Privacy Settings You Should Change on Your Phone Today
A guide to locking down your smartphone
Sarah Jenkins
Security Lead
Smartphones are the most intimate tracking devices in human history. Operating systems and third-party applications continuously collect telemetry, location coordinates, biometric signatures, and behavioral profiles. While hardware manufacturers advertise their security features, default settings are optimized to harvest data for advertising and diagnostic networks. Regaining control of your personal information requires disabling these default options. This guide outlines the crucial phone privacy settings to change immediately, enabling you to conduct a comprehensive smartphone data privacy lockdown by navigating the complex ios android tracking settings panels.
1. Location Services: Disabling Background Tracking and Significant Locations
Location services are the primary source of personal profiling. Apps do not just track where you are when you use them; they construct a spatial timeline of your daily habits, relationships, and medical visits. To restrict this exposure:
- Precise vs. Approximate Location: Most apps (like weather, food delivery, or social media networks) do not need to know your exact coordinate down to the meter. Toggle off "Precise Location" in app settings, forcing them to use approximate regional data instead.
- Background Access: Set location access to "Only While Using the App" or "Ask Next Time". Never allow an app to access your location "Always" unless it is a dedicated navigation tool.
- Significant Locations & Location History: Both iOS and Android compile a list of places you visit frequently to generate predictive notifications. On iOS, navigate to
Settings > Privacy & Security > Location Services > System Services > Significant Locationsand clear the history, then disable the feature. On Android, access your Google Account settings, locate "Location History" (Timeline), and pause the tracking.
"Allowing background location access to non-essential applications is equivalent to wearing a GPS ankle monitor voluntarily. The data is sold through brokers to advertising networks and law enforcement agencies alike."
2. Auditing App Permissions: Bluetooth, Local Network, and Contacts
Modern application permissions have expanded beyond basic camera and microphone access. Attacking vectors now leverage secondary sensors to circumvent standard privacy walls:
Bluetooth Beacons
Retail stores and public venues deploy Bluetooth beacons that broadcast unique identifiers. If an app has Bluetooth permission, it can scan for these beacons, identifying your precise location inside a mall or store even if you have disabled GPS location tracking. Review your app permissions and disable Bluetooth access for any application that does not require it for hardware connection (like wireless headphones).
Local Network Access
Many apps request permission to scan your Local Network. While legitimate for smart-home utilities, other applications use it to map the devices connected to your home Wi-Fi. By identifying your smart TVs, gaming consoles, and smart plugs, trackers build a unique network fingerprint that links your mobile device to your home address and roommates.
Contacts and Photo Library
Avoid giving applications full access to your Contacts list. When you upload your address book, you are sharing the names, phone numbers, and email addresses of your friends and colleagues without their consent. Utilize the "Select Photos..." permission on newer OS versions to only grant access to specific images rather than your entire photo database.
3. Resetting and Disabling Advertising Identifiers
To deliver targeted ads, operating systems assign a unique tracking token to your device: the Identifier for Advertisers (IDFA) on Apple devices and the Google Advertising ID (GAID) on Android. Apps read this token to build a unified profile of your behavior across different platforms.
To disrupt this tracking loop:
- On iOS: Go to
Settings > Privacy & Security > Trackingand toggle off "Allow Apps to Request to Track". This blocks applications from reading your IDFA, returning a string of zeros instead. - On Android: Navigate to
Settings > Privacy > Ads(orSettings > Google > Ads). Tap "Delete Advertising ID". This completely removes the identifier, preventing apps from stitching your cross-app actions together.
Smartphone Privacy Controls: iOS vs. Android Comparison
The table below provides a comparative analysis of the primary privacy mechanisms available on Apple iOS and Google Android platforms, evaluating the default states, configuration steps, and security scope of each control.
| Privacy Control | Apple iOS Setting Location | Google Android Setting Location | Security Target |
|---|---|---|---|
| Ad Identifier Restriction | Privacy & Security > Tracking (Opt-in by default) | Settings > Google > Ads > Delete Advertising ID | Prevents cross-app profiling and target ad matching. |
| Approximate Location | Privacy > Location Services > Toggle "Precise Location" | Settings > Location > App Permission > Use Precise Location | Reduces coordinate tracking accuracy from meters to miles. |
| Local Network Access | Privacy & Security > Local Network | Not isolated (Handled via generic network permission) | Prevents mapping of home devices and household grouping. |
| App Telemetry / Analytics | Privacy & Security > Analytics & Improvements | Settings > Google > three dots > Usage & diagnostics | Stops OS manufacturers from collecting usage statistics. |
4. Hardening Network Privacy and Diagnostics Telemetry
Even with app permissions locked down, your phone continues to transmit metadata through the networks you connect to. To secure these communication channels:
Configure Private DNS
By default, your mobile service provider or public Wi-Fi router resolves your web requests, allowing them to compile a history of every domain name you visit. By configuring a Private DNS provider that supports DNS-over-TLS (DoT) or DNS-over-HTTPS (DoH), such as Cloudflare or Quad9, you encrypt these lookup requests. On Android, search for "Private DNS" in network settings and input a secure hostname (e.g., one.one.one.one). On iOS, you can install an encrypted DNS profile or use dedicated secure browser configurations.
Disable System Diagnostics Telemetry
Both Apple and Google collect usage and diagnostics telemetry. This includes crash logs, app load times, battery statistics, and search queries. While supposedly anonymized, this telemetry is linked to device hardware IDs and can be associated with your identity. Turn off "Share iPhone & Watch Analytics" (on iOS) or "Usage & diagnostics" (on Android) to block these automatic transmissions.
Frequently Asked Questions
Will changing my phone's privacy settings impact its performance?
No. Restricting background location tracking, disabling telemetry, and removing app permission rights actually improves battery life and reduces system resource utilization, as apps are prevented from running continuous tracking processes in the background.
What is the difference between precise and approximate location permissions?
Precise location permission uses GPS, Wi-Fi networks, and cellular towers to pinpoint your exact coordinates within a few meters. Approximate location uses cell tower data to estimate your position within a larger regional radius (typically a few square miles), protecting your specific address.
Does deleting my Advertising ID delete the profile Google has of me?
Deleting your Advertising ID prevents apps from reading a unique tracking identifier to match your activity. It stops new data from being added to your profile via that ID, but it does not delete historical search histories or profile data stored on Google's servers. You must log in to your Google Account and clear your history dashboard to delete that data.
Why do apps ask for Bluetooth permission if they do not connect to devices?
Many apps request Bluetooth permission to scan for public Bluetooth beacons located in retail outlets, airports, and billboards. By identifying which beacons are nearby, the app can calculate your precise indoor location for targeted advertising without relying on GPS access.
Is iOS more private than Android by default?
Out of the box, iOS offers stricter privacy boundaries, such as App Tracking Transparency (opt-in tracking prompts) and isolated Local Network controls. Android, being deeply integrated with Google's advertising business, requires more manual configuration to disable tracking networks, though it offers robust settings if configured correctly.
Conclusion
Securing your smartphone is not a single setting, but an ongoing audit process. By disabling background location services, removing unnecessary app permissions, deleting advertising identifiers, and encrypting your DNS traffic, you can transition your mobile device from an active surveillance tool to a secure, private communication terminal. Review these configurations quarterly to ensure system updates do not restore default permissions.
Enjoyed this read?
Get monthly updates on privacy engineering and web performance straight to your inbox.