Checklist for reviewing mobile app camera, microphone, photos, and contacts permissions. Mobile app camera, microphone, photos, contacts, location, Bluetooth, notifications, and tracking checklist
Image: Privacy Notes

Maintenance

Part of Mobile app privacy guide: permissions, location, contacts, photos, microphones, identifiers, and background access

Mobile app camera, microphone, photos, contacts, location, Bluetooth, notifications, and tracking checklist

Mobile app privacy checklist for source, version, camera, microphone, photos, contacts, location, nearby devices, notifications, background access, and removal.

What to take away

  • Check the phone's own settings first. In-app menus often hide or soften permission controls.
  • On iPhone use Settings > Privacy & Security. On Android use Settings > Privacy > Permission manager, or read the mobile app privacy permissions guide to see what each permission actually changes.
  • Prefer selected photos, approximate location and while-in-use access over full-library, precise and always-on.
  • A dashboard records access, not upload. Uninstalling an app usually leaves the account and server-side data intact.
  • Record Pass, Partial, Fail, Not applicable or Unknown, with a date.

Check the phone settings directly

Both platforms group apps by permission, so a single pass covers the whole device.

  1. Open the control. iPhoneSettings > Privacy & Security. Android: Settings > Privacy > Permission manager.
  2. Read the app list for one category before changing anything.
  3. Switch off apps whose core function does not need that access, then choose Ask every time where offered.
  4. Reopen the app and test the features you rely on.

Apple's App Privacy Report shows supported sensor and data access plus network activity after you enable it. Apple's instructions explain how.

On supported Android versions the privacy dashboard lists which apps used a permission in the past 24 hours. Google's help page covers the dashboard and the per-app change.

PermissionSetting to aim forWhat it changes
CameraAsk or while-in-useBlocks background capture
MicrophoneAsk or while-in-useStops silent recording
PhotosSelected itemsApp sees only the images you pick
ContactsDeny, or one contactStops address book upload
LocationApproximateCity level, not street level
Nearby devicesDeny unless pairingLimits Bluetooth scanning
TrackingOffBlocks cross-app advertising identifier use

App identity and source

Confirm what you installed before you touch permissions.

App identity and source

  • Record app name, developer, package, version
  • Confirm installation source is authorized
  • Check update history and current support
  • Know account and feature purpose
  • Save dated store label and privacy notice
  • Know managed-device restrictions and admin contact
  • Developer name and contact details match the app you installed.
  • Version and last update date are recorded.
  • The store listing states which data the app collects and which permissions it requests.
  • The build came from the App Store, Google Play, or a signed enterprise source you can name.
  • Work profile or managed-device rules are known.

For a repeatable routine that covers background access as well, follow how to audit mobile app permissions.

Camera and microphone

Camera and microphone access is the pair most often granted by accident.

Camera and microphone access

  • Map camera access to a chosen feature
  • Map microphone access to a named function
  • Match recent-use indicators to expected activity
  • Deny access when feature is not in use
  • Control retention of recordings and cloud copies
  • Document unexpected indicators with evidence
  • Camera access maps to a feature you use, such as scanning or video calls.
  • Microphone access is limited to calls, recording or voice input.
  • Denial is tested and the app still works.
  • Clips, transcripts and recordings have a stated retention period, or you ask the developer.
  • Unexpected activation is reported and reviewed.

Photos and files

  • Selected-item access replaces full-library access.
  • Shared images are checked for coordinates and visible location clues.
  • Screenshots do not expose codes, messages or account details.
  • Downloads and app-created files have known storage locations.
  • Revoking access is not confused with deleting copied files.

Contacts and calendars

  • Address book access matches a feature you use, such as inviting someone by name.
  • Read and write are separateddoes the app add or edit entries?
  • Calendar access is limited to the calendar the feature needs.
  • A manual alternative exists when access is denied.
  • Synced contacts and events are cleaned up after removal.

Location, Bluetooth and nearby devices

Decide precise versus approximate location before you allow anything. The two settings change what the app can infer about where you live and work.

  • One-time, ask-each-time, while-in-use or background duration fits the feature.
  • Location history, check-ins and shared location are reviewed separately.
  • Photo geotags and saved addresses are included.
  • Each paired accessory and companion app is recognized.
  • Unused pairings are removed before resale.

Notifications, background behavior and tracking

  • Previews do not expose sensitive content on a locked screen.
  • Marketing notifications are separated from security and service alerts.
  • Background app refresh and battery exceptions are reviewed on their own.
  • Account, installation, advertising and push identifiers are separated.
  • Analytics, advertising, crash, map and payment recipients are listed.
  • The platform tracking choice matches your decision.

In the United States, the FTC has brought cases about health data collected through apps and connected devices, and its health privacy guidance sets out how it treats that data. State privacy laws add access and deletion rights for some residents.

Removal and closeout

  1. Preserve local files and your account recovery options first, because closing an account can cut off the email you need.
  2. Remove special access and device-administrator roles safely.
  3. Revoke connected apps, tokens and shared access.
  4. Treat uninstall, account closure and data deletion as separate actions.
  5. Retest calls, alarms, navigation, health and safety alerts.

Common questions

How do I check which permissions an app has on my phone?
Open Settings > Privacy & Security on iPhone or Settings > Privacy > Permission manager on Android, then choose a permission and read the app list.
Should I allow precise or approximate location?
Approximate covers weather, local news and store finders. Choose precise only for navigation, ride-hailing or delivery.
Does uninstalling an app delete my account and data?
Usually not. Use the service's account and deletion controls and keep the confirmation.
Can Bluetooth or nearby-device access reveal my location?
It can support proximity and location-based features. The effect depends on permissions, system design and the recipients.

More in Maintenance

Latest from Guides Desk