The difficulty in this unit is that collecting data is not a malfunction: it is the intended working of a great many apps, declared in the privacy notices and permitted by the permissions you granted.
So there are no signals of “something wrong”. There are clues of disproportion — things that do not add up between what an app does and what it needs in order to do it.
It expands on the recommendation checking what your apps can do.
The signals before installing
They are the most useful, because they prevent rather than remedy.
The permissions requested are listed in the store. Every app’s page shows what it will want to reach. Looking at it before installing costs ten seconds.
The disproportion between function and requests. An app doing something simple and asking for contacts, microphone and location is asking for more than it needs.
The number of installs and the reviews. An app with very few installs and generic reviews deserves more attention than one used by millions of people.
A missing or unreachable privacy notice. Every app should point to one. If the link does not work or leads to an empty page, that is data.
The developer. The name is shown, and it lets you see which other apps they published. A publisher with dozens of near-identical apps is a different model from one with a carefully made product.
The data safety section. The main stores now require every app to declare which data it collects and whether it shares it. It is self-declared, so it is not a guarantee — but a broad declaration is already information.
The signals after installing
The out-of-context request
An app asking for a permission at a moment with nothing to do with what you are doing. A request to access contacts while you are editing a photo, for instance.
Well-designed apps ask for permissions when they are needed, explaining why: “to take the photo we need the camera”. A request with no context is already a clue of disproportion.
Insistence after a refusal
An app repeating the same request at every launch, or making it hard to continue without granting, is treating the permission as a requirement and not as a choice.
Functional blackmail
“To use this feature you must grant access to X”, where X is not technically necessary. It is a practice the stores discourage, but it exists.
The permission that reappears
A permission you had revoked coming back granted after an update. It should not happen, and when it does it deserves attention.
The signals in the device’s behaviour
| Signal | What it may indicate |
|---|---|
| A battery draining quickly | Continuous activity in the background |
| High data use | Regular transmission of information |
| The device warming up | Continuous processing |
| Slowdowns | Many active processes |
| The microphone or camera indicator | An app is using them now |
| Advertising following too closely | Profiling based on shared data |
The first four are weak clues with many ordinary explanations. They become meaningful only when the battery screen or the data usage screen points at a specific app you do not use.
The fifth, by contrast, is a fact: if the indicator appears and you are not using anything needing the microphone or camera, an app is using them.
The best tool: the privacy report
Both main systems now offer a function making visible what used to be invisible.
Where: in the settings’ privacy section, with names that vary — privacy dashboard, privacy report, app activity.
What it shows: which apps used which permissions, when and how many times, on a timeline of the last hours or days.
How to read it. Two questions only:
Does an app appear far more often than you use it? That is the signal of background activity.
Did an app use something at times when you did not touch it? The same thing, more clearly.
It is the most effective tool in this unit because it turns an impression into verifiable data, and it takes two minutes.
What is NOT a signal
Essential, because false alarms in this area are very frequent.
| What | Why it does not indicate a problem |
|---|---|
| An app asking for a permission at first launch | It is the intended behaviour: weigh it and answer |
| Advertising consistent with your interests | Ordinary profiling, not listening |
| Advertising for something you talked about | A statistical coincidence, plus other data |
| A battery lasting less over the years | Batteries age |
| An app using data in the background | Syncing, updates, notifications |
| The microphone indicator during a call | It is the call |
| Many apps with internet access | Practically all of them have it |
The third row deserves explaining because it is the most widespread belief: advertising that “seems to know” is nearly always the result of profiling based on searches, location, purchases and the people around you — not on listening. The result resembles it, the origin is different, and the effective countermeasure is reducing shared data, not switching off the microphone.
Reading an app’s page before installing it
It is the moment when the signals cost the least, and it is worth knowing what to look at. Thirty seconds, four entries.
1. The declared permissions. Every store lists them. The question is not “are there many?” but “are they consistent with what the app does?”
2. The data safety section. The main stores now require every app to declare which data it collects, whether it shares it and for what purpose. It is self-declared, so it is not a guarantee — but a broad declaration is already data, and an absent one even more so.
3. The developer. Tapping the name shows the other apps published. A publisher with a carefully made product is different from one with dozens of near-identical apps.
4. The recent reviews. Not the ones at the top, which can be selected: the ones from the last updates. If many report a change — advertising appearing, features becoming paid, new requests — the app changed recently.
A fifth element, if you have ten seconds more: the date of the last update. An app not updated for years receives no security fixes, and that holds for an honest app too.
None of these checks requires technical skill. Together, they reduce the later review work more than any other habit in this unit.
The signals that deserve a reaction
Three cases where it is worth acting at once.
An app with the accessibility permission that is not an assistive tool. It is the most serious signal in this unit.
An app reading notifications that is not a watch or car app. It sees the verification codes.
An installed app you do not remember downloading. Check the installation date and uninstall it.
In all three cases the reaction is the same: revoke, uninstall, and — if the app had accessibility or access to notifications — change the credentials of the main services.
Why “disproportion” is the right criterion
It is worth explaining why this unit turns on a word instead of a list of symptoms.
In every other unit in the series there is an anomalous behaviour to recognise: a sign-in that is not yours, a forwarding rule you did not create, an unencrypted connection. They are facts that should not be there.
Not here. An app collecting data it has permission for is doing nothing anomalous. There is no anomaly to identify, because the behaviour is exactly what was intended.
What remains is a judgement of proportion: between what the app does for you and what it asks in return.
| Question | What it reveals |
|---|---|
| What does this app do for me? | The benefit |
| What does it ask in order to do it? | The cost |
| Is the second consistent with the first? | The proportion |
It is a less precise criterion than a list of symptoms, and for that reason some people find it unsatisfying. It has two advantages, though: it works on apps that do not exist yet, and it requires knowing nothing technical.
And it is, at bottom, the same criterion applied outside the digital world whenever somebody asks for more than they need.
A five-point check
To be done every few months, or after installing several new apps.
1. The privacy report. Two minutes, and it says more than anything else: which apps used what, and how many times.
2. Accessibility. It should contain only assistive tools. It is the most important check and the quickest.
3. Access to notifications. Only wearable and car apps.
4. The apps you do not recognise. Sort the list by installation date: the most recent at the top makes plain what you do not remember downloading.
5. Browser extensions. The most neglected point. Remove the ones you do not use and look at the permissions of the ones that remain.
Five minutes in all. The difference from other checks in this series is that here nothing needs interpreting: you look at a list and decide whether each entry makes sense.
And if something does not make sense, the reaction is always the same and always reversible: revoke, and see what happens.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that collection is intended behaviour, not an anomaly |
| Skills | Reading the privacy report and the permissions in the store |
| Secure Behaviour | Weighing before installing, not afterwards |
Reference level: FL3 — Autonomous.
Summary
- There are no signals of malfunction: there are clues of disproportion.
- The most useful signals are seen before installing, on the store page.
- The privacy report turns an impression into data: two minutes.
- Advertising that “seems to know” is profiling, not listening — and it shrinks by reducing the data.
One thing to do today. Open your phone’s privacy report and look at the last 24 hours. If an app appears many more times than you opened it, you have found something concrete.
Related content
- Checking what your apps can do — the recommendation this expands on
- How to review granted permissions — what to do when you find something
- Impact of excessive permissions — why accessibility and notifications count more than the rest
- Permission abuse — the techniques these signals reveal
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



