Skip to content
THE TECHLEEZ / INDIA-FIRST DIGITAL INTELLIGENCE Wednesday, 19 August 2026
The Signal AIUPISmartphonesStartupsStreamingTravel TechEsports
Technology

Android Privacy Checkup: 15 Settings Worth Reviewing

A calm, step-by-step privacy review for permissions, location, notifications, account access, backups and safer app habits.

Android privacy is not one switch. It is roughly forty small decisions spread across the system settings, your Google account, and every app you have ever installed — and the defaults are set by companies whose interests are not identical to yours.

You do not need to change forty things. Fifteen of them do most of the work. Set aside twenty minutes and go through this in order; menu names vary slightly by manufacturer, so use the search box at the top of Settings if something is not where described.

Part one: what apps can see

1. Review the permission manager

Settings, then Security and privacy, then Privacy, then Permission manager. Go through Location, Camera, Microphone, Contacts and Files one at a time. The question for each app is simple: does it need this to do the job I installed it for? A photo editor needs Files. A torch app does not need Contacts.

2. Move location permissions to “only while using”

Almost nothing needs background location. Delivery and navigation apps are the genuine exceptions during use. Everything else set to “Allow only while using the app”, and anything that does not need it at all set to Deny.

3. Turn off precise location where approximate will do

Android lets you give an app your rough area rather than your exact position. Weather, news and shopping apps work perfectly with approximate location. Ride-hailing and food delivery genuinely need precise.

4. Check the camera and microphone indicators

Modern Android shows a green dot when the camera or microphone is active. Spend a day noticing when it appears. If it lights up while an app is in the background, that app has a permission it should not have.

5. Turn on automatic permission removal for unused apps

Under each app’s info page there is an option to remove permissions and free up space if the app is unused. Turn it on globally where your version supports it. It quietly cleans up permissions from apps you forgot about.

Part two: what Google collects

6. Review your Activity controls

Open myactivity.google.com. Three toggles matter: Web and App Activity, Location History, and YouTube History. You can turn each off, or leave it on with auto-delete after three months. Auto-delete is the practical middle ground — personalisation keeps working, the archive stops growing forever.

7. Turn off ad personalisation

In your Google account under Data and privacy, or in Settings under Google, Ads. Turning it off does not reduce the number of ads; it reduces how much of your behaviour is used to choose them.

8. Delete the location timeline if you do not use it

Location History builds a detailed map of everywhere you have been. Some people find it genuinely useful. If you are not one of them, turn it off and delete the existing history.

9. Audit third-party account access

In your Google account, under Security, look at “Your connections to third-party apps and services”. This is where every “Sign in with Google” you have ever used still sits. Remove anything you no longer use — each one is a standing door into your account.

Part three: locking the device and the account

10. Use a PIN of at least six digits, or a password

Four digits is guessable and shoulder-surfable. Biometrics are convenient but the PIN is the real lock — biometrics only unlock what the PIN protects.

11. Hide sensitive notification content on the lock screen

Settings, Notifications, Notifications on lock screen. Choose to hide sensitive content. OTPs and message previews visible on a locked phone defeat a large amount of other security.

12. Turn on two-factor authentication and move to passkeys

This is the highest-value item on the list. See our guides on enabling two-factor authentication and what passkeys are. An SMS-based second factor is far better than none, and a passkey or authenticator app is far better than SMS.

13. Check which devices are signed into your Google account

Security, then Your devices. Old phones you sold, a laptop at a former workplace, a device you do not recognise. Sign them all out.

Part four: the settings most people never open

14. Turn off nearby scanning when Wi-Fi and Bluetooth are off

Settings, Location, Location services. Android scans for Wi-Fi networks and Bluetooth devices to improve location accuracy even when both are switched off. It is genuinely useful for maps and genuinely a tracking surface in retail spaces. Your call, but make it knowingly.

15. Review apps with special access

Settings, Apps, Special app access. Three sublists matter: Display over other apps, Accessibility, and Usage access. Accessibility is the one to take seriously — it is the permission most malicious Android apps request, because it can read the screen and act on your behalf. If anything is listed there that is not a genuine accessibility tool or a password manager, remove it and treat the phone as compromised.

The bonus check: what did you install outside the Play Store

Sideloaded apps are the single largest source of Android compromise in India, and they usually arrive as an APK forwarded on WhatsApp — a wedding invitation, a bank update, a lottery result. Settings, Apps, and look for anything you do not recognise. Our guides on the APK scam spreading through WhatsApp and how to find hidden apps cover what to look for.

Also worth doing once: turn on Play Protect scanning, and switch off “Install unknown apps” for every app that has it enabled, particularly your messaging apps and browser.

A short maintenance routine

How oftenWhat to check
MonthlyNew apps and the permissions they were granted at install
Every three monthsThird-party account access, and devices signed into your Google account
Every six monthsFull permission manager sweep, and delete apps you have not opened
ImmediatelyAny app you did not install, or anything in the Accessibility list you do not recognise

Beyond the phone

Two adjacent items worth doing in the same session, because they close the loops this list cannot. Locking your Aadhaar biometrics removes an entire category of identity fraud, and checking how many SIM cards are registered in your name through Sanchar Saathi catches connections issued fraudulently against your ID.

Frequently asked

Does turning off ad personalisation reduce ads?

No. You will see the same number, chosen with less information about you.

Will these changes break my apps?

Some apps will ask again for a permission you removed, which is the system working correctly. If an app refuses to function without a permission that has nothing to do with its purpose, that is useful information about the app.

Is a privacy or cleaner app worth installing?

Generally no. Most request extensive permissions to do things Android already does, which makes them a larger risk than the one they claim to solve.

The short version

Permissions to “only while using”, auto-delete on Google activity, six-digit PIN, hidden lock-screen previews, passkeys or an authenticator app, and a hard look at anything sitting in the Accessibility list. Fifteen settings, twenty minutes, and it holds for months. More practical Android and online safety guides on Techleez.

About the author

Smith Leopard

A contributor to The Techleez editorial desk, focused on practical, clearly explained digital guidance for readers in India.

More from this author →