Social media platforms are designed to collect as much information about you as possible and share it as broadly as their settings allow — the data is their product. The default privacy settings on social media across Facebook, Instagram, X (Twitter), LinkedIn, and TikTok are optimised for the platform’s data collection interests, not yours. If you’ve never adjusted these settings, you’re almost certainly sharing far more than you intend with far more people than you realise. If you want the full context, see our Complete Guide to Security and Privacy.
Two distinct layers need attention: audience visibility settings (who can see your posts) and data sharing settings (what the platform shares behind the scenes with advertisers and data brokers). Adjusting only the visibility layer while leaving data sharing defaults untouched addresses only half the problem.
Platform-by-platform settings audit
A settings audit across the platforms you actively use is the most impactful single action available. Most users created accounts years ago, accepted defaults, and never returned to the privacy menu. Platforms periodically introduce new data collection features that are automatically enabled for existing users — these slip through unnoticed without periodic review.
Facebook: Settings & Privacy → Privacy Checkup runs you through a guided review of post visibility, contact permissions, and data use. The most important setting most users haven’t changed: Settings → Ads → Ad Preferences → Ad settings → “Data about your activity from partners” → Off. This stops Facebook from tracking your activity on third-party websites via its pixel network. It doesn’t reduce ads — it stops the cross-site surveillance that follows you around the web. Separately, Settings → Your Facebook Information → Off-Facebook Activity → “Future off-Facebook Activity” → Off disconnects the continuous off-platform data stream from your account. These two settings together address what Facebook knows about your life outside the app itself.
Instagram: Settings → Privacy → Account Privacy → Private account restricts post visibility to approved followers. Story sharing controls (Settings → Privacy → Story → Sharing) prevent resharing outside your approved audience. Since Instagram and Facebook share the same data infrastructure, the Meta Privacy Checkup accessible from either platform covers the shared ad and data settings.
X (Twitter): Settings → Privacy and safety → Audience and tagging. “Protect your posts” switches to a private account where only approved followers see content. Disable “Allow others to find you by phone/email” and turn off location information on tweets. By default, X is fully public — every post is indexed by search engines and visible to anyone with no account required.
LinkedIn: Settings → Privacy → Profile viewing options → controls what others see when you view their profile. Activity broadcasts → Off prevents your network from being notified of profile changes. Settings → Data privacy → Third-party data sharing → Off limits LinkedIn’s sharing with its advertising partners.
TikTok: Privacy → Private account → On (new accounts default to fully public). Settings → Privacy → Suggest your account to others → Off removes your profile from location-based and contact-based discovery. Comments and direct messages can be restricted to followers or no one.
Platform comparison at a glance
| Platform | Default audience | Most important settings to change | Off-platform tracking? |
| Friends | Ad preferences → Data from partners → Off; Future posts → Only me or Friends | Heavy (Meta pixel, partner network) | |
| Public (new accounts) | Private account; Story sharing controls | Heavy (shared with Facebook) | |
| X (Twitter) | Public | Protect posts; disable location; disable find by phone/email | Moderate (ad targeting, data licensing) |
| Connections | Activity broadcasts off; third-party data sharing off | Moderate (ad network, recruiter data) | |
| TikTok | Public | Private account; Suggest your account → Off | Significant (device data collection) |
| Snapchat | Friends only | Ghost Mode (location); Who can find me | Limited compared to others |
X and TikTok both default to fully public — every post visible to the entire internet, indexed by search engines, accessible without an account. New account holders who’ve never adjusted settings have shared everything publicly by default. Switching to private/protected mode is the first and most impactful single change on these platforms.
Location data — the most overlooked exposure
Location information is among the most sensitive data social platforms collect, and one of the easiest to unknowingly share. Two distinct sources:
EXIF metadata in photos: smartphone photos embed GPS coordinates in the image file. Most platforms strip this on upload, but this behaviour has changed multiple times across platforms and isn’t guaranteed. The safest approach: disable location tagging in the phone’s camera settings before taking photos intended for social media posting.
Platform-level location tags: the “Add location” prompt when posting is a deliberate action, but habits form quickly. A complete timeline of location tags across years of posts creates a detailed movement record revealing home address, workplace, frequently-visited venues, and daily routines. Limit location tags to general city-level information for travel posts rather than specific venue information for daily life. Removing precise location data from past posts is available through most platforms’ post editing interface.
Location-based discovery features deserve specific attention. Snapchat’s Snap Map shows your real-time location to all contacts unless Ghost Mode is enabled (Settings → Privacy → My Location → Ghost Mode → On). TikTok’s suggestion features use device location to recommend your profile to people physically near your regular locations — disabling “Suggest your account to others” removes your profile from this discovery entirely.
Profile information hygiene
The information displayed on social profiles is frequently more than the platform actually needs. Phone numbers, email addresses, birth dates, employers, schools, home cities, and relationship statuses are all data points that social engineering attackers use to craft targeted phishing attacks, reset account credentials, or build profiles for identity theft.
Review each profile field and remove or restrict anything not essential to how you actually use the platform. Profile information has scope settings independent of post visibility — on Facebook, your phone number might be visible to “Friends” even if your posts are “Only me,” making the phone number more public than the posts. Settings → Privacy → How people find and contact you covers phone number, email, and search engine indexing. Setting these to “Only me” removes the ability to find your account through phone number lookup — a deanonymisation vector that has been used to link accounts people thought were separate from their real identity.
