OptOut Shelf

Best Privacy Tools for Remote Consultants Using Public Wi-Fi

2026.09.09
Best privacy tools for remote consultants using public Wi-Fi, including a VPN and password manager open on a laptop at a coffee shop table on South Congress Avenue

After you click "remove my info" on a people-search site, here's what actually happens: most remote consultants never check. They submit the form, feel a flicker of relief, and go back to invoicing clients from whatever coffee shop has decent outlets that day. Working out of cafés along South Congress Avenue with a laptop full of client logins taught me that a removal form is a request, not a guarantee, and that digital privacy for someone on public Wi-Fi takes more than one layer.

Quick note before the technical part: some links below are affiliate links for tools I've actually paid for and used on my own client work — Proton, DeleteMe, RoboForm, and EaseUS BitWiper. If you sign up through one, I earn a commission at no extra cost to you.

Full disclosure — some links on this page are affiliate links. If you buy through one, I get a referral fee, and it never changes what you pay.

The 'Connect' Button Isn't the Security Step You Think It Is

Most advice for remote workers stops at "get a VPN," which is true but incomplete enough to be misleading. A VPN masks your IP address and encrypts the tunnel between your laptop and the internet. It's genuinely useful on an open network, where a man-in-the-middle attack is a real, if uncommon, risk. What it doesn't do is stop the dozen other signals your browser keeps broadcasting on every site you visit: the same logged-in accounts, the same extensions, the same fonts and screen resolution stacking up into a fingerprint no IP change touches. A college friend of mine, Rodrigo Stein — a freelance UX designer who's borderline compulsive about browser fingerprinting countermeasures — is the one who convinced me that swapping your IP without touching any of that is like wearing a disguise that only covers your shoes.

Coffee shop networks compound this in a specific, nameable way. If the network operator can log which domains you're visiting (and most public Wi-Fi providers can, encrypted traffic or not), then a VPN's real job is moving that visibility off a stranger's router and onto a provider you actually trust. That's the working test for judging a VPN on public Wi-Fi: not "does it hide my IP" but "does it stop the local network from logging my DNS queries." I ran a well-known free VPN app for about a month before switching off it; it handled the IP part fine but left DNS queries and fingerprinting untouched (the free tier, not the paid one, to be fair), which told me it was solving maybe a third of the actual problem.

A remote consultant checking a VPN connection on a laptop screen while working from a public Wi-Fi café table, focused on digital privacy and data security

Building a Data Security Anchor With Proton

Once the DNS-leak test made sense, the next decision was what to actually route through that tunnel. I moved my consulting workflow into the Proton ecosystem after comparing a handful of setups, largely because it operates under Swiss data protection law, which sets a higher bar than most US-based providers bother clearing. That's not really a preference; it's a checkable fact, since the jurisdiction a provider sits in determines what a court or a government can actually compel it to hand over.

Email was the first piece I swapped, mostly because a "pro" Gmail account for client communication is a single point of failure with an unencrypted-by-default setup underneath it. Proton Mail applies OpenPGP encryption by default, which is closer to a sealed envelope than a postcard every server in between can read. The migration details — forwarding rules, contact re-imports, which features still feel unfinished a while in — are covered separately in a piece on Proton Mail features for self-employed consultants, if you want the full walkthrough instead of the summary.

For the public Wi-Fi problem specifically, Proton VPN is the piece that matters most. It's open-source, so the fingerprinting and DNS-leak claims aren't just copy on a landing page; outside researchers can actually check the code instead of taking the company's word for it. Sitting at a café table, the practical effect is that the local network stops being able to log which client dashboards I've opened, because DNS resolution happens inside the encrypted tunnel rather than on the coffee shop's router.

Data Brokers Keep Re-Listing You

Here's the part a VPN can't touch at all: information that's already public. You can run the most locked-down connection on the planet and still lose the game if a client Googles your name and finds your home address sitting on a people-search site. That's a source-removal problem, not a traffic-encryption one, and it needs a completely different tool to fix.

Before paying for anything, I spent a weekend manually filling out opt-out forms on Whitepages, Spokeo, and BeenVerified one at a time — the kind of task that feels productive right up until you check back a month later and find half of them quietly re-listed. One broker's opt-out form made the point especially well: the CAPTCHA wouldn't accept my entry until I'd solved it a third time, like it wanted proof I actually meant it. That's the real argument for a paid removal service — not that manual opt-outs don't work at all, but that they don't hold, and re-checking a dozen broker sites every few months isn't a habit anyone with a full client load keeps up.

