Skip to content
Bellator Cyber Guard
Personal Cybersecurity45 min readDeep Dive

Social Media Privacy Settings Guide: Lock Down Your Accounts

Lock down Facebook, Instagram, LinkedIn, TikTok, and X with this social media privacy settings guide. Platform-by-platform steps to protect your data in under an hour.

By Bellator Cyber Guard Security Team
Social Media Privacy Settings Guide: Lock Down Your Accounts — social media privacy settings guide

Why Your Default Social Media Privacy Settings Put You at Risk

Every major social media platform ships with settings configured for maximum engagement, not maximum protection. Your full name, date of birth, employer, hometown, and personal photos may be publicly indexed by search engines and visible to anyone with an internet connection, including people who want to use that information against you.

This social media privacy settings guide gives you a platform-by-platform action plan covering Facebook, Instagram, LinkedIn, TikTok, and X (formerly Twitter). Most people can complete the core changes in under an hour, and the protection is immediate.

The threat is concrete. Cybercriminals use Open-Source Intelligence (OSINT) techniques to scrape social profiles for data that fuels targeted attacks: phishing emails referencing your real employer and colleagues, account recovery bypasses using your date of birth and childhood hometown, and fraudulent tax returns filed using your personal identifiers. According to Pew Research Center, 72% of U.S. adults actively use at least one social media platform, creating an enormous pool of exposed personal data.

If you haven't reviewed your settings since creating your accounts, you are almost certainly sharing far more than you intend. The personal cybersecurity risks created by social media oversharing extend beyond your own accounts. Your visible profile exposes colleagues, family members, and professional contacts, giving attackers a ready-made social graph to exploit in targeted campaigns.

Social Media Privacy: The Exposure at a Glance

72%
U.S. Adults on Social Media

Share personal details via at least one major platform, per Pew Research Center

87M
Profiles Harvested

Facebook profiles affected in the 2018 Cambridge Analytica incident via third-party app permissions

#1
Most-Reported FTC Complaint

Identity theft has topped FTC consumer complaint reports for over a decade

How Attackers Use Your Public Profile Against You

Threat actors who target individuals for financial fraud, account takeover, or spear-phishing follow a consistent playbook that starts with passive reconnaissance. They don't need to hack anything. They read your profile.

A public Facebook profile might reveal your full name, date of birth, hometown, relationship status, employer, and school history. LinkedIn adds your job title, reporting structure, and recent projects. Instagram exposes your daily routines, travel patterns, and social circle. TikTok reveals your interests, location check-ins, and behavioral patterns through posted videos.

Individually, each piece seems harmless. Combined, they give attackers enough material to answer knowledge-based security questions, craft targeted spear-phishing emails that reference your real employer and colleagues, bypass account recovery processes that rely on personal identifiers, and build synthetic identity profiles used in tax identity theft schemes.

The MITRE ATT&CK framework classifies this passive data collection as the first stage of most targeted attacks. The information is already public, so there is nothing to detect. Every piece of personal data you share publicly lowers the barrier to becoming a victim.

Your Privacy Settings Can Reset Without Warning

Social media platforms update their privacy policies frequently and often introduce new data-sharing features with permissive defaults, sometimes tucked behind a notification you dismissed or buried in an updated terms-of-service rollout. A settings review done two years ago may not reflect your current exposure. This social media privacy settings guide is most effective when it becomes a recurring practice rather than a one-time task.

How to Complete Your Social Media Privacy Audit

1

Run Each Platform's Built-In Privacy Checkup

Facebook, Google, and several other platforms offer guided privacy wizards. Start there to address the highest-priority settings quickly before diving into manual adjustments.

2

Lock Down Post and Profile Visibility

Set future post visibility to Friends or Connections only. Use retroactive restriction tools where available (Facebook's Limit Past Posts). Remove personal identifiers such as date of birth, phone number, and specific hometown from bio fields that default to public.

3

Audit and Revoke Third-Party App Access

Navigate to Connected Apps or Apps and Websites in each platform's settings. Remove anything you don't actively use, and pay close attention to apps with access to your friends or connections list.

