Skip to content

Burner Devices Guide

A “burner” is a device used for a single identity or purpose and then retired. Used well, it creates a hard separation between a sensitive activity and your everyday digital life. Used carelessly, it is theater that adds cost without adding privacy — and the way most people defeat their own burner is through behavior, not the hardware.

When a burner helps — and when it doesn’t

Section titled “When a burner helps — and when it doesn’t”

A burner helps when the threat is linkage: keeping one identity’s accounts, contacts, location history, and hardware identifiers (IMEI, MAC, advertising ID) from ever touching another identity’s.

A burner does not help when:

  • You sign into a personal account (email, app store, social) on it — that instantly links the device to you.
  • You carry it powered-on alongside your real phone — the two co-locate in carrier and Wi-Fi records, defeating the separation.
  • The activity’s real risk is software fingerprinting or network metadata, which a new phone does nothing about on its own. See Browser Fingerprinting.

Decide what you are separating from before spending money. If you can’t name the linkage you’re breaking, a burner is the wrong tool.

The purchase is the most common point of deanonymization.

  • Pay cash, in person, away from your normal patterns. Card payments tie the purchase to your identity permanently.
  • Prepaid gift cards bought with cash can fund app stores or top-ups without a personal payment method — but note many require activation that leaks data.
  • Mind the cameras. Retail purchases are recorded; time + store + register links a cash purchase to CCTV. Avoid buying near home or work.
  • Buy the SIM/data separately from the device where possible, and not at the same time and place.

Set the device up so it shares nothing with your real life:

  1. Provision on a network you don’t use personally (not your home/work Wi-Fi).
  2. Create fresh accounts for it — never reuse an email, phone number, or recovery address tied to you. See Sock Puppet Accounts.
  3. Disable advertising IDs, ad personalization, and cloud backup/sync.
  4. Route traffic through a trusted VPN or Tor from first boot — see VPN Recommendations.
  5. Apply baseline device hardening — see Mobile Hardening.
  • Registration: many countries require ID to activate a SIM, which undermines anonymity at the source. Know your jurisdiction’s rules.
  • eSIM is convenient but is provisioned through an account and an internet connection, creating a digital trail the moment you activate it; a cash-bought physical SIM can be cleaner depending on local registration law.
  • The IMEI/SIM pairing is durable. Once a given SIM and device have been seen together by the carrier, swapping one while keeping the other links the two — rotate device and SIM together, not piecemeal.

The hardware is the easy part; discipline is what actually preserves separation.

  • Never power the burner on near your real phone, home, or workplace.
  • Keep a strict wall: no shared logins, no cross-posting, no contacts in common.
  • Treat location as identity — consistent patterns (always on at night at one address) re-link a “burner” to a person quickly.
  • Retire and physically destroy the device at the end of its purpose; don’t resell or reuse it for a second identity.