An answer from the library
Which online privacy habits are actually worth the bother?
Woven from five library pages on small privacy habits; every count, correction and hard rule belongs to the page named beside it, and the copyright lines are that page's own checks against the US Copyright Office.
Five pages in this library are about privacy, and none of them is a lecture or a product. Each is one habit, built from people comparing what actually happened to them, and each carries its own limits, including the cases where the habit does nothing. Read together they share a shape: the trick is small, the rule about when not to use it is the valuable part, and none of the five asks you to buy anything.
Tag your email address, but only for the accounts that do not matter. Give each website its own email tag says that when you sign up for something, adding a plus sign and a tag before the @ still delivers the mail to your inbox, labelled with who you gave it to, on most major providers. That page will not tell you which providers support it, because that advice goes stale; it gives a one-minute test instead, sending yourself mail at your own address with a tag added. The two honest uses on that page are tracing, so that junk mail addressed to a tag names who leaked it, and sorting, so a filter can sweep a tag into a folder or to trash. Whether the tracing survives professional spammers is genuinely contested there, five accounts to three: one camp has caught specific companies this way, the other reports that the list trade routinely strips the suffix, and the page’s own decider is the opponent, careless leakers ship the tag and industrial ones scrub it. The rule the page calls its one hard rule, straight from the people it bit: tags are for the low-stakes tier, newsletters, shops, forums, and never for an account you might need to recover, reply from, or argue with on the phone, because people there report registrations that worked but logins that did not, unsubscribe pages that choke on the plus, and services that require replies from the exact registered address. A tag is a tracer, not a shield, and one person notes tagged signups get no more spam than bare ones. The page also draws a boundary on purpose: these tricks get used to re-register for free trials and dodge one-account limits, and nothing on it is written to help with that.
Put a Wi-Fi code on the fridge, for the guest network only, made on your phone. Put the guest network on the fridge comes from twelve conversations and 367 accounts. Four separate conversations say a Wi-Fi code is the password itself in plain text, readable by whoever scans it, so the only question that matters is which password it is; three separate conversations say the code that hangs in your kitchen should be for a guest network, the second network most routers can run, and never the main one, and the conversation that page began from is its own correction, because the original advice was to print the main network and the poster changed it after being told so. Two contraindications say do not print the main network’s code if you have devices you do not patch or visitors you do not fully trust. Three separate conversations say the phone that is already connected makes the code itself, from the network’s settings or the saved-passwords screen, and one contraindication and one caution say never type your network name and password into a website that offers to make the code, because you have just given them to the website. Taking it back is the easy part, two separate conversations say: change the guest network’s password and every code ever scanned stops working that moment. Two contraindications name the homes this is not for, a house that strangers pass through often, and a small town where the network’s name tells everyone whose it is, and if your router has no guest network the page is not telling you to put the main password on paper.
Before you press play on anything private, look at what your phone is connected to. Check the speaker before you press play is built from thirty conversations and 405 accounts about a phone sending private audio to the wrong speaker. Five separate conversations say the one line most worth keeping: when you press play and hear nothing from the phone in your hand, the usual cause is not that the volume is low; the sound is being sent to a speaker, earbuds or a car the phone is paired with, and it is already playing there, so turning the volume up to check is the exact wrong move, and several accounts describe doing it and making the leak suddenly loud. Eighteen separate conversations, the widest agreement on that page, say the reliable prevention is to turn Bluetooth off before you play anything private, and one correction catches people who think they are safe: on many phones the quick tap in the control panel only pauses Bluetooth until the next day or the next known speaker, and the full off is in the settings menu. Four separate conversations say it is not only Bluetooth, because a phone can cast or mirror to a television or a networked speaker over Wi-Fi, and the casting button is easy to tap by accident. If you keep Bluetooth on for earbuds or a watch, the page’s rule for you is not off but verify, every time, and one caution names the failure for earbuds specifically: when their battery dies mid-play, the audio jumps back to the phone’s own loudspeaker, or to the next paired device, out loud.
Upload a slightly cropped version, and keep the whole picture where the internet is not. Upload the crop, keep the whole picture draws on thirty conversations and 425 accounts. Seven separate conversations crop a small piece off an image before uploading it and keep the uncropped file, so that if the picture is stolen the thief’s copy is missing the edge only you can produce. Two cautions on that page settle what that is worth: enough in most ordinary disputes, and not security, because a thief can crop further, and sharing your proof image to win the argument hands them a fuller copy. Three separate conversations keep the file no repost can fake, the camera’s raw data or the layered project file with every stroke on its own layer. The page carries two lines from public guidance, checked against the US Copyright Office and the UK position: in the US and the UK your copyright exists the moment you make the work, without registering anything, and mailing a sealed copy to yourself provides no legal protection whatsoever, whatever you were told. Its safety line is about what the tricks are not: nothing on it is legal advice, the law differs by country, and the crop, the watermark and the original file are proof for an online argument and a takedown request, which one account says have never been tested in court. For the other direction, five separate conversations run a stranger’s profile picture through a reverse image search before they reply, three conversations then ask for a new photo doing something specific that a catfish working from a stolen set cannot supply, and three conversations say not to use the same picture on a dating app as on your other accounts, because the search then leads a stranger straight to your name, your workplace and your friends. One last line from two accounts there, for anyone sending a photo of a document: blurring is not enough, because software can reconstruct what is blurred, so crop or black out instead.
Photograph the serial numbers, not just the things, and keep the photos outside the house. Photograph the serial numbers says a photo of your TV proves a TV was once in a room, and the serial proves which TV and that it was yours, and that difference is where insurance claims and police recoveries live. People on that page met it from both directions: an insurer that refused to take photos by themselves as ownership proof when receipts were gone, and a police department that returned a stolen bike because the frame number was on file, with the officer admitting that stolen bikes almost never make it home, since owners almost never have the number. The people who had this ready built it in one unhurried pass, a slow video through every room with drawers and cabinets open, plus still shots of the serial labels on the expensive things, then copies somewhere the disaster cannot reach, cloud storage or an email to yourself, with someone you trust able to get at it if you cannot. The privacy line is the page’s own: keep the inventory private, because it is, functionally, a shopping list of your home, so store it off-site but never post it, and skip location tags.
Who this is not for, and what these pages leave open. If your worry is whether an employer or a network can see your screen or your traffic, the speaker page says that is a different question about monitoring and does not answer it. If your question is whether you are legally answerable for what a guest does on your Wi-Fi, the fridge page names that as a gap that differs by country. If someone has already reposted your work and you want to sue, the crop page’s accounts say court is prohibitively expensive and rarely worth pursuing against an individual, and the practical remedy they name is a takedown request to the platform. And none of these pages names a provider, a router, a phone maker or a service; each says so in its own caveats.