Everyday privacy
For normal people who want less tracking, fewer leaks, and better defaults.
- Password manager + unique passwords
- Signal for private chats
- Firefox + uBlock (PrivyDeck optional)
- 2FA on email & banking
- Review phone app permissions
Owned by Vassbrekke AS · Mostly not our apps
We build privacy tools. This guide exists so you’re not stuck with only ours — find the best apps, harden phone and desktop, and build habits that keep your life yours.
Open-source first, audited when it matters, no dark patterns.
Android, iOS, Windows, macOS, and Linux — practical steps.
Social, home, money, and physical privacy that actually sticks.
Start here
Not everyone needs a Faraday bag. Pick a level that matches your risk — then level up when you're ready.
For normal people who want less tracking, fewer leaks, and better defaults.
For freelancers, journalists-lite, and anyone who wants a real private stack.
For activists, whistleblowers, and high-risk targets. Assume skilled adversaries.
App directory
Independent tools first. Ours are labeled and listed after the open ecosystem — filter Ours if you want our stack.
Gold standard for private messaging. End-to-end encryption, disappearing messages, open source, and no ads.
Use when: friends/family will actually install it.
No phone number required. Onion-routed metadata resistance. Stronger anonymity model than mainstream chat apps.
Use when: you want identity-light chat.
Federated, E2EE rooms, bridges to other networks. You can self-host and own the infrastructure.
Use when: groups, orgs, or self-hosting matter.
Best balance of usability and control. Pair with PrivyDeck and/or uBlock Origin, multi-account containers, and strict tracking protection.
Use when: daily browsing for most people.
Chromium-based with aggressive built-in ad/tracker blocking and private windows with Tor option.
Use when: you want Chrome-like UX with better defaults.
Routes traffic through the Tor network. Essential for high-risk research and censorship circumvention. Not for everyday logins.
Use when: threat model needs anonymity, not just privacy.
Tor Browser technology without the Tor network — privacy-hardened Firefox build designed to reduce fingerprinting.
Use when: pairing with a trustworthy VPN.
Anonymous accounts (no email), cash/crypto payment, audited, no-logs reputation. Privacy-first business model.
Use when: you care more about privacy than fastest streaming.
Solid free tier, open-source apps, Secure Core, and ties into the Proton ecosystem. Good for beginners.
Use when: you already use Proton Mail/Drive.
Transparent privacy company, no email signup, strong anti-tracking features, and clear ethics around marketing.
Use when: you want Mullvad-like values with more features.
Open source, audited, free for individuals, works everywhere. Self-host with Vaultwarden if you want full control.
Use when: you still reuse passwords (start here today).
Local-first password database. You control the file, the backups, and the sync method. Zero cloud dependency by design.
Use when: you don't want a third-party vault cloud.
Integrated with Proton accounts. Clean UX, hide-my-email aliases, and open-source apps.
Use when: you live in the Proton suite.
Encrypted email based in Switzerland. Easy onboarding, calendar/drive ecosystem, strong brand for privacy email.
Use when: switching off Gmail for the first time.
Encrypted email and calendar from Germany. Minimal tracking surface and transparent development.
Use when: you want a focused privacy-mail alternative.
Desktop email client with OpenPGP support. Use with any provider — including your own domain and self-hosted mail.
Use when: you want client-side control of mail.
No search history profiling for ads. Simple switch from Google that immediately cuts a major tracking vector.
Use when: you want zero friction privacy.
Independent indexes or privacy proxies for web results without building an ad profile around your queries.
Use when: DDG results aren't enough.
Self-hostable metasearch. Aggregate engines without handing one company your entire curiosity graph.
Use when: you run your own services.
End-to-end encrypted cloud storage. Better than trust-us consumer clouds for sensitive documents.
Use when: files must sync but stay encrypted.
Client-side vaults that sit on top of Dropbox, Google Drive, or any folder. Encrypt before upload.
Use when: you can't leave your current cloud yet.
Self-host files, photos, and calendars (Nextcloud) or peer-to-peer sync with no central server (Syncthing).
Use when: you're ready to leave big cloud entirely.
Open-source Android 2FA app with encrypted exports and no cloud lock-in. Prefer TOTP over SMS always.
Use when: replacing Google Authenticator.
Cross-platform open-source authenticator with optional encrypted sync. Clean alternative to proprietary 2FA apps.
Use when: you need 2FA on multiple devices.
Phishing-resistant MFA. Use security keys for email, password manager, GitHub, and critical accounts.
Use when: account takeover would be devastating.
Hardened Android for Pixel devices. Best mobile security/privacy posture available to consumers today.
Use when: phone security is non-negotiable.
Leave Windows telemetry behind. Fedora/Debian for daily driving; Qubes OS for serious compartmentalization.
Use when: desktop privacy is a long-term goal.
Strong sandboxing out of the box. Lock down with Lockdown Mode, limit iCloud, disable ad tracking, and review permissions.
Use when: you stay in Apple's ecosystem carefully.
Offline maps based on OpenStreetMap. Navigate without constantly broadcasting your location to Google.
Use when: maps without the surveillance tax.
Encrypted notes with cross-device sync. Keep journals and drafts out of plain-text cloud notes.
Use when: Apple/Google Notes feel too exposed.