PeopleFinder is the broker that taught me the most about how re-listing actually works: it took roughly three months and two separate re-listings before my old address stopped resurfacing there for good. That's less a sign the removal failed than proof broker data gets re-sourced from public records and other brokers faster than a single opt-out request can keep pace with — which is exactly why a subscription model beats a one-time cleanup.

This is where a direct comparison becomes useful instead of academic. I ran a DeleteMe vs Incogni review over a 90-day stretch to see which service actually kept data off broker sites for good, instead of trusting either company's own coverage claims.

I ended up sticking with DeleteMe for the heavy lifting. Its coverage includes harder-to-remove sites some competitors skip entirely, and the quarterly reports show exactly which brokers got hit and what came back — which matters, because "we handle removals" means nothing without a paper trail behind it. A reader named Devin Kwon emailed in after an earlier piece on this to say he checks every removal against his own personal list before marking a broker "done," which is honestly more disciplined than I manage most weeks. The decision rule I'd hand anyone comparing services: don't sign up for one that can't show you dated, broker-by-broker proof of what it actually removed.

Passwords, Yubikeys, and the Physical Layer of Consultant Security

Encryption in transit and broker removal cover two layers; the third is what happens if a password leaks regardless of either. Back in my office — a spare bedroom in a South Austin house that never quite lost its builder-grade 1990s bones — the Yubikey lives clipped to a lanyard on my left monitor rather than on my keychain, because that's the spot I actually remember to tap it. A whiteboard by the door tracks broker status in colored dots, and a printed timeline of re-listings taped beside it keeps getting longer every quarter (a small, slightly annoying reminder that this isn't a project with an end date).

For the password side, I use RoboForm, mainly because its family plan covers enough people to make the per-person cost sensible, and its form-fill engine still handles messy client-portal checkout flows that trip up some newer competitors. Pairing a password manager with a hardware key is the actual model worth understanding: even a phished or leaked password becomes useless to whoever has it without the physical key in hand, which is a stronger guarantee than the password manager gives on its own.

Hardware isn't only about logins, though. If you're ever retiring a consulting laptop, don't just drag files to the trash and reset it — deleted doesn't mean gone on a drive holding as much client data as mine does. I used EaseUS BitWiper for a full disk wipe on an old Dell before it went to a recycler, and it surprised me a little by handling free-space scrubbing and individual file shredding in a way a standard delete command just doesn't reach. One thing worth knowing before you pick a tool: the wipe method that actually works depends on whether the drive is an SSD or a traditional hard disk, since they don't store or erase data the same way — check which one you have first.

Making Yourself a Harder Target Than the Next Search Result

None of this adds up to invisibility, and any service promising "complete removal" is selling marketing copy, not a guarantee — brokers create new records faster than any single tool retires old ones. The realistic goal is raising the cost of finding you above the reward of finding you, the same logic behind a credit freeze: it doesn't make fraud impossible, it just makes you a worse use of somebody's time than the next name on the list.

The other habit worth building is treating your own footprint like something you audit on a schedule, not something you fix once and forget. A quick self-search every few months catches a re-listed broker or a stray account before a client stumbles onto it first. If a breach notice ever lands in your inbox, the accounts tied to that email need fresh, unique passwords right away — not a mental note to deal with it later.

Two distinctions are easy to blur here. Getting a listing out of Google's search results is not the same as getting it off the broker's own site — the first hides the page from search, the second stops the data from existing there at all, and only the second one actually holds up. And once your number and address are circulating among brokers, they tend to feed straight into telemarketing and lead-gen lists, which is usually where the spam calls that started "right after" some broker leak actually come from.

Public Wi-Fi was never really the core problem — it's just the place I finally noticed how thin my setup was. What replaced it is layered on purpose: Proton for the traffic still moving, a removal service for the records already sitting in some broker's database, and a hardware key so a leaked password doesn't automatically turn into a breach. None of those pieces alone would have been enough, and if you want the fuller technical case for why the free café connection isn't actually free, I wrote about that separately.