8 WhatsApp Privacy Settings to Change — Most People Never Touch Them

Change these 8 WhatsApp privacy settings now — stop strangers from seeing your profile photo and last-seen time before they have sent you a single message.

WhatsApp ships with almost every profile field visible to everyone who has your phone number. A stranger, a spammer, or someone who pulled your number from a leaked database can see your profile photo, your About text, and exactly when you last opened the app — before they send you a single message. The WhatsApp privacy settings to change are all sitting in the Privacy menu, and most users never open it.

I found this out after an unknown number sent me an unsolicited sales pitch, having clearly already viewed my profile photo before writing. A five-minute check of Settings > Privacy closed every gap I could find. The single most important insight: WhatsApp privacy settings default to permissive on purpose, and locking them down costs you nothing in normal day-to-day use.

Quick Answer

Open WhatsApp, go to Settings > Privacy, and set Last Seen, Profile Photo, About, and Status to “My Contacts.” Turn off Read Receipts. Set Groups to “My Contacts.” Go to Account > Two-step verification and create a 6-digit PIN. Return to Privacy and enable App Lock. All eight changes take under five minutes.

Why Are WhatsApp’s Default Settings a Privacy Risk?

WhatsApp’s end-to-end encryption protects what you send in transit — that part is genuinely strong. What encryption does not protect is your profile metadata. Your photo, Last Seen timestamp, About text, and online status are all readable by any phone number that has yours, even if you have never interacted. Spam networks use this data to confirm which numbers are active and build target profiles. WhatsApp’s privacy policy confirms it collects usage metadata visible to users who have your number. Changing your Privacy settings is the only lever you control here.

WhatsApp encrypts your messages but leaves your profile metadata open to anyone with your number — only the Privacy settings menu changes that.

Which Visibility Settings Should You Change First?

These four settings are all in WhatsApp > Settings > Privacy and take one tap each to update.

Setting Default Recommended What It Stops
Last Seen & Online Everyone My Contacts Hides your activity pattern from unknown numbers
Profile Photo Everyone My Contacts Shows a grey silhouette to non-contacts
About Everyone My Contacts Removes your bio from public view
Status My Contacts My Contacts (verify) Confirms this has not been reset by an app update

Last Seen and Online Status

This setting has two separate dropdowns — Last Seen and Online — and both default to “Everyone.” Set both to “My Contacts.” Unknown numbers see a dash instead of a timestamp. Spam operations actively use Last Seen patterns to verify a number is live before targeting it; this one change removes you from that check entirely.

Profile Photo and About

Set both to “My Contacts.” Phrases like “Mum of two, Bristol” in your About text hand free profile-enrichment data to anyone who finds your number. A grey silhouette replaces your photo for non-contacts, which also stops cold-callers from confirming they have reached the right person before they message you.

Pro tip: After changing Profile Photo to “My Contacts,” ask a friend whose number you have not saved to look you up. They should see only a grey silhouette — no photo, no About text, no Last Seen.

Setting Last Seen, Profile Photo, and About to “My Contacts” immediately removes your personal data from anyone who has your number but is not in your address book.

Which Messaging and Group Settings Matter Most?

Read Receipts — Setting 5

Go to Privacy > Read Receipts and switch it off. Blue ticks no longer turn blue when you read a message. The setting is mutual — you also stop seeing read receipts from other people in one-to-one chats. I have had this off for over a year and have never wanted it back on. It removes the pressure to reply the instant you open a message.

Groups — Who Can Add You — Setting 6

Under Privacy > Groups, change “Who can add me to groups” to “My Contacts.” Anyone not in your address book now receives an invitation link instead of adding you directly. Bulk spam groups target fresh numbers by adding them automatically using the default “Everyone” setting; switching to “My Contacts” stops this cold.

Troubleshooting tip: If a genuine contact says they cannot add you to a group after this change, check that you have their number saved in your phone. WhatsApp defines “My Contacts” from your device address book, not from your chat history, so unsaved numbers are treated as strangers even if you message regularly.

Turning off Read Receipts and restricting group adds to “My Contacts” removes two of the most-exploited WhatsApp defaults without affecting any of your normal conversations.

How Do You Lock Down Your WhatsApp Account Against Takeovers?

