SELINA.ai
Sign in

Online Privacy Tools That Actually Reduce Your Data Exposure

Most guides on online privacy tools hand you a shopping list: buy a VPN, buy a password manager, buy encrypted email, buy a data removal subscription, buy antivirus. Stack it all up. The implicit argument is that every category deserves your money and attention equally. That argument is wrong. Some of these tools matter a great deal for nearly everyone. Others matter only in specific threat models. A few are, for most people, optional. This is a guide organized around that distinction, written by someone who builds a privacy-focused product and has an obvious interest in being honest about where the real risks sit.

Key Takeaways

What Does "Threat Model" Mean, and Why Should You Start There?

Your threat model is the set of realistic risks you face given your behavior, location, and profession. A journalist working under an authoritarian government has a different threat model than a remote worker in Denver who shops on Amazon and uses Gmail. Privacy tools exist on a spectrum of effort and cost, and deploying all of them without thinking about your actual exposure is both expensive and, in some cases, counterproductive (more tools means more accounts, more attack surface, more things to maintain).

Before you read any further, ask yourself three questions. Who would benefit from having your data? Where does your data actually leak (hint: it's usually not your ISP)? And what's the realistic cost of that leak, in dollars or disruption? If you can answer those honestly, the rest of this guide becomes a lookup table rather than a sales pitch.

Do You Need a Password Manager?

Yes. This is the one category where the answer is close to universal. Only about 36% of US adults currently use a password manager, a number that has barely moved year over year. That means roughly two-thirds of American adults are reusing passwords, writing them in notebooks, or relying on browser autofill without understanding what it does.

The reason a password manager matters more than almost anything else on this list is simple math. Credential-based attacks have historically dominated breach statistics for nearly two decades. The 2026 Verizon Data Breach Investigations Report found credential abuse dropped to 13% of breaches, falling off the top spot for the first time in 19 years. That's progress, but 13% of all breaches is still an enormous number, and the decline likely reflects increased adoption of multi-factor authentication and password managers among organizations rather than a decrease in attacker interest.

The practical advice: pick a dedicated password manager. Google Password Manager leads US usage at roughly 32%, followed by Apple's iCloud Keychain at about 23%, with dedicated tools like LastPass and Bitwarden each around 10-11%. Browser-integrated managers are better than nothing. Dedicated ones (Bitwarden, 1Password, and similar) tend to offer better cross-platform support, stronger sharing controls, and more transparent security audits. Bitwarden is open-source and has a usable free tier. 1Password is not free but is well-regarded for family and team use. Pick one and actually use it. The tool you use consistently beats the theoretically superior tool sitting unused.

Should You Wait for Passkeys Instead?

No. Not yet. Consumer awareness of passkeys hit 90% in 2026, up from 75% the year before. Three-quarters of consumers have enabled passkeys on at least one account. The FIDO Alliance estimated 5 billion passkeys in use worldwide as of May 2026. Those are impressive numbers.

Here's the problem: academic web scans found only a few hundred confirmed passkey-enabled sites among top domains. Consumer readiness is outpacing actual website support by a wide margin. You might have a passkey for Google, Apple, and a handful of other large services, but the long tail of sites you use daily (your bank, your insurance portal, your kid's school system, the random SaaS tool your team relies on) probably doesn't support passkeys yet.

Passkeys are the future of authentication. They are not the present of authentication for most people's daily browsing. Use a password manager now. Enable passkeys where they're available. These are complementary actions, not competing ones.

Do You Need a VPN?

Maybe. This is the category where the honest answer diverges most sharply from what VPN companies want you to believe.

One independent review concluded that for someone who works from home, visits mainstream sites, uses HTTPS everywhere, and isn't doing anything especially sensitive, a VPN offers limited practical benefit for that specific situation. The reasoning is straightforward: HTTPS already encrypts the content of your traffic between your browser and the site you're visiting. Your ISP can see which domains you visit but not what you do on them. A VPN shifts that visibility from your ISP to the VPN provider. Whether that's an improvement depends on whether you trust your VPN provider more than your ISP.

Real use cases where a VPN provides meaningful benefit:

If none of those describe your situation, a VPN is a nice-to-have, not a necessity. Spending that money on a good password manager or enabling two-factor authentication on your critical accounts will reduce your actual risk more.

One additional note: the VPN industry itself faces regulatory pressure, with the VPN Trust Initiative expecting continued tension between encryption, lawful access demands, and proposals like the EU's "Chat Control." The political landscape around VPNs is shifting, and that's worth tracking if you depend on one.

Do You Need a Data Removal Service?

This depends on where you live and how much your time is worth.

Data brokers aggregate your name, address, phone number, email, relatives' names, estimated income, and other details scraped from public records, social media, purchase histories, and other sources. They sell this data to anyone willing to pay, including marketers, skip tracers, and people who want to find you for reasons you haven't consented to.

