Scroll through the list of apps on your phone and sooner or later you will find them: the game you downloaded for a trip two summers ago, the app for a concert, the parking app for a city you visited once, the loyalty scheme of a shop that has since closed. None of them bothers you. They just sit there, at the bottom of a folder, “in case they come in handy”.
The thing is, an installed app is not an object sitting quietly in a drawer. It is a program that can receive data, run in the background (that is, while you are not using it), keep the permissions you granted it and stay linked to an online account. When nobody uses it any more — and sometimes when even the people who built it have stopped looking after it — it becomes a door left ajar that nobody is watching.
This recommendation — R22 of the Cyber Welfare Framework — suggests something simple: removing apps you no longer use through a regular clear-out, starting with the outdated ones. It does not require technical skills. It takes a quarter of an hour every now and then, and a few clear criteria for deciding what to keep.
What this recommendation says
Recommendation R22 states that the only apps that stay installed on your phone are the ones you actually use and that are still being updated; everything else is removed, with a check repeated at regular intervals.
The apps to remove fall into two groups:
- apps you no longer use, because a habit has changed, a project has ended, or they did their job once and that was it;
- outdated apps, meaning apps the developer no longer updates: even if you still open them now and then, they have stopped receiving security fixes.
What it is not. It is not a competition to see who has the fewest icons: the apps you need stay, and the choice is yours. Nor is it about “moving an app into a folder” or taking its icon off the home screen: in that case the app is still installed, with its data and its permissions. Removing an app means uninstalling it from the device and, where needed, closing the account linked to it as well.
Where it applies. To your personal phone and your work phone, to the family tablet, and to the devices of relatives who ask you for a hand. The same principle extends to the computer: programs you never open any more and browser extensions installed for a single occasion follow the same logic.
Why it matters
Every app is made of code, and code can contain mistakes. Some of those mistakes are vulnerabilities: flaws that, once discovered, can be exploited to make the app do something it should not. Developers fix them through updates. That is why keeping your software current is one of the most effective protections there is, as the recommendation on keeping your software up to date explains.
The problem with forgotten apps is that they slip through exactly this protection. In security, people talk about the attack surface: the set of points through which someone might try to get in. The more apps you have, the more points there are to keep in order. If one of those apps no longer receives updates, its flaws stay where they are, even once they become known.
The concrete consequences show up on four fronts:
- data collected for no reason — some apps keep reading your location, contacts or activity even if you have not opened them for months, if their permissions allow it;
- flaws that nobody fixes — an app abandoned by its developer stays stuck at the version you have, with all its security limits;
- accounts and data left lying around — behind many apps there is a profile with your email, address and sometimes a payment method; if the app or the company changes hands, that data can end up going places you never expected;
- a phone that is harder to read — storage taken up, battery drained, pointless notifications: and amid all that noise it becomes harder to notice when something is not right.
One case deserves special attention: apps you have given lots of permissions to. A photo-editing app used once, with access to your gallery, camera and location, keeps holding those keys for as long as it stays installed. The recommendation on checking what your apps can do helps you narrow them down; removing the app closes all of them in one go.
| Benefit of clearing out your apps | Why it counts |
|---|---|
| Shrinks the attack surface | Fewer programs installed, fewer points to protect and keep updated |
| Gets rid of abandoned apps | Unfixed flaws stop being your problem |
| Limits background data collection | Apps that are not there cannot read your location, contacts or activity |
| Frees up storage and resources | More memory, longer battery life, fewer notifications to ignore |
| Makes your phone easier to keep an eye on | You recognise every installed app and spot straight away what does not fit |
A concrete example
Mark is a surveyor and uses his phone for almost everything: work, family, the odd game in the evening. One Saturday, trying to make room for his holiday photos, he opens the full list of apps. There are more than ninety. He recognises about thirty at a glance.
Among the rest he finds a document-scanning app installed for some paperwork three years earlier: its last update was a long time ago and it no longer appears in the official store. It still has access to the camera and to the file storage, where there are scans of an identity document. A little further down is the app for a five-a-side football tournament that still asks for his location “all the time”, and one for a chain of shops that holds his address and a saved card.
None of these apps has ever caused him a problem. But Mark realises that each one is a small piece of his digital life that nobody is looking after any more.
In twenty minutes he removes twenty-six of them. Before uninstalling the shop app, he goes into his profile and closes the account; for the scanning app, he saves the files he needs elsewhere and deletes the rest. He puts a reminder in his calendar to repeat the check in three months. His phone has not become “one hundred per cent secure”: it has become a phone he knows.
When to apply it
A clear-out is always worthwhile, but some moments make it easier and more useful.
- At regular intervals. Once every three months is a sustainable rhythm: frequent enough that apps do not pile up, rare enough that it does not become a chore.
- When a habit changes. You have switched gyms, finished a course, wrapped up a work project, sold your car: the apps tied to that phase can go with it.
- After a trip or an event. Local transport apps, festival apps, museum or trade fair apps: they are useful for a few days, then they stay for years.
- Before a major system update. A lighter phone updates with fewer hiccups, and it is a chance to see which apps are no longer compatible.
- When your phone flags an unused or outdated app. Many operating systems let you know when an app has not been opened for a while or has stopped receiving updates: treat it as a helpful reminder, not an alarm.
- When you move to a new phone. Rather than transferring everything automatically, choose what you take with you.