4

Verify Account Recovery Contacts and Enable MFA

Confirm that recovery email addresses and phone numbers are current on every platform. Enable multi-factor authentication (MFA) using an authenticator app rather than SMS where the option is available.

5

Address Data Broker Exposure

Submit opt-out requests to major data broker sites. Platform settings only control what others see on the platform itself. Data brokers aggregate your information from external sources regardless of your social media privacy settings.

6

Schedule a Recurring Six-Month Review

Set a calendar reminder to revisit all settings twice per year. After major platform updates, check post visibility, connected apps, and location permissions before exploring new features with permissive defaults.

Facebook Privacy Settings: The Most Impactful Changes

Facebook offers more granular privacy controls than most platforms, but finding them requires deliberate effort. Start with Settings and Privacy, then select Privacy Checkup. This built-in wizard steps you through the highest-priority controls in sequence and is the fastest entry point for anyone using this social media privacy settings guide for the first time.

Posts and Profile Visibility

Under Settings, go to Privacy, then Your Activity. Set "Who can see your future posts?" to Friends. Then use the "Limit Past Posts" tool to retroactively restrict all previous public posts to Friends only. This is a one-way change that cannot be reversed globally, so save anything you want to preserve before running it.

In Settings, then Profile and Tagging, turn on tag review so every tag from another user goes into an approval queue before appearing on your timeline. This prevents others from publicly linking you to events or locations without your knowledge, which matters especially for professionals whose employer relationships should remain private.

Search Engine Visibility

Under Settings, then Privacy, then How People Find and Contact You, disable "Do you want search engines outside of Facebook to link to your profile?" This removes your Facebook profile from Google and Bing results over the following weeks. Also change "Who can send you friend requests?" to Friends of friends to reduce exposure from fake and throwaway accounts.

Connected Apps and Websites

Go to Settings, then Apps and Websites. Most longtime users will find dozens of applications with active read access they've forgotten about. Remove anything you don't actively use, and pay particular attention to apps that requested access to your friends list. These apps frequently harvest social graphs, not just your own data. Phishing campaigns often begin with data pulled from dormant app connections, giving attackers verified social relationships to reference in targeted messages.

Instagram and LinkedIn: Platform-Specific Controls

Instagram

The single most impactful Instagram change is switching from a public account to a private account. Go to Settings, then Account Privacy, and toggle on Private Account. All future follower requests must be approved before those accounts can view your posts or stories. For existing followers, your content remains visible immediately. This setting only gates new requests going forward.

Beyond that, disable your activity status under Settings, then Privacy, then Activity Status, so others can't see when you're online. In Settings, then Privacy, then Story, restrict who can reshare your stories and turn off the option that allows others to add your posts to their own. Review connected apps under Settings, then Apps and Websites, and revoke anything inactive. Instagram's Close Friends list lets you share content with a vetted subset of followers, which is useful for professionals who want some personal content visible without broadcasting it to everyone who has followed you.

LinkedIn

LinkedIn requires a different balance. You want to be discoverable by legitimate professional contacts, but not expose personal data to bad actors. Go to Settings, then Visibility, then Profile Viewing Options, and set yourself to appear as "LinkedIn member" when browsing other profiles. This prevents competitors or social engineers from seeing who is researching them.

Under Settings, then Visibility, then Connections, hide your connections list. A visible network is a ready-made targeting list for anyone impersonating a colleague, a tactic frequently used in Business Email Compromise (BEC) schemes. Also turn off data sharing with third-party applications under Settings, then Data Privacy, and disable the "People also viewed" widget on your profile page. Remove your personal phone number and personal email from your contact info section entirely. A work email address is sufficient for professional discovery.

TikTok and X: Locking Down the Most Permissive Defaults

TikTok

TikTok's algorithm relies heavily on personal data, making its privacy settings especially important to review. The platform's defaults are among the most permissive of any major social media service. Switch to a private account under Settings, then Privacy, then Privacy and Safety. Turn off all "Suggest your account to others" features that draw on your phone contacts, Facebook friends, or browsing patterns.