Third-party application access is one of the largest but least visible privacy exposures on most platforms. Apps that offered “Sign in with Facebook” or “Sign in with Twitter” received ongoing access to account information — sometimes including reading posts, accessing the friend list, and posting on your behalf — that persists indefinitely after a single use. Review and revoke these regularly:
- Facebook: Settings → Apps and Websites → remove inactive or unnecessary apps
- X/Twitter: Settings → Security and account access → Apps and sessions
- LinkedIn: Settings → Data Privacy → Third-party applications
- Google (for Sign in with Google): myaccount.google.com/security → Third-party apps with account access
The average social media user has dozens of third-party applications with active access permissions — most from services used once and forgotten. Treat this as a quarterly maintenance task, not a one-time cleanup.
Our guide on checking if your email was hacked covers the connected app audit for email accounts that parallels this social media review, and our guide on protecting your online identity covers the broader identity security context. For country-specific data access and deletion rights, the Privacy Rights Clearinghouse covers how to exercise data subject rights under GDPR, CCPA, and other privacy frameworks.
Long-term habits that matter
Privacy on social media isn’t a one-time configuration — it’s shaped by daily habits.
The most important habit is pausing before posting: would you be comfortable with an unknown employer, a future landlord, or a determined adversary seeing this? Content shared publicly persists even after deletion through screenshots, archive services like the Wayback Machine, and cached copies. Information that seems harmless in isolation can combine with other public posts to reveal more than intended.
Reviewing and auditing old content is neglected but important. Most platforms provide data download tools that reveal all your historical posts, likes, comments, and metadata. Facebook’s Activity Log and Manage Activity tools allow bulk-archiving or deleting old posts. Third-party services built on X’s API allow bulk removal of old tweets. Periodically curating the public record you’ve created is as important as controlling what you share going forward.
Children and household members: a family member’s inadvertent public post tagging your location or sharing household information affects your privacy as well as theirs. Platforms like Instagram Supervision and TikTok Family Pairing allow monitoring and restricting younger users’ privacy settings. Understanding social media privacy extends to everyone in your household whose accounts could indirectly expose your information through shared tags, posts, or check-ins.
If you decide to leave a platform: account deletion rather than deactivation is the correct choice. Deactivated accounts retain all data and remain accessible to platform analytics and data partner sharing. Under GDPR (EU users) and various US state privacy laws, every major platform is required to provide data deletion. Facebook’s “Delete account” option is permanent and removes all data from Meta’s servers within 30 days — more thorough than deactivation, which preserves everything.
Social media privacy is genuinely possible without abandoning social networking. The platforms want you to believe that sharing everything is the cost of using the service — the settings exist to prove otherwise. Using them actively means using the platform on your terms rather than the platform’s default terms.
The Facebook Off-Facebook Activity tool — the setting most users never find
This is worth its own section because it’s that important. Facebook’s “Off-Facebook Activity” page (Settings → Your Facebook Information → Off-Facebook Activity) shows exactly which websites and apps have sent your browsing data to Meta via the Facebook pixel — regardless of whether you were logged into Facebook while visiting those sites. The off-platform data feed is continuous and follows you across the web through tracking pixels embedded on millions of commercial websites.
What you typically see in this report surprises most users: news sites, retailers, restaurants, healthcare providers, government services — any site that uses Facebook advertising infrastructure has likely sent your visit data to Meta. This data is linked to your Facebook account profile and used for ad targeting, audience modelling, and content ranking.
To limit this going forward: Settings → Your Facebook Information → Off-Facebook Activity → “More options” → “Manage future activity” → “Disconnect future activity.” This stops new off-platform data from being linked to your account. It doesn’t delete historical data (Facebook keeps it disconnected from your account but in anonymised form), and it doesn’t stop the pixel from firing on external sites — it just disconnects the data from your specific account profile.
Clearing the accumulated history: same page → “Clear history.” This doesn’t delete the data from Facebook’s servers but disconnects it from being associated with your profile for ad targeting. It’s imperfect, but it’s the control Facebook makes available.
What social media platforms know beyond what you post
Beyond the posts, likes, and comments you deliberately create, social platforms collect:
- Behavioural data: what you click, how long you hover over specific content, what you type but don’t post, what you screenshot, what you search for within the app
- Device data: phone model, operating system version, battery level, screen resolution, installed apps (TikTok is particularly noted for device data breadth)
- Network data: IP address, WiFi network name, nearby Bluetooth devices
- Cross-app data: if you’ve given the social app camera, microphone, contacts, or location permissions, that data is accessible to the app beyond your deliberate sharing
Reviewing and restricting app permissions at the operating system level — not just within the app — addresses some of this collection:
- iOS: Settings → [App name] → review each permission individually
- Android: Settings → Apps → [App name] → Permissions → review and restrict as needed
For most social apps, camera and microphone permissions can be set to “Ask each time” or “Only while using the app” rather than “Always allow.” Location can be set to “While using the app” rather than “Always.” Contacts access should be disabled entirely on any platform you don’t want to use your contact list for “People You May Know” style suggestions. Our guide on Online Privacy Tools covers an adjacent issue.
The combination of platform-level privacy settings, off-platform tracking controls, third-party app revocation, regular old content auditing, and OS-level permission management covers the major exposure vectors for most social media users. None of these steps individually provides comprehensive privacy — but together they represent a substantially more private social media experience than the default state that most accounts exist in indefinitely. See also Biometric Data Privacy for a related case.







