Privacy is not a one-time setup. It is a maintenance habit. The tools you configure today will leak tomorrow when a new tracking method ships or when a service you forgot about gets breached.

A quarterly privacy audit takes about fifteen minutes. Three checks. Three tools. No sign-up required.

This is the routine I follow. You should too.

**Step 1: Check your browser fingerprint**

The Duelling Hares browser fingerprint tool shows you every identifying property your browser exposes. Canvas hash. WebGL renderer. Installed fonts. Screen resolution. Timezone. Language settings. Audio processing profile.

Open the tool and hit scan. Look at your entropy score. It measures how unique your browser is among all browsers on the web.

If your entropy is below 10 bits, your browser is relatively common. That is good. It means you are harder to single out.

If your entropy is between 10 and 15 bits, you are identifiable. A tracking script could pick you out of a crowd.

If your entropy is above 15 bits, your browser is highly unique. You are leaving a signature on every site you visit.

Write down your score. Next quarter, run the check again. If the score changed significantly, investigate what changed on your system. A new font pack. A browser update. A screen resolution change. Each change is a data point that trackers can use to keep identifying you.

The tool also flags which fingerprinting methods your browser is vulnerable to. Canvas. WebGL. AudioContext. Font enumeration. Each flag is a vector that needs protection.

[Run the browser fingerprint check] at the start of every quarter.

**Step 2: Scan your most used sites for trackers**

The Duelling Hares tracking scanner checks any URL for third-party trackers, fingerprinting scripts, and security headers.

Make a list of the ten websites you visit most. Not the ones you think you should visit. The ones you actually open every week. Social media. News. Email. Banking. Shopping.

Run the scanner on each one. Record the tracker count and the fingerprinting status.

If a site has more than 20 trackers, consider whether you need to visit it directly or whether you can access the same content through a privacy-preserving alternative. RSS readers for news. Privacy-focused front-ends for social media. Direct banking apps instead of browser access.

If a site runs fingerprinting scripts, check whether you need an account there. If you do, use a separate browser profile or container for that site. Firefox containers and Chrome profiles isolate site data so fingerprinting scripts cannot correlate your activity across sites.

If a site lacks security headers, be careful about what data you enter on it. No CSP means a compromised ad script can exfiltrate data. No HSTS means your connection can be downgraded.

[Run the tracking scanner] on your top ten sites this week. Recheck the list every quarter. Sites change their tracking infrastructure more often than you think.

**Step 3: Check your digital exposure**

The Duelling Hares digital exposure check scans an email address against known breach data and public records.

Run this check on every email address you use. Your primary address. Your work address. The address you use for newsletters and shopping. Each one has a different exposure profile.

For each address, take three actions:

First, identify the breaches that contain your data. If any of them exposed passwords you still use, change those passwords immediately. Use a password manager. Generate unique passwords for every service.

Second, delete accounts you no longer use. Every old account is a future breach waiting to happen. If you have not logged into a service in over a year, delete your account. Most services allow this in their settings or through a support request.

Third, enable two-factor authentication on every account that supports it. SMS two-factor is better than nothing. App-based or hardware key two-factor is significantly better. Prioritize your email account. If someone takes over your email, they can reset passwords for everything else.

[Run the digital exposure check] for each of your email addresses.

**The quarterly routine in fifteen minutes**

Browser fingerprint check: two minutes.
Scanning ten sites: five minutes.
Digital exposure check, one email: two minutes.
Digital exposure check, additional emails: one minute each.
Reviewing results and taking action: five minutes.

Fifteen minutes per quarter. Less time than you spend scrolling through a single social media feed. The difference is that this time investment pays off in reduced tracking, fewer breaches, and better security hygiene.

Set a calendar reminder for the first day of every quarter. Q3 2026 starts July 1. That is your next audit date.

All three tools are available at the Duelling Hares workshop. They run in your browser. No data leaves your machine. No accounts required. No tracking.

Run the full privacy audit now.