Browser privacy settings review with tracking protection, cookies, permissions, and sync controls. How to review and tighten browser privacy settings
Image: Privacy Notes

Guides

Part of Browser privacy guide: cookies, storage, fingerprinting, permissions, history, extensions, and profiles

How to review and tighten browser privacy settings

A browser privacy review that audits permissions, cookies, extensions and sync, then tests the sites you rely on before trusting the changes.

What to take away

  • Confirm recovery email, phone, passkey, security key and backup codes before you clear anything.
  • Change one control group at a time, then test sign-in, payments, video and document editors.
  • Review camera, microphone, location and notification grants site by site, not by global default.
  • Delete one site's cookies and storage instead of wiping everything, so sessions and preferences survive.
  • Recheck after major browser updates, because setting names and defaults move.

Menus differ across products, operating systems, versions and managed devices. Use the browser maker's current help page for exact clicks. Do not override employer or school controls without permission.

Preserve access before cleanup

Verify Recovery Access First

  • Recovery email works
  • Recovery phone works
  • Passkey works
  • Security key works
  • Password-manager vault works
  • Backup codes work
  • Test the recovery path

Save receipts or records you still need. Do not export passwords to an unprotected file merely to feel safe. If the browser is managed, record the organization and policy shown, because some settings are locked for a valid administrative reason.

Update the browser and the device

Install current stable browser and operating-system updates, then restart if required. Check that the update completed rather than assuming the notification meant it installed.

Remove obsolete browser versions and unsupported profiles only after confirming bookmarks, credentials and needed records are preserved.

Draw profile boundaries

Decide whether work, personal, shopping, research or shared-household activity gets separate profiles or separate device accounts. Name each profile clearly and give it a distinct visual theme so you notice when you are in the wrong one.

Profile Boundaries by Activity

Separate profile

Work
Yes
Personal
Yes
Shopping
Yes
Research
Yes
Shared household
Yes

Shared profile

Work
No
Personal
No
Shopping
No
Research
No
Shared household
No

Turn on sync only for the categories you want copied to the account. Review synced history, tabs, passwords, addresses, extensions and settings one at a time. Protect the sync account itself, because it now holds all of them.

Set tracking protection

Find the privacy or tracking-protection controls. Start with the browser's balanced or standard level, then move stricter if you need it. Test sign-in, payments, video, document editors and embedded tools before you keep the change.

When a Site Breaks

  1. Identify blocked feature
  2. Trust the site?
  3. Need the feature?
  4. Understand what you allow?
  5. Create site-specific exception
  6. Write reason and revisit date

Mozilla's current recommended Firefox privacy settings cover tracking protection, cookie controls, site permissions, browser data collection, HTTPS-only mode and deceptive-content protection. That page applies to supported Firefox versions; other browsers use different names and different behavior.

When a site breaks, identify which blocked feature it needs. Create a site-specific exception only if you trust the site, need the feature and understand what you are allowing. Write down the reason and the date you will revisit it.

Review cookies and site data

Sort stored sites by recent use or storage size where the browser allows it. Remove unknown and stale entries. Clearing one site's data is usually safer than wiping everything.

What Clearing Site Data Removes

Local data

Sessions
Removed
Preferences
Removed
Offline documents
Removed
Cached files
Removed

Server-side records

Sessions
May remain
Preferences
May remain
Offline documents
May remain
Cached files
May remain

Know the consequence before you delete. Cookies hold sessions and preferences. Local databases can hold offline documents. Cached files are copies kept for speed. A site may still hold server-side records after your local data is gone.

Audit site permissions

Review these items: camera, microphone, precise or approximate location, notifications.

Review these items: pop-ups, clipboard, automatic downloads, background sync.

Review these items: motion sensors, USB and Bluetooth.

For each saved grant, ask:

Audit Each Saved Permission

  • Do I recognize the site?
  • Does the feature still need this?
  • Can the browser ask each time?
  • Is a narrower level available?
  • What breaks if I reset it?

Reset the old grants. Visit the site again and allow access only when the feature calls for it.

Clean history, downloads and autofill selectively

Review browsing and download history, saved addresses, payment information, form entries and search suggestions. Delete stale or sensitive items, then confirm whether the synced copy changed too.

Removing a download-list entry does not remove the file. Check the downloads folder and application storage separately. Clearing autofill does not correct the records a merchant already holds.

Inspect saved passwords and passkeys

Use the browser or password manager's audit tools to find reused, exposed, weak and obsolete credentials. Move toward unique credentials and the phishing-resistant option the service offers, which is usually a passkey or a security key.

Do not store a credential in two unmanaged places. Delete the old browser copy only after the intended manager holds it and you have tested recovery.

Review extensions

List every extension with its publisher, source, purpose, permissions, private-window access and site access. Remove anything unused or unclear. Restrict optional site access where the extension still works without it.

Recheck after an update that adds permissions. A theme should not need broad page access. A password manager may need page access to fill credentials, but its publisher, update path and vault security still deserve scrutiny.

Test and record

Open a small test set: a public page, an account sign-in, a payment page without completing a purchase, a video call test, a document editor and any accessibility tool you rely on. Confirm that address and certificate warnings still appear and that your exceptions stayed narrow.

Record the date, browser version, changed controls, exceptions, unresolved problems and next review date. Repeat after a new device, a compromised account, a major update or an unfamiliar extension appears.

Common questions

Should I clear every cookie every day?

Not necessarily. It breaks sessions and accessibility preferences you set on purpose. Use a schedule and site-specific deletion that match your actual risk and workflow.

Does strict tracking protection block all tracking?

No. Logged-in activity, first-party records, fingerprinting, link parameters and server-side sharing can all remain. Tracking protection reduces what the browser passes along; it does not control what a site does with what you give it.

Can I trust an extension from an official store?

Store distribution removes some risk but not the review. Check the publisher, the permissions it requests, when it last updated and whether you still need it.

What if a site stops working?

Identify the blocked feature, confirm the site is the one you think it is, then apply the smallest temporary or site-specific exception that restores the function. Record it so you can undo it later.

More in Guides

Latest from Guides Desk