Two-Step Verification — Setting 7

Go to Settings > Account > Two-step verification > Enable. Create a 6-digit PIN. WhatsApp requires this PIN whenever your number is re-registered on a new device — the exact step a SIM-swap attacker would take after porting your number to their SIM. Without the PIN, the hijacked SIM is useless for accessing your account. Add a recovery email on the same screen so a forgotten PIN does not trigger a seven-day re-registration lockout.

App Lock — Setting 8

Go to Settings > Privacy > App Lock (Android) or Privacy > Screen Lock (iPhone) and enable biometric unlock. This stops anyone who picks up your unlocked phone from opening WhatsApp and reading your messages. It is a different threat layer than Two-Step Verification — one protects remote access, the other protects physical access.

Two-step verification stops remote account hijacking; App Lock stops physical access by someone holding your unlocked device — both layers address different real-world risks and are worth enabling together.

What Common Mistakes Make These Changes Less Effective?

1. Choosing “Nobody” instead of “My Contacts” for Last Seen

“Nobody” hides Last Seen from your real contacts too, which creates friction in personal relationships. Fix: Use “My Contacts” as the practical middle ground unless you have a specific reason for complete invisibility.

2. Skipping the recovery email for Two-Step Verification

Without a recovery email, a forgotten PIN means a seven-day re-registration lockout. Fix: Add your email address immediately after enabling Two-Step Verification — it takes ten seconds.

3. Reusing your phone’s lock-screen PIN

If someone already knows your device PIN, using it for Two-Step Verification defeats the purpose entirely. Fix: Choose a different 6-digit number that you do not use anywhere else.

4. Never rechecking settings after app updates

WhatsApp adds new settings at permissive defaults. A separate “Online Status” control appeared in a 2023 update — I nearly missed it and it had been set to “Everyone” the whole time. Fix: Run a five-minute Privacy review after every major WhatsApp update.

5. Leaving Live Location running after you no longer need it

Live Location does not expire automatically unless you chose a time limit when you started sharing. Fix: After any navigation session or meet-up coordination, tap the active location in the chat and select “Stop Sharing.”

Frequently Asked Questions

Does changing Last Seen also change who sees my Profile Photo?

No — each setting has its own toggle. Changing Last Seen to “My Contacts” does not affect Profile Photo; you need to set them individually under Settings > Privacy. I always go through the list from top to bottom so I do not skip one by accident.

If I turn off Read Receipts, can I still see when others read my messages?

No — the setting is mutual. Turning it off means neither you nor your contacts see read receipts in one-to-one chats. Group chats are an exception: delivery and read tallies for your own group messages still appear regardless of your personal Read Receipts setting, because group receipts follow the sender’s preference.

What happens if I forget my Two-Step Verification PIN?

WhatsApp blocks re-registration for seven days if you cannot supply the PIN and have no recovery email. After seven days the PIN requirement is waived, but WhatsApp sends a warning email if you added a recovery address — which means you can detect an unauthorized re-registration attempt even while locked out.

Can I block all group add requests entirely?

Not entirely, but “My Contacts Except…” lets you build an exclusion list for specific numbers. Anyone outside your contacts gets an invitation link rather than an automatic add. I use “My Contacts” across the board and have not received an unsolicited group add since making the change.

Does end-to-end encryption make these settings unnecessary?

No. End-to-end encryption protects message content in transit. It does not protect your profile photo, Last Seen timestamp, or About text — those are visible metadata that anyone with your number can access. These privacy settings operate at the metadata layer that encryption does not cover.

How often should I review my WhatsApp privacy settings?

I check mine every three to six months, or right after a major WhatsApp update. New features tend to launch with permissive defaults. Doing a five-minute review after each update has caught two new open-by-default fields on my account over the past year.

Conclusion

These eight WhatsApp privacy settings — Last Seen, Profile Photo, About, Status, Read Receipts, Groups, Two-Step Verification, and App Lock — take five minutes to lock down and immediately stop strangers from building a profile on you before they have sent a single message.

If you want to protect your chat history before making changes, start by backing up your WhatsApp messages first. For a full device-level audit, my guides on iPhone privacy settings worth changing and Android privacy settings that stop app tracking cover the next layer.

Android App Permissions Explained: What to Allow and What to Deny

Android app permissions explained: discover what each permission accesses, which ones are safe to deny, and how to audit all your apps in Settings in minutes.

