Account, App, and Extension Hygiene
Your AI account is now a valuable target. It may hold months of your conversations, your writing, your work, and maybe personal details you shared without thinking. If someone breaks into it, they get all of that. So the account itself needs to be locked down, not just the chats inside it.
This lesson covers the basics of good account hygiene: strong login, two-step verification, reviewing what you have connected, and being careful with the AI browser extensions and permissions that quietly get access to your data.
What You'll Learn
- How to make your AI login hard to break
- Why two-step verification matters most
- How to review app permissions and connected accounts
- The real risk of AI browser extensions
Strong login is the foundation
Most accounts are lost to weak or reused passwords, not clever hacking. Fix that first.
- Use a long, unique password for each AI tool. Length beats complexity. A phrase like "orange-river-cabin-42" is strong and easy to type.
- Never reuse a password across sites. If one site leaks, reused passwords open all your other accounts. This is the most common way people get hacked.
- Use a password manager. It remembers a unique password for every site so you do not have to. Your phone and browser have one built in, and there are free standalone apps. This one change removes most password risk.
Two-step verification is the big one
If you do only one thing from this lesson, do this. Turn on two-step verification, also called two-factor authentication or 2FA, on your AI accounts and on the email tied to them.
Two-step means that after your password, you also need a second code, usually from an app on your phone. So even if a scammer steals your password, they still cannot get in without your phone.
- Prefer an authenticator app over text-message codes when the option exists. App codes are harder to intercept.
- Protect your email account first. Your email can reset every other password. If your email has 2FA and a strong password, you have protected the master key.
- Save your backup codes somewhere safe offline, in case you lose your phone.
Review what you have connected
Over time you click "Sign in with Google" or "Connect account" and forget about it. Each connection is a door. Clean them up.
- Check third-party app access in your Google, Apple, or Microsoft account settings. Look for a page called something like "Apps with access to your account." Remove anything you do not recognize or no longer use.
- Review what your AI tools can reach. Some AI assistants can connect to your email, calendar, files, or messages. That is powerful and convenient, and it is also a lot of access. Only connect what you truly need, and disconnect the rest.
- Do this a couple of times a year. A quick review clears out old access before it becomes a problem.
The hidden risk: AI browser extensions
Browser extensions that add AI features to your web browser are popular. Many are genuinely useful. But a browser extension can be one of the most powerful pieces of software on your device, and people install them without a second thought.
Here is the part most people miss. An extension often asks to "read and change all your data on the websites you visit." If it has that permission, it can potentially see what is on your screen, including your email, your bank pages, and anything you type. A shady or hacked extension with that access is a serious leak.
AI browser extensions can see a lot. Treat them with care.
| Criteria | Safe extension habits | Risky habits |
|---|---|---|
| Where you install | Official browser store, known maker | A pop-up or random website telling you to install |
| Permissions | Read them before you accept | Click through without looking |
| How many | Only the few you actually use | Dozens, most forgotten |
| Upkeep | Remove ones you stopped using | Never review the list |
Safe extension habits
- Where you install
- Official browser store, known maker
- Permissions
- Read them before you accept
- How many
- Only the few you actually use
- Upkeep
- Remove ones you stopped using
Risky habits
- Where you install
- A pop-up or random website telling you to install
- Permissions
- Click through without looking
- How many
- Dozens, most forgotten
- Upkeep
- Never review the list
Practical rules for extensions:
- Install only from the official browser store and from a maker you recognize.
- Read the permissions before you accept. If a simple tool wants access to everything, that is a red flag.
- Keep the list short. Remove extensions you no longer use. Fewer extensions, fewer doors.
- Be extra careful on shared or work computers. Do not add extensions that can read everything to a machine that touches sensitive accounts.
A five-minute hygiene routine
You do not need to do all of this every day. Once, then a quick check now and then.
- Turn on two-step verification for your AI tools and your email. Do this today.
- Set a unique password for each, saved in a password manager.
- Open your Google or Apple or Microsoft account and remove apps you do not recognize.
- Open your browser extensions list and remove ones you do not use.
- Put a reminder in your calendar to repeat steps 3 and 4 twice a year.
You will run through this again in the capstone checklist, so keep it handy.
Key Takeaways
- Most accounts are lost to weak or reused passwords. Use a long, unique password per site, kept in a password manager.
- Two-step verification is the highest-value habit. Turn it on for your AI tools and especially your email.
- Review connected apps and what your AI tools can reach, and disconnect anything you do not need.
- AI browser extensions can often read everything on your screen. Install only trusted ones, read permissions, and keep the list short.
- Protect your email first. It can reset every other password you own.

