Social Media Privacy Checkup: Lock Down Every Account in 20 Minutes

Run a social media privacy checkup in 20 minutes: lock down post visibility, revoke old connected apps, kill location tags, and turn on two-factor login.

I assumed my social media accounts were locked down because I’d set them to private years ago and never touched the settings again. Then I ran a full social media privacy checkup on my own Facebook and Instagram accounts and found 47 forgotten apps still authorized since 2019, two old sessions logged in from cities I’ve never visited, and a public location tag on a photo from my kid’s school.

The real risk isn’t one leaked password — it’s the years of accumulated app permissions, forgotten sessions, and public tags that quietly pile up while you’re not looking.

Quick Answer

A social media privacy checkup means reviewing who can see your posts, revoking old connected apps, turning off precise location tagging, and enabling two-factor authentication on every account you use. Spend about 20 minutes total, start with Facebook and Instagram, and you close the biggest exposure gaps that scammers and stalkers actually exploit.

What Does a Social Media Privacy Checkup Actually Cover?

A privacy checkup isn’t one toggle. It touches four layers: post audience, third-party app access, location and tag exposure, and login protection. Skip one layer and the other three don’t matter much.

I run mine every six months alongside my Google Security Checkup, since both catch stale connected apps and old sessions.

Treat a privacy checkup as four separate layers, not one setting, or you’ll miss the gap that actually gets exploited.

How Do You Lock Down Facebook Privacy Settings?

Audience and Visibility Settings

Open Settings & Privacy > Settings > Audience and Visibility. Set “Who can see your future posts” to Friends, not Public, and run the “Limit Past Posts” tool to retroactively hide old public updates.

Timeline and Tagging Review

Under Profile and Tagging, turn on “Review posts you’re tagged in before they appear on your timeline.” This is the one setting most people skip, and it’s what let a stranger’s tagged photo of me sit in search results for months.

Pro tip: Facebook’s “Off-Facebook Activity” page, under Settings, lists every site and app that reported activity back to Facebook. Clear it and disconnect future tracking in one click.

Facebook’s audience and tagging settings decide whether a stranger can find you through someone else’s post, not just your own.

How Do You Lock Down Instagram and TikTok Privacy?

Instagram Privacy Basics

Switch your account to Private under Settings > Account Privacy, then check Settings > Story and turn off “Allow Sharing” so screenshots and replays don’t spread past your followers.

TikTok Privacy Basics

Go to Settings and Privacy > Privacy > Discoverability, set the account to Private, and turn off “Suggest your account to others.” TikTok defaults new accounts more openly than most people expect, so verify this even on an account you set up years ago.

Instagram and TikTok both bury the settings that stop your content from being screenshotted or recommended to strangers.

What Should You Check on X and LinkedIn?

Both default to public visibility, making them the easiest place to overshare. Here’s where each platform stands by default.

Platform Default Post Visibility Where to Change It Biggest Risk If Ignored
Facebook Public (new accounts) Settings & Privacy > Audience Old public posts stay searchable
Instagram Public Settings > Account Privacy Strangers can DM and screenshot stories
TikTok Public Privacy > Discoverability Videos get recommended to strangers
X (Twitter) Public Settings > Privacy and Safety Location and tagging exposed by default
LinkedIn Public Settings & Privacy > Visibility Connections list fully exposed

On X, go to Settings and Privacy > Privacy and Safety and turn off photo tagging and precise location. On LinkedIn, turn off “Profile viewing options” under Visibility so you browse anonymously, and hide your connections list.

X and LinkedIn both leak location and network data by default, so check them even if you post there rarely.

How Do You Stop Location Sharing and Tag Exposure?

Turn off precise location for each app in your phone’s system settings, not just inside the app: iPhone is Settings > Privacy & Security > Location Services; Android is Settings > Location > App Permissions.

Also disable “Nearby Friends” style features you enabled once and forgot, since they broadcast your live location.

Troubleshooting tip: if a photo still shows a location tag after disabling Location Services, the tag was likely added manually at posting time. Edit or delete that old post directly; the system setting only affects future uploads.

