First, protect your device with a password lock. (If you don't know how to do this, check your manual, or one of the how-tos posted by Cornell University IT.)
Consider setting up two-step authentication to make changes to your device settings.
Enable the auto-lock function, so if the device has been idle for a time (5 - 10 minutes is advised), you have to enter the password to access it.
Set up a tracking function (like the Android Device manager or Apple's Find My iPhone) on another device, so you can locate it if it is lost or misplaced.(link is external)or the
When signing up for something on the web, be sure that:
If you use your personal devices for work purposes, follow all updates and cautions that your workplace requires or recommends rigorously.
When it is time to replace or discard any device that once held any kind of personal data - your phone or laptop, but also iPad or tablet, digital camera, media player or game device, external hard drive or ISB (thumb) drive - be sure that data is deleted securely. It may not be sufficient to just "delete" files.
Don't connect to insecure networks, and don't auto-connect to wifi.
Turn off wifi and Bluetooth when not using them (this will also extend battery life).
If you backup regularly (and you should), also set up the ability to wipe your device remotely if it is lost or stolen.
Check the settings for all apps installed, and (if possible) don't allow them to stay running in the background, or to access to your information (like your Location) when not in use.
If an app needs to stay running, or to push information to you at anytime, or to constantly track your location by GPS, research the provider to see whether you think you can trust them before you allow that. Do: