Apps & Software

Your App Privacy Audit: A Step-by-Step Checklist

Your App Privacy Audit: A Step-by-Step Checklist

Photo credit: GadgetLite.net | All Things Tech

Work through this checklist to review permissions, connected accounts, and data-sharing settings across your installed apps.

Key Takeaways

  • Many apps collect far more data than their core function requires — a regular audit helps you spot and limit unnecessary access.
  • Permissions for location, camera, microphone, and contacts carry the highest privacy risk and deserve the closest review.
  • Connected third-party accounts and forgotten app logins are common sources of data exposure that are easy to clean up.
  • Both Android and iOS have built-in privacy dashboards that make auditing your installed apps much faster.
  • Deleting apps you no longer use is one of the simplest and most effective privacy steps you can take.

Why You Need a Privacy Audit — Not Just a One-Time Settings Check

Installing an app takes seconds. Reviewing what that app can access, share, and store often never happens at all. Over time, most people accumulate dozens of apps — many of them rarely opened — each potentially holding permissions granted years ago under different circumstances.

A privacy audit is different from a one-time settings tweak. It's a structured review of every layer where your data might be exposed: hardware permissions, data-sharing toggles, connected accounts, and apps you've simply forgotten about. Think of it as a periodic health check for your digital life.

This checklist walks you through that process systematically. If you want to go deeper on any individual setting after completing the audit, the App Privacy Settings You Should Review Right Now guide covers the most commonly overlooked options in detail. And for building habits that keep your privacy in good shape long-term, see Staying in Control: Ongoing Habits for Better App Privacy.

Required

iOS Privacy & Security Settings

Built-in dashboard for reviewing app permissions, tracking requests, and App Privacy Report on iPhones.

Required

Android Privacy Dashboard

Built-in tool on Android 12 and later that shows a timeline of which apps accessed sensitive permissions.

Required

Google Account Security Page

Lists all third-party apps connected to your Google account so you can review and revoke access.

Required

Apple ID Account Settings

Shows every app using 'Sign in with Apple' so you can manage or revoke those connections.

Optional

Spreadsheet or Notes App

Useful for tracking which apps you've reviewed and any follow-up actions you want to take.

The Full App Privacy Audit Checklist

Work through each group in order. You don't need to complete everything in one sitting — the audit naturally breaks into stages. Start with permissions since those carry the most immediate risk, then move to connected accounts and data settings.

Revoking Permissions May Affect App Features

Removing a permission doesn't delete the app or your account — it simply restricts what the app can access going forward. However, some features may stop working as expected. For example, revoking location access from a maps app will prevent turn-by-turn navigation. Review each revocation carefully and decide whether the trade-off is worth it for your usage.

For a dedicated deep-dive into deciding what hardware access to grant or revoke, the App Permissions Audit: What to Allow and What to Deny guide walks through each permission type with practical guidance on what's actually necessary.

Preparation

Open your phone's Settings app and navigate to the Apps or Privacy section to get a full list of installed apps. Must
Make a note of any apps you haven't opened in the past three months — these are your first deletion candidates. Must
On iOS, open Privacy & Security > Privacy Report; on Android, open Privacy > Privacy Dashboard to get an overview of recent permission use. Should

Hardware Permissions Review

Check which apps have access to your location and verify whether each one genuinely needs it — revoke or downgrade to 'While Using' for any that don't. Must
Review camera and microphone access and remove permissions from any app that has no clear reason to use them. Must
Check contacts access and limit it to apps where syncing your contact list is a core, expected feature. Must
Review calendar and health data permissions and revoke access from any app you no longer actively use. Should
Check which apps can access your photo library and limit full access to apps that truly need it — use 'Selected Photos' where available on iOS. Should

Connected Accounts & Third-Party Logins

Log in to your Google account and navigate to Security > Third-party apps with account access to see every app authorized to use your Google data. Must
Do the same in your Apple ID settings under Password & Security > Apps Using Apple ID and revoke access for services you no longer use. Must
Review Facebook, Microsoft, or other single-sign-on (SSO) accounts for apps authorized to connect — remove any you don't recognize or no longer need. Should
Check whether any app has been granted access to your email inbox (via OAuth) and revoke it if you don't recall authorizing it. Should

In-App Data & Tracking Settings

Open each major app you use regularly and locate its in-app privacy or data settings — many apps have their own controls beyond what your OS shows. Must
On iOS, go to Settings > Privacy & Security > Tracking and disable 'Allow Apps to Request to Track' if you prefer not to be targeted across apps. Should
Check whether apps offer a data deletion or account deletion option and use it for services you're permanently leaving. Should
Review any app that handles financial or health data and confirm you understand what it stores and whether it shares data with third parties. Must

Cleanup & Final Steps

Delete all apps you identified earlier as unused — uninstalling removes their permissions automatically and eliminates a potential data exposure point. Must
Schedule a reminder to repeat this audit every three to six months so permissions don't quietly accumulate again. Should
Skim the privacy policy of any app where you're unsure about data practices — focus on the 'data sharing' and 'data retention' sections; see how to read a privacy policy without losing your mind for a practical approach. Nice to have

Once you've worked through the checklist, it's worth pairing this audit with a broader Account Security Audit to review passwords, two-factor authentication, and active sessions at the same time. If you also want to verify your data is properly backed up, the Personal Data Backup Audit is a natural follow-up.

Don't Confuse Deleting an App With Deleting Your Account

Removing an app from your device does not automatically delete your account or the data the company already holds. If you want your data removed, you typically need to request account deletion through the app or the company's website before uninstalling. Check the app's privacy policy or support pages for the correct process.

Apps & Software Editorial Team

Author

Apps & Software Editorial Team

Apps & Software Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles →
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.