SecuFocus
Under the hoodNetworks & self-hosting

The smartphone: the biggest spy in your pocket?

Permissions, location, advertising and histories: understand the flows and reduce collection on iPhone and Android without giving everything up.

A phone partly tucked into a dark pocket, with fine illuminated paths leading to representations of location, contacts and photos.

Original AI-generated illustration · SecuFocus

At a glance

Key points

Apps, the operating system, your mobile carrier and online accounts can each collect different information from your phone. Start by removing unused apps, reviewing persistent permissions and checking the histories saved in your accounts. The iPhone and Android settings below show where to look.

Why this object knows so much

Our phones know our routes, store our photos and follow us into the bedroom. Their sensors and signed-in accounts give them access to much of our daily lives. The “spy in your pocket” in the title refers to this capacity to collect data; it does not mean every phone secretly records everything around it.

An app may request your location to show a route, send a report after a crash or use an identifier for advertising. These exchanges serve different purposes. You can restrict some while keeping the features you use.

Start with three separate decisions: which access an app receives, which activity an account records and how that information may subsequently be used. Changing one layer does not automatically settle the other two.

From sensor to server: several actors

When an app requests your location, the operating system grants or refuses access according to your settings. An authorised app may need it only on the device, or send it to a service. A component provided by a partner may also take part in processing. Permissions alone therefore do not describe the whole journey.

Microphone access is not proof that a recording was uploaded. A connection to a domain does not necessarily reveal what was exchanged. Conversely, an app without GPS permission can still know the searches and orders associated with your signed-in account. A sound investigation separates local access, transmission, storage and reuse.

The layerWhat to examine
Device and operating systemPermissions, sensors, backups, synchronisation and the manufacturer’s services.
ApplicationThe requested feature, granted access and information sent to the provider.
Libraries and partnersAnalytics, advertising, diagnostics or other embedded components. Assess their role rather than judging by their name alone.
Online accountHistory, recorded activity, linked devices and retention choices.
Mobile networkThe carrier provides connectivity. App permissions do not control all the information needed to maintain that connection.

An unsettling advert is not proof of eavesdropping

You mention a product, then an advert appears. It is a striking experience, but not sufficient evidence that the microphone recorded your conversation. An earlier search, a visited page, an inferred interest, the current context or coincidence offer other explanations. Technical evidence would be needed to distinguish those hypotheses in a particular case.

That does not mean no app can misuse a permission or that spyware does not exist. It means a conclusion should match its evidence. If a microphone or camera indicator appears for no understandable reason, check which app is responsible and remove access while investigating. Do not turn an advert into a diagnosis of compromise.

Ordinary tracking already deserves attention. It can work without listening to a single conversation. A browsing history or persistent identifier can support some types of personalisation.

The first fifteen minutes: remove and reduce

Start with the apps you actually use. A forgotten app offers little value, while its account, permissions or synchronisation may remain active. Uninstalling removes its software from your phone; it does not necessarily close the account or erase information already held by the service.

For each permission, ask a simple question: which feature would stop working if I refused it? A clear answer makes the trade-off easier. Permanent access for a feature used once a month deserves another look.

  1. Remove unused apps. First check whether they hold important files or provide a sign-in method you still need.
  2. Prioritise location, contacts, microphone, camera and photos. Prefer temporary or limited access when the feature supports it.
  3. Avoid uploading a whole address book for a feature you do not need. Looking up a contact manually may be sufficient.
  4. When sharing an image, choose selected-photo access instead of the whole library where that option is available.
  5. Review signed-in accounts and devices. Remove an old device you no longer use after confirming that you retain a way to sign in.

On iPhone: location, tracking and photos

In Settings → Privacy & Security → Location Services, review apps individually. “While Using the App” often suits an occasional task. Turn Precise Location off when an approximate area is enough. Keep precision for functions that actually need it, such as detailed navigation.

In Settings → Privacy & Security → Tracking, review granted permissions and whether apps may request tracking. Apple’s system covers tracking across other companies’ apps and websites, including advertising uses. Refusal does not remove every type of information the service can process within its own app.

