Digital hygiene for organisers
A short checklist for any group holding other people's information.
A tenant group knows who is behind on rent. A mutual aid network knows who needed food. A union branch knows who is about to be disciplined. That information is the most valuable thing the group holds, and it is usually kept on personal phones with no plan at all. This is a workable baseline — not paranoia, and not nothing.
Start here. The single biggest risk to a small group is not a sophisticated attacker. It is a lost phone, a shared spreadsheet with open link access, and a group chat that keeps everything forever. Fix those three and you have removed most of the danger.
Know what you hold, and who holds it
- Write a one-page list of every place member information lives: group chat, spreadsheet, mailing list, notes app, someone's photos, a paper folder.
- Mark on that page who can currently see each one. Most groups discover two or three things are open to far more people than they assumed.
- Delete anything nobody can explain a use for. Old membership lists are a liability, not an archive.
Messaging
- Use one tool with end-to-end encryption for anything sensitive, and be honest that a regular group chat is fine for arranging a meeting but not for naming individuals.
- Turn on disappearing messages for the sensitive channel — a month is usually right. It limits what a seized or stolen device exposes.
- Never make a decision to exclude or report on a named person in a large chat. Move it to a small, named group.
- Assume anything forwarded from a chat will eventually be read by the person it is about. Write accordingly.
Accounts and access
- Give the group its own accounts. If the mailing list, bank or website lives on one person's personal address, the group's history dies with their phone.
- Turn on two-factor authentication on every group account, and use an authenticator app rather than text messages.
- Keep the recovery codes somewhere two people can reach — one offline copy, one with a second officer.
- When someone leaves the group, remove their access the same week and change the shared passwords they knew. Do this as a routine handover step, not as an accusation.
- Use a password manager. Shared logins in a group chat are the most common way a small group's whole digital life comes apart.
Devices
- Set a real passcode with no biometric-only unlock, on every phone used for group work.
- Turn on full-disk encryption: default on iPhones and modern Android, and worth checking on any laptop.
- Turn on automatic updates. Unpatched software is the ordinary way devices get compromised, not clever attacks.
- Do not install the group's contacts on a personal phone if you can avoid it. If you must, make sure that phone has a passcode and remote wipe enabled.
Documents
- Stop using "anyone with the link" sharing. Add people by name.
- Remove old collaborators from shared folders. Past members usually still have access.
- For anything genuinely sensitive — lists of names tied to allegations, legal papers — keep it on paper and in one agreed place, or in an encrypted archive with one holder.
When something goes wrong
Have this written down before you need it, because you will not think clearly in the moment:
- Who is told first. Name a person, not "the committee".
- How access is cut off the same day: passwords changed, sessions logged out, the missing device wiped remotely.
- Who contacts members. The people whose information was exposed should hear it from you, plainly, before they hear it elsewhere.
- What you will not do: do not ask members to delete evidence, and do not discuss what happened in the main chat.
Absolute limits. This page is general hygiene, not legal advice and not threat-model advice. If your group faces state attention, organised opposition, or is supporting people in criminal proceedings, general hygiene is not enough — get situation-specific guidance from an organisation that does this work for a living, and do it before the situation, not after.
Free to copy, adapt and pass on. Corrections to hello@solidaritytools.com.