itzgee.com

How to lock down your social media privacy settings

What a private account really hides, what your profile photo gives away, why stories leak your routine, and the settings worth changing per platform.

social-mediaprivacyphishingaccount-securitysecurity

What “private” actually switches off

A private account controls who sees your posts. It does not make you invisible. On every major platform your display name, your username, your profile photo and usually your follower counts stay visible to anybody who lands on the profile. That is deliberate — somebody has to be able to tell it is you before they send a follow request.

The European Commission made the same point in July 2026 when it sent TikTok preliminary findings that its account settings for minors fall short of the Digital Services Act. Part of the complaint was that a teenager can switch to public in seconds. The other part was that even a private account leaves information exposed.

Two things a private account does not do at all. It does not stop an approved follower screenshotting, and it does not stop the platform, which sees the lot either way. That second limit is the one no toggle reaches, and it is the subject of a different article.

Your profile picture is the most public thing you own

It is the one image that stays visible whatever else you lock down, and it is usually a clear, well-lit, face-on photograph. That is exactly the input a facial recognition system wants.

This is not hypothetical. Clearview AI built a searchable database by scraping billions of images from the public web and social media, mapping the faces into vectors, and selling lookups. The ICO fined the company £7.5m in May 2022 and ordered it to stop. Clearview won on appeal in 2023 on the narrow question of whether UK law reached it at all, and in October 2025 the Upper Tribunal restored the regulator’s jurisdiction, sending the case back to be heard on its merits. Clearview was granted permission to appeal again that December. Four years on, the fine is still unresolved — but nobody disputes the scraping happened.

Two practical consequences. First, a face-on photo is a permanent biometric anchor, and you can decide how good an anchor to hand over: an angle, a crop, a distance shot, or something that is not your face at all. Second, and more immediately useful, use a different profile photo on every platform. An identical image is the single easiest way for anybody to link your accounts together with a reverse image search — including a work account to a personal one.

ASSEMBLY
  1. 01 the profile photo a clear face, public on every account setting there is
  2. 02 the bio and the tags employer, town, gym, school run, the dog's name
  3. 03 the follower list who trusts you, and who would believe a message from you
  4. 04 this morning's story the one thing that expires, and the only one that says where you are now

None of this is a breach. Every line is a setting you chose, or a default nobody changed — which is why the fix is settings and habits, not software.

Four public fields, in the order somebody reads them.

Stories and status: the timing is the leak

A photo of a beach tells somebody you went to a beach. The same photo posted from the beach tells them your house is empty right now. Stories, status updates and live posting are the only part of social media that broadcasts your position in time, and that is what makes them the sharpest edge of the whole thing.

The fix is not to stop posting. It is to break the link between the event and the post. Put the holiday photos up when you get home. Post the restaurant on the way out, not on the way in. Leave the location sticker off entirely — it is a voluntary field that adds a map pin nothing else on the platform would have given away.

Then narrow the audience. Instagram’s Close Friends list, Snapchat’s private stories and WhatsApp’s per-status contact list all exist because “everyone who follows me” is the wrong audience for most of what people post to a story. On Snapchat, Ghost Mode on the Snap Map is worth turning on and leaving on; the map updates your position every time you open the app, not just when you post.

And treat the twenty-four hour expiry as a presentation choice rather than a security feature. Anybody who saw it could screenshot it, and on most platforms you will never know.

What is in the frame beats what is in the file

The metadata question comes up constantly, so: Instagram, Facebook, X, TikTok, LinkedIn and Snapchat all strip GPS coordinates and camera details from the copy other people can download. Sharing a photo as a file or document rather than as a photo can preserve them, and the platform itself read the original on the way in regardless. So the metadata risk is real but modest, and it is not where people actually get caught.

What catches people is visible detail nobody looked at twice. The house number behind your shoulder. The street sign at the end of the drive. A school logo on a jumper. A number plate. A work lanyard on the kitchen table, which gives a stranger your employer, your full name and your face in one frame. A letter, a boarding pass barcode, a set of keys photographed sharply enough to be cut.

Look at the background before you post, not the subject. The subject is the part you already checked.

The settings worth changing

Three questions cover almost everything: who can see, who can find, and who can contact. Menus move constantly, so work by function.

Instagram and Facebook. Private account first. Then, under how people can find and contact you, turn off lookup by phone number and by email address. Turn on review for tags and mentions so nothing attaches to your profile unseen. Set stories to Close Friends by default. In ad settings, turn down activity received from partners — the off-platform tracking that follows you around and comes back as targeting.

