Skip to content
itzgee.com

Blog Guides

How to lock down your social media privacy settings

What a private account really hides, what your profile photo gives away, why stories show your routine, and the settings to change on each platform.

Geeitzgee.comUpdated 28 Sept 202610 min read

What “private” actually switches off

A private account controls who sees your posts. It doesn’t make you invisible. On every major platform, anyone can still see your name, username, profile photo and usually your follower counts. That’s on purpose: people need to know it’s you before they send a follow request.

The European Commission made the same point in July 2026. It sent TikTok preliminary findings saying its account settings for under-18s fall short of the Digital Services Act (the EU law on online platforms). Part of the complaint was that a teenager can switch to public in seconds. The other part was that even a private account leaves information on show.

A private account doesn’t stop a follower you approved taking a screenshot. And it doesn’t stop the platform, which sees everything either way. No setting reaches that, and it’s covered in a different article.

Your profile picture is the most public thing you own

It’s the one image that stays visible whatever you lock down, and it’s usually a clear, well-lit photo of your face. That’s exactly what facial recognition software needs.

This really happens. Clearview AI copied billions of images from the public web and social media, turned the faces into data it could match, and sold searches. The ICO (the UK’s data protection regulator) fined the company £7.5m in May 2022 and ordered it to stop. Clearview won an appeal in 2023 on whether UK law applied to it at all. In October 2025 the Upper Tribunal ruled that the regulator did have power over it, and sent the case back to be heard in full. Clearview was given permission to appeal again that December. Four years on the fine is unsettled, but nobody disputes the copying happened.

So, two things. First, a clear face photo can identify you for good, and you choose how clear a one to give away: an angle, a crop, a distant shot, or not your face at all. Second, and more useful, use a different profile photo on every platform. The same image everywhere lets anyone link your accounts, work and personal included, with a reverse image search (uploading a photo to find where else it appears).

ASSEMBLY
  1. 01the profile photoa clear face, public whatever settings you choose
  2. 02the bio and the tagsemployer, town, gym, school run, the dog's name
  3. 03the follower listwho trusts you, and who would believe a message from you
  4. 04this morning's storythe one thing that disappears, and the only one that shows where you are now

None of this is a hack. Every line is a setting you chose, or a default nobody changed. So the fix is settings and habits, not software.

Four public details, in the order somebody reads them.

Stories and status: the timing gives you away

A photo of a beach tells people you went to a beach. The same photo posted from the beach tells them your house is empty right now. Stories, status updates and live posts are the only part of social media that shows where you are at that moment, which makes them the riskiest part.

You don’t need to stop posting. Just post later. Put the holiday photos up when you get home. Post the restaurant on the way out, not on the way in. Leave off the location sticker. It’s optional, and it adds a map pin nothing else would have given away.

Then make the audience smaller. Instagram’s Close Friends, Snapchat’s private stories and WhatsApp’s status contact lists exist because “everyone who follows me” is the wrong audience for most stories. On Snapchat, turn on Ghost Mode on the Snap Map and leave it on. The map updates your location whenever you open the app, not just when you post.

And the 24-hour limit isn’t a safety feature. Anyone who saw the story could screenshot it, and you’ll rarely know.

What’s in the photo matters more than what’s in the file

People often ask about metadata (hidden details stored inside a photo file). Instagram, Facebook, X, TikTok, LinkedIn and Snapchat all remove GPS location and camera details from the copy other people can download. Sending it as a file or document can keep those details in, and the platform reads the original either way. So the risk is real but small, and it isn’t how people get caught out.

What catches people out is things in the picture nobody looked at twice. The house number behind your shoulder. The street sign at the end of the drive. A school logo on a jumper. A number plate. A work lanyard on the table, giving a stranger your employer, full name and face in one photo. A letter, a boarding pass barcode, or keys shown clearly enough to be copied.

Before you post, check the background, not the subject. You’ve already checked the subject.

The settings worth changing

Three questions cover almost everything: who can see, who can find, and who can contact. Menus move, so look for what a setting does, not where it sits.

Instagram and Facebook. Make the account private first. Then, in the settings for how people can find and contact you, turn off search by phone number and by email address. Turn on review for tags and mentions, so nothing appears on your profile unseen. Set stories to Close Friends by default. In ad settings, turn off activity from partners: the tracking of what you do on other sites, which comes back as targeted ads.

TikTok. Make the account private. Then find Suggest your account to others and turn off all of it: contacts, Facebook friends, and people who open or send you links. Separately, find contact syncing. Turn it off and delete what was already uploaded, because turning it off doesn’t remove the copy they already have. Hide your liked videos and following list, and choose settings for comments, direct messages, Duet, Stitch and downloads on purpose. Privacy International has a step-by-step walkthrough of these.

