I recommend using Tor over a VPN like Mullvad. NordVPN may say they have a no-log policy, but they actually do log and send data to the feds as I’ve seen from my hacker friend (who works with the feds) with that they have indeed hacked into NordVPN (Ethically, they’ve been permitted to do so from a Bug Bounty Program, which means this hacking isn’t illegal since they’ve been allowed to do it) and seen their code whereby they actually do log some user information; I’m not sure about TunnelBear as I’ve not used it before, but Mullvad seems to be the best as it generates for you a unique code used to sign in from cryptography without having to use a username or password to login to your account and accepts crypto as payment. So, it’s like a unique serial number assigned to you, making it decentralized. ProtonVPN on the other hand claims to have no logging policy too but they most definitely and indeed have exposed my data to the feds and I know this for sure because they’ve banned me from using their VPN Services, and since it requires email and password (And email itself is a very common way of getting sensitive information off a person these days such as Computer Digital Footprints from online sources (In the form of JavaScript), passwords, physical addresses and such), I wouldn’t recommend it. The best of all I recommend is Mullvad.
You can use encryption mechanisms to protect USB Drives, Hard Drives and even other Physical Storage Media. Windows comes implemented with BitLocker (Recommended to enable this), but you’d be required to make a separate partition for your Hard Disk or Solid Disk from the Disk Manager on Windows before locking it with a secure password and keeping the Recovery Key in an encrypted USB as well in the case you forget your password. Best of all, BitLocker will even ensure to lock your Hard Disk to your PC so no one can use it even when it’s removed from your PC (This is only possible if your PC has a TPM Chip). BitLocker even comes with BitLocker Go which can be used to encrypt USB Drives.
An alternative to BitLocker is VeraCrypt as well, which can also be used to encrypt devices and comes with a special feature to create an extra partition on a USB to trick people who want access to your data to show them it’s not there when in reality it’s there but just in a different partition. A security expert like me would be able to know this though from Disk Manager or from analyzing the Disk using Terminal (In Linux) or Command Prompt (Windows).
NB: As a Forensic Investigator and Security Researcher, I have access to tools used by the FBI, Europol and other Top Secret Government Agencies that can break any encryption from VeraCrypt to even BitLocker, but that’s not for you to be concerned for now unless you somehow find out you’re getting in trouble with the feds, or if a security researcher is hired by your parents to find out if you’re hiding something since they have access to Forensics (The study of investigating crime and gathering evidence) too.
Anyways, you must learn to protect your devices from being infected by malware as well and practice good Operational Security (This is a security risk management practice of protecting sensitive information from going into the wrong hands). Know the websites you visit (Don’t click on links you don’t trust or sent to you by strangers, some links could be phishing links and some could be loggers that could actually get your exact location and some could even lead your devices to be reverse shelled (Maybe from a script or a outbound connection or something) giving an attacker full access to your device without you even noticing it), If someone sends you a link that looks like Facebook and it’s not (Check the URL and confirm it’s Facebook or not), don’t login to it (This doesn’t only apply to Facebook but also links like ToZ Forums or literally any website that requires login. They’re basically extracting your login information from you so they can compromise your account), Never use your real name online, never refer yourself to your aliases, if you have emails with your real information (School Mail and such. Keep these separate from your normal mails that don’t have your real information and never link them together), don’t click on random apps from people you don’t trust, run a local account on your computer and keep an Administrator Account only for installing apps or modifying system components and settings (This is done to make sure to Hardern your PC in case any unauthorized malware tries to run, it won’t, since UAC will be displayed asking for Admin Password and so malware won’t affect the system easily), install apps from trusted sources and dont use your real name as your PC name and username (You can use an Alias as long as it’s not linked to you. I’ve seen cases whereby a virus was sent for research and information extracted from it was a PC username, name and so on, so you have to be careful with this because once it’s online, it can never be taken down), don’t give out personal information online (This is happened to me couple of times with e-Whores texting me, asking me for personal information, I just Social Engineer them by giving them wrong information then ask them serious questions like a Fed would till they confess and give out their information and what they’re up to as well as why they’re doing what they’re doing, as I’ve thoroughly studied MK-Ultra and Mind Control as well as Interrogations, I know how to handle such situations and thereafter I report their profiles if they confess something serious like fraud or similar and their profiles get taken down. Some of them leave their emails open to view (Bad OpSec Practice), this gives me the opportunity to even further get their personal information myself without even having to ask them for it (This includes passwords to even login to their accounts from Data Breaches, Geographical Locations and other very personal information). Yes, it’s possible to get a password of someone just by using their email and that’s why email as well is something you should consider keeping private and not putting it on display on Social Media. Same goes with Phone Numbers as well, Aliases or literally anything linked to your digital identity can literally reveal who you really are), Never connect to an Open Network (WiFi Networks without passwords, not safe without a VPN), always check for HTTPS whenever you visit a website (Attackers such as Threat Actors, believe me, I’ve come across many people of these kind who still give me death threats and bomb threats till today, I even know the person who hacked GTA 6 and Uber as well (Names are to be kept secret here), getting back to the point, they use a technique called SSL Stripping which removes the Security of the HTTP Protocol within any network they’re connected to in order to monitor your websites traffic and even extract login data such as usernames and passwords. They can see your history since the time you’ve connected to the network too and if they decide can even perform a Man-in-the-Middle Attack to gain full access to your system without you even knowing it, watching your screen the whole time), always update and patch your system to keep it up to date with the latest security features and use the latest Operating System provided by the company that your PCs Operating System is using (Windows 7 and even 8 have most vulnerabilities that makes them more riskier to use. Anyone with access to EternalBlue or BlueKeep can even see everything you’re doing without having to send you anything since it’s a software made by the NSA but was hacked and released to the Public Internet, as long as they have your IP Address, which is why it’s important to use a VPN and best of all, patching and keeping your system up-to-date helps protect against vulnerabilities and malware too. Windows itself has plenty of vulnerabilities, apps too have vulnerabilities, so make sure you keep these up-to-date too because sometimes it’s not just the System that could be used to gain access to your personal data and whole PC but even the apps installed on it, so be sure to keep these apps up-to-date), change passwords often, never use the same passwords, if an Autofill Breach happens then you’ll have to change all your passwords, never use a password for an encrypted device as a password online (an email is just good enough to get that password easily). There’s a lot to learn when considering practicing OpSec as well, this is just the start but I guess you get it.
As for Moderators, if you find anything leading to personal information in this post, you can remove that segment and leave the post as it is and not delete the whole post as it took me time to actually outline all this information. Hope you understand. Thanks.