Also review Photos, Contacts, Microphone and Camera under Privacy & Security. Available choices depend on the iOS version and app. Then test the useful function: share two images, call someone or start a route. A setting is easier to keep when you understand its effect.

On Android: permissions and advertising are separate controls

Go to Settings → Apps → choose an app → Permissions to review access. The permission manager, usually under Security & privacy, also lets you start with a type of information. For location, microphone or camera, examine “Allow only while using the app”, “Ask every time” and “Don’t allow” where offered.

Google separately documents ad privacy controls: Settings → Google → All services → Privacy & security → Ads → Ads privacy. On supported devices, these cover ad topics, app-suggested ads and ad measurement. Manufacturers may move the menus.

Also search settings for “advertising ID”. Deleting it, where supported, prevents apps from obtaining a usable advertising identifier through the relevant API. It does not remove a signed-in account, browser cookies or information a provider already holds. Resetting an identifier and deleting it are different actions.

Turning off GPS does not erase location everywhere

A mobile carrier must manage the phone’s connection to its network. Location information can arise from that connection even when an app cannot access GPS. EFF explains the distinction between cellular-network location tracking and information available to apps. Refusing a permission remains useful, but does not make a phone invisible to its network.

Precision also varies. An IP address may indicate an area without necessarily revealing an exact address. A location you voluntarily attach to a post is another source. Choose settings according to the information you want to limit, rather than a promise of general invisibility.

Reserve persistent location access for apps that need it. For others, try approximate location or access only while using the app. Check location sharing with family and friends separately from location saved in your accounts.

Stopping recording and deleting history

Phone permissions and account history are different issues. Google Timeline has its own controls. Turning it off does not stop every other location record. Review account services and activity separately; depending on the account and rollout, labels may refer to Web & App Activity or Search Services History.

Use Google account activity controls to inspect what is recorded and the available deletion options, including automatic deletion where offered. Distinguish pausing future collection from deleting existing records. Deletion in an interface does not mean every retention obligation or technical copy disappears instantly.

Apply the same reasoning to your other services: online gallery, shop, social network or fitness tracker. Before closing an account, check the files, subscriptions and sign-in methods that depend on it. Reducing collection is more useful than a sweeping cleanup that loses your own data.

Check access after changing settings

On iPhone, enable Settings → Privacy & Security → App Privacy Report. Recording starts after activation. The report includes sensor access and network connections over the last seven days. It can flag activity worth examining, but does not expose the content of every exchange or provide an exhaustive analysis.

On Android, Privacy Dashboard shows which apps have used certain permissions. The visible period depends on the version. It helps connect recent access to an app so you can adjust its permission. Look under Security & privacy or Privacy.

Return after a few days of normal use. Access you recognise may be justified. An unfamiliar domain deserves investigation, not an automatic accusation: it may deliver images or a useful feature. If a permission seems excessive, remove it and check whether the service you need still works.

VPNs, DNS and browsers: useful layers with limits

A VPN changes the network route and the IP address visible to websites. It does not revoke app permissions or sign you out of accounts. A service can associate activity with your signed-in account despite the VPN. You also entrust part of the route to another intermediary.

DNS filtering can block the resolution of certain known domains. It cannot always separate a useful function from tracking that shares the same domain. Depending on configuration, an app may also use another resolution mechanism. A filter is not proof that no information leaves the device.

Choosing browser protections and limiting persistent sign-ins can reduce some linkage on the web. Those choices do not automatically control native apps. Start with accounts and permissions, then add network layers when you understand their role.

Revisit permissions as your use changes

Privacy settings are easily abandoned when they become burdensome. Keep the routine short: review new apps, revisit permissions after a major update and check histories occasionally. Not every phone session needs to become an audit.

Device security remains the foundation: updates, a strong unlock code, protected accounts and a recoverable backup. Those measures do not eliminate commercial tracking. However, a compromised account or an unprotected phone can undo some of your other efforts.

After making these changes, pay attention to new permission requests and apps you no longer open. Data collection will not disappear entirely, but an access permission granted once need not remain open for years.

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

  1. Google: manage Timeline ↗support.google.com ·

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.