Checklist for auditing mobile app permissions and background data access. How to audit mobile app permissions and background data access
Image: Privacy Notes

Guides

Part of Mobile app privacy guide: permissions, location, contacts, photos, microphones, identifiers, and background access

How to audit mobile app permissions and background data access

Audit mobile app permissions app by app and by category, then tighten location, camera, microphone, contacts, photos, and background data access.

What to take away

  • Record the device, operating-system version, app version, account, and review date for every app you check.
  • Review twiceonce app by app, once by permission category. Each view catches what the other misses.
  • Move location from always to while-in-use, and from precise to approximate, unless a feature breaks.
  • Background location, background data, refresh, battery, and notifications are separate switches. Check each.
  • Preserve local files and account recovery before uninstalling anything.

Menu names vary by phone maker, operating-system release, device management, app source, and region. Use current help for exact steps. On a work, school, health, or family-managed device, follow the owner's policy and support process.

Build the inventory first

App inventory fields

  • App name and publisher
  • Install source
  • Last use date
  • Signed-in account
  • Update date
  • Categorypreinstalled, work, keyboard, launcher, VPN

Include these categories:

  • preinstalled ones
  • work-profile apps
  • keyboards
  • launchers
  • VPN clients

Those hold access that never appears in a store listing.

Do not copy full device identifiers, authentication secrets, private messages, or health data into the audit sheet. Record the app name and the permission, nothing more.

Review one app end to end

Per-app review checklist

  • Requested and current permissions
  • Battery mode and cellular data
  • Background refresh and notifications
  • Storage and default-link settings
  • Special access on app info page
  • Justify each setting by a used feature

Then ask which feature you actually use needs each setting. "The app asked for it" is not a purpose. Mark anything you cannot justify as Unknown and test it later.

Review by permission category

The system permission manager lists every app holding certain access types.

Permission categories to review

  • Camera, microphone, location
  • Contacts, calendar, photos, files
  • Nearby-device, call, message
  • Health, motion, notification
  • Read once per category

Google's instructions for changing Android app permissions cover the app-by-app and permission-type views, choices such as while in use or ask every time, and automatic pausing of unused apps on supported versions. Use that page for Android concepts and current steps, not for iOS or every manufacturer's menu.

Apple documents the iPhone side in controlling app access to information on iPhone, including the per-app permission list, the App Privacy Report showing how granted permissions were used, and where to revoke future access.

The category view earns its place by catching the app that looks harmless alone but sits among five microphone grants.

Tighten location

For each app with location access, record six things:

Location access audit

  • Precise or approximate
  • One time, ask, while using, always
  • Feature that needs it
  • Saved history or home labels
  • Shared with others
  • What happens after revoke

Move from always to while-in-use, from precise to approximate, or from permission to typing the place by hand. Test the feature afterward. A weather app set to approximate still finds your city; a delivery app may not find your door.

Limit contacts and media

Offer selected contacts or manual invitations instead of full address-book access where the app supports it. If a contact list was already uploaded, use the app's own controls to remove it and keep the confirmation.

Photo sharing check

  • Location metadata
  • Documents behind subject
  • Badges
  • Addresses
  • Screens
  • Reflections in glass

Choose selected photos rather than the whole library. Before sending any image, check these details:

  • location metadata
  • documents behind the subject
  • badges
  • addresses
  • screens
  • reflections in glass

Check camera and microphone history

Privacy dashboards and recent-use indicators show when the camera or microphone was active. Match each event to something you did. The dashboard covers a limited window, and access does not prove that anything was uploaded.

If an event makes no sense, revoke the permission, save the time and app details, update the app and the system, and ask the publisher or platform support. An indicator alone is not an accusation.

Separate the background controls

Background location, background data, app refresh, and unrestricted battery are different switches. Persistent notifications and foreground services are also different switches. Each has different effects. Review each one on its own.

Turn off background access for an app that only needs data while it is open. Test navigation, calls, file sync, and health accessories carefully. Also test alarms and safety features carefully. Over-tightening breaks the service you wanted.

Inspect special access

Accessibility services and device administrators reach further than ordinary permissions. The same is true for notification access and display over other apps. So do install-unknown-apps and usage access. Several more roles also reach further:

  • unrestricted data
  • VPN
  • keyboard
  • password-manager roles They are worth a separate pass.

Remove a role before uninstalling the app when the platform requires that order. If a sideloaded app asks you to bypass restricted settings, check the publisher and purpose somewhere independent first.

Compare what the app claims

Read the current store data label and the privacy notice. Record what they say about collection, sharing, advertising, retention, and deletion:

  • Collection
  • Sharing
  • Advertising
  • Retention
  • Deletion

Then set that beside the permissions and dashboard events you found.

A network domain in a report shows a connection, not what data moved. A store label is the developer's own statement, not independent proof. Turn each mismatch into a precise question for the publisher.

Test, then close

Use the feature after tightening. Confirm that a denial gives you a clear choice instead of a dead end. Recheck permissions after the test and again after the next app update.

Before uninstalling, save local files and confirm you can still recover the account. Then remove connected access and close or delete the account separately if you want that. Log the change, the exception, the owner, and the next review date.

Common questions

Should every permission be denied by default?

Start narrow and grant access when a feature you chose needs it. Navigation, calling, safety, and accessibility functions may genuinely need continuing access, so judge those by use rather than by principle.

Does a permission dashboard show everything an app collected?

No. It covers supported device access during a limited period. It does not show account records the app already holds, network transfers, or anything from before the dashboard window.

Does uninstalling remove a VPN or device-management role?

Platforms differ. Remove special roles through system settings first, and follow managed-device policy before uninstalling. On a work or school device, the administrator controls that order.

When should the audit repeat?

After a major system or app update, a new phone, an unexpected indicator, a change of device owner, or a material change to what the app does.

More in Guides

Latest from Guides Desk