactive-account settings. Decide now what happens to the account if you cannot manage it, rather than leaving it for someone to work out later.
Afterwards
Two things make an audit stick. Put a reminder in the calendar to repeat it: platforms add settings and occasionally reset them, and a review after any major app redesign is worth the twenty minutes. What the platforms collect underneath all of these switches is described in the FTC's material on how websites and apps use your information, and the sign-in half of the same review is CISA's guidance on multi-factor authentication. And re-run the discovery and contact sections specifically after any incident, because those are the settings that determine whether the next unwanted approach reaches you at all.
For the underlying principles behind these choices, see privacy settings. Where the audit turns up a sign-in problem rather than a visibility one, the order to work through is account security, and the messages that arrive because you were easy to find are the subject of phishing scams.
Common questions
Does a private account make me safe?
It reduces exposure; it does not make content unrecoverable. Anyone you approve can screenshot and share. Treat privacy settings as narrowing the audience, not as a guarantee about what happens next.
Should I delete old posts or just hide them?
Bulk-limiting the audience is faster and reversible, and it handles the overwhelming majority of the risk. Delete individually where a post contains an address, a document, a ticket, a phone number, or someone else's child.
Is it worth doing this on an account I barely use?
Especially there. Dormant accounts keep old defaults, old passwords, and old connected apps, and they are the ones most often used to clone an identity. Either audit it or close it.
My friend list is how people find me. Do I have to hide it?
Hiding the list does not hide you: people can still find and follow you. It removes the ready-made contact list that makes a cloned account convincing, which is the specific harm.