Your Chrome browser knows more about you than your closest friend does. It holds your passwords, your credit cards, your addresses, years of browsing history, and a list of every site allowed to use your camera, microphone, and location. Most of that data got there quietly, one “Save” click at a time, and most people have never once looked at what piled up.
This guide is a complete privacy audit for Chrome. We will walk through every place the browser stores something sensitive, check it, clean it, and lock it down. You do not need to be technical. You need about 45 minutes, and you can split the work across a few days since every change saves as you go. By the end, you will know exactly what Chrome knows about you, and you will have decided, on purpose, what it gets to keep.
What This Audit Covers
We will work through thirteen stops, grouped around three pillars:
- Passwords. What is saved, which ones are compromised or weak, and how they are protected at rest.
- Payments. Which cards and addresses Chrome can autofill, and how to control that.
- History. What Chrome remembers about where you have been, on this device and in your Google Account.
Around those pillars, we will also audit the supporting cast: sync, Safe Browsing, cookies, site permissions, extensions, and connection security. Skipping these would be like locking the front door and leaving the windows open.
One ground rule before we start: this audit is about making informed choices, not maximum paranoia. Some Chrome features trade a little data for a lot of convenience or protection. Where that trade exists, we will spell it out so you can decide for yourself.
Step 1: Run Safety Check
Chrome has a built-in auditor, and it is the right place to begin because it finds the loudest problems in seconds.
- Open Chrome on your computer.
- At the top right, select More, then Settings.
- On the left, select Privacy and security.
- Under “Safety Check,” select Go to Safety Check.
- Select any item with an issue and follow the on-screen instructions.

Safety Check looks for compromised, reused, or weak passwords saved in Google Password Manager, confirms Chrome is up to date, flags potentially harmful extensions, and reviews things like notification permissions and permissions from sites you have not visited in a long time. Chrome also runs Safety Check automatically in the background and notifies you when something needs attention, so anything it shows you now is worth taking seriously.
Fix what it flags, but do not stop here. Safety Check catches problems. The rest of this audit catches accumulation: the quiet buildup of data that is not a “problem” until the day it is.
Step 2: Take the Privacy Guide Tour
Still in Privacy and security, look for Privacy Guide. This is a step-by-step walkthrough of Chrome’s most important privacy controls, including cookies, history sync, Safe Browsing, and the “Make searches and browsing better” setting. For each one, Chrome explains what the setting does and what you give up or gain by changing it.
The guide takes about five minutes, and your choices save as you go, so you can leave and come back. Think of it as the orientation session before the real inspection. It will not cover everything in this article, but it puts you in the right frame of mind: every setting is a choice, and the defaults were chosen for everyone, not for you.
Step 3: Open Google Password Manager and Face the List
Now the first pillar. Every password you ever told Chrome to save is sitting in one place:
- At the top right, select More.
- Select Passwords and autofill, then Google Password Manager.
You will see the full list of sites with saved credentials. For most people who have used Chrome for years, this list runs into the hundreds, and that is the moment the audit becomes real. Scroll through it slowly and ask three questions about each entry:
- Do I still use this account? Old forum logins, dead shopping sites, services you tried once in 2017. If the account is dead, the saved password is pure risk with zero benefit. Delete the entry, and where it matters, delete the account on the site itself.
- Should this password be here at all? Some credentials are too important for convenience storage. Many people choose to keep their primary email and banking passwords out of any browser and type them every time. That is a personal call, but make it consciously.
- Is this a work credential in my personal browser? If so, it belongs in a separate work profile or your company’s approved password tool, not mixed into your personal vault.
If you are signed in to Chrome, these passwords live in your Google Account and are also available at passwords.google.com from any browser. If you are signed out, they stay local to this one computer. Knowing which situation you are in matters for the next steps.
Step 4: Run Password Checkup
With the list trimmed, check the health of what remains:
- In Google Password Manager, on the left, select Checkup.
- Review the three categories: compromised, reused, and weak passwords.
- Start with compromised passwords and change every one of them, beginning with email and financial accounts.

“Compromised” means the username and password combination appeared in a known data breach somewhere on the internet. Criminals take those leaked lists and try them on other sites, which is exactly why “reused” is the second category: one breached site plus one reused password equals many breached accounts.
