You’re reading this in your browser. The picks below block trackers and ads by default.
PrivacyTests
Every major browser, tested and scored.
Blocks ads and trackers out of the box and works like any Chromium browser. Turn the crypto and rewards prompts off in settings.
Get Brave →Firefox with the telemetry stripped and privacy turned up — a solid daily driver that still keeps your logins and tabs.
Get LibreWolf →
Built by the Tor Project to kill fingerprinting, but for everyday use: pair it with a VPN and you blend into a crowd of identical-looking users. Clears itself on close, fast enough to live in. Use this when you want day-to-day privacy without Tor's slowdown.
Get Mullvad Browser →
For when you need to be genuinely unlinkable — sensitive research, getting around censorship, protecting a source. Routes through the Tor network so no single party sees both who you are and what you're loading. Slower, and overkill for normal browsing.
Get Tor Browser →Runs its own index, so no Google or Bing sees your searches — and it's genuinely tunable. Goggles let you re-rank results with your own or shared rules: favor independent sites, bury SEO spam, build a lens for a topic. That customization is why it stays our pick even as rivals build their own indexes.
Try Brave Search →
French and privacy-respecting, and building its own European index (Staan) to cut its reliance on Bing. A reasonable default — but it still leans on Bing today, and has nothing like Goggles for shaping what you get back.
Try Qwant →
The paid option that makes you the customer instead of the product. It's funded entirely by subscriptions — no ads, no tracking, no profile — runs its own indexes, and lets you up- or down-rank domains and build lenses to bury SEO spam. Your searches aren't tied to your account, and you can pay anonymously or add a Privacy Pass token for more. The trade-off is the honest one: it's an account with a US company, so it's a promise backed by aligned incentives, not the anonymity of self-hosting. From $5/mo, or $10 for unlimited.
Try Kagi →
Run your own metasearch: it pulls from Google, Bing, and others without any of them profiling you, because the queries come from your server, not you. The maximalist option if you'll host it.
Set up SearXNG →The right messenger depends on your threat model — what you're guarding against, and which tradeoffs you're willing to accept. The two below are both worth recommending; they fit different needs, not a ranking.

Private texts and calls no one else can read — not even Signal. Free, works like a normal messaging app, and it's where the club organizes. Since 2024 you can connect by username without sharing your number — though a number is still required to create the account.
Get Signal →
Assigns no identifier at all — no phone number, email, username, or random ID. You connect by sharing a one-time link or QR code, so no directory maps a person to an account and the relay servers cannot tell who is talking to whom. Independently assessed twice by Trail of Bits (2022 and 2024). The tradeoffs: push notifications on iPhone can be intermittent, there is no cloud backup, and it is a newer, smaller network.
Get SimpleX →- End-to-end encrypted by default — every chat and call.
- Keeps almost no metadata, so there's little it could ever hand over.
- Open-source, independently audited, run by a non-profit.
- Big enough that the people you text are already on it.
Briar — peer-to-peer over Tor, with no servers and no phone number. Built for high-risk or internet-blackout situations rather than everyday texting.
Session — another option with no phone number or account, on a smaller and newer network.
Discord isn’t a private messenger. It’s a community and voice platform, closer to a social network, and there’s no private tool that drops in to replace it — its servers see your messages, and there’s no end-to-end encryption for servers or DMs. But a lot of communities live there, so if you’re going to use it, Vesktop is an open-source client that carries no telemetry of its own, blocks Discord’s telemetry by default, and limits Discord’s access to your machine. It won’t make Discord private, since the servers still see everything, but it’s a cleaner client.

Free, open-source, and audited. A strong, unique password for every account, synced across your devices. The easy default that's also genuinely private.
Get Bitwarden →
End-to-end encrypted and audited, with a free tier. A natural fit if you already live in Proton's Mail and VPN ecosystem.
Get Proton Pass →
An offline vault stored as a file you control — nothing synced to anyone's cloud. You handle the backups; you hold the keys.