Turning off location in the app isn’t enough — check your phone’s system-level permission too, and clean up old tags manually.

How Do You Audit Connected Apps and Old Logins?

Every platform hides a list of third-party apps and active sessions.

Facebook and Instagram

Go to Settings > Apps and Websites (or Accounts Center > Connected Experiences) and revoke anything unused in the last year.

Active Sessions

Under Security and Login, review “Where You’re Logged In” and log out of any device or city you don’t recognize.

While you’re there, add a passkey or app-based two-factor authentication instead of SMS codes, the exact weakness SIM swapping attacks target. A free manager like the one in my Bitwarden setup guide removes the password risk entirely, and the Electronic Frontier Foundation keeps a solid account-security reference worth bookmarking.

Old connected apps and forgotten sessions are the quiet backdoor most people never think to close.

Common Mistakes to Avoid

  • Checking the app but not the phone’s location permission. Fix: review both; the app setting doesn’t override system-level access.
  • Assuming “Private” hides old public posts. Fix: run “Limit Past Posts” or delete old public updates manually.
  • Relying on SMS codes for two-factor authentication. Fix: switch to an authenticator app or passkey where supported.
  • Never revisiting connected third-party apps. Fix: set a six-month reminder to review and revoke unused access.
  • Ignoring tagging settings on other people’s posts. Fix: turn on tag review so nothing posts without your approval.

Frequently Asked Questions

How long does a full social media privacy checkup take?
About 20 minutes covering Facebook, Instagram, and one more platform you actually use. My own run took 24 minutes, including revoking nine old connected apps.

Do I need to do this on every platform I have an account on?
Focus first on platforms tied to your real name. I ignored an old MySpace-era account for years until a breach notice reminded me it still held my birthdate.

Will making my account private hurt my reach or followers?
Yes, it limits discovery, which matters if you’re building a public profile. For a personal account, that tradeoff is worth it.

Can someone find my old public posts after I go private?
Possibly, if they were indexed or screenshotted first. Run “Limit Past Posts” and search your own name to check.

What’s the single most important setting to fix first?
Two-factor authentication on your login. I’d rather a stranger see one old photo than lose the whole account to a password leak.

Conclusion

A social media privacy checkup takes less time than one scroll through your feed, and it closes the gaps that get exploited: stale app access, forgotten sessions, default public settings. Block 20 minutes this week, start with Facebook, and work down this list one platform at a time.

8 WhatsApp Privacy Settings to Change — Most People Never Touch Them

Change these 8 WhatsApp privacy settings now — stop strangers from seeing your profile photo and last-seen time before they have sent you a single message.

WhatsApp ships with almost every profile field visible to everyone who has your phone number. A stranger, a spammer, or someone who pulled your number from a leaked database can see your profile photo, your About text, and exactly when you last opened the app — before they send you a single message. The WhatsApp privacy settings to change are all sitting in the Privacy menu, and most users never open it.

I found this out after an unknown number sent me an unsolicited sales pitch, having clearly already viewed my profile photo before writing. A five-minute check of Settings > Privacy closed every gap I could find. The single most important insight: WhatsApp privacy settings default to permissive on purpose, and locking them down costs you nothing in normal day-to-day use.

Quick Answer

Open WhatsApp, go to Settings > Privacy, and set Last Seen, Profile Photo, About, and Status to “My Contacts.” Turn off Read Receipts. Set Groups to “My Contacts.” Go to Account > Two-step verification and create a 6-digit PIN. Return to Privacy and enable App Lock. All eight changes take under five minutes.

Why Are WhatsApp’s Default Settings a Privacy Risk?

WhatsApp’s end-to-end encryption protects what you send in transit — that part is genuinely strong. What encryption does not protect is your profile metadata. Your photo, Last Seen timestamp, About text, and online status are all readable by any phone number that has yours, even if you have never interacted. Spam networks use this data to confirm which numbers are active and build target profiles. WhatsApp’s privacy policy confirms it collects usage metadata visible to users who have your number. Changing your Privacy settings is the only lever you control here.