Disable location services entirely and review which personal information appears in your bio. TikTok also enables personalized advertising by default using data from your device and browsing history outside the app. Under Settings, then Privacy, then Ads Personalization, turn off both on-platform and off-platform data use. This doesn't eliminate ads, but it stops the platform from building a behavioral profile tied to your device's broader activity.

X (Formerly Twitter)

In Settings, then Privacy and Safety, then Audience and Tagging, enable "Protect your posts" to make your account private. Under Settings, then Privacy and Safety, then Location Information, turn off precise location access and remove stored location data from past posts. X collects granular location data by default. Disabling it going forward does not delete historical records, so submit a data deletion request through the platform's privacy settings if past location exposure concerns you.

Also review Settings, then Privacy and Safety, then Data Sharing and Off-X Activity. This controls whether X tracks your behavior on external websites. Turn off all off-platform data collection. Under Ads Preferences, opt out of interest-based and data-partner advertising to reduce the cross-site tracking profile the platform maintains on your account.

Social Media Privacy Settings Checklist

  • Set future Facebook post visibility to Friends only
  • Use Facebook's Limit Past Posts tool to restrict old public content
  • Enable Facebook tag review before content appears on your timeline
  • Disable Facebook profile indexing by search engines
  • Revoke all unused Facebook connected apps, especially those with friends list access
  • Switch Instagram to a private account requiring follower approval
  • Disable Instagram activity status so others cannot see when you're online
  • Turn off Instagram story resharing and external post additions
  • Review and revoke inactive Instagram connected apps
  • Enable LinkedIn anonymous browsing mode
  • Hide your LinkedIn connections list from other members
  • Remove personal phone number and email from LinkedIn contact info
  • Turn off LinkedIn third-party data sharing under Data Privacy settings
  • Switch TikTok to a private account
  • Disable TikTok contacts sync and Facebook friend suggestions
  • Turn off TikTok off-platform ad personalization
  • Disable TikTok location services
  • Enable Protect Posts on X (Twitter) to restrict your account to approved followers
  • Remove stored location history and disable future location collection on X
  • Turn off Off-X Activity tracking in X privacy settings
  • Enable multi-factor authentication on every social media platform
  • Use a unique, strong password for each platform and store them in a password manager
  • Remove date of birth, specific hometown, and phone number from all bio fields
  • Verify account recovery email addresses and phone numbers are current on every platform

Third-Party Apps: The Biggest Blind Spot in Your Privacy Settings

Connected applications represent the largest overlooked gap in any social media privacy settings review. When you sign up for a service using "Login with Facebook" or grant an app permission to post on your behalf, that application receives an access token with specific permissions. These tokens typically don't expire automatically, even after you stop using the service.

Popular fitness apps, gaming platforms, and productivity tools accumulate these permissions over years. Even after you delete the game or stop using the service, the app often retains the ability to read your profile data and friend lists, and in some cases post content on your behalf. Data brokers draw on these dormant connections as a data source because users rarely think to revoke them.

The most dangerous permissions involve friend list access. Apps that can read your social graph frequently mine that data to build targeting profiles for advertising or sell contact information to third parties. Games that request friend list access to enable social features often retain and monetize that data long after you've uninstalled them. The 2018 Cambridge Analytica incident demonstrated the scale of this risk: permissions granted to a third-party quiz app were used to harvest data from 87 million Facebook profiles without direct user consent.

The same principle applies to any service where you use a social login. "Sign in with Facebook" and "Sign in with Google" create a single point of failure. If your social account is compromised through a phishing attack or credential breach, every linked service is also at risk. Where possible, create standalone credentials and manage them with a dedicated password manager. For the identity security standard that governs how these authentication flows should work, see the NIST SP 800-63B Digital Identity Guidelines.

Review your connected apps at least once per year, or whenever a major breach involving a social platform is reported. Revoke access for everything that isn't actively in use.

Bottom Line

Third-party app access is the most dangerous and least-reviewed element of social media privacy. Remove every app you don't actively use, disable friend list access wherever it isn't necessary, and avoid using social logins for unrelated services. Each permission granted is a persistent data pipe that continues flowing long after you've forgotten it exists.

