Additional resource for the lesson “App Permissions: Deciding What Each App Can Reach” — Online Security course
App permissions are the part of installing that happens after the decision. Location, microphone, camera, contacts, files — each is a door you open, usually while trying to get to something else.
A. Why this matters
An app asks for a permission at the moment you are trying to use it, which is the moment you are least inclined to think about it. You grant it, the app works, and the permission stays.
Modern phones have improved this considerably: permissions can be temporary, granted only while the app is in use, and revoked automatically from apps you stop opening. Most of these options are available and not enabled.
The key idea: the useful principle is consistency. Does this permission match what the app is for? A map needs location. A torch does not.
B. Key concepts
Six ideas about granting and reviewing.
Least access
Granting the minimum an app needs to do what you want, rather than everything it asks for.
Why it matters to you: Most apps work fine with less than they request. Refusing and seeing whether anything breaks is a reasonable approach.
Consistency with purpose
The test: does this permission relate to what the app does?
Why it matters to you: It is a better rule than trying to remember which permissions are dangerous. A photo editor needs photos; it does not need contacts.
The sensitive ones
Location, microphone, camera, contacts, files, and — on Android — the ability to display over other apps.
Why it matters to you: These are where the consequences of over-granting are largest. The last one is what makes adware possible, as the companion resource describes.
Temporary and while-in-use
Granting access only while the app is open, or only once.
Why it matters to you: Available for the most sensitive permissions on both platforms, and the right default for anything you use occasionally.
Permissions after an update
An app can request new permissions when it updates, or change what it does with existing ones.
Why it matters to you: An app that has been on your phone for three years may not be the app you originally installed.
Automatic revocation
Removing permissions from apps you have not opened in months.
Why it matters to you: Both platforms offer this. Turning it on handles the accumulation without you having to remember.
C. A practical example: reviewing by permission
Most people review permissions app by app, which is slow and reveals little. Reviewing by permission takes the same time and reveals more.
Which apps have your location?
- Maps and weather: expected.
- A shopping app: plausible, and probably not needed always.
- A game installed for a flight two years ago: no.
Which apps can use the microphone?
- Messaging and calls: expected.
- A photo editor: worth questioning.
- Anything you cannot explain: revoke and see whether anything stops working.
Nothing here implies wrongdoing. It shows permissions granted for a reason that has passed.
Revoking is reversible: if the app needs the permission, it will ask again the next time you use that feature.
D. Try it yourself: the permission-first review
Fifteen minutes, and it is the most revealing exercise in this cluster.
Step 1 — Open the permission manager
- Android: Settings, Privacy, Permission manager.
- iOS: Settings, Privacy and Security.
Step 2 — Go through the sensitive ones
- Location, microphone, camera, contacts, files.
- For each, read the list of apps rather than the other way round.
Step 3 — Apply the consistency test
- Does this permission match what the app is for?
- If not, revoke. If unsure, set it to while-in-use or ask-every-time.
Step 4 — Turn on automatic revocation
- Android: remove permissions if the app is unused.
- iOS: check the app privacy report to see what has been accessed.
Step 2 is the change in method that matters. Reading by permission rather than by app is what makes the mismatches visible.
E. Videos, articles and further resources
Independent and institutional sources in English.
Google — Use Play Protect to keep your apps safe and your data private
Where the permission manager is and how automatic revocation works. Platform documentation.
https://support.google.com/android/answer/2812853?hl=en
FTC — Online privacy and security
Consumer-facing advice on protecting your identity, securing your home network and browsing safely.
https://consumer.ftc.gov/identity-theft-and-online-security/online-privacy-and-security
NCSC (UK) — Smart devices: using them safely in your home
The same principle applied to connected devices and their companion apps.
https://www.ncsc.gov.uk/guidance/smart-devices-in-the-home
FTC — How to protect your phone from hackers
Practical steps for the device that holds most of your digital life.
https://consumer.ftc.gov/articles/how-protect-your-phone-hackers
Electronic Frontier Foundation — Surveillance Self-Defense
Broader background on what applications can collect and why it matters.
https://ssd.eff.org/
NCSC (UK) — Cyber security advice for you and your family
The UK national authority’s advice hub for individuals: short, practical guidance written for people who are not IT professionals.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family
Links checked in August 2026. Apple and Google document their permission settings directly.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits on the Skills pillar at level FL2 and closes the app cluster.
Skills
- Using the permission manager and reviewing by permission rather than by app.
- Setting permissions to while-in-use or ask-every-time.
- Enabling automatic revocation.
For professionals and organizations
- Reviewing permissions on apps with access to company accounts.
Awareness
- Understanding that permissions are granted under time pressure and reviewed rarely.
- Recognising that an update can change what an app does with what it already has.
- Knowing that revoking is reversible.
For future instructors and ambassadors
- Running the permission-first review live. Everyone finds at least one mismatch.
Secure Behavior
- Applying the consistency test when an app asks.
- Preferring while-in-use over always.
- Reviewing permissions once or twice a year.
For organizations
- Setting permission policies on managed devices rather than relying on individual judgement.
G. Questions to sit with
- Which apps on your phone currently have your location, and do they all need it?
- Which can use your microphone?
- Have you ever revoked a permission and found nothing stopped working?
- Is automatic revocation switched on?
H. What to do now
The recommendations (R) and security measures (MS) that apply.
Permissions
- MS7 — Review the permissions you have granted and revoke what is not needed.
- R32 — Turn off location tagging, which is one of the most granted and least noticed.
- MS6 — Keep social accounts private, which is the same principle applied to visibility.
Around them
- R6 — Keep apps updated, and check permissions after a major update.
- R17 — Install only from official stores, where permissions are declared before installing.
In short
- The consistency test is the rule worth remembering: does this match what the app is for?
- Review by permission, not by app — the mismatches become obvious.
- While-in-use is the right default for anything sensitive.
- Revoking is reversible: the app will ask again if it genuinely needs it.
Related resources in this course
Before installing, and clearing out afterwards:
- Check App Details: The Filter Before You Install
- Review Installed Apps: The Twenty-Minute Clear-Out
- Adware on Your Phone: Reading the Unwanted Ads
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply