Everything here will be for iPhones and Windows computers because I'm basically thinking of what I would do for my parents. Everything for iPhones is applicable to iPads. I don't think there's anything groundbreaking here, but from reading a ton of guides and advice and so on, discerning what a "threat model" is, I feel pretty confident about paring down a lot of the advice to this bare minimum. You can do more, but these lists are high impact, easy changes that won't affect how anyone uses the internet. If it does, then you probably saved them from having their identity stolen or something.
iOS
If they're using a browser that's not Safari, uninstall it and tell them to use Safari.
In Settings > Apps > Safari, make sure all of the Privacy & Security settings are green (switched on), except for Highlights unless they're into that AI business.
In Advanced (in Safari's settings), make sure Advanced Tracking and Fingerprinting Protection is set to "All Browsing" and turn off Privacy Preserving Ad Measurement.
Install the Safari extension uBlock Origin Lite and keep it on "Optimal."
Optional: If you don't want them getting into all that AI business, add in Stevo's GenAI Blocklist.
Install the Safari extension uBlacklist for Safari and add the Huge AI Blocklist. This will helpfully filter out slop websites from search engines.
Switch their default search engine to DuckDuckGo, probably.
Install the AdGuard DNS configuration profile. imo don't install the app, just download the configuration file (under Option 2: Configure AdGuard manually) and let it run in the background. That will block a lot of the shit coming through the apps.
Bonus points: In Settings > Privacy & Security > Tracking, turn off Allow Apps to Request to Track. In Privacy & Security > Apple Advertising, turn off Personalized Ads. (This won't be an option if they've never opened Apple News or something.)
Windows
You know, if you can get them to interact with Linux, then probably just install Linux Mint and be done with it. Presuming they won't want to do that...
If they're using Google Chrome, try to get them to use Firefox. There's really not a great winner here and Google Chrome certainly isn't the worst except for the Google of it all, but the switch will do them good. This list is for Firefox.
Install uBlock Origin and LocalCDN.
Import the Huge AI Blocklist to clean up search results. Import Stevo's GenAI Blocklist if they don't need to be messing with all that.
Add the Betterfox user.js. All of the default settings are good.
If you made them switch, be nice and import all of their bookmarks and stuff.
If you want to be extra nice, install the Bypass Paywalls Clean add-on.
Here's Chrome:
Install uBlock Origin Lite and Decentraleyes.
So many settings to change:
...actually I can't remember everything that should be changed and I don't want to download Chrome, so...I'll update this later. General privacy advice applies here, so things like block third-party cookies, and so on.
For Windows itself, if all they need is a dead simple computer, there's a very opinionated script to simplify Windows: Win11Debloat. Then double check settings for no analytics, telemetry, and the like. Ideally, imo, you'd run tiny11builder and then give them a fresh install of Windows so there's nothing dragging it down. These are both rather extreme options as far as it goes, but Windows is just really awful.
Bonus points: Set the default DNS resolvers on their router to the AdGuard Public DNS just to set up some redundancy.