WhatsApp encrypts your messages but leaves your profile metadata open to anyone with your number — only the Privacy settings menu changes that.

Which Visibility Settings Should You Change First?

These four settings are all in WhatsApp > Settings > Privacy and take one tap each to update.

Setting Default Recommended What It Stops
Last Seen & Online Everyone My Contacts Hides your activity pattern from unknown numbers
Profile Photo Everyone My Contacts Shows a grey silhouette to non-contacts
About Everyone My Contacts Removes your bio from public view
Status My Contacts My Contacts (verify) Confirms this has not been reset by an app update

Last Seen and Online Status

This setting has two separate dropdowns — Last Seen and Online — and both default to “Everyone.” Set both to “My Contacts.” Unknown numbers see a dash instead of a timestamp. Spam operations actively use Last Seen patterns to verify a number is live before targeting it; this one change removes you from that check entirely.

Profile Photo and About

Set both to “My Contacts.” Phrases like “Mum of two, Bristol” in your About text hand free profile-enrichment data to anyone who finds your number. A grey silhouette replaces your photo for non-contacts, which also stops cold-callers from confirming they have reached the right person before they message you.

Pro tip: After changing Profile Photo to “My Contacts,” ask a friend whose number you have not saved to look you up. They should see only a grey silhouette — no photo, no About text, no Last Seen.

Setting Last Seen, Profile Photo, and About to “My Contacts” immediately removes your personal data from anyone who has your number but is not in your address book.

Which Messaging and Group Settings Matter Most?

Read Receipts — Setting 5

Go to Privacy > Read Receipts and switch it off. Blue ticks no longer turn blue when you read a message. The setting is mutual — you also stop seeing read receipts from other people in one-to-one chats. I have had this off for over a year and have never wanted it back on. It removes the pressure to reply the instant you open a message.

Groups — Who Can Add You — Setting 6

Under Privacy > Groups, change “Who can add me to groups” to “My Contacts.” Anyone not in your address book now receives an invitation link instead of adding you directly. Bulk spam groups target fresh numbers by adding them automatically using the default “Everyone” setting; switching to “My Contacts” stops this cold.

Troubleshooting tip: If a genuine contact says they cannot add you to a group after this change, check that you have their number saved in your phone. WhatsApp defines “My Contacts” from your device address book, not from your chat history, so unsaved numbers are treated as strangers even if you message regularly.

Turning off Read Receipts and restricting group adds to “My Contacts” removes two of the most-exploited WhatsApp defaults without affecting any of your normal conversations.

How Do You Lock Down Your WhatsApp Account Against Takeovers?

Two-Step Verification — Setting 7

Go to Settings > Account > Two-step verification > Enable. Create a 6-digit PIN. WhatsApp requires this PIN whenever your number is re-registered on a new device — the exact step a SIM-swap attacker would take after porting your number to their SIM. Without the PIN, the hijacked SIM is useless for accessing your account. Add a recovery email on the same screen so a forgotten PIN does not trigger a seven-day re-registration lockout.

App Lock — Setting 8

Go to Settings > Privacy > App Lock (Android) or Privacy > Screen Lock (iPhone) and enable biometric unlock. This stops anyone who picks up your unlocked phone from opening WhatsApp and reading your messages. It is a different threat layer than Two-Step Verification — one protects remote access, the other protects physical access.

Two-step verification stops remote account hijacking; App Lock stops physical access by someone holding your unlocked device — both layers address different real-world risks and are worth enabling together.

What Common Mistakes Make These Changes Less Effective?

1. Choosing “Nobody” instead of “My Contacts” for Last Seen

“Nobody” hides Last Seen from your real contacts too, which creates friction in personal relationships. Fix: Use “My Contacts” as the practical middle ground unless you have a specific reason for complete invisibility.

2. Skipping the recovery email for Two-Step Verification

Without a recovery email, a forgotten PIN means a seven-day re-registration lockout. Fix: Add your email address immediately after enabling Two-Step Verification — it takes ten seconds.

