Most people do not have a privacy problem because they are careless. They have a privacy problem because the settings are scattered: phone permissions here, browser cookies there, a chatbot history somewhere else, and an old account they forgot still forwarding mail.
This is a 15-minute monthly routine for everyday users — not lawyers, not security engineers. The goal is simple: keep AI tools useful while cutting the data they do not need, locking down account recovery, and making sure a lost phone or a reused password cannot quietly open the rest of your digital life.
Last checked: September 2026. Menus move. Official settings pages always win over screenshots in an old blog post.
What this routine is — and what it is not
This is a defensive checklist. It is not legal advice, not a guarantee against scams, and not a guide to hiding activity, bypassing security, or monitoring anyone else. If you handle other people’s data at work, follow your employer’s policy and the law in your country.
Use official sources when a setting matters. In the U.S., start with the FTC privacy and security guidance and CISA’s Secure Our World basics. In the U.K., the NCSC top tips and the ICO public guides are the right first stop. In Canada, use the Office of the Privacy Commissioner technology pages.
The 15-minute monthly loop
Do this on the first weekend of the month. Phone first, then laptop, then one AI account you actually use. If you run out of time, stop after the phone. A half-done routine that you repeat is better than a perfect audit you never finish.
| Minute | Task | Done when |
|---|---|---|
| 0–3 | App permissions | Camera, mic, location, and contacts are off unless you used them this month |
| 3–6 | Account recovery | You can name your 2FA method and a working recovery email or number |
| 6–9 | Browser and saved logins | Unused extensions gone; password manager is the source of truth |
| 9–12 | AI chat and memory settings | You know whether chats train the product and how to delete history |
| 12–15 | One old account | You either keep it with 2FA or you start a proper deletion request |
Step 1: App permissions — keep the ones you used
Open your phone’s privacy dashboard. On iPhone that is Settings → Privacy & Security. On Android it is usually Settings → Privacy → Permission manager. Sort by camera, microphone, location, and contacts. Those four cause the most damage if an app is sloppy or an account is stolen.
A useful rule: if you have not used the feature in 30 days, set the permission to Ask or Don’t allow. Navigation apps can have location while using the app. A flashlight app does not need contacts. An AI writing app rarely needs your microphone unless you dictate into it.
Then check which apps can run in the background. Background location is the one people forget. If a shopping or weather app only needs your city, it does not need “always” location.
Step 2: Account recovery before you add more AI tools
AI tools inherit the weakness of the email inbox they sit on. If someone can reset Gmail, Outlook, or iCloud, they can often reset ChatGPT, Gemini, Claude, Copilot, and every shopping agent tied to that address.
- Turn on two-factor authentication with an authenticator app or a hardware key. SMS is better than nothing, but SIM-swap attacks make it the weaker option.
- Write down one backup code and put it where you would look after a lost phone — not in the same notes app as the password.
- Confirm the recovery email and phone number still belong to you.
- Remove old devices you no longer own from Google, Apple, Microsoft, and Meta device lists.
If you share a family computer, create a separate browser profile. Shared sessions are how a “quick ChatGPT question” leaves a month of prompts behind for the next person.
Step 3: Browser, extensions, and saved prompts
Extensions can read the page you are on. That includes banking tabs, webmail, and AI chats. Once a month, open your extension list and remove anything you installed for a single task. Keep the password manager. Be skeptical of “free AI sidebar” add-ons that ask for permission to read all site data.
Then decide where prompts live. If you paste customer names, invoices, medical details, or school records into a chatbot, assume that text can be stored, reviewed, or used to improve the product unless the vendor’s current settings say otherwise. The safe default for work and family matters is: do not paste identifiers. Summarize the problem. Leave names out.
Step 4: AI product settings people actually miss
Every major assistant has a slightly different label. Look for these four controls, even if the wording differs:
- Chat history. Can you turn saving off, or only delete after the fact?
- Model training / improve the product. Is your content used to train? Is there an opt-out?
- Memory / custom instructions. What has the tool stored about you, and can you clear it?
- Connected apps. Gmail, Drive, shopping accounts, and calendars should be connected only while you need them.
Delete chats you would not want forwarded to your employer or your family. Export first if you need a record, then delete. Clearing a thread is not the same as deleting an account. If you are leaving a tool, use the vendor’s official deletion or data-request page and wait for confirmation.
U.K. and EU users often have a clearer right to access and erase personal data through the ICO and GDPR process. Canadian users can start with the OPC. U.S. rights vary by state — California’s consumer tools are among the most specific — but you can still use each company’s privacy dashboard even if your state has no extra law.
A sample “use / review / do not automate” map
| Task | AI is fine | Review before you send | Do not automate |
|---|---|---|---|
| Drafting an email | Yes, for tone and structure | Anything with money, legal, or HR language | Sending mail from your account without you clicking send |
| Shopping research | Comparing public specs and prices | The final checkout total, shipping address, and return policy | Saving a card inside a new shopping agent you have not tested |
| Photos | Background cleanup on pictures you took | Faces of other people, kids, or ID documents | Uploading passports, visas, or school records “just to summarize” |
| Work files | Public or dummy data | Internal drafts with client names removed | Customer lists, medical notes, unpublished financials |
Country notes without the legal fog
United States. There is no single federal “AI privacy button.” You rely on the company’s settings, your state law if you have one, and FTC rules against deceptive data practices. Start with the product’s privacy dashboard, then your Google/Apple/Microsoft account.
United Kingdom. You can ask an organization what data it holds and request deletion in many cases. The ICO explains how. The NCSC is better for the practical stuff: password managers, 2FA, and software updates.
Canada. Federal privacy law plus provincial rules can apply. The Privacy Commissioner’s office publishes plain-language technology guidance. If a company is in another country, you can still use its in-product controls; the local complaint process is the backup, not the first step.
The one-page monthly checklist
- Review camera, mic, location, and contacts on your phone.
- Confirm 2FA and recovery details on email, Apple/Google/Microsoft, and your main AI account.
- Remove unused browser extensions and unknown logged-in devices.
- Check whether AI chat history and training are on; delete what you would not forward.
- Disconnect shopping, mail, or drive integrations you are not using this month.
- Update the phone and laptop. Pending updates are how old bugs stay open.
- Pick one stale account: keep it hardened, or start an official deletion request.
When to get extra help
If you see a login you do not recognize, a password change you did not make, or a shopping agent that placed an order, do not debug it inside the chat window. Change the email password from a device you trust, sign out other sessions, and contact the company through its official support page. For identity theft in the U.S., IdentityTheft.gov is the structured next step. In the U.K., Action Fraud and the ICO cover different parts of the problem. In Canada, the Canadian Anti-Fraud Centre is the reporting path for scams.
Final word
You do not need a bunker. You need a habit. Fifteen minutes a month will not make you anonymous, and it should not. It will make AI tools smaller in your life: useful for drafts and research, less free with your camera, your chats, and the inbox that unlocks everything else.
Print the checklist, put it on the fridge or in your notes app, and run it before you add the next assistant. The best privacy setting is the one you actually review.
