Give away less, starting today.
Most of your exposure comes from ordinary signups โ a shop here, an app there. These are everyday habits that shrink your footprint, free, no dirigent report required.
One rule: only give false details where it's legal and harmless. Never on banking, ID, insurance, or anything contractual โ that's fraud, not privacy.
No affiliate links, no kickbacks โ just the tools we'd actually use.
01
Use email aliases
Give every service its own alias โ
Proton Pass,
SimpleLogin,
addy.io or
Firefox Relay (Apple users have Hide My Email built into iCloud+). When one leaks, you know exactly who leaked it โ and you can switch it off without changing your real address.
โ Keep track of which alias belongs to which service.
02
Keep a "signup" email
A second free address โ
Proton Mail or German-made
Tuta โ for newsletters, trials and one-off accounts keeps your real inbox out of the breach lists entirely.
โ Don't use it for anything you'd need to recover later.
03
A pseudonym where it's harmless
Food delivery, loyalty cards, raffles and newsletters rarely need your real name. A consistent pseudonym there shrinks what links back to the real you.
โ Never on banking, ID, insurance or contracts โ that's fraud.
04
A second phone number
A spare prepaid SIM or eSIM โ or a VoIP number (
Google Voice in the US,
MySudo in the US/Canada) โ for marketing and signups keeps your real number off the lists.
โ Some banks and 2FA reject VoIP โ keep your real number for critical logins.
05
Masked / virtual cards
Per-merchant virtual cards โ
Revolut across the EU and beyond,
Privacy.com in the US โ limit how far a leaked card travels; cancel one without touching your real card.
โ Subscriptions break if you cancel the card they're billed on.
06
Lock down what's public
Remove your birthday and family from LinkedIn, set
Strava privacy zones around home, tighten social defaults. The cheapest fixes โ and the ones attackers lean on most.
07
Unique passwords + passkeys
Reused passwords are how a decade-old breach becomes a live account takeover. A password manager โ
Bitwarden (free, open-source),
1Password or
Proton Pass โ plus passkeys where offered, ends it.
โ Protect the manager itself with a strong key and 2FA.
08
Opt out of brokers, freeze your credit
People-search sites resell your details. In the EU you can demand deletion under GDPR; elsewhere, opt out site-by-site or use a removal service like
Incogni. A credit freeze โ or a
Schufa block in Germany โ stops new accounts opened in your name.
โ Opt-outs need repeating; credit freezes are region-specific.