The organiser privacy kit
The full kit for a group that holds other people's information — the worksheet, the settings, the decisions, and the file you keep.
The digital hygiene checklist is the 20-minute version of this page. This is the whole kit: it gives you a threat model you can write down, a data inventory you can actually maintain, the settings that matter on phones and in group chats, a plan for the day something is seized or leaked, and a one-page pack you hand to a new member on their first week.
How to use it. Work through it once as a group, out loud, in a room — it takes about two hours and it is the single highest-value thing a small group can do. Then re-do the worksheet every six months, or whenever a member leaves. Do not try to do all of it on your own: the sections only work if the whole group follows the same rules, because you are only as private as the least careful phone in the chat.
1. The threat model worksheet
Write the answers down. A threat model that lives only in someone's head is not a threat model, it is a feeling. Answer these five questions with specific names, not categories.
- Who are we? How many people, how are they connected, who is publicly associated with the group already, and who is not.
- What do we hold that would hurt someone if it were read out loud? Membership lists, immigration status, tenancy details, health information, workplace grievances, who attended what.
- Who would want it? Be concrete: a landlord, an employer, an opposing campaign, a platform, a state body. The answer decides everything else on this page.
- What actually happens if they get it? For each item: nothing, a difficult conversation, a lost job, a court case, a deportation, a person in danger.
- What will we do, and who does it? Every decision needs one named person responsible for it, and a date to review.
The honest limit. If your answer to question 3 includes a state body with legal powers, ordinary hygiene is not the answer. Get situation-specific guidance from an organisation that does this for a living, before the situation, not after. This page will reduce exposure to landlords, employers, platforms and opponents. It will not defeat a lawful seizure order.
2. What you hold, where it lives, when it dies
Data you no longer have cannot be seized, leaked, or subpoenaed. Most groups hold five years of records because nobody ever decided to delete them.
| What it is | Where it lives now | Who can see it | Delete after |
|---|---|---|---|
| Member contact list | Group chat + one spreadsheet | Everyone in chat | Reviewed every 6 months |
| Attendance record | Someone's notes app | That person only | Not kept |
| Case files (a named member's dispute) | Email threads | Whoever was CC'd | End of case + agreed period |
| Photographs and video | Three phones | Unclear | Published or deleted, not "kept just in case" |
Fill in the real version for your group, print it, and keep it where the group can see it. The rules that make this work:
- One place per type of information. Not "the spreadsheet and also the chat".
- A default lifespan. If nobody has written a delete-after date, the record goes at the next review.
- Named handlers. Two people, not "whoever set it up".
- Nothing with a name in it on a personal phone that has no passcode and no backup decision.
3. Signal hygiene
Signal is the right default for group organising: end-to-end encrypted, no plaintext on the server, open source, and it does not sell the metadata. The app being good is not the same as your use of it being good. These are the settings and habits that matter.
Settings, per member, once
- Registration lock — on. Without it, a phone number re-registration can take over the account.
- Screen lock — on. Signal's own lock, plus the phone's.
- Disappearing messages — set a default for every new chat (1 week is a sane starting point for organising, 1 day for sensitive logistics).
- Read receipts and typing indicators — off for sensitive groups. They leak who is awake and who is watching.
- "Who can see my number" / find-by-number — turn off discovery for people who are not in your contacts.
- Backups — decide as a group and be consistent. A local encrypted backup is fine. "Whatever the phone default is" is not a decision.
- Linked devices — check the list. Unlink anything you do not recognise. Desktop clients keep message history.
Habits, per group
- Verify safety numbers with each member in person, once. This is what stops a swapped-SIM or re-registration attack. It takes two minutes and it is the single most skipped step.
- No group invite links for anything that matters. Add people by number, after the group agrees.
- Assume screenshots. Anything sent to a group of eight is a document. Note it in the pack: 40 people is not a private room.
- Do not use group chats for case files. Named people, legal matters, and health information go in person or through the group's agreed case channel.
