Privacy
Permission minimisation
A practical way to decide which apps and services should access location, contacts, files, microphones and cameras.
Permission is a decision, not a button
When an app asks for access, decide whether the feature you want actually requires the permission. A map may need location while it is in use. A flashlight usually does not need contacts. A photo editor may need one selected file rather than the entire photo library.
Grant the narrowest scope available: one-time location instead of always, selected photos instead of the whole library, and approximate location instead of precise location when the task allows it.
Review later
Permissions accumulate. Review them after installing a new app, changing phones, or noticing that an app has not been used for months. Revoke access that no longer matches a current purpose. A revoked permission may break a feature; that is useful information about what the app depends on.
Separate the app from the account
Changing a device permission does not erase data already uploaded to the service. Check the account’s privacy controls separately, and delete stored data when the service provides a meaningful option. The app may also collect information through analytics or advertising systems that do not appear as a sensor permission.
Topics
Sources
- Control access to information in apps Accessed
- Android permissions Accessed
Related archive entries
-
Archive corporate privacy
Apple App Tracking Transparency (Archive)
Apple introduced a permission requirement for app tracking across companies and access to the advertising identifier.
Related guides
-
Guide Intermediate
Mobile Device Privacy (Guide)
What a phone knows that a laptop does not, which platform settings matter, and the limits of user control.
-
Guide Intermediate
Data brokers and the market for personal information (Guide)
How personal information is collected, combined, scored and resold, and where practical limits on collection begin.