The browser settings worth changing, and the defaults worth leaving alone
Browser settings screens are long because they are exhaustive, not because most of it matters. You can change browser settings all afternoon and alter nothing: a handful of entries change real behaviour, and the rest can stay exactly as shipped.
The browser settings worth changing
Third-party cookies
Blocking third-party cookies is the single setting with the widest effect on tracking, and the one most likely to break something visibly. Safari and Firefox block them by default; Chrome's handling has changed repeatedly. If a site's embedded login or payment step fails after you turn this on, an exception for that one site is a better answer than switching it back off globally.
HTTPS-only mode
Every major browser can refuse plain HTTP and warn you instead. There is very little left on the web that this breaks, and the failure it prevents, a page silently served unencrypted on a network you do not control, is one you would otherwise never notice.
Safe Browsing level
Chrome offers standard and enhanced protection; the enhanced setting sends more data to Google in exchange for faster warnings. This is a genuine trade rather than an obvious win, and it is worth making deliberately rather than accepting whichever way it was left.
Site and browser permissions
Location, camera, microphone and notifications are the four that matter. Setting each to "ask" rather than "allow" costs one tap per site and removes an entire category of surprise. Sites that already have permission are listed under the same screen and the list is usually longer than people expect.
Browser permissions run in two layers, and only the inner one is on this screen: what a site may ask the browser for, and what the browser may ask the phone for. If a site cannot reach the camera after you have allowed it, the second layer is usually why — the phone has not granted the browser itself the permission, which is fixed in the operating system rather than here.
The default browser itself
Which app opens a link tapped in a message or a mail client is a system setting rather than a browser one. The default browser is chosen under Settings → Apps → Default apps on Android, and under Settings → Apps → the browser → Default Browser App on iPhone. It is worth setting deliberately, because the default browser is the one that receives every link you did not open yourself.
Default search engine
The address bar is a search box, so this setting decides who receives most of what you type. It is a one-line change and it is the setting with the highest ratio of consequence to effort.
The defaults to leave alone
Some browser settings are famous and useless. Do Not Track sends a request that almost nobody honours and that adds one more bit to your fingerprint; it is close to inert. User-agent overrides break sites more often than they fix them. And clearing cookies on every exit sounds tidy but means re-authenticating everywhere, every day, which most people turn back off within a week.
Settings by what you are trying to achieve
The same browser settings read differently depending on what you are trying to fix, so the table below is arranged by intent rather than by the order the menus use. MDN’s overview of privacy on the web is a good companion for the reasoning behind the tracking entries.
| Goal | Setting | Cost |
|---|---|---|
| Less cross-site tracking | Block third-party cookies | Occasional embedded login breaks |
| No unencrypted pages | HTTPS-only mode | A warning on a handful of old sites |
| Stop notification prompts | Notifications: block | None worth mentioning |
| Keep work and personal apart | A second profile | One extra window to manage |
| Search elsewhere than the default | Default search engine | None |
| Nothing left after a session | Clear on exit, or incognito | Signed out constantly |
The last row is the one people pick and then abandon. Wanting to leave no trace is reasonable; paying for it with a fresh login to every service every morning is a cost most people reconsider after a week. Incognito for the sessions that need it, normal browsing otherwise, is the arrangement that survives contact with daily use.
Notifications deserve a paragraph of their own
Web notifications are the one permission that changed the feel of the web for the worse, and the one most worth shutting off wholesale. A site you visited once can put messages on your desktop or phone indefinitely, and the prompt asking for that right appears before you have read a word of the page.
Every browser lets you block the prompt entirely rather than answering it each time. Chrome and Edge do it under site settings; Firefox has a single checkbox to block new requests; Safari asks you to allow each site explicitly and is the least aggressive by default. The existing grants are listed on the same screen, and clearing that list is a five-minute job that most people have never done.
Content blockers, where a phone differs from a desktop
On a desktop the answer to unwanted content is an extension. On a phone it depends on which browser you are in, and the difference is large enough to be the reason to switch. Firefox for Android supports a subset of real extensions, which is the only route to the desktop toolset on a phone. Safari on iOS uses content blockers: a different design in which an app hands Safari a list of rules in advance and never sees your browsing, which is more private by construction and less flexible. Chrome on Android supports neither.
Two things follow from that. First, some of what an extension would do is available in the browser settings themselves, and those entries are the ones worth finding: tracker blocking in Firefox and Samsung Internet, and the third-party cookie control described above. Second, a blocker cannot help with anything that is not in the browser, which includes links opened inside other apps. Those use an in-app view with its own configuration, and the setting to send links to your real browser instead is usually in the other app rather than in this one.
Anything that promises to filter at the network level instead, whether a DNS service or a profile you install, moves the decision off the page and onto the connection. That is a genuine alternative on a phone, and it belongs to the same set of trade-offs as the browser settings here: it sees every lookup you make in exchange for the filtering it does.
One habit is worth more than any single entry: read the per-site browser permissions list rather than the global toggles. Every browser keeps a per-site record of what has been granted, and it is where a permission you allowed once, on a site you no longer use, quietly persists. Reviewing that list takes a minute and it is usually more revealing than anything in the main settings screen.
Where these live
Where you change browser settings depends on the browser and, on an iPhone, on the operating system rather than the app. Chrome and Edge put them under Settings → Privacy and security, Firefox under Settings → Privacy & Security, Safari splits them between Settings → Safari on iOS and Safari → Settings → Privacy on macOS. On a phone the same screens are reachable from the three-dot or three-line menu, and on Android the storage-side controls sit outside the browser entirely — see clearing the cache.
Questions people actually ask
Where are browser settings on a phone?
Behind the three-dot or three-line menu, then Settings. On iPhone, Safari’s settings live in the iOS Settings app rather than in Safari itself.
Which setting should I change first?
The default search engine. The address bar is a search box, so that one setting decides who receives most of what you type.
Should I block third-party cookies?
Yes for most people. It is the setting with the widest effect on tracking. If an embedded login or payment breaks, add an exception for that site rather than switching it off globally.
What is HTTPS-only mode?
It makes the browser refuse plain HTTP and warn you instead. Very little on the modern web breaks, and it prevents a failure you would otherwise never notice.
Is Do Not Track worth enabling?
No. Almost nobody honours it, and it adds one more bit to your fingerprint.
What is enhanced Safe Browsing?
Chrome’s stronger protection tier. It sends more data to Google in exchange for faster warnings: a genuine trade rather than an obvious win.
Should I clear cookies on exit?
Only if you accept re-authenticating everywhere, every day. Most people turn it off within a week.
How do I stop notification pop-ups?
Set notifications to "ask" or block them entirely under site settings. It is among the highest-value changes on the list.
What site permissions matter?
Location, camera, microphone and notifications. Set each to "ask" and review the list of sites that already have permission, which is usually longer than expected.
Does changing my user agent help?
No. It breaks sites more often than it fixes them and makes you more identifiable, not less.
How do I change the default browser?
Android: Settings, Apps, Default apps. iPhone: Settings, Apps, the browser, then Default Browser App.
What is a browser profile?
A separate identity inside one browser, with its own history, bookmarks, extensions and sign-ins. The right tool for keeping work and personal accounts apart.
Should I let the browser save passwords?
It is far better than reusing passwords. A dedicated password manager is better still, mainly because it works outside the browser too.
Do settings sync between my devices?
Most do, if you are signed in. Worth knowing before you sign into a browser on someone else’s machine.
Where do I clear what is already stored?
That is a separate operation: see clearing the cache.