Most smartphone apps ask for permissions long before anyone thinks to read the request. Location, contacts, microphone and cross-app activity often get handed over during setup and then never revisited, quietly feeding advertising and data-broker pipelines for years. Here are twelve familiar apps that collect far more than their function suggests.
1. Facebook: Permissions Stacked At Signup
Facebook’s app requests some of the broadest permission sets on a typical phone: location, contacts, and tracking of activity that happens in other apps and on other websites. A privacy guidance overview notes those requests are bundled into ordinary setup screens, where they are usually approved without much thought. The result is a continuous profile built from movement, social graph, and browsing behavior.
Because the app runs in the background, the collection does not stop when the feed is closed. Revoking location and contact access in system settings preserves core functionality for most people, and the off-platform tracking toggle can be switched off separately.
2. Instagram: Activity Logged Beyond The App
Instagram’s data collection extends past the photos and videos in its own feed. Guidance on iPhone tracking controls describes how the app logs activity across other apps and websites to sharpen advertising targets, which is why a product viewed on an unrelated retail site can reappear in the feed hours later. That cross-context record accumulates whether or not anything is posted.
Apple’s App Tracking Transparency prompt is the main lever here, and declining it limits the identifier that ties outside behavior back to the account. Android offers a comparable advertising-ID reset. Neither step blocks collection inside the app itself.
3. TikTok: Device Fingerprints At Scale
Scale is what separates TikTok from smaller apps. Privacy documentation for iPhone users points to collection spanning device identifiers, location, and granular in-app behavior, including every pause, replay, and rewatch that feeds the recommendation engine. The same signals that make the feed uncannily accurate also constitute a detailed behavioral record tied to one handset.
Turning off precise location and denying contact access reduces the footprint without changing how the feed works. The behavioral logging inside the app cannot be switched off, which makes account-level data downloads the only practical way to see what has been retained.
4. Snapchat: Precise Location On By Default
Snapchat leans on precise location and camera access from the moment the app opens, and both are enabled by default rather than requested later. A rundown of app tracking settings flags the combination as unusually permissive, since the Snap Map feature broadcasts a live position to friends unless it is deliberately disabled. Camera access stays open across sessions.
Ghost Mode hides the map position without removing the underlying location permission. Switching the setting from Always to While Using cuts background collection, and the app continues to function normally for messaging and photos.
5. Free Weather Apps: Forecasts Funded By Location Sales
A forecast needs an approximate location, not a continuous precise one. Several free weather apps monetize that gap, and a guide to blocking app tracking notes that some in this category pass precise coordinates to data brokers, who resell movement patterns to advertisers and analytics firms. The forecast is the visible product; the location trail is the one being sold.
Setting location permission to Approximate, available on both major mobile platforms, keeps forecasts accurate to within a few miles while stripping the precision brokers pay for. Paid or open-source weather apps avoid the model entirely.
6. Flashlight Apps: A Torch That Wants The Address Book
Few categories illustrate permission creep as plainly as the flashlight. Toggling an LED requires no personal data at all, yet documented tracking behavior shows these utilities routinely demanding contacts, location, and storage access before they will run. The permissions have nothing to do with the function and everything to do with resale value.
Modern versions of iOS and Android include a flashlight toggle in the control panel, which removes any reason to install a third-party version. Deleting one already installed also revokes the permissions it was granted.
7. Google App: Web And App Activity Keeps Running
The setting that matters most on the Google app is not a permission prompt but an account switch called Web and App Activity. As privacy guidance on app tracking explains, it records searches, voice queries, and location history across every signed-in device until it is turned off. It is enabled by default on new accounts.
The controls sit at myactivity.google.com rather than inside the phone’s settings, which is why many people never find them. Auto-delete windows of three, eighteen, or thirty-six months are available, and pausing the setting stops new logging without erasing what already exists.
Messenger asks for microphone and contact access during setup so voice notes and calls work, and both stay granted indefinitely afterward. An overview of iPhone tracking points out that most users never revisit the prompt, leaving an always-available microphone permission attached to an app that also runs in the background.
There is no evidence of covert recording, but a standing permission is still a standing risk if the app is ever compromised. Switching microphone access to per-use, then re-granting it when a voice call is actually placed, closes the gap with minimal inconvenience.
9. WhatsApp: Encrypted Messages, Shared Metada
Message contents on WhatsApp are end-to-end encrypted, which is often mistaken for full privacy. Metadata is a separate matter: analysis of app privacy settings notes that contact lists, who talks to whom, and how often are shared upward with the parent company, and that pattern data can be revealing even when the words are unreadable.
Declining contact-book access limits what leaves the device, at the cost of manual number entry. For conversations where metadata itself is sensitive, apps that collect less of it by design are the more consistent choice.
10. Third-Party Keyboards: Full Access Means Every Keystroke
Installing a replacement keyboard triggers a prompt labeled Full Access, and the warning attached to it is literal. Security guidance on keyboards confirms that a keyboard granted this permission can transmit everything typed into it, including passwords, card numbers, and private messages, to the developer’s servers.
Some keyboards need the connection for cloud prediction or synced dictionaries; others simply ask because most people approve it. Declining Full Access keeps the keyboard usable in offline mode, and the stock keyboard remains the safest option for banking and login screens.
11. Shopping And Coupon Apps: Discounts Priced In Location Dat
Coupon and loyalty apps have a commercial reason to know where a phone goes. Reporting on mobile tracking describes background location used to log store visits, building a record of which retailers were entered, how long the visit lasted, and which competitor was checked afterward. That footfall data is valuable to retailers and to the brokers who aggregate it.
The discount is real, and so is the trade. Setting location to While Using preserves in-store features such as barcode scanning while ending the silent background log of every errand.
12. Voice-Assistant Apps: A Microphone Waiting For Its Cue
Wake-word detection only works if the microphone never fully closes. Privacy analysis of assistant apps notes that these tools hold continuous microphone access to listen for a trigger phrase, and that short audio clips captured around a false trigger have historically been retained and reviewed by human contractors for quality grading.
Both major platforms now offer opt-outs for human review plus deletion controls for stored recordings, though neither is enabled by default. Revoking microphone access disables the hands-free wake word while leaving the assistant reachable through a button press.