Instagram's defaults are terrible for privacy. The bare minimum to change :
- Account private (Settings > Privacy > Private account)
- Activity status off (Privacy > Activity status)
- Story sharing off (Privacy > Story)
- Limit data collection for ads (Ad preferences > all toggles off)
- Two-factor auth on (Security > Two-factor)
- Review login activity monthly
Anything I missed? Drop your additions below.