Your phone is the most intimate surveillance device you’ll ever voluntarily carry. It knows where you sleep, who you’re with, what you say near it, and what you do all day — and dozens of apps are quietly monetizing pieces of that. The good news: both iOS and Android now give you real controls. You just have to find and flip them. This is a one-time, thirty-minute audit. Do it once and you’ve shut off the biggest data faucets.

Work through your platform’s section below. The single highest-impact idea, on both: apps should get the least access that still lets them do their job, and nothing more.

iOS (iPhone)

Kill the advertising identifier

Settings → Privacy & Security → Tracking → turn off “Allow Apps to Request to Track.” This makes iOS deny cross-app tracking by default, app by app. Then Settings → Privacy & Security → Apple Advertising → turn off Personalized Ads.

Rein in location

Settings → Privacy & Security → Location Services. Go through the list app by app:

  • Set anything that doesn’t truly need location to Never or Ask Next Time.
  • For apps that need it only while you’re using them, choose While Using, never “Always.”
  • Turn Precise Location off for apps that only need your rough area (weather, news). They get a fuzzy location instead of your exact coordinates.
  • Scroll to System Services at the bottom and turn off Significant Locations history and the location-based ad/suggestion toggles.

Audit sensor and data access

Still under Privacy & Security, walk through Camera, Microphone, Photos, Contacts, and Local Network. Revoke anything that looks wrong — a game does not need your contacts, a flashlight app does not need your microphone. For Photos, prefer Limited Access (you pick which photos an app sees) over full library access.

Turn off the data-sharing extras

  • Settings → Privacy & Security → Analytics & Improvements → turn off Share iPhone Analytics.
  • Settings → Safari → turn on Prevent Cross-Site Tracking and Hide IP Address from Trackers.

Apple’s defaults are better than Android’s, but “better” still leaves personalized ads and location history on unless you turn them off.

Android

Android varies by manufacturer (Samsung, Pixel, etc.), so menu names differ slightly — search Settings for the keywords if a path doesn’t match.

Reset and limit the advertising ID

Settings → Privacy → Ads (or search “Ads”). Delete advertising ID entirely if your version offers it — that’s the strongest option and stops apps from using a stable ad identifier at all. Otherwise, Reset it and turn off ad personalization.

Rein in location

Settings → Location → App location permissions. For each app:

  • Choose Allow only while using the app or Ask every time; avoid Allow all the time.
  • Turn off Use precise location for apps that only need your general area.

Then turn off Location History (Timeline) and Location Sharing under your Google account, and set auto-delete for any history you leave on. More on cutting Google specifically in the de-Google guide.

Audit the permission manager

Settings → Privacy → Permission manager. This groups every permission (Camera, Microphone, Contacts, Physical activity, Files) with the list of apps that have it. Go category by category and revoke anything that doesn’t make sense. Watch especially for Microphone and Camera access on apps that have no reason for it.

Cut the telemetry and extras

  • Turn off Usage & diagnostics under Settings → Google → (your account) → Manage → Data & privacy.
  • Disable Web & App Activity in the same area (auto-delete what remains).
  • If your manufacturer runs its own analytics program (Samsung’s “Customization Service,” etc.), turn those off too.

Both platforms: the habits that matter more than settings

  • Uninstall apps you don’t use. Every app is a data-collection endpoint. The single most effective phone-privacy move is having fewer apps. Use the website in your browser instead when you can — it usually collects far less than the app.
  • Prefer the mobile web for one-off needs (checking a menu, a store, a schedule). No install, no background access, no push-notification tracking.
  • Say no to notification and “improve our services” prompts during setup. Those are data-collection opt-ins dressed up as features.
  • Review new apps’ permissions at install and again a month later — apps sometimes request more over time.

Don’t forget the lock screen and backups

Privacy from corporations is one thing; privacy from someone who grabs your phone is another. While you’re in Settings:

  • Use a strong passcode (six+ digits, or alphanumeric), not a four-digit PIN or an easily-shoulder-surfed pattern.
  • Turn on automatic device encryption (on by default on modern iOS and Android, but confirm it).
  • Make sure your cloud backup is encrypted — enable Advanced Data Protection on iCloud, or a strong password on your Google/Android backup.

Recheck after big updates

Major OS updates occasionally reset or introduce settings, and new apps arrive constantly. Put a reminder on your calendar to redo this audit once or twice a year — it takes five minutes the second time. When you’ve finished today’s pass, tick it off in the privacy checklist.