TikTok. Private account, then Suggest your account to others, and turn off all of it: contacts, Facebook friends, and people who open or send links to you. Separately, find contact syncing, turn it off and delete what was already uploaded — turning the toggle off does not remove the existing copy. Hide your liked videos and your following list, and set comments, direct messages, Duet, Stitch and downloads deliberately. Privacy International keeps a step-by-step walkthrough of these.

Snapchat. Ghost Mode on the Snap Map. Contact Me set to Friends. See Me in Quick Add off, which stops your profile being suggested to strangers through mutual connections. Who Can View My Story set to a custom list rather than everyone you have ever added.

X. Privacy and safety, then Audience, media and tagging, then Protect your posts. Then Discoverability and contacts, and turn off both options that let people who have your email address or phone number find you.

That discoverability pair deserves singling out on every platform that has it. It turns your phone number into a lookup key in both directions: somebody with the number finds the profile, and somebody with the profile can confirm the number. It is on by default nearly everywhere, and almost nobody needs it.

How accounts are actually stolen

Not by guessing passwords. Four routes cover the overwhelming majority.

The scare. A message or email claiming a copyright violation, with an appeal form and a deadline of twenty-four or forty-eight hours. Trustwave documented a campaign that went a step further and asked victims for their two-factor backup codes, which are single-use and bypass the second factor entirely. The tell is always the destination: a genuine platform notice appears inside the app, and never sends you to a domain that is not the platform’s.

The flattery. Verification, monetisation, a brand partnership, a media kit to download. Same mechanism, opposite emotion.

The favour. In August 2026 Malwarebytes wrote up a version spreading through WhatsApp — a message from a real contact asking you to vote for a child in a competition. The link never asks for your password. It asks you to link a device, and the attacker’s session simply appears in your account as another linked device. No password reset email, no failed login alert, nothing to notice unless you go and look at the linked devices list. The older variant is simpler still: someone forwards you a six-digit code “sent by mistake”, and passing it back lets them register your number on their phone.

The reason these work is that the message genuinely comes from somebody you know. Action Fraud calls the pattern on-platform chain hacking — each stolen account is used to harvest codes from its own contacts, so the attack arrives wearing a face you trust.

The infostealer. This one needs none of the above. Malware on the machine lifts saved passwords and, more importantly, session cookies. A session cookie is proof that a login already happened, so replaying it skips the password and the second factor together. Europol’s Operation Endgame took down 1,025 servers behind one such operation in November 2025, covering hundreds of thousands of infected computers and millions of stolen credentials — and most of those victims had no idea they were infected.

Hardening, in the order that matters

  1. The email account first. Every other account resets through it. It deserves your strongest password and your best second factor.
  2. A unique password per account. Reuse is what credential stuffing feeds on, and it is why one old breach takes four accounts.
  3. Passkey where offered, authenticator app otherwise, SMS last. Meta added passkeys to Facebook in 2025 and support across the industry is still patchy, so take what is there. SMS is better than nothing and worse than everything else, because a number can be moved to another SIM.
  4. Recovery codes offline. On paper, in a safe, in a password manager — anywhere except typed into a page that asked you for them.
  5. Review active sessions and linked devices. Do both. The linked-device attack shows up nowhere else, and takes ten seconds to check.
  6. Never pass on a code. Not to support, not to a brand, not to your sister. If your sister asks, ring your sister.

If you want to know what a platform is holding while you are in there, the subject access request route works on all of them and costs nothing.

If it has already happened

Change the email password before the social account, or the attacker simply resets it back. Then change the account password, revoke every session and linked device, and check that the recovery email and phone number are still yours — swapping those is usually the first thing an attacker does.

Then tell your contacts, quickly and publicly. Chain hacking means the people most likely to be hit next are the ones in your messages.

In the UK, report it to Action Fraud on 0300 123 2040, or Police Scotland on 101, and forward phishing emails to [email protected]. It is worth doing: account hacking is the most-reported cybercrime in the country, with 35,434 reports in 2024 against 22,530 the year before, and reports are what tell anyone the scale of it.

Being fair about it

The privacy controls on these platforms are better than their reputation. A private account does what it says. Tag review works. Meta now puts under-18s into private accounts with restricted messaging by default, TikTok does the same for 13-to-17s, and defaults matter far more than settings pages because almost nobody opens a settings page. Regulators are pushing on all of it, which is why the defaults have moved at all.

It is also worth keeping the threat in proportion. Very few people reading this are of interest to anybody sophisticated. The realistic risk is an opportunist working a list with a phishing kit, and the measures above stop an opportunist cold.

But notice what every one of those controls has in common. They all govern what other users can see. Not one of them governs the platform, which reads the private posts, the stripped metadata and the deleted drafts alike. That is the boundary a settings page cannot cross, and the reason some things are worth running yourself.

Settings decide who watches. Habits decide who gets in.

more in guides

← back to blog more in guides →