Most of us tapped “Allow” on a permission pop-up years ago and never looked again. This guide gives you a repeatable routine, the 4×5 Permission Audit, that you can finish in one sitting. You do not need technical skills, and you can undo any change later.
Why should you audit app permissions at all?
A permission is a standing yes. Once you grant access to your location, microphone, contacts or photos, the app can keep using it until you change the setting. Apps you installed for a single trip, a one-off discount or a free trial often still hold those permissions months later. An audit shrinks the amount of personal data sitting with apps you barely use, and it limits what a compromised or poorly built app can reach.
Both Apple and Google let you review and change this per app and per data type. Apple describes the process as turning access on or off for each app in a list under Privacy & Security, and Google describes the same idea through its Permission manager.
What do you need before you start?
- Your phone, charged, and a timer (20 minutes).
- Your screen lock and OS updated, because newer versions have better privacy controls.
- A willingness to deny first and re-allow later. Denying is reversible: the app will simply ask again when it needs the feature.
Author’s note: [PLACEHOLDER: add 2–3 sentences from your own run-through, for example how many apps you found with location access, what surprised you, and how long it really took. First-hand details like this are the strongest experience signal on the page.]
What is the 4×5 Permission Audit?
It is a time-boxed routine built around one rule, the Job Test: “Would this app fail at its main job without this permission?” If yes, keep it, ideally at the narrowest setting. If no, revoke it.
Block |
Time |
Goal |
|---|---|---|
1. Clear |
Minutes 0–5 |
Delete apps you do not use |
2. Sensitive three |
Minutes 5–10 |
Location, camera, microphone |
3. Personal data |
Minutes 10–15 |
Contacts, photos, files, calendar and other data |
4. Lock in |
Minutes 15–20 |
Turn on automatic cleanup and check recent activity |
Block 1 (minutes 0–5): Which apps should you delete first?
The safest permission is the one that no longer exists. Scroll your app list and remove anything you have not opened in three months, anything you installed for a one-time purpose, and duplicates (two flashlight apps, three PDF scanners).
- iPhone: press and hold the app icon, then tap Remove App > Delete App.
- Android: open Google Play, tap your profile icon, go to Manage apps and devices > Manage, choose the app and tap Uninstall. Google also notes that some pre-installed system apps cannot be deleted and may only be disabled, depending on the manufacturer.
Block 2 (minutes 5–10): How do you check location, camera and microphone access?
These three carry the highest privacy risk, so review them first.
On iPhone
- Open Settings > Privacy & Security > Location Services. For each app choose Never, Ask Next Time or When I Share, or While Using the App. Avoid Always unless the app is a navigation, tracking or similar tool you rely on.
- Inside the same app entry, turn off Precise Location if city-level accuracy is enough (weather, news, shopping).
- Go back to Privacy & Security and tap Camera, then Microphone. Switch off any app that has no clear reason to record.
On Android
- Open Settings > Security & privacy > Privacy > Permission manager. On some phones the path differs slightly by manufacturer; search “permission manager” in Settings if you cannot find it.
- Tap Location. Google lists four choices per app: allow all the time, allow only while using the app, ask every time, and don’t allow. Pick the narrowest one that still works.
- If an app offers it, choose approximate rather than precise location when exact position is not needed.
- Repeat for Camera and Microphone.
What does “good” look like for each app type?
App type |
Reasonable permissions |
Question the permission |
|---|---|---|
Maps / ride-hailing |
Location (while using) |
Location “always” for casual use |
Weather / news |
Approximate location |
Precise location, contacts, microphone |
Messaging / video calls |
Camera, microphone, notifications; contacts if you want friend-finding |
Location “always” |
Photo editor |
Selected photos only |
Full library, microphone, contacts |
Flashlight / calculator / wallpaper |
Usually none |
Anything beyond basic features |
Shopping / coupons |
Notifications (optional) |
Contacts, location “always”, microphone |
This table is a rule of thumb, not a verdict. A tool that reads or sends your information to a server may have a legitimate reason you can confirm in its privacy policy.
