Chrome Privacy Settings: What to Change and Why
A practical walk-through of Chrome's privacy and security settings: Safety Check, cookies, site permissions, Safe Browsing, sync and history, with sensible choices for each.
The most useful privacy and security settings in Chrome are in its “Privacy and security” section: run Safety Check to catch weak passwords, old versions and risky extensions, block third-party cookies, tighten site permissions for location, camera, microphone and notifications, choose a Safe Browsing level, and decide what you sync to your Google account. Together these cut tracking and close the most common security gaps without making the browser hard to use.
Chrome’s layout changes from time to time, so this guide describes each setting by what it does rather than exact clicks. If you can’t find one, type its name into the search box at the top of Chrome’s settings page, which is the quickest way to reach any option.
Where Chrome’s privacy settings live
Open Chrome’s menu (the three dots), choose Settings, and look for the privacy and security section. Most of what’s below lives there or close by. When people search for “chrome settings privacy and security,” this is the page they’re looking for.
A few related settings sit elsewhere:
- Your Google account settings control what Google stores about your browsing when you’re signed in and syncing.
- Extensions are managed from their own page, reached from Chrome’s menu.
- Chrome on phones has similar options in a shorter menu, with some differences between Android and iPhone.
Step 1: Run Safety Check
Safety Check is Chrome’s built-in review. It looks at several things at once and suggests fixes:
- Updates: whether Chrome is up to date. Updates fix security flaws, so install them promptly.
- Passwords: whether passwords saved in Chrome’s password manager have appeared in known breaches, are weak or are reused.
- Extensions: whether any installed extensions have been flagged as harmful or removed from the Chrome Web Store.
- Safe Browsing: whether it’s turned on.
- Site permissions: in recent versions, whether sites you haven’t visited in a while still hold permissions, or send lots of notifications.
Work through anything it flags. If it reports compromised passwords, change them on the affected sites, starting with email and banking. Our guide on what to do if your password is leaked covers the order.
Step 2: Control cookies and tracking
Cookies are small files websites store in your browser. First-party cookies, set by the site you’re visiting, keep you logged in and remember preferences. Third-party cookies, set by other companies embedded in the page, are often used to track you across sites for advertising.
- Block third-party cookies. Chrome’s cookie settings let you block them, either everywhere or only in Incognito. Blocking them everywhere reduces cross-site tracking. A few sites, such as some sign-in or payment pages, may break; you can allow exceptions for those specific sites.
- Consider clearing cookies when you close Chrome. There’s an option to delete cookies and site data every time you close all windows. It’s more private, but you’ll need to log in again each time.
- Review ad privacy settings. If Chrome shows an ad privacy section, check what’s turned on and switch off anything you don’t want.
For clearing cookies you already have, see our guide on how to delete cookies. Cookie blocking is one part of reducing ad tracking; our guide on how to opt out of targeted ads covers the rest.
Step 3: Tighten site permissions
Websites can ask for access to your location, camera, microphone, notifications, clipboard and more. Over time, many people grant permissions they forget about. Chrome’s site settings let you review them.
| Permission | Sensible default | Why |
|---|---|---|
| Location | Ask each time, or block | Few sites need your precise location. Maps and delivery sites can be allowed individually. |
| Camera and microphone | Ask each time | Allow only for video-call sites you trust, and remove access when you stop using them. |
| Notifications | Block, or use quieter prompts | Notification prompts are a common route for spam and scam pop-ups. |
| Pop-ups and redirects | Blocked | Chrome blocks these by default. Keep it that way. |
| Automatic downloads | Ask each time | Stops sites from downloading several files without your say. |
Also look at the list of individual sites with permissions and remove any you don’t recognize. If you see a flood of alarming notifications about viruses, a site you allowed is probably behind it; remove its notification permission.
Step 4: Choose a Safe Browsing level
Safe Browsing warns you about dangerous sites, downloads and extensions. Chrome offers several levels:
- Enhanced protection: the strongest option. It checks sites and downloads more proactively, which means sending more browsing data to Google for real-time checks. Good for people at higher risk of phishing.
