You are at a cafe in Melbourne, paying with your phone, checking the BOM app, opening myGov, sending a photo in WhatsApp, and using Google Maps to get to the next tram stop. In that ordinary half hour, Android permissions are doing useful work. Location, camera, notifications and files are not automatically suspicious; they are often the reason the app works.
The problem is that permissions tend to accumulate. An app you installed for one event still has your location. A shopping app can still send alerts. A photo editor you tried once can still see media. A parking app from a weekend in Adelaide or a telco app you used to troubleshoot NBN may still have more access than it needs. A 10-minute audit is not about becoming paranoid. It is about removing access that no longer matches how you actually use your phone.
Start with the permission manager
On most recent Android phones, go to Settings, then Security and privacy or Privacy, then Permission manager. On some Samsung, Oppo, Motorola and older Android layouts, the path may be slightly different, so use the Settings search bar and type Permission manager.
Work by permission type, not app by app. It is faster and it helps you spot outliers. You are not trying to make every list empty. You are asking: does this app still need this permission for a feature I use?
Spend most of the audit on these categories:
- Location: the highest-value permission to review because it can be useful, sensitive and easy to over-grant.
- Camera and microphone: usually obvious when needed, so strange entries stand out.
- Photos and videos: worth checking if you try lots of social, editing, marketplace or rental apps.
- Contacts, SMS, phone and call logs: narrow permissions that should have a clear reason.
- Notifications: not a privacy disaster by itself, but a major source of attention leakage.
- Special app access: powerful settings such as display over other apps, install unknown apps and unrestricted battery use.
Location: choose the smallest setting that still works
Location is not one setting. Android can offer choices such as Allow all the time, Allow only while using the app, Ask every time and Don’t allow. You may also see a Use precise location toggle.
For navigation, rideshare, delivery, weather, banking fraud checks and emergency-adjacent services, location may be reasonable. The trade-off is convenience versus exposure. A maps app needs live location while you are navigating. A parking app may only need it when you are finding or paying for a spot. A bank app might use location as one signal for fraud detection, but that does not automatically mean every finance, rewards or budgeting app needs constant access. A retail app often works fine with suburb-level or manually entered location.
A practical pass looks like this:
- Set maps, rideshare and delivery apps to Allow only while using the app, unless you knowingly use a background feature.
- Turn off Precise location for apps that only need your area, such as weather, local deals, store finders or a council waste app.
- Use Ask every time for apps you rarely use but do not want to break, such as parking, venue, event or travel apps.
- Use Don’t allow for apps where location is only for advertising, personalisation or a feature you never touch.
The limit is worth stating plainly: permission settings reduce app-level access to Android’s location service. They do not make you invisible to mobile networks, Wi-Fi operators, websites, account logins or services that infer location from other signals.
Camera and microphone: simple rules work
Camera and microphone permissions are easier to judge. Video calling, banking identity checks, QR scanning, voice notes, translation and camera apps need them. Medicare or myGov-related sign-in flows may need the camera when you are scanning a document or completing an identity check. A calculator, wallpaper app, coupon app or simple game usually does not.
Set casual apps to Ask every time if you occasionally scan a code or upload a clip. Set them to Don’t allow if you cannot name the feature that needs access. If an app breaks, it will ask again at the moment it needs the permission, which is the right time to decide.
Android also has system-level camera and microphone toggles on many devices. These are useful blunt instruments for meetings, travel or lending your phone to someone. They are not a substitute for fixing app permissions, because you will probably turn them back on later.
Photos and videos: avoid “all photos” by habit
Photo access is easy to over-approve because the prompt appears when you are in a hurry. A messaging app, social app or photo editor has a sensible reason to access media. The better question is whether it needs your entire library.
On newer Android versions, some apps can use a photo picker or limited media access rather than broad file access. Prefer selecting specific photos where the option exists. For apps you use once to upload a Medicare document, submit a rental inspection photo, sell an item, lodge a parking dispute or make a profile picture, limited access is usually enough.
Be more careful with apps that ask for broad file access. Files or all files access is much broader than choosing a few images. File managers, backup tools and some media utilities may need it. Most ordinary apps do not.
Contacts, SMS, phone and call logs: look for a direct purpose
These permissions are narrow but sensitive. A contacts permission can help a messaging app find friends, a car Bluetooth companion identify callers, or a payments app split bills. SMS access can support messaging apps or automatic verification in limited cases. Phone and call log access may make sense for dialler, voicemail, spam filtering or wearable apps.
The test is directness. If the feature is not obvious, remove the permission. Many apps can still function if you type a contact manually, enter a verification code yourself, or skip social discovery. Your bank, myGov or telco app may send codes by SMS, but that does not mean it must be able to read all SMS messages; manual entry is often fine.
One thing permission changes cannot do is erase information already shared. If you previously uploaded contacts to a service, revoking the Android permission stops future access from the phone, but it does not necessarily delete data already synced to that service. Use the app’s account or privacy settings if you want to check deletion options.