If you’ve ever wondered what android app permissions actually do — why one app wants your microphone or why a flashlight asks for your contacts — every app you install requests access to something on your phone, and some of those requests have nothing to do with why you downloaded it.

The most important thing to know: you can deny any permission, use the app anyway, and change your answer at any time. No app is entitled to everything it asks for.

Quick Answer

Android app permissions control what each installed app can access — camera, microphone, location, contacts, and more. Grant permissions only when an app clearly needs them, choose “While using the app” for location rather than “All the time,” and review or revoke access anytime in Settings > Apps > [App name] > Permissions.

What Are Android App Permissions?

Android permissions fall into two categories. Install-time permissions — like internet access or checking network state — are granted silently when you install an app. They’re low-risk and you never see a pop-up for them.

Runtime permissions are the ones that matter. Android prompts you the first time an app requests something sensitive — camera, microphone, location, or contacts. You choose “Allow,” “Deny,” or for location, “Allow only while using the app.”

This system has grown more granular over time. Android 12 separated precise and approximate location into distinct options. Android 13 replaced the broad “Storage” permission with specific photo and video grants, giving you more targeted control over what each app can see.

All runtime permissions are managed in one place: Settings > Apps > [app name] > Permissions.

What Does Each Permission Category Do?

Not every permission carries the same risk. Here’s how the major categories break down:

Permission What it accesses Safe to deny?
Location (Precise) GPS coordinates, meter-level accuracy Yes — offer approximate instead
Location (Approximate) ~1-mile radius via cell/Wi-Fi Fine for weather and local apps
Camera Photos and video in real time Yes, unless the app’s purpose is photography
Microphone Live audio input Yes — grant only for calls or voice features
Contacts Your full address book Deny for most; needed for calling/messaging apps
Phone / Call logs Numbers you’ve called and received Deny for everything except your default dialer
Storage / Photos Files and images on the device Deny broad access; allow specific photo/video as needed
Notifications Right to send alerts to your screen Deny for apps you don’t need real-time pings from

Grant permissions only for features you actually plan to use — if you never use an app’s voice search, there’s no reason to hand over your microphone.

How Do I Check and Change App Permissions on Android?

Step 1: Open the Permission Screen

Go to Settings > Apps, tap the app you want to review, then tap Permissions. Every permission the app has ever requested appears here with its current status.

Step 2: Read the Labels and Adjust

Each entry shows Allowed, Allowed only while using, or Not allowed. Tap any entry to change it — changes apply immediately. For location, look for “Allowed all the time” and consider switching it to “While using.”

Pro tip: Android 11 and later automatically resets permissions for apps you haven’t used in months. You’ll receive a notification when this happens. You can disable auto-reset per app from the same permissions screen.

Which Location Option Should You Pick?

Almost always pick While using the app. I switched every social media and shopping app on my phone from “All the time” to “While using” and saw no change in functionality — but the background location pings in my Google account activity dropped right away. Only live location-sharing services need “All the time.”

Troubleshooting tip: If an app stops working after you deny a permission, go to Settings > Apps > [app name] > Permissions and re-enable just that one. Most apps explain exactly what they need when you re-open them.

The choice you make at that first location pop-up is the single most impactful permission decision on most Android phones.

Which App Permissions Can I Safely Deny?

Some permissions have almost no legitimate use outside their obvious app category:

  • Phone / Call logs — deny for anything that isn’t a dialer or SMS app
  • Precise location for social or retail apps — approximate location covers their actual needs
  • Contacts for utilities or games — a flashlight or puzzle game has no reason to read your address book
  • Nearby devices (Bluetooth scan) — grant only if the app needs to pair with hardware you own
  • Microphone for apps with no voice features — news readers, shopping apps, and calculators don’t need to listen

Denying these rarely breaks anything — and if an app truly needs one, it will tell you and guide you back to Settings to re-enable it.

What Mistakes Should I Avoid With App Permissions?

  1. Tapping “Allow” without reading. The pop-up appears mid-onboarding when you’re eager to start. Two seconds to read the one-line description is all it takes.
  2. Assuming you can’t change your mind. Every permission is reversible. Settings > Apps > [app name] > Permissions is always one minute away.
  3. Missing “All the time” location prompts. Apps default to requesting maximum access. Manually scroll to “While using” each time you see location options.
  4. Granting broad storage on older Android versions. On Android 12 and earlier, one “Storage” toggle exposed your entire file system. Deny it for any app that doesn’t need to open or save your documents.
  5. Never auditing after app updates. Updates can add new features — and quietly expand permission requests. A five-minute audit every few months catches what slipped through.