Chrome can help with the fixing, too. For some sites, when a saved password is found in a public data breach, Chrome offers an automated password change feature that updates the password to a new, secure one for you. Where that is not available, use Chrome’s password suggestions to generate a strong, unique replacement as you change each one manually.
Also confirm the early-warning system is on: go to Privacy and security, then Security, and under “Advanced,” turn on Warn you if a password was compromised in a data breach. This feature works alongside Safe Browsing and alerts you at sign-in time, not months later.
Step 5: Lock Down How Your Passwords Are Stored
Auditing the list is half the job. The other half is how that list is protected.
Consider on-device encryption. Google Password Manager supports on-device encryption, which means your passwords are locked with a key that only you hold, such as your Google password or the screen lock on a compatible phone. Once set up, even Google cannot read your saved passwords. The trade-off is responsibility: if you lose access to your key, you can lose access to the passwords, so read Google’s setup notes carefully before turning it on. In Google Password Manager, open Settings and look for the on-device encryption option to check whether it is set up.
Decide whether Chrome should keep offering to save passwords. In Google Password Manager settings you can turn Offer to save passwords off if you have moved to a dedicated password manager and want Chrome to stop collecting new credentials. If Chrome is your password manager, leave it on. Half-using two password managers is how passwords end up scattered and forgotten.
Treat password export like a live grenade. Google Password Manager can export every saved password to a CSV file through Settings, then Export passwords. That file is plain text. Anyone who opens it sees everything. Export only when you are migrating to another tool, import immediately, then delete the file and empty the trash. Never leave a password export sitting in your Downloads folder.
Know the nuclear option exists. The same settings page includes Delete all Google Password Manager data, which removes all saved passwords and passkeys. You will probably never need it, but if you ever decide to move entirely off Google Password Manager, this is how you leave nothing behind.
Step 6: Audit Payment Methods and Addresses
Second pillar. Chrome’s autofill can store credit cards and addresses so checkout takes seconds, and this audit stop is about knowing exactly what it holds.
- At the top right, select More, then Settings.
- Select Payments and autofill (labeled Passwords and autofill in some versions), then open Payment methods.
- Review every saved card. Delete expired cards and any card you no longer want the browser to know about.
- Go back and open Addresses and more, and do the same cleanup for saved addresses.
A few facts worth knowing while you decide what stays:
- Chrome does not store full payment information without your permission. If you decline to save a card, Chrome keeps only the last four digits, and only so it does not keep asking you about the same card.
- Cards can be saved in two places. Some cards are stored locally in Chrome, and some are saved to your Google Pay account, where they follow you across devices. Cards saved in Google Pay are managed through your Google Account, so if a card in the list will not delete from Chrome’s settings, that is usually why.
- Autofill for payments can be turned off entirely. If you would rather type card details every time, turn off the save-and-fill option on the Payment methods page. Slower checkout, smaller attack surface. It is a fair trade for some people.
One honest note on threat models: saved payment methods are mostly a risk when someone else has access to your computer or your Google Account. The defenses that matter most are a locked screen, a strong Google Account password, and two-factor authentication on the account. The browser setting is the last line, not the first.
Step 7: Clean Up Your Browsing History
Third pillar. Chrome keeps a record of the pages you visit, and over the years it becomes a surprisingly detailed diary.
See what is there. Press Ctrl+H on Windows or Cmd+Y on Mac, or type chrome://history in the address bar. Search for anything sensitive: medical terms, financial sites, job hunting while employed. You can delete individual entries right from this page, which is the scalpel option.
Use Delete browsing data for the bigger sweep.
- Press Ctrl+Shift+Delete on Windows or Cmd+Shift+Delete on Mac.
- Choose a time range, from the last hour to all time.
- On the Basic tab, pick from browsing history, cookies and other site data, and cached images and files.
- Switch to Advanced for more categories, including download history, autofill form data, saved passwords, and site settings.
- Select Delete data.
Two cautions before you go wild with “All time.” Deleting cookies signs you out of most websites, which is annoying but harmless. Deleting autofill form data or passwords from the Advanced tab removes real saved information, not just traces, so read the checkboxes carefully. This dialog does exactly what it says, immediately, with no undo.