Privacy Mistakes That Leave You Exposed After Updating Settings

Reviewing Settings Only Once

Completing a privacy review and considering the job done is the most common mistake. Social media companies routinely introduce new features with permissive defaults. Scheduling a semi-annual review ensures nothing has changed without your knowledge. When a major platform update ships, check post visibility, connected apps, and location permissions before exploring new features.

Commenting on Public Posts

Your account's privacy settings protect your own posts, not your replies on other people's public content. A comment on a news outlet's post or a public figure's update is visible to anyone who views that thread, regardless of your account's privacy level. Your comment history is accessible to anyone online. For professionals whose employers are identifiable from their profile, a pattern of public comments can reveal political views, personal circumstances, or employer relationships that a locked-down profile deliberately hides.

Neglecting Account Recovery Options

Users who enable strong passwords and multi-factor authentication sometimes leave account recovery pointing to an email address they no longer control or a disconnected phone number. Attackers regularly exploit stale recovery options as the path of least resistance. The strongest account password means nothing if recovery routes to an abandoned inbox. Verify your recovery contacts on every social platform at least once per year.

Password Reuse Across Platforms

Password reuse turns a single breach into a cascade of account takeovers. The Cybersecurity and Infrastructure Security Agency (CISA) recommends a unique, strong password for every account. Attackers automate reuse attacks using exposed credential lists in a technique called credential stuffing. If one platform exposes your password, every account sharing it is immediately at risk. A dedicated password manager eliminates the friction of maintaining unique credentials across dozens of accounts.

Oversharing in Bio Fields

Even with post visibility locked down, many users leave their full date of birth, current city, employer, and phone number visible in profile bio sections that default to public. These fields feed directly into the OSINT reconnaissance process. Remove or generalize any bio field that isn't professionally necessary. Your date of birth is particularly sensitive: it appears in multiple account recovery flows and is one of the primary identifiers used in financial identity theft.

Advanced Controls for High-Risk Individuals

Certain professions and personal circumstances require additional privacy measures beyond the standard settings adjustments. Healthcare workers, legal professionals, financial advisors, tax preparers, and public figures face elevated targeting from social engineers who view professional data as a gateway to client records or sensitive systems.

If you fall into a high-risk category, apply these additional steps: use different names or initials on professional versus personal social platforms, maintain strict separation between work and personal networks, audit tagged photos regularly for embedded location metadata, and monitor your online presence with Google Alerts for your name, employer, and professional credentials appearing in unexpected places.

For tax preparers operating under FTC Safeguards Rule requirements, personal social media exposure factors into a broader risk management assessment. The IRS Written Information Security Plan (WISP) framework for financial professionals extends to the personal device and account practices of anyone with access to client data. Healthcare providers should review HIPAA cybersecurity requirements that extend to how staff use personal devices and social accounts in ways that could expose protected health information.

Executives and high-net-worth individuals are frequent targets of whaling attacks, which are spear-phishing attempts that use detailed personal information gathered from social media to impersonate attorneys, accountants, or family members. For these individuals, a professional personal cybersecurity review identifies exposure points that automated tools and platform settings alone cannot address.

Smartphone App Permissions: The Companion Step

Social media privacy settings control what others see on the platform. Device permissions control what the apps themselves collect from your phone. Many social media apps request microphone, camera, contacts, and location access that goes well beyond what they need to function. On both iOS and Android, you can review and restrict app permissions under Settings, then Privacy.

Location permissions deserve particular attention. Most social media apps default to Always location access, meaning they can track your physical location even when the app is closed. Change these to While Using or disable them entirely. Instagram, TikTok, and Snapchat all use background location data to serve targeted content and advertising. That data can be exposed if the platform suffers a breach or shares it with third parties.

A VPN adds another layer of protection when accessing social media on public networks. Coffee shop Wi-Fi and hotel networks expose unencrypted traffic to anyone on the same network segment. Our guide on how to choose a VPN covers what to look for and what to avoid in consumer and professional VPN products.