The core problem with data removal is that it decays. Data brokers tend to re-scrape public records roughly every 60 to 90 days. You can submit removal requests today, and your profiles will start reappearing within two to three months. This is why one-time removal requests don't stay effective and why data removal services charge annual subscriptions: they're re-submitting requests on a recurring schedule to match the brokers' re-scraping cadence.

The category is starting to mature. At least one major removal service has undergone a Deloitte Independent Limited Assurance Assessment confirming that removal requests are sent, tracked, and renewed as advertised. Others lack equivalent third-party verification. If you're evaluating services, ask whether they have independent audits, not just marketing claims about removal rates.

What About California's Free DELETE Request System?

If you're a California resident, the math has changed significantly. California's DELETE Request and Opt-out Platform (DROP) went live for consumer registration on January 1, 2026, with registered data brokers required to process those requests since August 1, 2026. Brokers must check the platform at least every 45 days.

This is the first US state-run, one-stop data-broker opt-out mechanism. It's free. It covers brokers registered with the state. It doesn't cover every broker everywhere, and enforcement will take time to shake out. But for California residents, the question of whether you need a paid removal service just became a lot harder for vendors to answer with a straight face. Register with DROP first. Then evaluate whether the incremental coverage of a paid service (which may reach brokers outside California's registry) justifies the cost for your situation.

For residents of other states, a paid service or manual opt-outs remain the primary options. Manual opt-out is free but tedious: each broker has its own removal process, and you'll need to repeat it quarterly.

What About Encrypted Email?

Encrypted email solves a real problem, but it's a narrower problem than most people think. Standard email (Gmail, Outlook, Yahoo) is encrypted in transit (TLS) and encrypted at rest on the provider's servers. What it is not: encrypted in a way that prevents the email provider from reading the contents. Services like ProtonMail and Tuta provide end-to-end encryption between users of the same service, meaning the provider cannot read the email content.

The practical limitation: encryption only works end-to-end when both sender and recipient are on the same encrypted platform, or when the recipient uses PGP (which almost nobody does outside of specific technical communities). If you send an encrypted email to someone's Gmail address, it arrives as a link to a web portal, which is better than plaintext but creates friction that most recipients won't tolerate for routine communication.

Encrypted email is worth using if you regularly exchange sensitive information with people who are also on an encrypted platform. For general-purpose email, the bigger privacy win is usually reducing the amount of sensitive information you send via email at all. Use a secure file transfer tool for documents. Use a messaging app with end-to-end encryption for conversations. Use email for what it was designed for: asynchronous, non-urgent communication that you wouldn't mind someone reading on a postcard.

Which Browser Settings Actually Matter?

Browser choice and configuration are a high-leverage, zero-cost privacy action. The specifics matter more than the brand.

Firefox with a few setting changes (Enhanced Tracking Protection set to Strict, HTTPS-Only Mode enabled) blocks most third-party trackers and downgrades or blocks unencrypted connections. Brave ships with aggressive tracker blocking by default and includes built-in ad blocking. Safari's Intelligent Tracking Prevention is decent on Apple devices. Chromium-based browsers without modifications are, from a privacy standpoint, the weakest default option because of their tight integration with advertising infrastructure.

Browser extensions worth considering: uBlock Origin (ad and tracker blocking, open-source, efficient). A cookie auto-delete extension if your browser doesn't handle this natively. Skip "privacy" extensions from companies you haven't heard of; they often collect the data they claim to block.

The single highest-impact browser privacy action is also the simplest: use separate browser profiles or containers for different activities. One profile for work, one for personal browsing, one for shopping. This prevents cross-site tracking from correlating your identities across contexts. Firefox Multi-Account Containers does this natively.

Does Encrypted Messaging Replace All of This?

No, but it handles one category well. Signal is the standard for end-to-end encrypted messaging. It's open-source, independently audited, and used by security researchers, journalists, and anyone who takes message privacy seriously. WhatsApp uses the Signal protocol for encryption but is owned by Meta, which collects metadata (who you message, when, how often) even though it cannot read message contents. That metadata is valuable and is used for advertising.

If your concern is message content privacy, Signal is the clear choice. If your concern is metadata privacy, the options are more limited, and this is where most consumer tools hit their ceiling. Metadata analysis (who talks to whom, at what times, from which locations) is often more revealing than content, and very few tools address it effectively at the consumer level.

How Should You Think About AI Assistants and Privacy?

AI assistants are a newer category, and the privacy landscape here is still forming. The core question is straightforward: when you interact with an AI assistant, where does your data go, who can read it, and how long is it retained?

Most AI assistants send your input to a cloud-based model for inference. The input travels over an encrypted connection, is processed by the model, and a response is returned. What happens to that input after inference varies by provider. Some retain it for training. Some retain it for abuse monitoring. Some claim to delete it immediately but keep operational metadata.