Most permission mistakes happen during installation — a few seconds of attention at that moment saves a longer audit later.

Frequently Asked Questions

Can I grant a permission just once?

Yes. Android offers “Only this time” for camera, microphone, and location — the permission auto-revokes the moment you leave the app. It appears as the third option in the pop-up, below “Allow” and “While using.”

What happens if I deny a permission the app actually needs?

Most apps show an explanation and ask again. Deny twice and the system stops prompting — you’ll need to grant it manually in Settings > Apps > [app name] > Permissions. I had this happen with a QR scanner that needed camera access; one trip to Settings fixed it immediately.

Does “All the time” location drain battery faster?

It can, especially on older devices. I’ve seen background GPS add 5–10% extra drain per day. Switching to “While using” is a free win — it doesn’t break core features for the vast majority of apps.

What’s the difference between precise and approximate location?

Precise uses your GPS chip and is accurate to a few meters. Approximate uses cell towers and Wi-Fi and is accurate to roughly a mile. Weather, food delivery, and local search work fine with approximate. Turn-by-turn navigation needs precise.

Can I see every app that has access to my camera or microphone?

Yes. Go to Settings > Privacy > Permission Manager and tap any permission type to see every app with that access. On Android 12+, the Privacy Dashboard shows a recent-use timeline — the fastest way to spot anything that shouldn’t be watching or listening.

The Permission Manager and Privacy Dashboard are two of the most underused tools in Android’s built-in privacy toolkit.

Conclusion

Android app permissions are door locks you control. Grant access when an app genuinely needs it, choose “While using” for location every time you see that option, and run a quick audit through Settings > Privacy > Permission Manager every few months. For more on hardening your phone, my guides to Android privacy settings that stop apps tracking you and cutting screen time with Digital Wellbeing are natural next steps. If something already feels off, see what to do when you suspect your phone has been compromised. For the full technical picture, Google’s Android permissions documentation is an authoritative reference.

8 iPhone Privacy Settings to Change Right Now

Review these 8 iPhone privacy settings to change right now — limit location tracking, block ad targeting, and hide lock screen previews in under 10 minutes.

Most iPhones ship with privacy settings that quietly share your location, usage habits, and Siri interactions with Apple and third-party apps by default. I audited my own device recently and found six apps still holding “Always” location access — including a food delivery app and a weather widget I had completely forgotten about. The core insight about iphone privacy settings to change: Apple’s defaults lean toward convenience and data collection, not user privacy — every adjustment in this guide is something you have to opt out of yourself.

The good news is that none of these changes require technical expertise, and most take under a minute each. You can back up your iPhone first if you want peace of mind, though none of these tweaks touch your photos or personal files.

Quick Answer

Open Settings → Privacy & Security and work through eight changes: limit Location Services to “While Using,” block all app tracking requests, disable Siri learning and audio sharing, revoke unneeded camera and microphone access, opt out of Analytics, hide lock screen notification previews, and confirm Safari’s cross-site tracking prevention is active.

Which iPhone Privacy Settings Leak the Most Data?

1. Location Services — Per-App Controls

Go to Settings → Privacy & Security → Location Services. Every app with location permission is listed here. Change anything set to “Always” to “While Using the App” unless it’s a navigation app that needs background access. A setting of “Always” lets an app log your physical location even when you’re not actively using it — there is no good reason for most apps to have this.

2. App Tracking Transparency — Block All Requests

Go to Settings → Privacy & Security → Tracking. Toggle off “Allow Apps to Request to Track.” This prevents apps from asking to follow your behavior across other apps and websites for advertising. Scroll down on the same screen to see which apps already have permission — I found three from years ago still active and revoked all of them.

Pro tip: After revoking tracking for old apps, force-close those apps once so the change takes effect immediately rather than at the next launch.

3. Siri & Search — Stop Siri From Profiling Your Habits

Go to Settings → Siri & Search → scroll down and disable “Improve Siri & Dictation” and “Share Audio with Apple.” These options send voice recordings to Apple for human review. I also turn off “Show Suggestions” for apps I rarely open — it limits how much Siri learns about my daily routines.

