Security & Privacy

How to Protect Yourself on Social Media

A calm, jargon-free guide to staying safe on social media, covering privacy settings, oversharing, suspicious messages, and keeping control of your accounts.

A person holding a smartphone showing colorful social media app icons
Photograph via Unsplash

The three changes that protect you most: set your account to private, turn on app-based two-factor authentication (not SMS), and use a unique password stored in a password manager. Everything else in this guide refines those three, but if you only do them once and walk away, you have already closed the doors attackers use most often.

Lock down who can see you#

Every major platform ships with defaults tuned for reach, not privacy. Your first job is to reverse that. Here is where the switch lives on each app as of 2026, though menus shift with redesigns:

  • Instagram: Profile > menu (three lines) > Settings and privacy > Account privacy > toggle on Private account. Then open Settings and privacy > How others can interact with you > Tags and mentions and restrict tags to "People you follow."
  • Facebook: Settings & privacy > Settings > Audience and visibility > Posts and set "Who can see your future posts" to Friends. Run the Limit past posts tool on that same page to retroactively pull old public posts back to Friends.
  • TikTok: Profile > menu > Settings and privacy > Privacy > Private account.
  • X (Twitter): Settings > Privacy and safety > Audience and tagging > Protect your posts.
  • Snapchat: Settings > Privacy Controls > View My Story > My Friends, and set Contact Me to Friends.

A private account matters because it changes who can screenshot, forward, or scrape your content. Public profiles are routinely harvested by automated tools that build marketing and impersonation databases. Going private does not make you invisible to friends; it just means new followers need your approval.

While you are in those menus, find the setting that controls whether people can locate you by phone number or email. On Instagram and Facebook this sits under "How people find and contact you." Turning off discoverability by phone number severs a common link between a leaked number and your social identity.

Treat this as quarterly housekeeping. Platforms genuinely do reset preferences after major redesigns, and features you disabled a year ago sometimes reappear switched on.

Stop your posts from quietly leaking data#

The risk is rarely one dramatic overshare. It is the accumulation of small signals that together map your routine, your home, and the people around you.

Location is the big one#

Turn off automatic location tagging in each app's posting flow, and disable the camera app's own geotagging so it never gets embedded in the first place. On iPhone: Settings > Privacy & Security > Location Services > Camera > set to Never. On Android: open the Camera app > settings gear > turn off Location tags (sometimes "Save location").

Most large platforms strip EXIF metadata (the hidden data block that stores GPS coordinates, device model, and timestamp) when you upload a photo. But that protection disappears the moment you send the original file directly, over email, a messaging app, or a cloud share link. If a photo could reveal where you live, scrub it first: on iPhone, open Photos, tap the info button, and use Adjust to remove the location before sharing.

Post after, not during#

Sharing a holiday album the day you fly home avoids broadcasting an empty house to anyone watching. The memories are identical a few days later. Apply the same logic to a new car with a visible plate, a delivery box showing your full address, or a child's school logo on a uniform in the background.

Before posting, ask one concrete question: could a stranger use this to find where I am right now, or where I live? If yes, hold it or crop it.

Secure the login, not just the password#

Your login is the front door. A weak lock here undoes every privacy setting behind it.

Use a unique password and a manager#

Reused passwords are the single biggest cause of account takeovers, through a technique called credential stuffing: attackers take username-and-password pairs leaked from one breached site and try them everywhere else. A password manager (1Password, Bitwarden, or the one built into your browser or phone) generates a different long password for each account so a breach at one service cannot cascade. Check whether your address appears in known breaches at haveibeenpwned.com, and change any password it flags. Modern guidance from NIST favors length over forced monthly changes, so a long unique passphrase you keep is better than a complex one you rotate and forget.

Turn on app-based 2FA, and prefer passkeys#

Two-factor authentication requires a second proof beyond your password. Enable it on Instagram and Facebook under Accounts Center > Password and security > Two-factor authentication, and on X under Settings > Security and account access > Security.

Here is the detail most guides skip: not all second factors are equal. Choose an authenticator app that generates rotating TOTP codes (Google Authenticator, Authy, Aegis, or the code feature inside your password manager) over SMS text codes. SMS is vulnerable to SIM swapping, where a scammer convinces your carrier to move your number to their SIM and intercepts your codes. Better still, if the platform offers a passkey (a phishing-resistant credential tied to your device's fingerprint or face unlock, built on the FIDO/WebAuthn standard), turn it on. X, Facebook, and WhatsApp all support passkeys now.

When you enable 2FA, the app shows a set of backup recovery codes. Save them somewhere offline, a note in your password manager or a printout, because they are how you get back in if you lose your phone.

Audit sessions and connected apps#

Two more menus are worth five minutes. First, "Where you're logged in" (Instagram and Facebook under Password and security; X under Apps and sessions) lists every active session; log out anything unfamiliar. Second, review third-party apps with access to your account, the quizzes and games you once connected. That access can persist for years and is a classic route for quiet data harvesting. Revoke anything you no longer use.

Spot impersonation and phishing#

Scams work on social media precisely because the setting feels trustworthy. Watch for these patterns:

  • A friend request from someone you already follow (a cloned account copying a real friend to reach their contacts).
  • A message pushing urgency, secrecy, or a prize, a refund, or a "is this you in this video?" link.
  • A request to move the conversation to another app, or to send a login code "to verify you."

No legitimate service or real friend asks you to read out a login code. If a message from a friend feels off, contact them through a different channel, a phone call or a different app, before acting. Their account may be compromised. And before clicking any link, read the actual domain: instagram-support.co is not instagram.com.

Common mistakes people make#

The most frequent error is treating privacy as a one-time setup rather than an ongoing habit, then never checking again after a redesign quietly changes things. Close behind is relying on SMS 2FA and assuming it is enough. People also forget that going private does not retroactively hide old public posts, which is exactly what Facebook's "Limit past posts" tool fixes. Finally, many secure the account but keep oversharing location in real time, protecting the lock while leaving the windows open.

FAQ#

Is SMS two-factor authentication better than nothing?#

Yes, meaningfully. Any 2FA stops the majority of automated attacks that rely on a password alone. But move to an authenticator app or passkey when you can, because SMS can be defeated by SIM swapping, whereas an app-based code or passkey never leaves your device.

Do I need to delete old posts, or is private enough?#

Setting your account private protects future and existing posts from non-followers, but old content you made public can linger in caches and search results. Use a bulk tool like Facebook's "Limit past posts," and manually delete anything sensitive rather than assuming the privacy toggle reaches back in time.

Are those fun personality quizzes actually risky?#

They can be. Many request broad access to your profile, friend list, and email in exchange for a result, and that data can be sold or used to build targeting profiles. Check your account's connected-apps list and remove any quiz or game you no longer use.

What should I do the moment I think my account is hacked?#

Change the password immediately from a device you trust, then log out all other sessions in the security settings. Confirm your recovery email and phone number have not been swapped, re-enable 2FA if it was turned off, and warn your contacts not to trust messages sent from your account in the meantime.

Theo Vance
Written by
Theo Vance

Theo writes about online safety the way a good friend would — clearly, calmly, and without trying to scare you. He's interested in the simple habits that stop most problems, and he thinks staying private online is a skill anyone can learn.

More from Theo