Morning Overview

12 hidden iPhone settings that lock down your privacy

Apple builds a long list of privacy controls into iOS, then buries most of them several taps deep in Settings. Left at their defaults, those switches quietly permit ad networks, data brokers, and even email senders to build a detailed profile of one phone’s owner. Twelve of the most useful controls are laid out below.

1. Allow Apps To Request To Track: The Master Switch Most Owners Miss

Settings, Privacy & Security, Tracking holds a single master switch called Allow Apps to Request to Track. Turned off, it stops apps from even asking for permission to follow activity across other companies’ apps and websites, which, as one iOS tracking guide notes, cuts off cross-app advertising identifiers at the source.

Apps that never receive the identifier cannot stitch a shopping session in one app to a news feed in another. The trade-off is modest: ads still appear, they simply lose much of their personal targeting.

2. Significant Locations: The Hidden Log Of Everywhere The Phone Has Been

Buried under Privacy & Security, Location Services, System Services sits Significant Locations, a running log of the places an iPhone visits most often, complete with dates and durations. A step-by-step privacy walkthrough describes clearing that history and switching the feature off so the phone stops adding to it.

The log is encrypted and stays on the device, but anyone who knows the passcode can read it. For a shared household phone, or one handed to a repair shop, an empty history removes an unusually detailed record of daily movement.

3. App Privacy Report: Seven Days Of Proof About Chatty Apps

Switching on App Privacy Report, found at the bottom of the Privacy & Security menu, starts a seven-day record of which apps touched the camera, microphone, contacts, and location, and which outside domains they contacted. Security researchers point to that network activity log as the fastest way to spot an app quietly talking to data brokers.

A flashlight utility reaching dozens of ad servers looks very different once the domains are listed by name. The report changes nothing on its own; it simply supplies the evidence for deciding which apps deserve deletion.

4. Lockdown Mode: Apple’s Extreme Setting Against Spyware

Apple built Lockdown Mode for journalists, activists, and executives facing targeted spyware, and it lives at the very bottom of Privacy & Security. Enabling it blocks most message attachments, disables link previews, restricts web fonts and JavaScript features, and refuses wired accessory connections, closing the common spyware attack paths that mercenary exploits rely on.

Ordinary use becomes noticeably clunkier, so the mode suits high-risk periods rather than everyday life. Toggling it back off takes one restart, which makes it practical to enable during travel or an unusual threat and disable afterward.

5. Mail Privacy Protection: Blocking The Pixel In Every Newsletter

Marketing emails routinely carry invisible tracking pixels that fire the moment a message is opened, reporting the time, the device, and an approximate location back to the sender. Mail Privacy Protection, under Settings, Apps, Mail, loads that content through Apple’s relay instead, and email tracking explainers credit it with masking both the open time and the IP address.

Senders still see that a message reached the inbox, but their open-rate dashboards stop reflecting real behavior. The setting applies only to Apple’s own Mail app, so a Gmail or Outlook client needs its own equivalent.

6. Hide My Email: Burner Addresses For Every Signup Form

Every retailer signup form that collects a real address hands over a permanent key for linking records across databases. Hide My Email, bundled with iCloud+ and offered inline at Sign in with Apple prompts, generates a unique forwarding address for each site, a burner address feature that keeps the genuine mailbox out of circulation.

Messages still arrive normally, and a leaking or spamming address can be deactivated without touching anything else. Because each alias is site-specific, a breach notification also reveals exactly which company lost the data.

7. Precise Location Toggle: Neighborhood Instead Of Street Address

Inside each app’s entry under Location Services sits a separate Precise Location switch. Turning it off narrows what the app receives from exact coordinates to a rough area several miles wide, and iOS location guidance recommends the downgrade for weather, news, shopping, and social apps that have no operational need for a street address.

Navigation and ride-hailing tools genuinely require the precise feed and should keep it. For everything else, an approximate area still delivers local forecasts and store results while stripping out the movement trail advertisers value most.

8. Safety Check: One Pass That Cuts Off Old Access

Safety Check, added under Privacy & Security, exists for situations where a former partner, roommate, or family member still has access. Its Emergency Reset option severs location sharing, revokes app permissions, signs other devices out of the Apple Account, and resets privacy settings in one pass, a rapid access cutoff designed for people leaving unsafe situations.

A gentler Manage Sharing option walks through each person and app individually. Either path surfaces sharing arrangements that were set up years earlier and quietly forgotten, which is often where unwanted monitoring actually lives.

9. Apple Advertising: Turning Off Ads Built From Personal Data

Apple runs its own ad business inside the App Store, News, and Stocks, and personalization for it is enabled by default. The Personalized Ads switch, tucked under Privacy & Security, Apple Advertising, turns that off, and privacy checklists for iOS flag it as the setting most owners never find.

Segmentation there draws on downloads, reading habits, and purchase history rather than third-party trackers. Disabling personalization does not reduce the number of ads shown; it stops the company from tailoring them using the account’s own behavioral record.

10. Safari Privacy Settings: Cross-Site Trackers Blocked At The Source

Safari’s own settings panel carries two controls worth checking: Prevent Cross-Site Tracking and Hide IP Address from Trackers. Together they block the third-party cookies that follow a browsing session between unrelated sites and route tracker connections through Apple’s relay, which browser hardening advice treats as the baseline for mobile web privacy.

Advanced settings add a privacy report listing every tracker Safari has blocked in the past month. Occasional breakage on older shopping or banking sites is the main cost, and exceptions can be granted per site.

11. Location Services Per App: The Highest-Yield Cleanup In Settings

Scrolling the full Location Services list usually turns up a dozen apps with standing permission that nobody remembers granting. Each entry can be set to Never, Ask Next Time, While Using, or Always, and an app permission audit is the single highest-yield cleanup available in the Settings app.

Always is the setting that matters most, because it allows background collection even when the app sits unopened. Very few consumer apps justify it, and demoting them to While Using removes most passive location harvesting in a few minutes.

12. Automatic Security Updates: Patches That Arrive Without Prompting

Under General, Software Update, Automatic Updates, a separate line item covers Security Responses and System Files. Leaving it enabled lets Apple push emergency patches for actively exploited flaws without waiting for a full iOS release, and mobile security recommendations rank prompt patching above almost every other defensive step.

Most spyware infections documented in recent years relied on vulnerabilities already fixed in an available update. Automatic delivery closes the window between a patch shipping and a phone owner getting around to installing it.