Notifications: privacy is not the only reason to audit
Notification permission is less about secret access and more about control. In Australia, plenty of useful apps compete for your lock screen: banking alerts, myGov messages, Medicare updates, delivery updates, school apps, footy scores, pharmacy reminders, telco usage warnings, parking expiry notices and retail promos.
Keep notifications for apps where timeliness matters. A bank transaction alert, parking expiry warning, school message, medication reminder or telco outage update can be worth the interruption. So can some emergency and incident alerts, especially during bushfire, flood, heatwave or severe storm season. The trade-off is that more alert channels can also mean more noise, duplicated warnings and lock-screen exposure. Keep the ones you would actually act on.
Turn notifications off for stores, games, streaming apps and social apps that mainly pull you back in. For messaging apps, consider leaving notifications on but hiding sensitive lock-screen content in Android’s notification settings.
A good rule: if you would not open the app today without a prompt, it probably should not be allowed to prompt you.
Check unused apps before fine-tuning everything
Android can automatically pause activity for unused apps. Depending on your device and Android version, this can remove permissions, stop background activity and silence notifications for apps you have not used in a while. Android 15 also supports app archiving on some devices and stores, which can remove an app’s software, permissions, temporary files and notifications while keeping its icon and data.
Go to Settings, then Apps, then look for Unused apps. If your phone shows a list, review it before doing detailed permission work. Uninstall what you clearly do not need. For apps you might use again but do not trust with ongoing access, leave pause enabled.
The trade-off: pausing or archiving an unused app can interfere with background reminders, syncing or alerts. That matters for a medication app, work authenticator, school communication app, airline app before a trip, emergency information app, or a state government service app you rely on occasionally. It does not matter much for an old sale-tracking app from last Christmas.
Do one pass through special app access
Search Settings for Special app access. This section is separate from normal runtime permissions and can include powerful abilities. Names vary by Android version and phone maker, but the important entries are usually recognisable.
- Install unknown apps: leave off unless you deliberately install apps from that source. Your browser and file manager should not keep this forever after one download.
- Display over other apps: useful for chat heads, password managers and accessibility tools, but suspicious for random utilities.
- Accessibility access: powerful and sometimes necessary, especially for screen readers, automation tools and password managers. Remove it from apps you do not actively rely on.
- Notification access: allows an app to read notifications. Keep it only for wearables, launchers, automation or notification-management tools you trust.
- Unrestricted battery: useful for apps that must run reliably in the background, but unnecessary for most apps.
Do not rush this section. Some accessibility and device-admin settings support legitimate safety, work, health or accessibility needs. The aim is not to disable anything unfamiliar on sight; it is to remove powerful access from apps that no longer have a job.
What to ignore, mostly
Not every permission-looking item deserves attention. Android and Google Play may show technical permissions that are automatically granted or tied to ordinary app functions. Network access, vibration, Bluetooth behaviour and foreground service notices can look noisy without being meaningful choices for most users.
Also avoid spending the whole audit on preinstalled system components unless you know what they are. Android phones include services from Google, the device maker and your telco. Some look oddly named because they are background components, not normal apps. If you are unsure, leave system apps alone and focus on downloaded apps first.
Keep the job in proportion. Permissions matter, but so do account settings, browser cookies, ad personalisation, cloud backups, data broker exposure, weak passwords and what you voluntarily post or upload. A permission audit is worthwhile because it is quick and concrete, not because it solves everything.
A sensible 10-minute order
If you want this done without getting stuck, use a timer:
- Minutes 1-3: open Permission manager and review location. Remove all the time access unless you clearly need it. Turn off precise location where approximate is enough.
- Minutes 4-5: review camera and microphone. Change unclear apps to Ask every time or Don’t allow.
- Minutes 6-7: review photos, contacts, SMS, phone and call logs. Remove anything without a direct purpose.
- Minute 8: review notifications. Keep alerts that are genuinely timely; silence the rest.
- Minutes 9-10: check unused apps and special app access. Uninstall old apps and remove powerful access that no longer makes sense.
For source context, see Google’s specific Android Help page Change app permissions on your Android phone at https://support.google.com/googleplay/answer/9431959, Google’s Android Help page Archive unused apps on Android at https://support.google.com/android/answer/15523443, Android Developers’ Permissions on Android overview at https://developer.android.com/guide/topics/permissions/overview, Request runtime permissions at https://developer.android.com/training/permissions/requesting, and Request special permissions at https://developer.android.com/training/permissions/requesting-special.
Practical recap
- Focus on location, camera, microphone, photos, contacts, SMS, phone, call logs, notifications and special app access.
- Prefer while using, ask every time and approximate location when they suit the app.
- Do not break apps you rely on for banking, myGov, Medicare, work, health, school, travel, parking or safety alerts without checking the trade-off.
- Uninstall apps you no longer use; permission trimming is second best for apps that have no reason to stay installed.
- Treat the audit as maintenance, not a panic ritual. Ten calm minutes every few months is enough for most people.