Remember the second copy. If you are signed in and your Google Account saves activity, your browsing and search history may also live in your Google Account, separate from the local copy. Visit myactivity.google.com to review it. There you can delete activity and set auto-delete so history older than a chosen period is removed on a schedule. Cleaning the local history while ignoring the account copy is only half an audit.
Step 8: Review Sync, the Data That Leaves Your Computer
Sync is wonderful and worth auditing precisely because it is invisible. When you are signed in and syncing, your bookmarks, history, passwords, open tabs, and settings flow to your Google Account and onto your other devices.
Open Settings, select your account section at the top, and review what is being synced. You can keep sync on for everything, or pick and choose data types. Two choices matter most for a privacy audit:
- History sync. Decide whether you want your browsing history following you across devices and stored with your account. Privacy Guide walks through this exact choice.
- Passwords. Synced passwords are convenient everywhere and protected by your account’s security. This is another reason your Google Account deserves a strong password and two-factor authentication more than any other account you own.
For the strongest control, Chrome also lets you encrypt synced data with your own sync passphrase. With a passphrase set, Google stores your synced data but cannot read it. The cost is convenience: some features that depend on Google reading that data stop working, and if you forget the passphrase, you must reset sync. It is a power-user option, but it exists, and an audit should know its options.
Step 9: Choose Your Safe Browsing Level Deliberately
Safe Browsing is Chrome’s protection against dangerous sites, downloads, and extensions, and it involves a genuine privacy trade-off that you should choose rather than inherit.
- Open Settings, then Privacy and security, then Security.
- Pick a Safe Browsing level.

Standard protection is the default. It warns you about sites, downloads, and extensions known to be dangerous. To protect your privacy during checks, Chrome sends an obfuscated portion of the URL through a privacy server that hides your IP address, so neither Google nor the server operator sees both your address and the site you are visiting. Fuller details are sent only when a site does something suspicious.
Enhanced protection is stronger and chattier. It warns you about dangerous sites even ones Google did not previously know about, and it does this by sending more data in real time: the URLs you visit, small samples of page content, extension activity, and system information. You get the highest level of protection Chrome offers, and Google sees more of your browsing to provide it.
No protection also exists and is not recommended for anyone reading a privacy audit in good faith. Turning off the seatbelt is not a privacy strategy.
There is no universally right answer between Standard and Enhanced. If you frequently open unfamiliar links or download files from around the web, Enhanced earns its keep. If you stick to a routine set of trusted sites and want minimal data sharing, Standard is a reasonable, deliberate choice.
Step 10: Cookies and Ads Privacy
Cookies are how sites remember you, and third-party cookies are how advertisers remember you across sites. In Privacy and security, open the Third-party cookies section and review your setting. Blocking third-party cookies cuts off the most common form of cross-site tracking, at the cost of occasionally breaking embedded content or sign-in flows on some sites. Chrome blocks third-party cookies in Incognito by default, which tells you something about their reputation.
While you are in the neighborhood, open Ads privacy. This section controls Chrome’s built-in ad interest system, including ad topics estimated from your browsing, site-suggested ads, and ad measurement. Each has its own switch. If you do not want the browser itself participating in ad targeting, turn them off here. The web will show you ads either way, but they will lean generic rather than personal.
Finally, back in the cookies section, look at the site-specific lists. You can name sites that are always allowed or never allowed to use cookies, which lets you block broadly while keeping the handful of sites that genuinely need an exception working.
Step 11: Sweep Your Site Permissions
Every time you clicked “Allow” on a popup asking for your location, camera, microphone, or notifications, Chrome wrote it down and kept honoring it. Years later, that list is worth a hard look.
- Open Settings, then Privacy and security, then Site settings.
- Open each major permission in turn: Location, Camera, Microphone, and Notifications.
- Remove any site you do not recognize or no longer use.
Notifications deserve special attention because they are the permission people regret most. Sites you visited once can keep pushing alerts forever. Clear the list down to the few you actually want, and consider setting new requests to be blocked or quieted by default.