3. Reusing your phone’s lock-screen PIN

If someone already knows your device PIN, using it for Two-Step Verification defeats the purpose entirely. Fix: Choose a different 6-digit number that you do not use anywhere else.

4. Never rechecking settings after app updates

WhatsApp adds new settings at permissive defaults. A separate “Online Status” control appeared in a 2023 update — I nearly missed it and it had been set to “Everyone” the whole time. Fix: Run a five-minute Privacy review after every major WhatsApp update.

5. Leaving Live Location running after you no longer need it

Live Location does not expire automatically unless you chose a time limit when you started sharing. Fix: After any navigation session or meet-up coordination, tap the active location in the chat and select “Stop Sharing.”

Frequently Asked Questions

Does changing Last Seen also change who sees my Profile Photo?

No — each setting has its own toggle. Changing Last Seen to “My Contacts” does not affect Profile Photo; you need to set them individually under Settings > Privacy. I always go through the list from top to bottom so I do not skip one by accident.

If I turn off Read Receipts, can I still see when others read my messages?

No — the setting is mutual. Turning it off means neither you nor your contacts see read receipts in one-to-one chats. Group chats are an exception: delivery and read tallies for your own group messages still appear regardless of your personal Read Receipts setting, because group receipts follow the sender’s preference.

What happens if I forget my Two-Step Verification PIN?

WhatsApp blocks re-registration for seven days if you cannot supply the PIN and have no recovery email. After seven days the PIN requirement is waived, but WhatsApp sends a warning email if you added a recovery address — which means you can detect an unauthorized re-registration attempt even while locked out.

Can I block all group add requests entirely?

Not entirely, but “My Contacts Except…” lets you build an exclusion list for specific numbers. Anyone outside your contacts gets an invitation link rather than an automatic add. I use “My Contacts” across the board and have not received an unsolicited group add since making the change.

Does end-to-end encryption make these settings unnecessary?

No. End-to-end encryption protects message content in transit. It does not protect your profile photo, Last Seen timestamp, or About text — those are visible metadata that anyone with your number can access. These privacy settings operate at the metadata layer that encryption does not cover.

How often should I review my WhatsApp privacy settings?

I check mine every three to six months, or right after a major WhatsApp update. New features tend to launch with permissive defaults. Doing a five-minute review after each update has caught two new open-by-default fields on my account over the past year.

Conclusion

These eight WhatsApp privacy settings — Last Seen, Profile Photo, About, Status, Read Receipts, Groups, Two-Step Verification, and App Lock — take five minutes to lock down and immediately stop strangers from building a profile on you before they have sent a single message.

If you want to protect your chat history before making changes, start by backing up your WhatsApp messages first. For a full device-level audit, my guides on iPhone privacy settings worth changing and Android privacy settings that stop app tracking cover the next layer.

5 Checks That Reveal a Fake App Before You Install It

Learn to spot a fake app before installing with 5 quick checks — verify the developer, read review patterns, and audit permissions in under two minutes.

Learning to spot a fake app before installing is one of the most useful habits you can build for your phone. Every year, millions of people download malicious clones that look legitimate but secretly steal personal data, serve aggressive ads, or quietly charge hidden subscriptions. I nearly fell for one myself — a flashlight app in the Play Store with polished screenshots, five-star reviews, and tens of thousands of downloads. The single most effective defence is knowing what to check in the two minutes before you tap Install.

Fake apps — also called copycat apps or malicious clones — mimic trusted software closely enough to fool careful users. The good news: once you know which signals to check, the whole routine takes under two minutes and applies to any app store on any platform.

Quick Answer

Before installing any app, verify the developer name exactly matches the official company, confirm that reviews span months rather than days, check that permissions match the app’s stated purpose, and search the developer name in your browser. If any check fails, don’t install.

How Do Fake Apps End Up in App Stores?

App store review processes catch most threats, but bad actors find workarounds. A common method: submit a harmless app that passes review, then push a malicious update weeks later. Others clone a popular app’s name and icon precisely, counting on users rushing through search results without reading carefully.