The things worth checking when evaluating any AI assistant for privacy:

We built Selina as a privacy-focused AI assistant that remembers you across conversations. Content is encrypted at rest, and operational metadata is kept for a short retention window. Files and transfers via SelinaSEND are end-to-end encrypted. Memory is not end-to-end encrypted, because a slice of each request reaches a frontier provider at inference, and we think stating that clearly is more useful than pretending otherwise. The assistant runs on a stack of frontier models, routed per task.

What's the Minimum Viable Privacy Stack?

If you do nothing else, do these three things. They're free or cheap, they take less than an hour to set up, and they address the most common vectors of data exposure for a typical person:

  1. Use a password manager and turn on two-factor authentication for your email, bank, and any account that would cause real damage if compromised. This addresses the single largest category of account compromise. Bitwarden's free tier is sufficient for an individual.
  2. Set your browser to block third-party trackers and enable HTTPS-only mode. This reduces passive data collection with zero ongoing effort.
  3. Review your Google, Apple, and Meta privacy settings once. Turn off ad personalization, location history, and any data sharing toggles you don't actively want enabled. This takes fifteen minutes and reduces the largest data collectors' intake meaningfully.

Everything beyond this (VPN, encrypted email, data removal services, hardware security keys) is situation-dependent. It might be necessary for you. It might not. The right answer depends on your threat model, not on a listicle telling you to buy everything.

Which Tools Are Overrated for Most People?

A few categories get more attention than their actual impact warrants for a typical user.

Antivirus software on modern operating systems. Windows Defender on Windows and XProtect on macOS are competent. Third-party antivirus tools often add more attack surface (browser extensions, network monitoring hooks, kernel-level drivers) than they remove. If you're not downloading pirated software or opening email attachments from strangers, the built-in protections are usually sufficient.

"Privacy-focused" search engines as a standalone measure. DuckDuckGo and similar engines don't track your searches, which is good. But if you're logged into Google on the same browser and using Chrome with default settings, your search engine choice is a minor improvement in a system that's leaking data from dozens of other points. Search engine choice matters more when combined with the browser hygiene described above.

VPNs for "security." A VPN encrypts your traffic between your device and the VPN server. It does not protect you from phishing, malware, credential theft, or application-level vulnerabilities. The word "security" on a VPN's marketing page is doing a lot of heavy lifting. A VPN is a privacy tool in specific contexts. It is not a security tool in the way most people understand that word.

How Often Should You Review Your Privacy Setup?

Twice a year is a reasonable cadence for most people. Regulations change (California's DROP system is a good example of a new option appearing overnight). Services change their privacy policies. New tools mature. Old tools get acquired by companies with different incentives.

The things worth checking on a biannual review:

Privacy is not a product you buy once. It's a set of practices you maintain, with tools that reduce the effort of maintaining them. The best tools are the ones that require the least ongoing attention while providing the most coverage for your specific risks.

If you want an AI assistant that takes this seriously, start a free 7-day trial of Selina, no card required.

Frequently Asked Questions

What is a 'threat model' and why does it matter for choosing privacy tools?

Your threat model is the realistic set of risks you face based on your behavior, location, and profession, and it determines which tools are actually worth using. Deploying every privacy tool regardless of your situation is expensive and can even increase risk by adding more accounts and attack surface to maintain.

Is a password manager really necessary if I already use my browser's built-in one?

A dedicated password manager is recommended, though browser-integrated ones like Google Password Manager or iCloud Keychain are better than nothing. Only about 36% of US adults use a password manager at all, and dedicated tools like Bitwarden or 1Password tend to offer better cross-platform support and stronger security audits.

Should I switch to passkeys instead of using a password manager?

No, not yet. While consumer awareness of passkeys is high and about 5 billion are in use worldwide, only a few hundred top websites actually support them, so you should keep using a password manager and enable passkeys only where available.

Do I actually need a VPN for everyday browsing?

Not necessarily. If you work from home, visit mainstream HTTPS sites, and aren't facing targeted surveillance, a VPN offers limited practical benefit since HTTPS already encrypts your traffic content; it's most useful on public Wi-Fi, against ISP data sales, for bypassing geo-restrictions, or for journalists and activists facing real surveillance risks.

Why do data removal services require ongoing subscriptions instead of a one-time request?

Data brokers re-scrape public records roughly every 60 to 90 days, so removed profiles reappear within a couple of months, making one-time removal ineffective. This is why services charge subscriptions to resubmit removal requests on a recurring basis, and why California residents now have a free alternative through the state-run DROP platform.

Sources & References

Michael C.

Michael C.

Founder & Principal Engineer, Selina Labs

Michael builds Selina, a privacy-first AI that remembers you across conversations. He ships security-sensitive AI in production — real attacks, real fixes, measured in minutes and dollars — and writes about privacy, security, and LLMs from that seat. Top Rated Plus and expert-verified on Upwork.

Learn more about Selina.ai