Privacy & OPSEC
This guide focuses on operational habits that matter more than tool branding.
Threat model quick pass
Before changing any setting, answer:
- Who are you hiding from: ISP, platform, targeted actor?
- What data matters most: identity, location, communication graph, content?
- What is acceptable friction for your daily workflow?
Identity separation matrix
| Context | Identity | Device profile | Notes |
|---|---|---|---|
| Personal browsing | Personal | Default | Never mix with sensitive accounts |
| Research / monitoring | Pseudonymous | Dedicated browser profile | Separate cookies and mailbox |
| High-risk communication | Controlled identity | Dedicated device session | No overlap with personal messengers |
Session hygiene
- Use separate browser profiles for each identity.
- Clear session storage after high-risk tasks.
- Avoid account recovery methods tied to personal phone numbers.
- Prefer dedicated mailbox aliases for each context.
Messaging hygiene
- Keep contact lists compartmentalized.
- Disable cloud backups for sensitive chats where possible.
- Treat metadata as exposed by default.
- Rotate invite links and shared channels periodically.
Red flags
Stop and review your setup if:
- one account starts receiving cross-context recommendations;
- unknown sessions appear in account activity;
- location or language hints unexpectedly change;
- you repeatedly reuse the same profile for unrelated tasks.
Last updated on