Block 3 (minutes 10–15): How do you review contacts, photos, files and other personal data?
On iPhone
- In Settings > Privacy & Security, tap a data category such as Contacts, Photos, Calendars, Reminders or Motion & Fitness. The list shows every app that has asked for access, and you can switch each one off.
- For Photos, prefer Limited Access (only the pictures you pick) over full library access.
- Scroll through the other categories (Bluetooth, Local Network, Health). Remove anything you cannot explain.
On Android
- Stay in Permission manager and open Contacts, Photos and videos (or Files and media), Calendar, Call logs and SMS if listed.
- Tap an app and choose Don’t allow, or the most limited option offered.
- Check Nearby devices and Notifications as well. Apps that spam alerts rarely need them.
Do not skip this: if something stops working after you revoke a permission, simply re-allow it for that app. Nothing is lost, and you have learned that the permission was genuinely needed.
Block 4 (minutes 15–20): How do you make the cleanup last?
Switch on automatic safeguards
- Android: Google’s documentation says you can turn on Pause app activity if unused for an app (Settings > Apps > [app] > Unused app settings). Android also reviews apps you have not used for a long time, and the setting can revoke their permissions and stop background activity.
- iPhone: go to Settings > Privacy & Security > Tracking and switch off Allow Apps to Request to Track if you do not want tracking requests at all.
Check what apps actually did
- iPhone: in Privacy & Security, open App Privacy Report. Apple says it shows how apps used the permissions you granted and their network activity. Turn it on, and re-check it in a week.
- Android: open the Privacy dashboard (in the same Privacy menu on recent versions) to see which apps used sensitive permissions and when. Permission manager shows what is allowed; the dashboard shows what was used.
Which permission requests are red flags?
Red flag |
What to do |
|---|---|
A simple utility asks for contacts, microphone or location |
Deny; if the app breaks, uninstall it |
An app you rarely open uses location in the background |
Set to “while using” or “never” |
An app you do not remember installing |
Check its source, then remove it |
An app from outside the official App Store or Google Play |
Remove it unless you fully trust the publisher |
Unexpected privacy indicator (camera or mic) when you are not using the phone |
Close the app, revoke the permission, review recent activity |
How often should you repeat the audit?
Run the full 20-minute version every three to six months, and a 2-minute version (review only location and microphone) after installing several new apps. Put a recurring reminder in your calendar so the habit survives.
Your 20-minute checklist
- ☐ Deleted unused and duplicate apps
- ☐ Location set to “while using” or “never” (precise off where possible)
- ☐ Camera and microphone limited to apps that truly record
- ☐ Contacts, photos and files reviewed (photos set to limited where offered)
- ☐ Automatic unused-app cleanup (Android) and tracking requests (iPhone) set
- ☐ App Privacy Report or Privacy dashboard checked
- ☐ Reminder set for the next audit
Frequently asked questions
Is it safe to deny app permissions?
Yes. Denying a permission does not harm your phone or delete data. If an app needs the permission for a feature, it will ask again, and you can allow it then.
How do I see which apps have access to my location?
On iPhone, go to Settings > Privacy & Security > Location Services. On Android, go to Permission manager > Location. Both list every app and its current setting.
What is the difference between “allow while using” and “allow always”?
“While using” lets the app use the permission only when you are using it. “Always” lets it use the permission in the background as well. Choose “while using” unless the app’s core function needs background access.
Does deleting an app remove its permissions?
The app’s access ends once it is uninstalled, but any data it already collected may remain with the company. Check the app’s privacy settings or account page to request deletion if that matters to you.
Do iPhones and Androids use the same permission names?
Mostly, but not exactly. iPhone calls it Privacy & Security; Android calls it Permission manager, and menu paths can differ by manufacturer and OS version.
How long does a permission audit take?
About 20 minutes the first time, depending on how many apps you have. Later audits are faster because you only review new apps and changes.








