It’s been 2 years, and I’m trying to settle my privacy setup. There have been lots of ups and downs, and at one point I considered giving up and going back to a privacy-unaware life. But I never put down my sword.
As of now, I’ve tried to achieve whatever suits me best. I’ve kept self-hosting aside because it requires a lot of knowledge and time to set up. In these days, I’ve also learned how to maintain up-to-date backups of all the services I use, so there’s no risk of data loss.
Here are the parts of my privacy setup I’ve settled:
- Messaging — Most of my contacts have moved to Signal, which was a really tough battle. WhatsApp is still on my device, but frozen. SimpleX Chat is used for communicating with my family members because some of them (minors) don’t have their own numbers.
- Password Manager — I’ve settled with Psono (not self-hosted). 1Password is too costly for me, and I don’t like Bitwarden overall. Based on PG recommendations, I tried Psono and stayed with it.
- Notes — I wanted to settle with Cryptee, but it’s a web-based service and I need to access my notes mostly from my mobile, so a mobile app matters. That’s why I’ve settled with Notesnook. To be honest, I like Standard Notes more, but the paid plans don’t justify my needs.
- Multi-factor Authentication — I have multiple devices and I don’t carry all of them at a time, so cloud-based 2FA works better for me. I’ve settled with Proton Authenticator. It’s not recommended on PG, but I’ve found it better than Ente Auth. Also, I’m using Ente Photos, so I don’t want to store my photos and 2FA keys together in one account.
- Photos Management — I’m not aware of any cloud-based photos app except Ente Photos, so I’ve picked it. I’m already backing up all my data (including photos) on a separate cloud, so I might not need this service in the future.
- Cloud — I’ve picked two cloud services: Filen and Koofr. I have a 500GB lifetime plan in Filen, but so far there hasn’t been a security audit. That’s the only con that has been stopping Filen from coming onto the PG recommended list. If they don’t perform a security audit within this year, I might move to Koofr with rclone setup.
- Email Aliasing — Since the beginning, I’ve been using Anonaddy, and it has never betrayed me. I never faced a situation where websites refused to accept aliases generated by addy.io, so I’m staying with it.
These are the services I haven’t settled yet:
- Mail — You might wonder why I haven’t mentioned any mainstream Proton services so far; the reason is ProtonMail. I’ve used nearly all popular options including Proton, Tuta, Mailbox, Posteo, and Fastmail, but I prefer ProtonMail over others. The best feature of ProtonMail (with paid plans) is that users can create unlimited aliases, but only 10–15 of them stay active. The problem is that Proton will surely get banned in my country. I know I can still access my mails via Proton’s alternate routing, but the official services might stop sending mails to my ProtonMail addresses after the ban.
- VPN — I couldn’t find any need for a VPN in my usage. I haven’t accessed any restricted websites so far. I plan to go with either iVPN or Mullvad if I find any real use for it.
These are some irreplaceable services:
- Play Store on Android — Due to Google’s Play Integrity, many of my daily-used apps ask me to install and update only from the Play Store, otherwise they don’t work. So I have no choice but to use Play Store.
- Google Maps — I need to use maps every day, mainly for real-time traffic, navigation. Because no other maps have that level of accuracy like Google, I have to use Google Maps.
- Windows — I want to move to Linux, but as of now I have only one system and my professional work is done from it, so I don’t want to take the risk of any accident. I have a plan to buy/build a second system and install Linux on it, I’m just waiting for storage prices to come back to normal.
Lastly, these are the services where I’m too confused to decide:
- Custom domain for email setup — Using my own domain for email reduces dependency on the email provider, but we have to remember that domains aren’t permanent assets; users can rent them. Based on my observation, many official services in my country still send mails to old users even after closing their accounts. That’s why I haven’t settled with an email provider that recycles usernames. Those emails also include the real name and location of the account holder, so I don’t want to risk letting the future owner of the domain know anything about the past owner.
- Custom ROM on Android — Stock ROMs are heavily Google-dependent, which is why it’s always recommended to use a Pixel with GrapheneOS. But there are two problems for me: I keep a mobile for at least 3-4 years, and during that timeframe the device visits the authorized service center at least once or twice. Also, Pixel’s after-sales service is unreachable for me. Secondly, performance and battery are the main priorities when I buy a phone, so it should not hang or lag in the next 3-4 years. Pixel devices don’t have powerful hardware.
- Payment method — Nothing is free here, so I prefer to spend my money instead of handing over my data. There are mainly two ways to make transactions: sharing card details directly or paying via PayPal. Both have their pros and cons. Sharing card details on every site increases the chance of unauthorized transactions, while that risk becomes minimized when paying via PayPal. On the opposite side, credit cards have a chargeback policy, so the amount can be refunded, which might not be as smooth with PayPal. Moreover, PayPal has questionable data privacy.
After all of these, there is one service I’ve failed to set up: local AI. To set up AI locally, I need a powerful system that runs 24/7. To be honest, the whole process looks too complex to me. So, for now, I’ve given up on it.
That’s what I’ve achieved so far. Now I’m open to your suggestions on how to improve it further. Thanks.