
Guides
Mobile app privacy guide: permissions, location, contacts, photos, microphones, identifiers, and background access
Mobile app privacy guide covering permissions, location, contacts, photos, microphones, identifiers, and background access, plus what to revoke and when.
What to take away
- A permission grants capability under the operating system's rules; it does not prove access occurred.
- Grant the narrowest scope and shortest duration that still runs the feature you chose.
- Contacts, photos, and nearby-device access carry information about people who never installed the app.
- Revoking a permission stops future device access; it does not delete what a provider already holds.
- Ask the provider in writing for deletion, and keep the confirmation.
A permission screen controls part of how an app gets data. The rest arrives through sensors, the operating system, your account, and libraries inside the app. Connect each capability to a feature you actually use. Then check the platform controls named below, such as iOS App Tracking Transparency and Android permission auto-reset.
Match each permission to a feature you use
Name the task first. A video call needs camera and microphone while the call runs. A photo editor can work on images you select rather than your whole library. A restaurant finder can take one location fix; continuous background access needs a separate reason.
For each permission, record the feature that triggers it. Record the exact capability and whether access is once, while in use, or in the background. Record whether precise data is needed and what happens if the person declines. Then record these details:
Permission record checklist
- Name the feature that triggers it
- Capabilityonce, while in use, background
- Precise data needed?
- What happens if declined
- Who receives the result
- How to revoke and delete
To review permissions on iOS, open Settings, then Privacy and Security, then the permission type such as Location or Photos. To review one app, open Settings, scroll to the app, and tap its permission entries.
On Android, open Settings, then Apps, then the app, then Permissions. For location, choose Precise or Approximate. Android also offers one-time grants and permission auto-reset for unused apps.
Location
Location arrives from several sources:
Precise vs approximate location
Precise
- Exposes
- Exact spot
- Routine
- Full pattern
- Settings
- Separate toggle
- Saved data
- Check-ins remain
Approximate
- Exposes
- Neighborhood
- Routine
- Still revealed
- Settings
- Separate toggle
- Saved data
- Addresses remain
Approximate location still exposes a neighborhood and a routine. Turning off device permission leaves saved check-ins, delivery addresses, and photo coordinates in place.
Contacts and calendars
An address book describes people who never installed the app.
A full upload can carry:
Contacts vs calendar access
Contacts
- Exposes
- People not using app
- Data
- Names, numbers, emails
- Safer option
- Device-side matching
Calendar
- Exposes
- Meetings and notes
- Data
- Locations, participants
- Safer option
- Grant only half
Calendar access exposes meetings, locations, participants, and private notes. Where the platform separates reading from adding events, grant only the half you need.
Photos, camera, and microphone
Selected-photo access is narrower than full library access. A photo file can carry capture time, coordinates, device details, and faces.
Selected photos vs full library
Selected photos
- Access
- Narrower
- Metadata
- Capture time, coordinates
Full library
- Access
- Broad
- Metadata
- Device details, faces
Camera and microphone indicators show current or recent operating-system access. They do not show purpose, recording, upload, or retention. Unexpected use warrants a settings review, and in serious cases a report to the platform and to the Federal Trade Commission or your state attorney general. In Canada, the Office of the Privacy Commissioner takes complaints.
Bluetooth and nearby devices
Nearby-device access runs headphones, health accessories, cars, and local file transfer. It can also reveal that two devices were close at the same time. Grant it when you start a named feature, not because setup asked.
Identifiers and tracking
Apps use several identifiers:
- account IDs
- installation IDs
- advertising identifiers
- device tokens
- IP addresses
- generated identifiers
Apps also bundle libraries: analytics, advertising, crash-reporting, identity, payment, map, and messaging. A platform permission applies to the app process, not to one company inside it.
Resetting an advertising ID does not clear an account profile or the other identifiers tied to it.
Platform tracking controls limit defined cross-app or cross-company practices. On iOS, App Tracking Transparency is the switch that governs cross-company tracking. On Android, permission auto-reset and one-time grants limit how long an app keeps access. Read the platform's own definition; a denial is not a blanket ban on first-party analytics, fraud prevention, or account records.
Background activity
Background access refreshes routes, delivers calls, syncs files, and monitors devices while the app is closed. It also produces location, sensor, battery, and network activity you did not ask for.
Choose one-time or while-in-use access when it runs the feature. Review background location, background refresh, notifications, cellular data, and battery settings one at a time; each controls different behavior.
The FTC's guide for app developers starting with security tells developers to match security to the data they hold, limit collection, protect credentials, and keep updating after release. That is a lifecycle view. It does not certify any app as secure or compliant.
Build a practical baseline
- Install from a trusted store or an authorized enterprise source.
- Check the developer, update history, stated data practices, and whether an account is required.
- Deny permissions until a feature asks for them in context.
- Prefer selected, approximate, one-time, or while-in-use access.
- Review the permission dashboard and any unexpected indicator.
- Remove unused apps and revoke their linked account access.
- Use the service's deletion path for records held in the cloud.
A deletion request can be short. Send it to the provider's privacy contact and keep a copy.
"I am the account holder for [your email]. Please delete my account and all personal data you hold, including usage records, backups, and data shared with partners. Tell me which records you cannot delete and why. Confirm in writing when the deletion is complete."
Common questions
Does uninstalling an app delete its account data?
Not necessarily. Uninstalling removes the local app and some local data. Server records stay until you use the provider's account and deletion controls, and you should keep the confirmation they send.
Does denying tracking permission stop all analytics?
No. The platform control has a defined scope. First-party measurement, security events, and account activity can continue, and the platform's own page states what its switch covers.
Is approximate location harmless?
No. Repeated approximate areas with timestamps still sketch home, work, and routine. If that matters to you, revoke location and delete the saved places the service holds.
Can a permission prove the app used the data?
No. It establishes allowed capability. Indicators, dashboards, network logs, and provider records are what show actual use. For a suspected misuse in the United States, report to the FTC through its report fraud page or to your state attorney general. In Canada, the Office of the Privacy Commissioner takes complaints. A licensed lawyer can advise on your own situation.
In this guide
- How to audit mobile app permissions and background data accessAudit mobile app permissions app by app and by category, then tighten location, camera, microphone, contacts, photos, and background data access.
- Precise location, approximate location, foreground access, background access, geotags, and location history comparedMobile location modes compared by precision, timing, source, persistence, sharing, common uses, privacy exposure, device controls, account records, and deletion.
- Mobile app camera, microphone, photos, contacts, location, Bluetooth, notifications, and tracking checklistMobile app privacy checklist for source, version, camera, microphone, photos, contacts, location, nearby devices, notifications, background access, and removal.







