
Maintenance
Mobile app camera, microphone, photos, contacts, location, Bluetooth, notifications, and tracking checklist
Mobile app privacy checklist for source, version, camera, microphone, photos, contacts, location, nearby devices, notifications, background access, and removal.
What to take away
- Check the phone's own settings first. In-app menus often hide or soften permission controls.
- On iPhone use Settings > Privacy & Security. On Android use Settings > Privacy > Permission manager, or read the mobile app privacy permissions guide to see what each permission actually changes.
- Prefer selected photos, approximate location and while-in-use access over full-library, precise and always-on.
- A dashboard records access, not upload. Uninstalling an app usually leaves the account and server-side data intact.
- Record Pass, Partial, Fail, Not applicable or Unknown, with a date.
Check the phone settings directly
Both platforms group apps by permission, so a single pass covers the whole device.
- Open the control. iPhoneSettings > Privacy & Security. Android: Settings > Privacy > Permission manager.
- Read the app list for one category before changing anything.
- Switch off apps whose core function does not need that access, then choose Ask every time where offered.
- Reopen the app and test the features you rely on.
Apple's App Privacy Report shows supported sensor and data access plus network activity after you enable it. Apple's instructions explain how.
On supported Android versions the privacy dashboard lists which apps used a permission in the past 24 hours. Google's help page covers the dashboard and the per-app change.
| Permission | Setting to aim for | What it changes |
|---|---|---|
| Camera | Ask or while-in-use | Blocks background capture |
| Microphone | Ask or while-in-use | Stops silent recording |
| Photos | Selected items | App sees only the images you pick |
| Contacts | Deny, or one contact | Stops address book upload |
| Location | Approximate | City level, not street level |
| Nearby devices | Deny unless pairing | Limits Bluetooth scanning |
| Tracking | Off | Blocks cross-app advertising identifier use |
App identity and source
Confirm what you installed before you touch permissions.
App identity and source
- Record app name, developer, package, version
- Confirm installation source is authorized
- Check update history and current support
- Know account and feature purpose
- Save dated store label and privacy notice
- Know managed-device restrictions and admin contact
- Developer name and contact details match the app you installed.
- Version and last update date are recorded.
- The store listing states which data the app collects and which permissions it requests.
- The build came from the App Store, Google Play, or a signed enterprise source you can name.
- Work profile or managed-device rules are known.
For a repeatable routine that covers background access as well, follow how to audit mobile app permissions.
Camera and microphone
Camera and microphone access is the pair most often granted by accident.
Camera and microphone access
- Map camera access to a chosen feature
- Map microphone access to a named function
- Match recent-use indicators to expected activity
- Deny access when feature is not in use
- Control retention of recordings and cloud copies
- Document unexpected indicators with evidence
- Camera access maps to a feature you use, such as scanning or video calls.
- Microphone access is limited to calls, recording or voice input.
- Denial is tested and the app still works.
- Clips, transcripts and recordings have a stated retention period, or you ask the developer.
- Unexpected activation is reported and reviewed.
Photos and files
- Selected-item access replaces full-library access.
- Shared images are checked for coordinates and visible location clues.
- Screenshots do not expose codes, messages or account details.
- Downloads and app-created files have known storage locations.
- Revoking access is not confused with deleting copied files.
Contacts and calendars
- Address book access matches a feature you use, such as inviting someone by name.
- Read and write are separateddoes the app add or edit entries?
- Calendar access is limited to the calendar the feature needs.
- A manual alternative exists when access is denied.
- Synced contacts and events are cleaned up after removal.
Location, Bluetooth and nearby devices
Decide precise versus approximate location before you allow anything. The two settings change what the app can infer about where you live and work.
- One-time, ask-each-time, while-in-use or background duration fits the feature.
- Location history, check-ins and shared location are reviewed separately.
- Photo geotags and saved addresses are included.
- Each paired accessory and companion app is recognized.
- Unused pairings are removed before resale.
Notifications, background behavior and tracking
- Previews do not expose sensitive content on a locked screen.
- Marketing notifications are separated from security and service alerts.
- Background app refresh and battery exceptions are reviewed on their own.
- Account, installation, advertising and push identifiers are separated.
- Analytics, advertising, crash, map and payment recipients are listed.
- The platform tracking choice matches your decision.
In the United States, the FTC has brought cases about health data collected through apps and connected devices, and its health privacy guidance sets out how it treats that data. State privacy laws add access and deletion rights for some residents.
Removal and closeout
- Preserve local files and your account recovery options first, because closing an account can cut off the email you need.
- Remove special access and device-administrator roles safely.
- Revoke connected apps, tokens and shared access.
- Treat uninstall, account closure and data deletion as separate actions.
- Retest calls, alarms, navigation, health and safety alerts.