How to apply it
You do not need to do everything at once. What you need is a sequence.
- Open the full list of apps. Do not stop at the home screen: your phone’s settings contain a list of every installed app, often showing when each one was last used and how much space it takes up. The resource on reviewing installed apps offers a quick method for this first sweep.
- Apply three simple criteria. An app should go if you have not opened it for about three months and it has no essential function; if the developer has stopped updating it or it is no longer in the official store; or if it does the same job as another app you use more.
- Save what you need. Photos, documents, notes or conversations that live only inside the app should be exported or saved elsewhere before you uninstall it.
- Close the account, not just the app. If the app had a profile, look in its settings for the option to delete your account. Uninstalling removes the program from your phone, but your data stays on the service’s servers.
- Cancel any subscriptions. Uninstalling an app does not cancel an active subscription: it has to be cancelled from the store’s subscription settings or from the service’s website. The resource on apps that charge you for almost nothing explains how to spot them.
- Revoke linked access. If you signed up to an app using your social network or email account, the settings of that account list the apps connected to it: remove the ones you have deleted.
- Uninstall. Only at this point should you remove the app. For pre-installed apps that the system does not let you remove, use the “disable” option, which stops them and limits what they can access.
- Set the next check. A reminder every three months turns the clear-out into a habit, rather than a big job you only tackle when your storage is full.
Common mistakes to avoid
- “It doesn’t take up any space anyway.” Security is not measured in megabytes. Even a tiny app can have wide-ranging permissions and a linked account.
- “I might need it one day.” If you do, you can download it again from the official store, and you will get the latest version.
- Hiding instead of removing. Taking an icon off the home screen or tucking it into a folder changes nothing: the app is still installed and active.
- Uninstalling without closing the account. The profile, with your personal details and perhaps a saved card, stays on the service’s servers even when the app is gone.
- Forgetting about subscriptions. A deleted app can keep costing you money every month if the subscription has not been cancelled.
- Hastily removing something you really need. Authenticator apps (the ones that generate codes for multi-factor sign-in), banking apps, emergency or health apps deserve a moment’s extra thought: if you remove one, first make sure you have another way to get into your accounts.
- Overlooking pre-installed apps. Many phones come with built-in apps you will never use: if they cannot be removed, disabling them still reduces their footprint.
How this connects to the Cyber Welfare Framework
R22 is a maintenance recommendation: it turns an occasional gesture — deleting something when your storage is full — into a habit that keeps protecting you over time.
| Pillar | How this contributes |
|---|---|
| Skills | Knowing how to find the full list of apps, tell when an app has been abandoned and close the linked account |
| Awareness | Understanding that every installed app is one more point to protect, even when you are not using it |
| Secure Behaviour | Clearing out your apps at regular intervals and installing only what you really need |
Digital maturity levels.
- FL1 — Basic. Apps pile up and only get deleted when storage runs out. It is the most common starting point, not a fault.
- FL2 — Beginner. You do a regular clear-out, removing the apps you do not use and those that are no longer updated.
- FL3 — Autonomous. When you remove an app you also close the account, cancel any subscriptions and revoke linked access.
- FL4 — Skilled. You assess every new app before installing it and regularly review permissions, updates and connected apps.
- FL5 — Expert-Guide. You help other people — in your family, your team, your organisation — do the same clear-out.
R22 is the key step from FL1 to FL2, and it remains an active requirement at every level after that.
How to check you are applying it properly
Three questions, to be answered honestly.
- If I open the full list of apps, do I recognise every one of them and know what it is for?
- When did I last remove an app because I no longer used it, rather than because I was running out of space?
- For the apps I have removed recently, did I also close the linked accounts?
Quick checklist
- ☐ There is no app in the full list that I do not recognise
- ☐ No installed app has gone a long time without updates
- ☐ The apps I have not opened for about three months have been reviewed one by one
- ☐ For every app I removed, I closed the account or checked there was none
- ☐ I am not paying for subscriptions to apps I no longer use
- ☐ I have a reminder set for the next clear-out
If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.
In short
The apps you no longer use are not harmless just because they are quiet. They can keep permissions, collect data, stay linked to an account and, if the developer has abandoned them, carry flaws that nobody will ever fix.
Removing apps you no longer use is one of the simplest forms of protection there is: open the full list, apply a few criteria, save what you need, close accounts and subscriptions, uninstall, and set the next check.
Digital security does not ask you to give up your apps. It asks you to know which ones are there, and to keep only the ones you have chosen.
Something to think about. If you had to explain to someone today what each app on your phone is for, how many would you have an answer for?
Explore this recommendation
This recommendation is the pivot of a content unit. Each post looks at a different aspect.
- Risks of abandoned apps — what gets hit, in terms of the confidentiality, integrity and availability of your data and your device
- Consequences of forgotten apps — the concrete effects on the operational, financial, legal, reputational and personal levels
- How to clean up your apps — the mitigations, from prevention to recovery
- Unused apps still active on your phone — the indicators to check and what they mean
- Tools for managing apps — the operating system features that help, with their advantages and limits
- Vulnerabilities in outdated apps — the ways a neglected app can be exploited
Related resources
Short reads from the Resources section, for anyone who wants to focus on a single aspect:
- Review Installed Apps: The Twenty-Minute Clear-Out
- App Permissions: Deciding What Each App Can Reach
- Fleeceware: Apps That Charge You for Almost Nothing
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