Data Brokers: The Threat That Persists After You Lock Down Social Media

Even after completing every step in this social media privacy settings guide, your personal information may still be publicly available through data broker databases. Companies like Spokeo, Whitepages, Intelius, and BeenVerified aggregate public records including property records, court filings, voter registrations, and data scraped from social media, then sell access to anyone willing to pay a subscription fee.

Data brokers pull from hundreds of sources including the very social platforms you're trying to secure. A private Instagram account doesn't prevent a data broker from listing your home address, phone number, and estimated income alongside your publicly visible LinkedIn profile photo. The two exposure vectors are independent. Locking one doesn't lock the other.

Most data brokers offer an opt-out process, but these vary significantly by company and require submitting requests individually to each broker. Some opt-out requests expire after one to two years and require re-submission. The process is time-consuming: there are hundreds of active data broker sites, and manual opt-outs typically cover only the largest. Automated opt-out services provide broader coverage, though results vary by service and broker responsiveness.

The Federal Trade Commission (FTC) has called for greater transparency and accountability from data brokers, but meaningful federal regulation of the industry remains limited as of 2026. Several states have enacted consumer data rights that require brokers to honor deletion requests within specific timeframes. California residents benefit from the California Privacy Rights Act (CPRA), and Virginia residents have protections under the Consumer Data Protection Act (CDPA). Check your state's consumer privacy law to understand what rights apply in your jurisdiction.

Taking personal action, including opt-outs, privacy settings adjustments, and limiting what you share publicly, remains the most reliable defense available regardless of where you live. For individuals handling sensitive professional data, the intersection of personal social media exposure and regulatory compliance adds urgency to data broker opt-outs. Our guide on personal financial security covers how data broker exposure affects identity theft risk for financial professionals.

State Privacy Rights for Data Broker Opt-Outs

California (CPRA), Virginia (CDPA), Colorado, Connecticut, and Texas have enacted consumer data privacy laws that give residents opt-out and deletion rights with data brokers. Requirements and timelines vary by state. If you live in one of these states, file opt-out requests directly with data brokers and request deletion confirmation in writing. Contact your state attorney general's office if a broker refuses a valid request under applicable state law.

Staying Ahead of Future Privacy Changes

Social media privacy is an ongoing practice, not a one-time configuration. Platforms update their privacy policies, introduce new data-sharing features, and occasionally reset user preferences during major product changes. The most effective approach treats privacy settings as infrastructure that requires regular maintenance.

Set a recurring calendar reminder every six months to revisit each platform. When a major update ships, check post visibility, connected apps, and location permissions before the notification prompting you to try new features creates an opening for permissive defaults. Subscribe to security advisories from CISA to stay informed when major platforms change their data practices in ways that affect users.

For parents, the same principles apply to minor children's accounts with additional considerations. Most platforms require users to be 13 or older, but age verification is minimal. Instagram and TikTok have introduced parental supervision tools that allow account monitoring without requiring access to the child's password. These are worth enabling for any minors with active accounts. The MFA step is especially important for teen accounts, which are disproportionately targeted in account takeover attacks using credentials stolen from gaming platform breaches.

If you have experienced an account compromise, a broader security review is warranted beyond simply resetting the compromised account's password. Connected apps across all platforms should be audited, recovery contacts verified everywhere, and breach notification services checked to identify what credentials were exposed. Our guide on what to do after a data breach covers the full post-compromise recovery process.

What This Means for You

A one-hour privacy audit across all five platforms closes the most significant exposure gaps immediately. Use this social media privacy settings guide as a starting point, then make it a habit. The platforms that collect your data update their settings regularly. What was private last year may be public again after the next product rollout.

See What Your Profile Looks Like to an Attacker

Our personal cybersecurity review covers your social media exposure, device security posture, and data broker presence, then delivers a prioritized action plan specific to your situation.

Get Your Free Personal Security Review

Our experts will evaluate your social media exposure, device security posture, and data broker presence, then give you a prioritized action plan tailored to your specific situation.

Frequently Asked Questions

Review your social media privacy settings at least twice a year. Major platforms update their privacy policies and introduce new data-sharing features regularly, sometimes with permissive defaults that override your previous choices. Set a recurring calendar reminder every six months, and do an additional check whenever a platform announces a significant product update or policy change.