Get KeePassXC →
Your login codes, encrypted and synced across every device — iPhone, Android, desktop. Open-source, free, and end-to-end encrypted, from the team behind Ente Photos.
Get Ente Auth →An offline authenticator for Android — your codes stay in an encrypted vault on the phone, nothing synced to a server. Open-source and free.
Get Aegis →A physical key like a YubiKey that you tap to log in — phishing-proof and the strongest 2FA there is. It costs money and is more than most people need — but it's the most bulletproof option if you want it.
See YubiKey →Your password manager can store these codes too — Proton Pass and Bitwarden both offer it. Convenient, but it drops both factors into one vault: break into that and your second factor falls with the first. A separate authenticator keeps them apart — which is the whole point of a second factor.

No account, no email — just a random number. Flat rate, no logs, cash accepted. The most transparent, most private option in a shady industry.
Get Mullvad →
A reputable Swiss provider with a genuinely usable free tier and easy apps — the easiest way to start if you're not ready to pay.
Get Proton VPN →
Zero-access encryption on Swiss servers — only you hold the keys, not Proton. Open-source and audited, and one login also covers Calendar, Drive, and the VPN. Skip an identifying recovery email if you want to stay unlinkable.
Get Proton Mail →Encrypts more than the rest — subject lines, contacts, and calendar too, with post-quantum crypto on by default. German and open-source; the catch is a walled garden, so no IMAP and no PGP to outside providers.
Get Tuta →
Built for PGP and standard protocols — an encrypted inbox, normal IMAP/SMTP, and it works with other PGP users. Around a euro a month, no free tier.
Get Mailbox.org →
Proton-owned, Swiss, and open-source. Give every site its own address, kill any one when it starts drawing spam, and reply straight from the alias — replies work even on the free tier.
Get SimpleLogin →
Open-source and self-hostable, with automatic PGP on every tier — even free — so your mailbox provider never sees plaintext. UK-based, or run it yourself.
Get Addy.io →The “but everyone I email uses Gmail” problem
When you send from Proton Mail to a Gmail address, the message isn’t end-to-end encrypted at the other end — Google can read what lands in their inbox. There’s a workaround: Proton’s Password-Protected Emails feature (free, no PGP setup) lets you send an encrypted message to any address; the recipient gets a link and enters a password you’ve shared with them to unlock it. The message never lands in their Gmail inbox as plain text. There’s a limit: replies are capped on free plans. Tutanota (Tuta) has an equivalent. It’s not a fix for every email, but for anything genuinely sensitive it closes the gap.

Free, encrypted DNS you can use without a Mullvad account, with ad, tracker, and malware-blocking variants. Point a device at it in minutes.
Set up Mullvad DNS →Hosted like Mullvad's, but you choose the blocklists — granular control and per-device profiles. The free tier is plenty.
Get NextDNS →
Resolves queries itself instead of trusting an upstream, and keeps no query logs by default. The most private of these if you'll run a server.
Get Technitium →
Network-wide ad and tracker blocking on a cheap device, with the biggest blocklist community behind it.
Set up Pi-hole →
The same idea with the friendliest interface and strong per-device controls.
Get AdGuard Home →The one cryptocurrency built for privacy. Ring signatures and stealth addresses hide the sender, receiver, and amount by default, so there's no public trail linking a payment to you — the opposite of Bitcoin's open ledger. Because that privacy is in the protocol, not a company promising to look away, there's no ledger to subpoena. The weak point isn't the coin, it's how you get it: buy Monero from an exchange that verified your ID and you've made a record tying the coins to you. Acquisition and network habits — using Tor, not leaning on a KYC on-ramp — are where the privacy is won or lost.
About Monero →
Mullvad already skips the email — you get a random account number, not a login tied to your identity. Pay for it in Monero (or cash by mail) and the subscription isn't linked to your name at all. Card and PayPal run through third parties that log everything, which quietly undoes the point.
