Smartphone App Permissions Explained and Which Ones to Deny
Why You Should Think Twice Before Granting Any App Permission
Stop granting permissions. The common assumption is that the system protects your data. That is wrong. It protects the app developer from liability, not you from surveillance. In Singapore, 46,563 scam cases were reported in 2024 and SGD 651.8 million was lost. The question is which permissions an app actually needs to function and which it uses to extract data it has no business collecting. Deny first, grant later. The Personal Data Protection Act's consent and purpose limitation obligations back you up.
The PDPA requires organisations to get your agreement before collecting, using, or disclosing personal data. It also demands purpose limitation: an app must not collect data beyond what its stated function requires. A photo-editing app that requests your contact list may be in breach of Singapore law. The same applies to a flashlight app that wants your whereabouts. Knowing what to block starts with understanding what each access level actually allows.
How To Find Your App Permissions Manager: iOS And Android Settings Paths
iOS 18 Privacy Dashboard
On an iPhone running iOS 18, open Settings, scroll to Privacy & Security, and you will see 17 system privacy access types. Each entry shows which apps have requested that access and whether it is set to Never, Ask Next Time, While Using the App, or Always. For app tracking, go to Settings > Privacy & Security > Tracking and toggle off Allow Apps to Request to Track for all apps at once.
Android 15 Permission Manager
On a phone running Android 15, open Settings, tap Apps, then tap Permission Manager. The system groups access into 13 categories requiring runtime user grant. You can see which apps have access to each category and revoke it individually. The OS also includes an auto-reset feature: privileges for apps you have not used for a few months are automatically revoked. The exact duration varies by manufacturer and version, but the feature exists.
Location Permission Risk In Singapore: What The App Actually Sees
Whereabouts access is the most abused privilege on both platforms. When you grant it, the app can read your device's GPS coordinates, Wi-Fi network names, and Bluetooth signals. That data can reveal your home address, workplace, daily commute route, and the exact time you leave and return. A legitimate use is a food delivery app that needs your position to route the rider. A red flag is a game, a wallpaper app, or a keyboard app requesting it. In Singapore, the PDPC has issued advisories that organisations should design apps to request only necessary access. Any app whose core function does not depend on your physical position should be blocked immediately.
When It Is Proportionate And When It Is Not
A ride-hailing app needs your whereabouts while you are using it. Set it to While Using the App on iOS or Allow Only While Using the App on the Google OS. A weather app needs it to give you local forecasts, but it does not need it in the background. A social media app may request it to tag a post, but that is a convenience, not a necessity. Deny background access to every app unless you have a specific reason to trust it with your movements, such as a fitness tracker that maps your run route.
| Permission | What The App Can Access | Legitimate Feature That Needs It | Misuse Risk In Singapore Context |
|---|---|---|---|
| Location | GPS coordinates, Wi-Fi networks, Bluetooth signals, movement patterns | Ride-hailing, food delivery, navigation | Stalkerware, profiling for targeted scams, revealing home and work locations |
| Microphone | Audio from the device microphone, even when the app is in the background | Voice recording, voice search, video recording with sound | Eavesdropping, recording private conversations, harvesting voice samples for impersonation scams |
| Camera | Live video feed, ability to take photos and record video without on-screen indicator | Video calls, photography apps, QR code scanning | Surveillance, recording sensitive documents or surroundings, deepfake creation material |
| Contacts | Full contact list including names, phone numbers, email addresses, and social media profiles | Messaging apps, email clients, social networks to find friends | Contact list harvested for phishing campaigns, scam messages sent to your network, social graph profiling |
| Photos / Media Library | All photos and videos stored on the device, including metadata and EXIF data | Photo editing, social media upload, file sharing | Extraction of EXIF data revealing position and device info, scraping images for identity theft, blackmail |
| Background App Refresh | Ability to run processes and fetch data while the app is not open | Email sync, messaging apps receiving messages, weather updates | Continuous data exfiltration, battery drain, tracking your movements without your knowledge |
Microphone And Camera Access: The Permissions That Turn Your Phone Into A Listening Device
Microphone and camera privileges are the most intimate data an app can request. On iOS, a green dot appears in the status bar when the camera is in use and an orange dot when the microphone is active. On the Google OS, the privacy indicator works the same way in recent versions. A legitimate use for microphone access is a voice memo app or a video conferencing tool. A legitimate use for camera access is a QR scanner or a camera app. A red flag is a game, a social media app, or a utility app requesting either when you are not actively using that feature.
In Singapore, the Singapore Police Force has issued advisories on malware scams where malicious apps request accessibility privileges to read screen content and intercept SMS OTPs. The same principle applies to microphone and camera: an app that requests them without a clear, immediate need is either poorly designed or deliberately harvesting data. The PDPA consent obligation means you must be informed of the purpose before you grant access. If the purpose is vague, "to improve your experience", block it.
Contact List And Photo Library Access: The Data Brokers' Favourite Permissions
When an app accesses your contact list, it does not just read names and numbers. It can extract email addresses, social media handles, relationship labels, and any notes you have saved. A legitimate use is a messaging app that needs to find which of your contacts also use the same service. A red flag is a photo-editing app, a calculator, or a game requesting contacts access. In Singapore, the PDPA's purpose limitation principle says the app can only collect data necessary for its function. A calculator has no function that requires your contact list.
