
Guides
How to review and tighten browser privacy settings
A browser privacy review that audits permissions, cookies, extensions and sync, then tests the sites you rely on before trusting the changes.
What to take away
- Confirm recovery email, phone, passkey, security key and backup codes before you clear anything.
- Change one control group at a time, then test sign-in, payments, video and document editors.
- Review camera, microphone, location and notification grants site by site, not by global default.
- Delete one site's cookies and storage instead of wiping everything, so sessions and preferences survive.
- Recheck after major browser updates, because setting names and defaults move.
Menus differ across products, operating systems, versions and managed devices. Use the browser maker's current help page for exact clicks. Do not override employer or school controls without permission.
Preserve access before cleanup
Verify Recovery Access First
- Recovery email works
- Recovery phone works
- Passkey works
- Security key works
- Password-manager vault works
- Backup codes work
- Test the recovery path
Save receipts or records you still need. Do not export passwords to an unprotected file merely to feel safe. If the browser is managed, record the organization and policy shown, because some settings are locked for a valid administrative reason.
Update the browser and the device
Install current stable browser and operating-system updates, then restart if required. Check that the update completed rather than assuming the notification meant it installed.
Remove obsolete browser versions and unsupported profiles only after confirming bookmarks, credentials and needed records are preserved.
Draw profile boundaries
Decide whether work, personal, shopping, research or shared-household activity gets separate profiles or separate device accounts. Name each profile clearly and give it a distinct visual theme so you notice when you are in the wrong one.
Profile Boundaries by Activity
Separate profile
- Work
- Yes
- Personal
- Yes
- Shopping
- Yes
- Research
- Yes
- Shared household
- Yes
Shared profile
- Work
- No
- Personal
- No
- Shopping
- No
- Research
- No
- Shared household
- No
Turn on sync only for the categories you want copied to the account. Review synced history, tabs, passwords, addresses, extensions and settings one at a time. Protect the sync account itself, because it now holds all of them.
Set tracking protection
Find the privacy or tracking-protection controls. Start with the browser's balanced or standard level, then move stricter if you need it. Test sign-in, payments, video, document editors and embedded tools before you keep the change.
When a Site Breaks
- Identify blocked feature
- Trust the site?
- Need the feature?
- Understand what you allow?
- Create site-specific exception
- Write reason and revisit date
Mozilla's current recommended Firefox privacy settings cover tracking protection, cookie controls, site permissions, browser data collection, HTTPS-only mode and deceptive-content protection. That page applies to supported Firefox versions; other browsers use different names and different behavior.
When a site breaks, identify which blocked feature it needs. Create a site-specific exception only if you trust the site, need the feature and understand what you are allowing. Write down the reason and the date you will revisit it.
Review cookies and site data
Sort stored sites by recent use or storage size where the browser allows it. Remove unknown and stale entries. Clearing one site's data is usually safer than wiping everything.
What Clearing Site Data Removes
Local data
- Sessions
- Removed
- Preferences
- Removed
- Offline documents
- Removed
- Cached files
- Removed
Server-side records
- Sessions
- May remain
- Preferences
- May remain
- Offline documents
- May remain
- Cached files
- May remain
Know the consequence before you delete. Cookies hold sessions and preferences. Local databases can hold offline documents. Cached files are copies kept for speed. A site may still hold server-side records after your local data is gone.
Audit site permissions
Review these items: camera, microphone, precise or approximate location, notifications.
Review these items: pop-ups, clipboard, automatic downloads, background sync.
Review these items: motion sensors, USB and Bluetooth.
For each saved grant, ask:
Audit Each Saved Permission
- Do I recognize the site?
- Does the feature still need this?
- Can the browser ask each time?
- Is a narrower level available?
- What breaks if I reset it?
Reset the old grants. Visit the site again and allow access only when the feature calls for it.
Clean history, downloads and autofill selectively
Review browsing and download history, saved addresses, payment information, form entries and search suggestions. Delete stale or sensitive items, then confirm whether the synced copy changed too.
Removing a download-list entry does not remove the file. Check the downloads folder and application storage separately. Clearing autofill does not correct the records a merchant already holds.
Inspect saved passwords and passkeys
Use the browser or password manager's audit tools to find reused, exposed, weak and obsolete credentials. Move toward unique credentials and the phishing-resistant option the service offers, which is usually a passkey or a security key.
Do not store a credential in two unmanaged places. Delete the old browser copy only after the intended manager holds it and you have tested recovery.
Review extensions
List every extension with its publisher, source, purpose, permissions, private-window access and site access. Remove anything unused or unclear. Restrict optional site access where the extension still works without it.
Recheck after an update that adds permissions. A theme should not need broad page access. A password manager may need page access to fill credentials, but its publisher, update path and vault security still deserve scrutiny.
Test and record
Open a small test set: a public page, an account sign-in, a payment page without completing a purchase, a video call test, a document editor and any accessibility tool you rely on. Confirm that address and certificate warnings still appear and that your exceptions stayed narrow.
Record the date, browser version, changed controls, exceptions, unresolved problems and next review date. Repeat after a new device, a compromised account, a major update or an unfamiliar extension appears.
Common questions
Should I clear every cookie every day?
Not necessarily. It breaks sessions and accessibility preferences you set on purpose. Use a schedule and site-specific deletion that match your actual risk and workflow.
Does strict tracking protection block all tracking?
No. Logged-in activity, first-party records, fingerprinting, link parameters and server-side sharing can all remain. Tracking protection reduces what the browser passes along; it does not control what a site does with what you give it.
Can I trust an extension from an official store?
Store distribution removes some risk but not the review. Check the publisher, the permissions it requests, when it last updated and whether you still need it.
What if a site stops working?
Identify the blocked feature, confirm the site is the one you think it is, then apply the smallest temporary or site-specific exception that restores the function. Record it so you can undo it later.