How payments work →
Virtual card numbers that sit in front of your real bank card. Give each merchant its own number, cap what it can charge, and pause or delete it in a tap — so a breached store can't keep billing you, and the merchant never sees your real card or, usually, your real name. But this solves a different problem than Monero: Privacy.com is a US company tied to your actual bank account, it logs every transaction, and it answers subpoenas like any bank. It hides you from merchants and data brokers, not from your bank or the government. Reach for it to cut what online stores learn about you — not to be anonymous.
About Privacy.com →These range from a quick switch to a full hardened setup.
Everything above runs on your OS — the one layer that sees all of it. A closed OS can only promise what it does with that; an open one makes it structural. But the closed options aren’t equal: Windows serves ads and collects telemetry through the OS itself, while macOS collects far less. And the open side runs from an everyday Linux desktop to systems built for anonymity. Turn down what you’re on, switch to Linux, or go further if your threat model calls for it.
Collects diagnostic telemetry by default, assigns an advertising ID, and shows ads in the Start menu and lock screen; setup pushes a Microsoft account, and on newer Copilot+ PCs the opt-in Recall feature can periodically screenshot your screen. Turn down what you can in Settings → Privacy & security, switch off the advertising ID, and leave Recall off.
Closed, so you’re trusting Apple — but far less ad-driven than Windows, with no ads in the OS. Turn off analytics in System Settings → Privacy & Security → Analytics & Improvements, and personalized ads under Apple Advertising.
The easiest switch from Windows: a familiar desktop, huge community, and it just works.
Get Mint →Clean GNOME desktop with no extra telemetry layered on top, a fast release cycle, and SELinux enforcing by default. Red Hat–backed and ships the latest kernel — a solid all-purpose pick if Mint feels too familiar.
Get Fedora →Made to look and feel like Windows or macOS — the gentlest on-ramp for switchers.
Get Zorin →These are a few starting points. There are hundreds of distributions — different desktops and styles, fixed or rolling releases, big communities and niche ones. A tool like Distrochooser can help you find one that fits.
Security by isolation — every app and task runs in its own VM, so a compromise in one stays contained. Whonix is a first-party template (Qubes-Whonix), meaning you can run a Tor-routed browser or an air-gapped workstation as just another VM alongside your regular work; Tails also runs in a disposable VM. Serious hardware requirements and a learning curve — but nothing else matches it for a full desktop threat model.
Get Qubes →An amnesic live system on a USB stick: it routes everything through Tor and leaves no trace when you shut down. Built for journalists, activists, and whistleblowers who need privacy without a permanent install.
Get Tails →
Splits your system into a Tor gateway and an isolated workstation, so even malware can’t discover your real IP. Pairs naturally with Qubes.
Get Whonix →The hardened Android build for Pixels that removes Google entirely — or sandboxes Play Services in a walled-off container if you still need them. Open-source with verifiable builds, per-app network-permission controls, hardened memory allocation, and forensic resistance comparable to a locked iPhone. Pixels only.
Get GrapheneOS →Closed source — you’re trusting Apple — but its Secure Enclave hardware encryption makes modern iPhones notably resistant to forensic extraction tools in a way stock Android is not. Turn off iCloud backup for anything sensitive, disable Siri and analytics under Settings → Privacy & Security, and enable Lockdown Mode if your threat model calls for it. A locked, updated iPhone is a strong baseline for most people.
For a side-by-side of GrapheneOS, CalyxOS, DivestOS, and others, Privacy Guides’ Android page keeps a maintained comparison. The GrapheneOS site covers its own hardening in detail at grapheneos.org/features.
Every category has a pick to start with; the more-private options ask more of you for more control. We go deeper — Tor, email aliases, self-hosting — at meetings. Wondering why any of this matters? That's the third-party doctrine — the rule that lets the government reach this data in the first place.
Get involved
It’s free, open to everyone at Pitt, and joining takes about a minute.
No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.