Photo library access is similarly broad. The app can read every photo and video on your device, including metadata known as EXIF data that can reveal the GPS coordinates where a photo was taken, the device model, and the date and time. A legitimate use is a photo-editing app you are actively using to edit a specific image. A red flag is a messaging app that requests access to your entire library rather than letting you pick individual photos. Deny full library access and grant limited access on iOS, or block it outright on the Google OS until you are using the feature.
Background App Refresh, Advertising Identifier, And App Tracking Transparency
Background App Refresh
Background App Refresh allows an app to fetch data and run processes when it is not open. A legitimate use is a messaging app that needs to receive messages in real time. A red flag is any app that does not need to update content in the background: games, utilities, media players. Deny background refresh to every app by default, then enable it only for apps that genuinely need it. On iOS, go to Settings > General > Background App Refresh. On the Google OS, go to Settings > Apps > [App Name] > Data usage > Background data.
Advertising Identifier And Tracking
The advertising identifier is a unique device ID used by advertisers to track your behaviour across apps and websites. On iOS, the App Tracking Transparency framework requires apps to request your agreement before tracking you across other companies' apps and websites. On the Google OS, you can reset or opt out of the advertising ID in Settings > Google > Ads. The PDPA does not specifically regulate advertising identifiers, but the consent and purpose limitation principles apply. An app that collects the advertising identifier without telling you what it is used for may be in breach.
Permission creep is the gradual expansion of privileges an app requests over time. An app that originally asked only for camera access may later request microphone, whereabouts, and contacts in an update. Review your settings regularly. Every three months is a good interval. The Google OS auto-reset feature helps, but it only revokes access for unused apps, not for apps you use frequently. On iOS, you must manually review settings in Privacy & Security.
How PDPA Consent And Purpose Limitation Obligations Apply To App Permissions
The Personal Data Protection Act's consent obligation requires organisations to get your agreement before collecting, using, or disclosing your personal data. The purpose limitation obligation requires that the data collected is necessary for the stated purpose. An app that collects whereabouts data to serve ads, when its stated purpose is photo editing, is likely in breach. The PDPC has published advisory guidelines stating that organisations should design apps to request only the privileges necessary for functionality and explain why each one is needed.
In practice, this means you can block any access that does not match the app's core function. If an app refuses to work without an irrelevant privilege, that is a red flag. The PDPA also includes a deemed consent provision: if you voluntarily provide personal data for a purpose and it is reasonable to do so, agreement may be deemed. But an access request is not deemed consent. You must actively grant it. The maximum penalty for a PDPA breach is 10% of annual turnover in Singapore or SGD 1 million, whichever is higher. That is a strong incentive for organisations to comply, but it does not replace your own scrutiny.
What To Do When An App Violates PDPA Principles
If you suspect an app is collecting data beyond its stated purpose, file a complaint with the PDPC. The commission publishes enforcement decisions on data breaches, and these decisions are public. You can also report scam-related app behaviour to the Singapore Police Force Anti-Scam Command at 1800-722-6688 or forward suspicious messages to the ScamShield Bot on WhatsApp. The National Anti-Scam Centre hotline is 1800-722-6688, and the anti-scam helpline for reporting phishing attempts is 1799, available 24/7.
Smartphone Privacy Settings Walkthrough: A Step-By-Step Routine For Singapore Users
Run this repeatable process once a quarter. Open your permissions manager on iOS or the Google OS and review every app. Start with location, then microphone, then camera, then contacts, then photos. For each app, ask: does this app need this access to work? If the answer is no, block it. If the answer is maybe, block it anyway. You can always grant it later when you need the feature.
Using App Store Privacy Labels
On iOS, the privacy nutrition label in the App Store shows what data the developer says it collects. On the Google OS, the Play Store data safety section does the same. These are self-reported, so they are not guarantees, but they are a starting point. An app that claims to collect no data but requests multiple privileges is lying. An app that lists data collection for tracking purposes is telling you what it does. Believe it.
The failure case here is privacy resignation: the belief that because data breaches happen, there is no point managing access. That is false. The 2024 scam figures in Singapore show that a significant proportion of losses come from apps that exploited privileges the user granted without thinking. Blocking unnecessary access is the single most effective step you can take to reduce your exposure. The one thing that most often goes wrong is granting a privilege to an app you downloaded for a single use and then forgot about. Delete those apps, or at least revoke their access.
Common Questions
Should I deny location permission to every app?
No. Deny it to apps whose core function does not require it. Grant it to ride-hailing, navigation, and food delivery apps while you are using them. Revoke background access for all apps unless you have a specific reason.
What is the difference between iOS one-time and while-using permission?
One-time grants access only for the current session. When you close the app, it must ask again. While-using allows access whenever the app is open. For most apps, one-time is safer and sufficient.
Can an app access my microphone after I deny the permission?
No. The operating system blocks access. However, some apps may show a privacy indicator (orange dot on iOS) even after denial if a system process uses the microphone. That is normal and not the app accessing it.
What should I do if an app I use requests an unnecessary permission?
Deny it. If the app stops working, the access was likely necessary for its core function. If it continues working, the request was data harvesting. You can also report the app to the PDPC if you suspect a breach.