Getting your phone ready for travel: a privacy checklist that actually works
Start with a threat model, not a shopping list
Before you touch a single setting, it helps to name what you’re actually worried about. “Phone privacy while travelling” usually breaks down into a handful of separate risks: your phone getting lost or stolen, someone snooping on the network at a hotel or airport, apps and ad networks tracking your location more aggressively because you’re somewhere new, and the possibility that a border agent or customs official asks to look at your device.
Those are four different problems with four different fixes. No single setting, app, or VPN subscription solves all of them at once, and treating “get a VPN” as a complete answer will leave gaps in the other three. The rest of this guide walks through each one in the order that matters most for a typical trip.
Update everything before you leave, not after
This is boring advice, but it’s boring because it’s foundational. Most real-world phone compromises don’t come from exotic surveillance tools, they come from known software bugs that were already patched months earlier. If your OS, browser, and messaging apps are behind on updates, you’re carrying unfixed holes into unfamiliar networks.
Do this at home, on your own wifi, a few days before departure. Airport wifi is a bad place to download a multi-gigabyte OS update, and you don’t want your phone mid-update when you need it at a gate or a checkpoint.
Lock screen basics that matter more than people think
Your lock screen is the single biggest privacy control on the device, and it’s the one people configure once and forget. A few specifics worth checking:
PIN length and type. A 6-digit PIN is meaningfully harder to brute-force than 4 digits, and an alphanumeric passcode is harder still. If your phone still has a 4-digit PIN from years ago, this is worth fixing before a trip.
Biometrics versus a passcode. Face unlock and fingerprint unlock are convenient, but they work differently from a passcode in one important way: in many jurisdictions, compelling someone to press a finger or look at a camera is treated differently under the law than compelling someone to reveal a memorized passcode. This varies by country and isn’t something we can give you a legal answer on here, but the technical fact worth knowing is that both iOS and Android let you disable biometric unlock temporarily (on iPhone, pressing the side button five times, or holding power and a volume button, triggers this; on Android it’s usually in the lock screen settings) and fall back to a passcode. Know where that toggle is before you need it.
Notification content on the lock screen. Check whether message previews, verification codes, and email subject lines show up when the phone is locked. This is a common leak: someone glances at your phone on a table and reads a two-factor code or a private message without ever unlocking it. Set previews to hidden or off for the trip.
Auto-lock timeout. Shorten it. A phone that stays unlocked for two minutes after you last touched it is a phone that’s readable by whoever picks it up off a cafe table while you’re in the bathroom.
Turn off what you don’t need broadcasting
Bluetooth and wifi, when left on with auto-join enabled, will happily connect to networks and devices you didn’t choose, and some of that activity is visible to anyone nearby with the right equipment, because wifi and Bluetooth radios broadcast identifying information as part of how they work, not because anyone is doing anything unusual. Two settings worth checking:
- Turn off “auto-join” or “auto-connect” for wifi networks, so your phone doesn’t silently attach itself to an open network with a familiar-sounding name (a technique sometimes called an evil twin, where an attacker names a rogue access point something like “Airport_Free_WiFi” to catch devices that auto-connect).
- Turn off AirDrop or Nearby Share discoverability, or set it to contacts-only, so your phone isn’t advertising itself to every nearby device in a crowded terminal.
None of this requires turning the radios off entirely for the whole trip. It just means your phone stops connecting to things automatically and instead asks you first.
Public wifi and what a VPN actually changes
Hotel and airport wifi networks are usually unencrypted at the network layer, or use a shared password that everyone on the network also has. That means, in principle, other devices on the same network can see the addresses of the sites you connect to, and if a site you’re using doesn’t use HTTPS, the content too. In practice, the overwhelming majority of sites you use daily are HTTPS now, so this is a smaller problem than it was a decade ago, but it isn’t zero, especially on networks run by a hotel or a small operator whose own equipment might be misconfigured or compromised.
This is what a VPN actually does: it wraps your traffic in an encrypted tunnel to a server run by the VPN provider, so the local network operator sees only that you’re connected to the VPN, not what you’re doing inside it. That’s a real and useful shift in who can see your traffic, on that specific hop.