Switching to a private account on Instagram or X limits new followers to people who request and receive your approval. Existing followers keep their access immediately. On LinkedIn, enabling anonymous browsing and hiding your connections list does not affect your ability to receive connection requests or messages from legitimate contacts. For most individuals, the security benefit of private accounts outweighs the minor reduction in discoverability by unknown contacts.

Your date of birth, current city, phone number, and employer name carry the highest risk when left public. These fields are used in financial account recovery, identity verification at banks and credit bureaus, and knowledge-based authentication questions. Combining your date of birth with your childhood hometown and mother's maiden name (often visible in tagged family photos) gives attackers enough to bypass account recovery on many financial platforms. Remove or generalize these fields wherever they default to public visibility.

Each platform has a dedicated section for connected apps. On Facebook, go to Settings, then Apps and Websites. On Instagram, go to Settings, then Apps and Websites. On LinkedIn, go to Settings, then Data Privacy, then Other Applications. On X (Twitter), go to Settings, then Security and Account Access, then Connected Apps. Review each list and revoke access for anything you don't actively use, particularly apps that have access to your friends or connections list.

Social logins create a single point of failure. If your Facebook or Google account is compromised through a phishing attack or credential breach, every service connected to it is also at risk. Social logins also grant the third-party service ongoing access to your social profile data, often including your public profile, email, and in some cases your friend list. Where possible, create standalone credentials for important services and manage them with a password manager. Reserve social logins for low-stakes services where you would accept losing access if the social account were compromised.

You can significantly reduce your data broker exposure, but complete removal is difficult to maintain. Most major data brokers including Spokeo, Whitepages, Intelius, and BeenVerified offer opt-out processes, but each requires a separate request. Some opt-outs expire after one to two years and must be resubmitted. Automated opt-out services can submit requests to hundreds of brokers simultaneously, though results vary by service and broker responsiveness. California, Virginia, Colorado, Connecticut, and Texas residents have statutory opt-out rights under state privacy laws that require brokers to process deletion requests within defined timeframes.

Act in this order: recover account access through the platform's official recovery process, change your password immediately to a unique and strong credential, enable multi-factor authentication if it wasn't already active, revoke all connected app permissions, check for any posts or messages sent without your knowledge, verify that recovery email addresses and phone numbers haven't been changed by the attacker, and run a breach check on other accounts that share the same email address or password. Review all connected platforms since attackers who compromise one account often attempt the same credentials on linked services.

Social media privacy settings are one important layer, but they are not sufficient on their own. Data brokers can list your personal information regardless of your social media settings. Content you've shared in comments on public pages is visible regardless of your account's privacy level. Previous public posts indexed by search engines may remain cached for months after you restrict them. A complete approach combines social media settings, data broker opt-outs, strong unique passwords with multi-factor authentication, and monitoring your credit reports and identity through a breach notification service.

Not automatically. Facebook's Limit Past Posts tool can retroactively change old public posts to Friends only in one step, but it's a one-way change and doesn't apply to content others reshared from your profile. On other platforms, older public posts typically remain public unless you manually change their visibility or delete them individually. Search engines may have already indexed that content, and cached versions can persist for months. If past exposure is a significant concern, deleting old posts individually or using the platform's bulk deletion tools is the most thorough approach.

Yes. Personal accounts should prioritize limiting visibility to known contacts and removing personally identifying information from public fields. Professional accounts, particularly on LinkedIn, require a balance between discoverability by legitimate contacts and protection against social engineering. For professionals handling sensitive client data, including tax preparers, healthcare providers, and financial advisors, the standard social media privacy settings guide applies to personal accounts, while professional accounts may have additional compliance considerations under frameworks like the IRS Written Information Security Plan (WISP), FTC Safeguards Rule, or HIPAA Security Rule.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

Start with the concern that matters most

Make your accounts, devices, or family safer one clear step at a time

You do not need to change everything today. Choose the account, device, scam, or family concern that brought you here and fix the highest-impact opening first.

People also look for

Keep exploring Passwords & account security

Make passwords, password managers, MFA, and passkeys work together to reduce account takeover risk.