Google Play has removed fake security and utility apps after tens of thousands of installs. The Apple App Store is harder to penetrate but not immune — phishing links on social media bypass the store entirely and point users straight to malicious downloads.

Understanding how fakes slip through tells you exactly which listing signals deserve the most scrutiny.

What Red Flags Should You Check Before Installing?

1. Verify the Developer Name Exactly

The most common trick is a one-letter swap or extra word — “Whatsup Inc.” instead of WhatsApp LLC, or “Adobe System” without the “s.” Tap the developer name in the store and look at their full catalog. A legitimate publisher has dozens of well-known titles, not three apps with vague names published in the last month.

Pro tip: On Android, tap “About this app” in the Play Store listing. On iPhone, tap the developer name to see every app they’ve ever published.

2. Read the Review Dates and Patterns

A real app collects reviews over months or years. If an app shows thousands of reviews but every one was posted within the last two weeks, that’s a paid-review farm. Look for a range of star ratings — genuine apps have unhappy users who name specific bugs. Rows of five-word five-star praise (“Great app!! Works perfectly!!”) repeated by dozens of accounts is a reliable signal to walk away.

3. Audit the App Permissions Before Downloading

On Android, tap “About this app” then “App permissions” in the Play Store listing before you download. On iPhone, permission prompts appear on first launch. A flashlight app that requests access to your contacts and microphone has no legitimate reason for either. I once installed a battery optimizer that wanted SMS read access — a permission no battery tool ever needs — and removed it within minutes.

Troubleshooting tip: After installing any app, open Settings > Apps (Android) or Settings > Privacy & Security (iPhone) and revoke any permission that doesn’t match the app’s stated purpose. My guide to Android app permissions explains exactly what each one accesses and which are safe to deny.

4. Read the Description and Screenshots

Legitimate apps list specific features, maintain a changelog in the “What’s New” section, and link to a real privacy policy and support page. Fake apps rely on vague copy: “Best utility performance optimizer 2024!” with no feature detail. Screenshots that show a UI unrelated to the app’s stated purpose — or generic stock photos — are a warning worth heeding.

5. Search the Developer Name Outside the Store

Spend 60 seconds searching “[developer name] reviews” or “[app name] scam” in your browser. Real apps have Reddit threads, tech-publication coverage, or an official website. If the only results are the app store listing itself, that absence is worth acting on before you download.

These five checks form a pre-install routine that takes under two minutes and catches the most common copycat patterns.

How Do Real and Fake Apps Compare?

Signal Legitimate App Fake / Copycat App
Developer name Exact official company name Subtle misspelling or added word
Review history Spread over months or years Clustered within days or weeks
Permissions Match the app’s stated purpose Overbroad; requests unrelated access
Description Specific features, changelog, support link Vague, generic, poor grammar
Publisher catalog Multiple well-known titles Few apps with unrelated names

Running this comparison against any unfamiliar listing takes under two minutes and highlights where a fake app can’t maintain the appearance of legitimacy.

Common Mistakes to Avoid

  • Trusting the icon alone. Copycats replicate official icons pixel-for-pixel. Always verify the developer name separately — a matching icon proves nothing on its own.
  • Skipping the permissions screen. Tapping “Allow” on every prompt without reading is how fake apps gain lasting access to your data. Revoke anything the app doesn’t need right after install.
  • Installing from links in messages or ads. Phishing links bypass app stores entirely. Navigate to the store yourself and search for the app directly rather than tapping a link someone sent you.
  • Treating high download counts as proof of safety. Fake review services inflate install numbers. Use download count as one signal among several, not the deciding factor.
  • Never rechecking permissions after an update. A clean app can gain new permissions through a later update. Revisit Settings > Apps (Android) or Settings > Privacy & Security (iPhone) every few months.

Each mistake follows the same root cause — moving too fast through the installation process without pausing to verify the basics.