- One phone number per role, not per person, where you can afford it. A group number that the organiser role inherits is better than a personal number that everyone in the group has memorised.
4. Device configuration
The phone is where the group actually lives. These are the settings that change outcomes.
- Six-digit passcode or longer, not four, and not a pattern.
- Auto-lock at one minute or less, and lock on the side button.
- Full-disk encryption on — on modern iOS and Android this is the default, but verify it and set the passcode that unlocks it.
- Notification previews hidden on the lock screen. A lock-screen preview is a plaintext copy of the message.
- Automatic updates on, for the operating system and for Signal. The exploits that actually get used are known ones, months old.
- Cloud backups of chat — off, or explicitly opted into with eyes open. Many devices upload the whole message database in a form the platform can read.
- Biometric unlock is a decision, not a default. In some jurisdictions you can be compelled to provide a fingerprint or face where you cannot be compelled to give a passcode, and elsewhere the opposite. Know which applies where you organise before you decide, and know how to disable biometrics quickly on your own device.
- A phone you can lose. For an action or a high-risk meeting, carry the phone that has nothing on it. Leave the one that has everything at home, powered off.
5. Accounts and access
- Password manager for the group, one vault, shared access for roles that need it. Not a notes app, not the chat.
- App-based second factor, never SMS for anything the group relies on.
- Write down who has admin on every account — domain, mailing list, socials, bank, website. Groups lose control of their own infrastructure when a person leaves and nobody knows what they held.
- Offboarding is a checklist, not a goodbye. Remove from groups, rotate shared passwords that the person knew, transfer admin, check the linked-device list.
- Do not run organising mail through a personal address that carries your real name and ten years of history.
- Separate the public and the private. The account that posts publicly should not be the account that holds the membership list.
6. Evidence safety
Groups hold footage, photographs and statements, usually from the moment things went wrong. Handle them as evidence, not as content.
- Originals stay untouched. Copy, then work on the copy. Never edit, crop, filter or re-save the original file.
- Note what it is, where, and who took it at the moment you receive it. Time, place, device, and the name of the person who recorded it.
- Do not strip metadata from evidence. Metadata is often the point. Strip it from published copies, keep it in the originals.
- Publishing identifies people. Before any image or video goes public, check every face, uniform, plate, and door for who it exposes — including your own side. Do not publish a person's image against their wishes.
- Secure storage with access control, not a public link. A link is a publication.
- Backups, two places, one offline. A seized laptop is not a backup.
- Material from a criminal matter goes to the solicitor, not the group chat.
7. When something goes wrong
The plan has to exist before the day. Write these four one-liners now, fill in the names and numbers, and put them in the pack.
- A phone is lost or stolen: who remote-wipes, who changes the group passwords that device knew, who tells the members whose numbers were in it.
- A device is seized or you are asked to unlock something: get legal advice from a solicitor before you act. Do not delete anything — destroying material during a live investigation is itself an offence in many jurisdictions, and it turns a manageable problem into a serious one.
- A leak: assume it will spread. Your first hour is spent telling the affected people, not the press.
- A member is in crisis or in custody: see the protestor information packs for contacts and the support structure.
Absolute limits. This kit is general hygiene. It is not legal advice and not threat-model advice for a group facing state attention. Situations involving criminal proceedings, immigration, or organised opposition need a practitioner who does that work for a living — get them early, and get them before you need them.
The one-page pack for new members
Copy this, fill it in for your group, and give it to every new member in their first week. Keep it to one side of A4.
- The group's agreed messaging app and the exact settings (from sections 3 and 4).
- Who to contact, on what number, in an emergency — two names, not one.
- The name and number of the group's solicitor or legal support organisation.
- What to do if asked for information about the group: say nothing, take a number, tell the contact.
- The group's data rules in five lines: what we hold, where, who can see it, when we delete it.
- Where the originals of any evidence are kept, and who holds the keys.
Free to copy, adapt and pass on. Corrections to hello@solidaritytools.com.