The classic open-source browser content blocker. Pair with Firefox for excellent ad and tracker filtering on desktop.
Use when: you want a free FOSS extension alongside or under PrivyDeck.
DNS + firewall style protection for Android. Block tracker domains system-wide beyond the browser.
Use when: you need network-level blocking on Android apps.
Encrypted photo backup (Ente) or self-hosted Google Photos alternative (Immich).
Use when: leaving Google Photos.
Prefer E2EE voice/video. Avoid putting sensitive conversations on SMS or unencrypted defaults.
Use when: the call content matters.
By Vassbrekke AS · vassbrekke.no
Our personal privacy dashboard. Privacy score, one-tap tracker blocking on phone and browser, encrypted vault (with file sanitization and secure cleanup built in), and one-click data-access requests — no Raspberry Pi required.
Use when: you want the simplest all-in-one blocker, vault, and privacy score (start here before stacking extras).
By Vassbrekke AS · vassbrekke.no
Privacy compliance SaaS for websites. Scan trackers and consent gaps across 16 law frameworks, fix violations, and earn a verifiable Certified Private badge.
Use when: you run a website or app and need real compliance — not a generic policy template.
By Vassbrekke AS · vassbrekke.no
Enhance privacy on Windows 10 and 11 with GUI and CLI tooling — cut telemetry and tighten defaults (open source, VassDev).
Use when: you're on Windows and want practical hardening without a full OS switch yet.
By Vassbrekke AS · vassbrekke.no
Practical security hardening scripts for a fresh install — a solid starting point for locking down a system (open source, VassDev).
Use when: you're setting up Linux and want a fast, sane baseline.
Vassbrekke AS products are marked Ours and show a publisher line. We do not take payment for rankings. Suggest corrections on GitHub. Always verify download sources (official sites, F-Droid, App Store, Play Store).
Real life
The best VPN can't fix oversharing, weak locks, or a camera pointed at your desk. Privacy is a lifestyle system.
Mobile
Your phone is a tracking supercomputer you carry everywhere. Lock it down by platform.
Computers
Laptops hold your life's work. Encrypt the disk, minimize telemetry, and stop treating browsers like dumpsters.
Lost laptop without FDE = full data breach. Always encrypt disks.
Browser-built-in is better than nothing; Bitwarden/KeePassXC is better.
Unpatched OS/browser is the #1 easy compromise path.
Don't run daily work as admin/root. Don't install random .exe/.dmg.
3-2-1 backups with at least one offline/encrypted copy.
Treat cafés and airports as hostile networks.
Action plan
Tick items as you complete them. Progress saves in this browser only — nothing is uploaded.
Mindset
Protect against the risks you actually face — not a movie villain. Different jobs need different stacks.
You can't leak what you never collect. Share less, keep less, delete what you don't need.
One tool fails. Layer passwords, 2FA, encryption, updates, and good habits.
Open source isn't magic, but secrecy is a worse bet for security-critical software.
The private tool you abandon is worse than the good-enough tool you use daily.
Plan recovery: backups, key escrow you control, and accounts you can still reclaim.
FAQ
Not always. A VPN hides your traffic from local networks and your ISP, and can reduce location-based tracking — but it does not make you anonymous, and a bad VPN is worse than none. Use a reputable no-logs provider on hostile networks; combine with HTTPS, good browsers, and account hygiene.
Signal encrypts message content excellently. Your number is an identifier for discovery — a tradeoff for usability. If that matters for your threat model, look at Session or similar. For most people, Signal is still the best everyone-will-actually-use-it choice.
A password manager + unique passwords + authenticator 2FA on email. Most account takeovers are reused passwords and SIM swaps, not nation-state zero-days.
If you can, it helps a lot. If you can't, lock down profiles, strip personal data, stop real-time location posts, and use a browser container so trackers don't follow you across the whole web.
No analytics, no cookies for advertising, no third-party trackers for ads. Checklist progress stays in your browser's local storage only. Verify with your own blocker if you like — that's the point.
Read project docs for tools you adopt (Signal, Bitwarden, GrapheneOS, Mullvad). Community resources like privacyguides.org and official security whitepapers beat random top-10 VPN lists.
No. The guide is owned by the same company, which we disclose upfront. Independent tools are listed first; Ours are labeled. We publish conflicts and methodology on the Trust page. If a listing feels unfair, open a GitHub issue.
No. PrivGuide does not use affiliate links. Tips via crypto donations are optional and do not buy rankings.
Support
PrivGuide stays free, tracker-free, and independent. If it helps you, you can send a tip — no accounts, no middlemen.
Native Bitcoin (SegWit). Send BTC on the Bitcoin network only.
bc1qr2suucmufh36yay6g2wuhnema7fwmm549ug4ha
Private by default. Send XMR on the Monero network only.
46gac1uxB8i6rCcmb7t2VzUtogwPPp5yVBuxqVbS2YoDcFw9BZu2E5kBRngSZRtQPB5JzHw4paZHuGaeWZ89BUhYPiUB481
One address for Ethereum and other EVM chains (e.g. Polygon, Arbitrum, Base).
0x5e314E2bB8FfC67dD75629d104890B5feC520f1e
Send only on the matching network. Double-check the address before confirming.
Privacy is a practice, not a product. Pick a path, install one better app, tick one checklist item — then keep going.