Frequently Asked Questions

Can fake apps appear on the Apple App Store?
Yes, though it’s rarer than on Google Play. Apple’s review process is stricter, but copycat apps with slightly altered names do get through. The same pre-install checks apply on iOS. For broader app privacy on iPhone, see 8 iPhone privacy settings to change right now.

What should I do if I already installed a suspicious app?
Uninstall it immediately, then open Settings and revoke every permission it was granted. Change passwords for any accounts you logged into while the app was active. If personal data may have been exposed, the recovery steps in how to protect your identity after a data breach apply directly here.

Does Google Play Protect scan apps automatically?
Yes. Open the Play Store, tap your profile picture, and select Play Protect to confirm it’s enabled and run a manual scan. Google’s Play Protect support page explains exactly what it checks. On iPhone, iOS sandboxing limits what a malicious app can access even after install.

Are free apps with no obvious revenue model more suspicious?
Worth extra scrutiny, yes. An app with no ads and no paid tier may be monetising your data instead. That said, many legitimate open-source apps are genuinely free — run all five checks regardless of price, not just for apps that cost money.

These answers cover the most common questions that come up once you start applying the pre-install checklist to unfamiliar apps.

Conclusion

Two minutes of checking before you tap Install can save hours of cleanup afterward. Verify the developer name, study the review patterns, audit permissions, and search outside the store — that four-step habit filters out the vast majority of fake apps. For more on how bad actors use the same manipulation tactics in a different context, my guide to spotting tech support scams is a natural next step.

Android App Permissions Explained: What to Allow and What to Deny

Android app permissions explained: discover what each permission accesses, which ones are safe to deny, and how to audit all your apps in Settings in minutes.

If you’ve ever wondered what android app permissions actually do — why one app wants your microphone or why a flashlight asks for your contacts — every app you install requests access to something on your phone, and some of those requests have nothing to do with why you downloaded it.

The most important thing to know: you can deny any permission, use the app anyway, and change your answer at any time. No app is entitled to everything it asks for.

Quick Answer

Android app permissions control what each installed app can access — camera, microphone, location, contacts, and more. Grant permissions only when an app clearly needs them, choose “While using the app” for location rather than “All the time,” and review or revoke access anytime in Settings > Apps > [App name] > Permissions.

What Are Android App Permissions?

Android permissions fall into two categories. Install-time permissions — like internet access or checking network state — are granted silently when you install an app. They’re low-risk and you never see a pop-up for them.

Runtime permissions are the ones that matter. Android prompts you the first time an app requests something sensitive — camera, microphone, location, or contacts. You choose “Allow,” “Deny,” or for location, “Allow only while using the app.”

This system has grown more granular over time. Android 12 separated precise and approximate location into distinct options. Android 13 replaced the broad “Storage” permission with specific photo and video grants, giving you more targeted control over what each app can see.

All runtime permissions are managed in one place: Settings > Apps > [app name] > Permissions.

What Does Each Permission Category Do?

Not every permission carries the same risk. Here’s how the major categories break down:

Permission What it accesses Safe to deny?
Location (Precise) GPS coordinates, meter-level accuracy Yes — offer approximate instead
Location (Approximate) ~1-mile radius via cell/Wi-Fi Fine for weather and local apps
Camera Photos and video in real time Yes, unless the app’s purpose is photography
Microphone Live audio input Yes — grant only for calls or voice features
Contacts Your full address book Deny for most; needed for calling/messaging apps
Phone / Call logs Numbers you’ve called and received Deny for everything except your default dialer
Storage / Photos Files and images on the device Deny broad access; allow specific photo/video as needed
Notifications Right to send alerts to your screen Deny for apps you don’t need real-time pings from

Grant permissions only for features you actually plan to use — if you never use an app’s voice search, there’s no reason to hand over your microphone.

How Do I Check and Change App Permissions on Android?

Step 1: Open the Permission Screen

Go to Settings > Apps, tap the app you want to review, then tap Permissions. Every permission the app has ever requested appears here with its current status.

Step 2: Read the Labels and Adjust

Each entry shows Allowed, Allowed only while using, or Not allowed. Tap any entry to change it — changes apply immediately. For location, look for “Allowed all the time” and consider switching it to “While using.”

