🧠AI Foundations
Your progress0%
0 of 49 lessons
Reading10 min·Lesson 3 of 5

Protecting Yourself Online

Knowing your rights is powerful. Acting on them is even more powerful. This lesson gives you a practical toolkit to protect your personal data every time you go online — from using WhatsApp to applying for jobs to chatting with AI assistants.

Start With Your Accounts: The Basics That Matter Most

The foundation of online privacy is controlling who can access your accounts. In Kenya, most people manage significant parts of their financial and personal lives through their phones — M-Pesa, mobile banking, email, WhatsApp, and increasingly AI platforms. A single compromised account can cascade into real harm.

  • Use a strong, unique password for each important account. "Password123" or your ID number are not safe. Use a phrase like "NairobiRain#2024Jua" — long, mixed, memorable.
  • Enable two-factor authentication (2FA) wherever it is available — especially for Gmail, WhatsApp, and banking apps. This means even if someone has your password, they cannot log in without your phone.
  • Never share your M-Pesa PIN or banking password — not with family, not with someone claiming to be Safaricom support, and certainly not with an AI chatbot.
  • Review which apps have access to your contacts, location, camera, and microphone. On your Android or iPhone, go to Settings and remove access that apps do not genuinely need.
📱
Kenyan Scam Alert: There is a common scam where someone impersonates a Safaricom or M-Pesa agent and asks you to "verify" your details. They may even use an AI voice or AI-generated SMS. Safaricom will never ask for your PIN by phone, SMS, or chat. If in doubt, hang up and call 100 directly.

Using AI Tools Safely

AI assistants are incredibly useful — but they should be treated like a public notice board, not a private diary. Here is how to interact with them wisely:

Instead of sharing your real details...
Do not type: "My name is Wanjiku Kamau, my ID is 3456789, and I need help writing a letter to KCB about my loan default." Instead: "Help me write a letter to a bank about a loan dispute — I'll fill in my name and details myself."
Instead of pasting real documents...
Do not upload your actual national ID or payslip to an AI tool to ask a question. Describe what the document says in general terms, or redact personal details before pasting.
Check the privacy settings of the tool...
Most AI platforms have a settings menu where you can turn off "Use my conversations to improve the model." Find this setting and consider disabling it if you share sensitive topics.

Understanding Privacy Policies — The Short Version

Nobody reads 30-page privacy policies. But you can learn a lot from just two minutes of scanning. Look for these specific things:

  • What data do they collect? Look for a section called "Information We Collect" or "Data We Process."
  • Do they share or sell your data? Look for "Third Parties" or "Sharing Your Information."
  • Where is your data stored? If a Kenyan startup stores your data on US or EU servers, the Kenya Data Protection Act still applies to them, but enforcement is harder.
  • How do you delete your account and data? A trustworthy platform makes this easy to find.
🔍
Shortcut Tool: The website tosdr.org (Terms of Service; Didn't Read) grades the privacy policies of hundreds of popular apps from A (excellent) to E (very poor). Check it before signing up for a new AI tool — it takes 30 seconds.

WhatsApp and Data Minimisation

Data minimisation simply means: only share what is actually needed for the task at hand. When you hail a boda boda through a ride app, they need your pickup and dropoff location — not your home address, not your employer, not your ID number. Apply the same logic online.

On WhatsApp, be careful about group chats — any of the hundreds of members in a job-seekers group can screenshot your messages. Do not share sensitive documents, phone numbers, or personal information in large WhatsApp groups you do not fully trust.

🛡️
Your Digital Safety Checklist: Strong unique passwords ✓ — 2FA enabled ✓ — App permissions reviewed ✓ — Chat history cleared on AI tools ✓ — Privacy policy checked before sign-up ✓

Now that you understand the principles, the next activity gives you a hands-on privacy audit you can do right now on your own phone — in about 10 minutes.