Chrome helps here too: Safety Check can automatically revoke permissions from sites you have not visited in a long time, which is one more reason to let it keep running in the background.
Step 12: Extensions, the Forgotten Back Door
Extensions can be the biggest privacy hole in any browser, because many of them can read the pages you visit, which may include your email, documents, and banking sessions.
Type chrome://extensions in the address bar and audit the list with one ruthless question: does the value this extension gives me justify what it can see? For each extension, check its site access. Anything with access to all sites should be something you truly trust and actively use. Remove what you do not recognize, do not use, or cannot justify. For borderline cases, many extensions let you limit access to specific sites or grant access only when clicked.
Also be suspicious of extensions that changed hands. A trustworthy extension can be sold to a new owner and quietly turn into adware while keeping its name and reviews. If an extension you removed leaves odd behavior behind, or Chrome shows a policy or “managed” message you cannot explain, see our guide on understanding and removing the “your profile is managed” message in Chrome.
Step 13: Connection Basics, HTTPS and Secure DNS
Two final switches harden how Chrome talks to the internet, both in Privacy and security, then Security.
Always use secure connections. When this is on, Chrome upgrades sites to HTTPS where possible and warns you before loading a site that does not support it. HTTPS encrypts the traffic between you and the site, which matters most on public Wi-Fi, where an open connection is a postcard anyone can read.
Secure DNS. When you visit a site, Chrome looks up the site’s address, and secure DNS encrypts that lookup so it cannot be casually observed. It is on by default in automatic mode, and you can select a custom provider if you prefer a specific DNS service. For most people, confirming it is on is enough.
Make It a Habit: The Ten-Minute Monthly Audit
The full audit is a once-a-year job. Staying clean takes ten minutes a month:
- Open Safety Check and clear anything it flags.
- Glance at Password Checkup and fix new compromised entries the day they appear.
- Skim chrome://extensions and remove anything you have stopped using.
- Run Delete browsing data for whatever time range matches your comfort level.
- Once a quarter, revisit notification and location permissions in Site settings.
Put it on the calendar next to paying the bills. Privacy hygiene works exactly like dental hygiene: small, boring, regular beats heroic and rare.
Three Warnings Before You Close This Tab
Deleted means deleted. The Delete browsing data dialog, password deletion, and payment method removal are immediate and permanent. There is no recycle bin for browser data. Read every checkbox before confirming, especially on the Advanced tab.
Your Google Account is the real vault. Synced passwords, payment methods in Google Pay, and account-level history all sit behind one login. Every hour spent on browser settings is undermined if that account has a weak password or no two-factor authentication. Secure the account first, the browser second.
Incognito is not invisibility. Incognito keeps your activity out of local history, cookies, and site data after the window closes. It does not hide your browsing from websites, your employer, your school, or your internet provider. Use it for what it is: a way to keep this device’s record clean, nothing more.
Quick Answers
Is it safe to save passwords in Chrome? For most people, yes, and far safer than reusing one password everywhere. Saved passwords are protected by your device and Google Account security, and on-device encryption can strengthen that further. The honest weak points are an unlocked computer and a poorly secured Google Account.
Should I save credit cards in the browser? It is a convenience-versus-exposure trade. If your computer is shared or often unattended, lean toward no. If your device and account are well secured, the risk is modest and the checkout speed is real.
Does deleting Chrome history delete it everywhere? No. It clears the local record, and if you sync history, the change flows to your synced devices, but activity saved to your Google Account is managed separately at myactivity.google.com.
Standard or Enhanced protection? Enhanced gives stronger protection and sends Google more browsing data to do it. Standard protects against known threats with more privacy-preserving checks. Pick based on how adventurous your browsing is.
How often should I do the full audit? Once a year in full, ten minutes monthly for maintenance, and immediately after any news of a breach at a service you use.
You Now Know What Your Browser Knows
That is the whole point of an audit. Your passwords are trimmed, checked, and properly stored. Your payment methods are a deliberate list instead of an accident. Your history, both local and account-level, reflects your choices. And the supporting doors, permissions, extensions, cookies, and connections, are closed as far as you want them closed.
Chrome gives you real control over all of this. It just never forces you to use it. Now you have, and the ten-minute monthly habit will keep it that way.