Browser privacy is not a switch; it is a posture — a set of defaults and habits. Auditing it means measuring what your browser exposes, deciding what matters to you, and changing the highest-impact things first.

What to check

  • Fingerprint surface. Run a canvas, audio, font, and WebGL fingerprint check and compare results across sessions. A stable fingerprint means a page can identify you even after you clear cookies. This site has Canvas, Audio, Font, WebGL, and WebGPU detectors for exactly this.
  • Third-party code. Inspect which domains load scripts on the sites you use daily. Fewer unknown domains is a direct reduction in exposure.
  • Data sent by default. Referrer policy, autofill behavior, and extension permissions all leak more than they need to.
  • Local-first options. For routine tasks, prefer tools that process data on your device — the data never enters the network at all.

Do the highest-impact things first

Most people get 80% of the benefit from three changes: block third-party scripts by default, use a privacy-respecting search engine, and choose local-first tools for sensitive work. Everything else — fingerprint-resistant browsers, isolated profiles, network-level filtering — is refinement on top of that base.

The honest caveat

An audit measures exposure; it does not eliminate it. No browser is invisible, and any page you load sees something. The goal is not zero exposure — it is knowing what the exposure is, and deciding deliberately what to share.