- Standard protection: the default, which checks against lists of known dangerous sites.
- No protection: not recommended.
There’s a real trade-off here. Enhanced protection gives better security but shares more with Google; standard protection is a reasonable middle ground for most people. Either is far better than turning it off.
Step 5: Decide what to sync
When you sign in to Chrome with a Google account and turn on sync, your bookmarks, history, passwords, open tabs and settings are saved to your account so they follow you across devices. That’s convenient, but it also means your browsing history can be stored with Google.
- Choose what to sync. You can sync everything or pick items, for example bookmarks and passwords but not history.
- Consider a sync passphrase if Chrome offers the option, which encrypts synced data with a passphrase only you know. If you forget it, you’ll have to reset sync.
- Check your Google activity controls. If Web and App Activity includes Chrome history, your browsing can appear in your Google account. Our guides to Google My Activity and Google privacy settings show how to review and auto-delete it.
- Using a shared computer? Don’t sign in to Chrome at all, or use a separate profile or guest mode.
Step 6: Clean up extensions and other settings
- Extensions: remove any you don’t use or don’t recognize. Extensions can often read and change data on sites you visit, so fewer is safer.
- Secure DNS: this setting encrypts the lookups your browser makes to find websites. It’s usually on by default.
- Password manager: Chrome’s built-in manager is fine for most people. Whatever you use, make passwords unique and turn on two-step verification for important accounts.
- Browsing data: clear history, cookies and cached files when needed, especially after using someone else’s device.
- Incognito: it stops Chrome saving history and cookies on your device after you close the window, but your employer, school, internet provider and the sites you visit can still see activity.
A worked example
This is an illustrative scenario, not a real client.
Beatriz, a freelance designer, notices her laptop showing “virus detected” pop-ups and ads for things she only searched once. She spends half an hour on Chrome’s settings.
- Safety Check finds two reused passwords that appeared in a breach and an extension that has been removed from the store. She changes the passwords and removes the extension.
- Site permissions show a site she doesn’t recognize with notification access. She removes it, and the fake virus pop-ups stop.
- Cookies: she blocks third-party cookies and adds an exception for her invoicing tool, which needs them for sign-in.
- Sync: she keeps bookmarks and passwords syncing but turns off history sync, and sets her Google activity to auto-delete.
Her browser works the same day to day. It just shares less and has fewer ways in.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditCommon mistakes
- Ignoring Chrome updates. Restart the browser when it asks. Updates are the simplest security win.
- Allowing notifications to get past a prompt. Many scam sites ask for notification access as a trick.
- Keeping every extension ever installed. Review the list a couple of times a year.
- Thinking Incognito makes you anonymous. It only keeps activity off your own device.
- Turning off Safe Browsing to fix a warning. If a site is flagged, don’t bypass the warning unless you’re certain it’s safe.
Browser settings and your wider privacy
Chrome settings control what happens on your device and in your Google account. They don’t remove information that’s already public about you, such as people-search listings or old posts. If you’re tightening your browser because you want more control over what’s known about you, our online privacy tips cover everyday habits, and our personal reputation management service handles what shows up in search.
Frequently asked questions
What are the most important Chrome privacy settings?
For most people: keep Chrome updated, run Safety Check, block third-party cookies, review site permissions (especially notifications and location), keep Safe Browsing on, and choose what you sync to your Google account.
Should I use Enhanced protection in Chrome?
It offers stronger protection against phishing and malware, which makes sense if you’re at higher risk. The trade-off is that it sends more browsing data to Google for real-time checks. Standard protection is a reasonable choice for most users.
Does blocking third-party cookies break websites?
Occasionally. Some sign-in, payment or embedded services rely on them. If a site stops working, add it as an exception in Chrome’s cookie settings rather than turning blocking off everywhere.
Does Chrome's Incognito mode stop tracking?
Partly. Incognito doesn’t save your history or cookies after you close the window, and blocks third-party cookies by default, but websites, your network and your internet provider can still see your activity while you browse.