Start with a threat model, not a tool list. Nobody's threat model is 'everyone'
Every week someone posts 'what's the most private phone/browser/messenger' and the honest answer is: it depends who you're hiding from, and you have to actually answer that first. Mine, written down, is roughly: data brokers scraping and reselling my life, an advertiser building a shadow profile, and a nosy ex who knows my old passwords. It is explicitly NOT a nation-state adversary, because if that were my threat model my whole life would look different and so would this post. Once you name the adversary, the choices get easy and cheap. Against brokers and ad-tech, the highest-leverage moves are boring: a browser that blocks third-party cookies and fingerprinting, an ad-blocker at the DNS or browser level, unique passwords in a manager, and opting out of the big data brokers. You do not need to move to a bunker in the woods. You need to make yourself an unprofitable target. Who are you actually defending against? Answer that in the comments before you ask what app to install.
Join the conversation
Facet is free to read. To reply you need an account: one private root identity, and up to ten public personas that can never be linked to each other or to you.
Create an accountThis is the post that should be pinned. Most 'privacy' burnout comes from trying to defend against everyone at once, which is exhausting and pointless, so people quit and go back to defaults. My threat model is basically identical to yours: I want out of the surveillance-advertising economy, I don't want my location history sold, and I want my accounts hard to take over. Against that, the ROI on password manager plus 2FA plus a tracker-blocking DNS resolver is enormous. Nation-state stuff is a fun thing to read about and a terrible thing to design your daily life around.
The 'unprofitable target' framing is exactly right and it's how security people actually think. You're not building an impenetrable fortress, you're raising the cost of attacking you above the value of the reward. The one thing I'll add: your threat model should include the mundane failure modes, not just the villains. Losing your phone, a laptop getting stolen, a random breach dumping your reused password. Full-disk encryption and a password manager quietly defend against the boring 90% while everyone's arguing about the exotic 10%.
and please write it down. an actual short document — who am I defending against, what am I protecting, what's the realistic cost of losing it. it takes twenty minutes and it stops you from spending three weekends on a threat you don't have while ignoring the one you do.
the writing-it-down step is doing a lot of quiet work. half the value is just forcing yourself to be specific instead of vaguely anxious. anxiety scales infinitely; a written threat model doesn't.
coming back to add the corollary to 'threat model first': revisit it. mine changed when I moved and again when I changed jobs — the adversaries and the assets both shifted. a threat model is a living document, not a one-time ritual. re-read yours once a year and see if it still describes your actual life.