Cyber Security

App Permissions Audit: What to Allow and What to Deny

App Permissions Audit: What to Allow and What to Deny

Photo credit: GadgetLite.net | All Things Tech

Use this checklist to review which apps can access your camera, microphone, location, and contacts — and decide what's actually necessary.

Key Takeaways

  • Most apps request more permissions than they actually need to function.
  • Camera, microphone, location, and contacts are the highest-risk permissions to review first.
  • Both Android and iOS let you revoke permissions at any time without deleting the app.
  • "Allow only while using" is safer than "always allow" for location-sensitive apps.
  • Unused apps with active permissions are a silent privacy risk worth removing.

Why Permissions Matter More Than You Think

Every time you install an app, it may request access to parts of your phone that go far beyond what it needs to do its job. A flashlight app asking for your contacts, or a game requesting your microphone — these are red flags that deserve scrutiny. Before you start this checklist, it helps to understand what each permission actually means so your decisions are informed, not guesswork.

Permissions fall into two broad categories: sensitive (camera, microphone, location, contacts, health data) and general (internet access, vibration, notifications). Sensitive permissions are where most privacy risk lives. This checklist focuses there.

Revoking a Permission Won't Delete Your Data

Removing an app's access to your camera or contacts stops future collection — it does not erase data the app may have already gathered. If you're concerned about data a specific app has collected, check its privacy policy for deletion request instructions or contact the developer directly. For apps you no longer use, uninstalling and submitting a data deletion request is the most thorough option.

Use this checklist on both your smartphone and tablet. The permissions systems on phones and tablets work similarly, but apps installed on tablets are often overlooked during audits.

How to Run Your Audit

On iPhone/iPad: Go to SettingsPrivacy & Security. Each permission type (Location Services, Microphone, Camera, etc.) shows every app that has ever requested it.

On Android: Go to SettingsPrivacyPermission Manager. You can browse by permission type and see which apps have access.

Work through the checklist below category by category. For each app listed under a sensitive permission, ask yourself: Does this app genuinely need this to work? If the answer is no or uncertain, deny or restrict it. You can always re-enable a permission if an app stops working as expected.

Required

iOS Privacy & Security Settings

Built-in iPhone and iPad tool for reviewing and revoking all sensitive app permissions by category.

Required

Android Permission Manager

System tool on Android devices for auditing which apps hold which permissions and revoking them individually.

Optional

Android Privacy Dashboard

Shows a timeline of recent microphone, camera, and location access to help identify unexpected app activity.

For a deeper look at what over-permissioning can cost you, see the hidden risks of granting too much access. And if you want to extend this review beyond permissions to connected accounts and data-sharing settings, the full app privacy audit checklist is a natural next step.

Permissions Checklist

Work through each group below. For any permission you decide to revoke, do so from your system settings — not from inside the app itself — to ensure the change takes effect immediately.

Location Access

Open Location Services and list every app set to "Always" — change any that don't require background tracking (like weather or fitness apps) to "While Using." Must
Deny location access entirely for apps that have no plausible need for it, such as productivity tools, games, or document editors. Must
Check whether precise location is enabled; switch to approximate location for apps that only need general area data (e.g., local news apps). Should

Camera & Microphone

Review every app with camera permission — deny access to any app that has no photo, video, or scanning feature you actually use. Must
Review every app with microphone permission — deny access to any app that is not a voice, video call, or audio recording tool. Must
On Android, check the Privacy Dashboard for a timeline of recent camera and microphone usage to spot any unexpected access events. Should

Contacts & Calendar

Deny contacts access for any app that has no clear communication or social feature — your address book contains other people's data, not just yours. Must
Deny calendar access for apps that don't explicitly offer scheduling, reminders, or event-based features. Must
For apps that do need contacts (e.g., messaging apps), verify they are from a reputable developer before allowing full access. Should

Storage & Files

On Android, revoke broad storage access ("All files") from any app that only needs to save or read its own files — most apps work fine with scoped access. Must
Deny photo library access for apps with no editing, sharing, or uploading function; choose "Selected photos" access when a full library grant is requested. Should
Review which apps can access your Downloads folder or Documents and remove any that have no business reason to be there. Nice to have

Notifications & Background Activity

Disable notifications for apps you rarely open — notification access is lower risk but contributes to information overload and can reveal app usage patterns. Should
On iOS, disable Background App Refresh for apps that don't need to update while closed (Settings → General → Background App Refresh). Should
On Android, restrict background data for non-essential apps under Settings → Apps → [App Name] → Mobile Data & Wi-Fi. Nice to have

Unused & Abandoned Apps

Identify apps you haven't opened in 90 days or more and uninstall them — dormant apps with active permissions are an unnecessary risk. Must
Before uninstalling, check whether the app has an account associated with it and request data deletion from the service if applicable. Should
Enable automatic app permission revocation on Android (Settings → Apps → [App Name] → Permissions → Pause app activity if unused) to automate this process going forward. Nice to have

Children's Devices Need Extra Scrutiny

Apps marketed to children — games in particular — have been documented requesting permissions that go well beyond gameplay. If you're auditing a phone or tablet used by a child, pay close attention to contacts, microphone, and location permissions. Many jurisdictions impose stricter data rules for apps used by minors, but enforcement is inconsistent. Manual review remains your most reliable safeguard.

After completing your audit, revisit app privacy settings most people overlook to catch anything this checklist doesn't cover, such as ad tracking identifiers and background data refresh.

Cyber Security Editorial Team

Author

Cyber Security Editorial Team

Cyber Security Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles →
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.