Limiting location access, blocking tracking requests, and reining in Siri learning together close off the three biggest passive data flows on a default iPhone.

How Do I Protect My Camera and Microphone Privacy?

4. Camera Access — Review Every App

Go to Settings → Privacy & Security → Camera. Revoke access for any app without an obvious need — a news reader, finance tool, or shopping app, for example. If an app truly needs camera access for a feature, it will ask again when you trigger that feature. Removing access now costs you nothing.

5. Microphone Access — The Same Audit Applies

Go to Settings → Privacy & Security → Microphone. I found a fitness tracking app on my phone with microphone access it had never explained in context — I revoked it immediately. If an app has no voice input, recording, or calling feature, it has no legitimate reason to hear you.

Auditing camera and microphone permissions takes under two minutes and eliminates the risk of apps recording audio or video in the background.

What Lock Screen Setting Should I Change First?

6. Notification Previews — Hide Them Until Unlocked

Go to Settings → Notifications → Show Previews → change “Always” to “When Unlocked.” Anyone who picks up your phone now sees only a generic badge, not your actual message or email content. This is the setting I recommend first to anyone who works in a shared office or takes public transit.

Troubleshooting tip: If you stop seeing expected alerts after this change, check whether your iPhone Focus mode is silencing specific apps independently — that’s a separate toggle from notification previews.

Which Analytics and Browser Settings Need Adjusting?

7. Analytics & Improvements — Opt Out Completely

Go to Settings → Privacy & Security → Analytics & Improvements. Disable “Share iPhone Analytics,” “Share iCloud Analytics,” and “Share with App Developers.” This stops your usage patterns from being uploaded to Apple and third-party developers. It has no effect on speed, battery life, or any app functionality.

8. Safari — Confirm Cross-Site Tracking Is Active

Go to Settings → Safari and verify “Prevent Cross-Site Tracking” is toggled on. Safari turns this on by default, but I’ve seen it disabled on phones restored from older backups. Apple’s privacy page explains exactly what this blocks if you want to understand the underlying mechanism.

Opting out of analytics and confirming Safari’s tracker blocker address the data your phone shares passively — no further action required once they’re set.

What Mistakes Undermine iPhone Privacy Settings?

  • Turning off Location Services entirely. This breaks Maps, Find My, and weather. Set each app individually to “While Using” instead — you keep useful features without the background tracking.
  • Only auditing recently installed apps. Permissions granted years ago are still active. Review the full list in each Privacy & Security category, not just apps you remember installing recently.
  • Assuming iOS defaults are already privacy-friendly. They’re not — Apple’s defaults favor data collection and product improvement. Privacy requires explicit opt-outs.
  • Skipping the review after a major iOS update. New iOS versions sometimes introduce new sharing options toggled on by default. Re-check Privacy & Security after each major update.
  • Revoking permissions without thinking through app needs. Removing microphone access from a voice-memo app breaks it. Think through what each app does before revoking.

Frequently Asked Questions

Will blocking app tracking break any features I rely on?

Almost never. App tracking is used for cross-app ad targeting — it’s not connected to core features like payments, navigation, or messaging. I’ve had tracking blocked for over a year with no noticeable impact on any app I use daily.

How often should I review my iPhone privacy settings?

I do a quick audit every three to four months and always after a major iOS update. New apps request permissions when installed, and iOS updates sometimes introduce new data-sharing options. A ten-minute check twice a year covers most people’s needs.

Can I see which apps recently accessed my microphone or camera?

Yes — iOS shows a green dot for active camera use and an orange dot for microphone use in the status bar. For a full access log, go to Settings → Privacy & Security → App Privacy Report. Enable it first if prompted; it then shows every app that accessed your hardware sensors and the domains each app contacted.

Does disabling Siri learning make Siri noticeably worse?

Slightly, over the long term. Siri may be marginally less tailored to your patterns without the feedback data. In practice, I’ve had Siri learning disabled for months and noticed no meaningful difference in everyday use — the privacy tradeoff is worth it.

Conclusion

These eight iphone privacy settings to change take about ten minutes and meaningfully reduce what your device shares by default. Start with Location Services and App Tracking Transparency — those two deliver the biggest gains with the least effort. Work through the remaining six at your own pace.

Once your privacy settings are locked down, take five minutes to set up Find My iPhone — it’s the security safety net that makes all the difference if your phone is ever lost or stolen.