What it doesn’t do is make you anonymous or untraceable. The VPN provider itself can see your traffic (which is why their logging policy matters more than their marketing copy), the sites you log into still know it’s you because you’re logged in, and your phone’s other identifiers (device fingerprint, app-level tracking, account cookies) aren’t touched by a VPN at all. Think of it as protecting one specific link in the chain, the link between you and the local network, not the whole chain.
SIM, eSIM, and roaming data
Roaming on your home SIM is the simplest option and it keeps your existing number reachable, but it can be expensive and it means your home carrier (and by extension, anyone with legal access to their records) knows which foreign towers you’re connecting to. A local prepaid SIM or eSIM is often cheaper for data and puts you on a local carrier’s network instead, which changes who holds that connection metadata but doesn’t eliminate the fact that some carrier, somewhere, always knows roughly where a connected phone is. That’s just how cellular networks are built to work, it’s not a privacy failure specific to one provider.
If you use a local eSIM, remember it’s an additional radio identity your phone is broadcasting. Delete eSIM profiles you’re done with rather than leaving old ones installed indefinitely.
Backups and what happens if the phone is lost or seized
Before you leave, do a full backup to somewhere you control, whether that’s an encrypted local backup on your own computer or an encrypted cloud backup. The point isn’t paranoia, it’s logistics: if the phone is lost, stolen, or damaged, you want a clean recovery path that doesn’t depend on the missing device.
Also worth deciding in advance: what’s actually on the phone that you’d rather not have on it for this specific trip. Old photos, financial apps, work email, saved passwords in a non-encrypted note. You don’t need to strip the device down to nothing, but a phone with less sensitive material on it is simply a smaller target if it’s lost, stolen, or examined, regardless of who’s doing the examining. This is a proportionality decision, not a legal one, and it’s one only you can make based on what you’re actually carrying and where you’re going.
Messaging and two-factor authentication
If you rely on SMS for two-factor codes, know that SMS can be intercepted through SIM-swap attacks or, in some cases, isn’t available at all on a foreign network until roaming settles. Where possible, set up an authenticator app or hardware key as a backup 2FA method before you travel, and write down (on paper, not a photo on the phone) your backup codes for accounts where losing your phone would otherwise lock you out entirely.
For messaging, apps with end-to-end encryption by default protect the content of your conversations from anyone sitting on the network in between, including the app provider in most cases. That’s a real protection worth having, but end-to-end encryption doesn’t hide who you’re messaging or when, that metadata is typically still visible to the service provider, so it’s a partial protection for a specific piece of the picture, not a blanket guarantee of privacy for the conversation.
App permissions worth checking before a trip
Go through location permissions specifically. Many apps default to “always allow” location access when “while using the app” would do the same job with far less background tracking. This matters more while travelling because your location data becomes more revealing when it’s tracing a new city, a border crossing, or a hotel address, rather than the same commute you make every day at home.
A realistic pre-flight checklist
- Update OS, browser, and key apps at home, on your own wifi
- Set a longer PIN or alphanumeric passcode, know how to disable biometric unlock quickly
- Hide lock screen notification previews and shorten auto-lock timeout
- Turn off wifi and Bluetooth auto-join
- Set up a VPN if you’ll be on hotel or public wifi, understanding it protects that one hop, not everything
- Decide on roaming versus a local SIM or eSIM based on cost and how much you care about which carrier holds your connection metadata
- Do a full encrypted backup before you leave
- Move sensitive apps or files off the phone if you don’t need them for this specific trip
- Set up an authenticator app and write down backup codes for accounts you can’t afford to lose access to
- Tighten location permissions from “always” to “while using”
None of this makes your phone untraceable or guarantees anything about a search at a border, and anyone promising that with a single app or setting is selling you something. What it does is close the ordinary, boring gaps that cause most real privacy problems while travelling: a lost phone with everything readable on it, an app leaking your location by default, or traffic sitting unencrypted on a hotel network. That’s a realistic goal, and it’s one you can actually finish before your flight.
Want more of this kind of practical, no-hype breakdown? Head back to the homepage for the rest of our guides.