App Permissions Audit: What Your Phone Apps Can Really See
A torch app that wants your contacts. A photo filter that wants your precise location. A game that wants your microphone. Everyone has tapped "Allow" on something absurd, usually because the prompt appeared while they were trying to do something else and saying yes was faster than thinking.
Those decisions accumulate. The average phone has dozens of apps, each holding permissions granted years ago and never reviewed. An hour spent auditing them is one of the highest-value privacy actions available, and unlike most security advice it costs nothing and breaks nothing.
What the Dangerous Permissions Actually Give Away
Location
The most revealing permission on the phone. Continuous location history exposes your home, workplace, gym, place of worship, clinics you visit, and who you spend nights with. Location data is also one of the most heavily traded categories in the data broker market.
Critically, there are three levels and most people never distinguish them: Never, While Using the App, and Always. Almost nothing needs "Always". A maps app needs it while you use it. A delivery app needs it while you use it. A retail app needs it never.
Also check precise vs approximate. Precise location is metre-level. A weather app works perfectly well with approximate.
Contacts
Granting this uploads other people's names, numbers, and email addresses — data they never consented to share. Many social apps use it to build shadow profiles of people who never signed up. This is the permission most worth refusing on principle.
Microphone
Needed by calling, voice note, and recording apps. Nothing else. Modern phones show a coloured indicator when the mic is active — an orange dot on iPhone, a green indicator on Android — so watch for it appearing unexpectedly.
Camera
Same principle. Grant "while using" and never "always". Check whether the app really needs it or is only using it for an occasional QR scan.
Photos and media
Full library access hands over every photo you have ever taken, with the location and timestamp embedded in each one. Both platforms now offer selected photos only, which lets you share individual images without exposing the library. Use it everywhere.
Files and storage
On Android especially, broad storage access can expose documents and downloads far beyond what the app needs.
Accessibility services (Android)
The most powerful permission on the platform. It lets an app read everything on screen and act on your behalf. Legitimate uses exist for genuine accessibility tools, but this is also the permission that banking trojans and stalkerware need. Treat any request for it as a serious event.
Notification access
An app with this reads every notification you receive — including message previews and one-time codes.
Device admin (Android)
Lets an app lock, wipe, or resist uninstallation. Almost nothing consumer-facing needs it.
Health, motion, and fitness
Step counts and motion data infer sleep, exercise, commuting, and health conditions. Combined with location, they are extremely revealing.
Background app refresh and background location
Not framed as privacy settings, but they determine whether an app collects data when you are not using it — which is when most collection happens.
Warning Signs an App Is Over-Reaching
- The permission has nothing to do with the function. A calculator asking for location. A wallpaper app asking for contacts.
- The app refuses to work without an unnecessary permission. Some are technically required; many are leverage.
- Your location indicator appears constantly in the status bar when you are not navigating.
- The camera or microphone indicator lights up unexpectedly.
- Battery drain from an app you barely open — background collection costs power.
- Adverts that reflect somewhere you physically went, not something you searched.
- The app requests accessibility or device admin access and is not an accessibility tool or a corporate device manager.
- A free app with no obvious business model asking for extensive permissions. If the product is free and demanding, the data is the product.
How to Run the Audit
On iPhone
- Open Settings → Privacy & Security. This lists permissions by category — Location Services, Contacts, Microphone, Camera, Photos and so on. Going category by category is faster than app by app, because you immediately see every app holding a given permission.
- Start with Location Services. Set everything to "Never" or "While Using", and turn off Precise Location for anything that does not need street-level accuracy.
- Scroll to the bottom of Location Services and open System Services, then turn off Significant Locations if you do not want a stored history of everywhere you go.
- Under Photos, switch apps to Limited Access wherever possible.
- Open Tracking and make sure "Allow Apps to Request to Track" is off.
- Check Analytics & Improvements and Apple Advertising, and turn off personalised ads.
- Review Settings → General → VPN & Device Management for profiles you did not install.
- Use the App Privacy Report (Privacy & Security → App Privacy Report) — it shows which apps actually accessed your camera, mic, and location, and which domains they contacted. This is the single most revealing screen on the phone.
On Android
- Open Settings → Security & privacy → Privacy → Permission manager. Like iPhone, it is organised by permission type.
- Work through Location first — set to "Allow only while using" or "Don't allow", and turn off Use precise location where unnecessary.
- Review Contacts, Microphone, Camera, Files and remove anything unjustified.
- Turn on "Remove permissions if app isn't used" for every app. Android will automatically revoke permissions from apps you stop opening — genuinely useful and rarely enabled.
- Check Settings → Accessibility and disable any service you did not deliberately enable.
- Check Settings → Apps → Special app access — this is where the powerful permissions hide: device admin, notification access, install unknown apps, display over other apps, and usage access.
- Open Settings → Privacy → Privacy dashboard to see which apps used sensitive permissions in the last 24 hours.
- Reset your advertising ID under Settings → Privacy → Ads, and delete it entirely if the option is available.
Then do the harder part
Delete apps you do not use. An uninstalled app has no permissions at all. Go through your home screens honestly — most people can remove a third of what is installed. Also check the account behind each deleted app, since removing the app does not delete the data it already collected.
Good Habits Going Forward
- Deny first, grant later. Say no to any permission prompt you were not expecting. If a feature genuinely breaks, the app will ask again and you will understand why it needs it.
- Choose "While Using" by default and never "Always" unless you can articulate the reason.
- Use "selected photos" every time rather than full library access.
- Read the permission list before installing, not after. Both stores show it, and both show a data-collection summary on the listing page.
- Prefer the website over the app for services you use occasionally. A browser tab has far fewer permissions than an installed app.
- Re-audit twice a year. App updates add features, features request permissions, and permissions accumulate quietly.
If You Find Something Alarming
- Revoke the permission immediately rather than waiting until you have investigated. You can always grant it again.
- Look up the app before deleting it if it is unfamiliar — a search for its exact name usually settles whether it is a system component or something that should not be there.
- If an app you did not install holds accessibility or device admin access, treat it as possible stalkerware. Do not remove it before reading guidance on doing so safely if you are in a situation where someone may react badly.
- Check the App Privacy Report or Privacy Dashboard to see what it actually accessed and when.
- Delete the account, not just the app, and use your data deletion rights to ask the company to erase what it collected.
- Change passwords from a different device if you suspect anything captured your screen or keystrokes.
- Consider a factory reset if you find something you cannot explain and cannot remove cleanly.
The Bottom Line
Permissions are the actual privacy settings on your phone. Everything else — the policies, the consent banners, the settings buried in each individual app — is secondary to the simple question of what each app is allowed to reach.
Set aside one hour. Go through Location, Contacts, Microphone, Camera and Photos by category, set everything to the minimum that still works, turn on automatic permission removal for unused apps, and delete the apps you never open.
Then look at the App Privacy Report or Privacy Dashboard once. Seeing which apps quietly used your location fourteen times overnight is more persuasive than any article on the subject.
Comments
Post a Comment