Snapchat. Turn on Ghost Mode on the Snap Map. Set Contact Me to Friends. Turn off See Me in Quick Add, which stops Snapchat suggesting you to strangers through friends you have in common. Set Who Can View My Story to a custom list, not everyone you’ve ever added.

X. Go to Privacy and safety, then Audience, media and tagging, then Protect your posts. Then go to Discoverability and contacts, and turn off both options that let people find you by your email address or phone number.

Look for that pair of find-me settings on every platform. They turn your phone number into a search tool both ways: your number finds your profile, and your profile confirms your number. They’re on by default nearly everywhere, and hardly anyone needs them.

How accounts actually get stolen

Hardly ever by guessing passwords. Four methods cover nearly all of it.

The scare. A message says you’ve broken copyright rules, with an appeal form and a 24 or 48 hour deadline. Trustwave, a security company, found one campaign that went further and asked victims for their two-factor backup codes. These are one-time codes that get round the second login step completely. The giveaway is where the link goes. A real notice appears inside the app, and never sends you to a website that isn’t the platform’s.

The flattery. An offer of a blue tick, a way to earn money, a brand deal, or a media kit to download. Same trick, good news instead of bad.

The favour. In August 2026 Malwarebytes described a version spreading through WhatsApp. A real contact messages you asking you to vote for a child in a competition. The link never asks for your password. It asks you to link a device, and the attacker appears in your account as another linked device. No reset email, no failed login alert, nothing to notice unless you check your linked devices. The older version is even simpler: someone forwards you a six-digit code “sent by mistake”. Send it back and they can move your number onto their phone.

The infostealer. This needs none of the above. Malware (harmful software) on your computer copies your saved passwords and, worse, your session cookies. A session cookie proves you’ve already logged in, so anyone who copies it skips the password and the second step. In November 2025 Europol’s Operation Endgame took down 1,025 servers behind one of these operations. It covered hundreds of thousands of infected computers and millions of stolen logins, and most victims had no idea.

These work because the message really comes from someone you know. Action Fraud calls this chain hacking. Each stolen account is used to get codes from that person’s contacts, so the attack comes from a face you trust.

Protecting your accounts, most important first

  1. Your email account first. Every other account can be reset through it. Give it your strongest password and your best second login step.
  2. A different password for every account. Criminals try passwords leaked from one site on others, which is how one old leak costs you four accounts.
  3. A passkey if it’s offered, an authenticator app if not, and text message codes last. A passkey lets you log in with your phone’s lock screen instead of a password. Meta added passkeys to Facebook in 2025, and support elsewhere is still patchy, so use whatever is there. Text codes beat nothing but lose to the rest, because your number can be moved to another SIM.
  4. Keep recovery codes offline. On paper, in a safe, in a password manager, anywhere except typed into a page that asked for them.
  5. Check active sessions and linked devices. Check both. The linked-device trick doesn’t show up anywhere else, and it takes ten seconds to check.
  6. Never pass on a code. Not to support, not to a brand, not to your sister. If your sister asks, ring your sister.

To see what a platform holds about you, a subject access request works on all of them and costs nothing.

If it’s already happened

Change your email password first, or the attacker just resets the account again. Then change the account password and log out every session and linked device. Check that the recovery email and phone number are still yours, because changing those is usually the first thing an attacker does.

Then warn your contacts, quickly and publicly. With chain hacking, the people most likely to be targeted next are the ones in your messages.

In the UK, report it to Action Fraud on 0300 123 2040, or Police Scotland on 101. Forward phishing emails to [email protected]. It helps: account hacking is the most-reported cybercrime in the country, with 35,434 reports in 2024 compared with 22,530 the year before. Reports are how anyone learns how big the problem is.

In fairness to the platforms

The privacy settings on these platforms are better than people think. A private account does what it says. Tag review works. Meta now makes under-18s’ accounts private with limited messaging by default, and TikTok does the same for 13 to 17 year olds. Defaults matter more than settings pages, because almost nobody opens one. Regulators are pushing on all of this, which is why the defaults have changed at all.

Keep the risk in proportion, too. Few people reading this interest a skilled attacker. The realistic risk is someone working through a list with a ready-made phishing kit, and the steps above stop them.

But every one of those settings has one thing in common. They all control what other users can see. None of them controls the platform, which reads your private posts, the removed metadata and your deleted drafts alike. A settings page can’t change that, and it’s the reason some things are worth running yourself.

Settings control who can see your posts. Habits control who can get into your account.

Written by

Gee

We run itzgee.com, a private cloud in daily use, on servers run by us. How it works has the full picture.