Pro tip: Android 11 and later automatically resets permissions for apps you haven’t used in months. You’ll receive a notification when this happens. You can disable auto-reset per app from the same permissions screen.

Which Location Option Should You Pick?

Almost always pick While using the app. I switched every social media and shopping app on my phone from “All the time” to “While using” and saw no change in functionality — but the background location pings in my Google account activity dropped right away. Only live location-sharing services need “All the time.”

Troubleshooting tip: If an app stops working after you deny a permission, go to Settings > Apps > [app name] > Permissions and re-enable just that one. Most apps explain exactly what they need when you re-open them.

The choice you make at that first location pop-up is the single most impactful permission decision on most Android phones.

Which App Permissions Can I Safely Deny?

Some permissions have almost no legitimate use outside their obvious app category:

  • Phone / Call logs — deny for anything that isn’t a dialer or SMS app
  • Precise location for social or retail apps — approximate location covers their actual needs
  • Contacts for utilities or games — a flashlight or puzzle game has no reason to read your address book
  • Nearby devices (Bluetooth scan) — grant only if the app needs to pair with hardware you own
  • Microphone for apps with no voice features — news readers, shopping apps, and calculators don’t need to listen

Denying these rarely breaks anything — and if an app truly needs one, it will tell you and guide you back to Settings to re-enable it.

What Mistakes Should I Avoid With App Permissions?

  1. Tapping “Allow” without reading. The pop-up appears mid-onboarding when you’re eager to start. Two seconds to read the one-line description is all it takes.
  2. Assuming you can’t change your mind. Every permission is reversible. Settings > Apps > [app name] > Permissions is always one minute away.
  3. Missing “All the time” location prompts. Apps default to requesting maximum access. Manually scroll to “While using” each time you see location options.
  4. Granting broad storage on older Android versions. On Android 12 and earlier, one “Storage” toggle exposed your entire file system. Deny it for any app that doesn’t need to open or save your documents.
  5. Never auditing after app updates. Updates can add new features — and quietly expand permission requests. A five-minute audit every few months catches what slipped through.

Most permission mistakes happen during installation — a few seconds of attention at that moment saves a longer audit later.

Frequently Asked Questions

Can I grant a permission just once?

Yes. Android offers “Only this time” for camera, microphone, and location — the permission auto-revokes the moment you leave the app. It appears as the third option in the pop-up, below “Allow” and “While using.”

What happens if I deny a permission the app actually needs?

Most apps show an explanation and ask again. Deny twice and the system stops prompting — you’ll need to grant it manually in Settings > Apps > [app name] > Permissions. I had this happen with a QR scanner that needed camera access; one trip to Settings fixed it immediately.

Does “All the time” location drain battery faster?

It can, especially on older devices. I’ve seen background GPS add 5–10% extra drain per day. Switching to “While using” is a free win — it doesn’t break core features for the vast majority of apps.

What’s the difference between precise and approximate location?

Precise uses your GPS chip and is accurate to a few meters. Approximate uses cell towers and Wi-Fi and is accurate to roughly a mile. Weather, food delivery, and local search work fine with approximate. Turn-by-turn navigation needs precise.

Can I see every app that has access to my camera or microphone?

Yes. Go to Settings > Privacy > Permission Manager and tap any permission type to see every app with that access. On Android 12+, the Privacy Dashboard shows a recent-use timeline — the fastest way to spot anything that shouldn’t be watching or listening.

The Permission Manager and Privacy Dashboard are two of the most underused tools in Android’s built-in privacy toolkit.

Conclusion

Android app permissions are door locks you control. Grant access when an app genuinely needs it, choose “While using” for location every time you see that option, and run a quick audit through Settings > Privacy > Permission Manager every few months. For more on hardening your phone, my guides to Android privacy settings that stop apps tracking you and cutting screen time with Digital Wellbeing are natural next steps. If something already feels off, see what to do when you suspect your phone has been compromised. For the full technical picture, Google’s Android permissions documentation is an authoritative reference.