You do not need to delete your social media accounts to protect your privacy. Most of the real exposure comes from a handful of default settings that nobody revisits, plus posting habits that reveal more than intended. This checkup takes about half an hour for all your accounts combined, and you only need to do the full version once a year.
Minute 0-5: See your profile as a stranger sees it
Open your profile in a private browsing window while logged out, or use the “View as” feature where available. This is what a scammer, an employer or an ex sees. Common surprises: your phone number publicly listed from a 2015 setting, old cover photos visible to everyone regardless of later privacy changes, and your friends list mapping your family for anyone building an impersonation scam. Whatever bothers you in this view is your to-do list for the next 25 minutes.
Minute 5-15: The settings that matter on every platform
- Audience defaults: set new posts to friends/followers only. Public should be a per-post decision, not the default.
- Profile discovery: disable “find me by phone number or email” unless you specifically want strangers connecting your number to your face and name. Data-broker and scam operations love this lookup.
- Friends/followers list visibility: set to only you. Impersonators clone profiles and message your list; hiding it removes their shopping catalogue.
- Tagging review: turn on approval for tags and for posts you are tagged in appearing on your profile. Other people’s posting judgement should not define your public record.
- Location data: revoke precise-location permission for social apps in your phone settings. Very few posts need it, and the app collects it constantly, not just when posting.
- Ad and data settings: disable ad personalisation based on off-platform activity, and while you are in that menu, review which third-party apps still have access to your account – revoke everything you no longer use.
Minute 15-20: Lock the front door
Privacy settings mean little if the account itself gets taken over. Enable two-factor authentication on every platform – preferably via an authenticator app rather than SMS – and check the list of active sessions and logged-in devices, logging out anything you do not recognise. Social accounts are prime hijack targets precisely because a stolen account makes scams against your friends devastatingly credible.
Minute 20-25: Audit what you post, not just who sees it
Settings cannot save you from the content itself. The classics that fuel real-world problems: boarding passes (the barcode contains your booking reference), photos showing your street or house number, “away for two weeks!” posts telling burglars the house is empty, children’s schools identifiable from uniforms, and answers to security-question quizzes (“your first car + your first pet = your rockstar name”) which are password-recovery harvesting dressed as fun. None of this requires paranoia – just a two-second “what does this reveal?” pause before posting, and posting holiday photos after you are home rather than during.
Minute 25-30: Deal with the archive
Your post history is searchable, and context does not travel well across a decade. Facebook’s “Limit Past Posts” converts everything old to friends-only in one click. On X, Instagram and TikTok, skim your oldest public posts and delete or restrict what no longer represents you. If there is a lot, third-party bulk-delete tools exist, but check what account access they demand – do not fix a privacy problem by granting full account control to an unknown app.
Keep it maintained in five minutes a year
Platforms change settings and add new defaults constantly, usually in the direction of more sharing. Once a year: repeat the logged-out profile check, re-skim audience and discovery settings, and re-audit connected third-party apps. Half an hour once, five minutes a year – that is the entire maintenance cost of social media that shares what you choose, rather than what a growth team chose for you.