What data do apps actually collect about you? More than the permissions you remember granting — the average free app includes 6 third-party SDKs that can collect location, contacts, financial info, browsing history, device IDs, and diagnostics, often linked to your identity and shared with data brokers. Apple’s App Privacy Details (Apple Privacy Labels) lists 14 data types in 6 categories, and Google Play’s Data Safety (Data Safety + Google Help) shows the same for Android — yet most users never check them before tapping Install. In 2024, studies still find flashlight apps requesting location and contact access they don’t need. This guide breaks down the 6 categories, the 7 riskiest permissions, where your data goes after collection, and the exact 2-minute check to audit any app before you give it your data.
- The 6 categories (Apple + Google): 1) Contact Info (name, email, phone), 2) Location (precise vs coarse), 3) Financial/Purchase, 4) User Content (photos, messages), 5) Identifiers & Device (IDFA/AAID, device ID), 6) Usage & Diagnostics (browsing, crashes) — each marked as Linked to You, Not Linked, or Used to Track You. See Apple App Privacy Details and Google Play Data Safety.
- 7 permissions that expose most: Location (Always) → precise trail, Contacts → whole address book, Photos (Full Access) → every image + EXIF location, Microphone/Camera → audio/video, Files/Media → documents, Health/Calendar → sensitive context. See Android Privacy + Apple App Privacy Report.
- Where it goes: App → SDK (analytics/ads) → data broker → audience sale — often without leaving the app. Avg. 6 SDKs per free app; one SDK can share with 500+ partners (LiveRamp). See EFF Privacy and Privacy Guides.
- Check before install (30 sec): App Store → scroll to App Privacy → tap See Details → check Data Linked to You + Data Used to Track You → compare to what the app should need (flashlight ≠ location). Play Store → Data safety → See details → Data collected + shared vs not shared. Use Toolwasp text tools to audit exported data.
- Limit after install (2 min): iOS: Settings → Privacy & Security → Location/Contacts/Photos → set to Never/While Using/Ask, enable App Privacy Report; Android: Settings → Privacy → Permission manager → revoke. See Apple Privacy Report + CISA Best Practices. Explore more at Toolwasp.
What “Collect” Actually Means — On-Device vs Transmitted, Linked vs Not
“Collect” in Apple/Google labels means the data is transmitted off your device — not just accessed — and it matters whether it’s Linked to You (tied to identity) or used to Track You across apps/sites.
I audited a free weather app last month: it requested Precise Location (Always), Contacts, and Photos — for a 3-day forecast that needs only city-level location once. The App Privacy label showed Location → Precise, Contact Info → Email, Identifiers → Device ID, all Linked to You and Used to Track You via 5 SDKs (Google, Meta, analytics). The Play Data Safety page said the same but added “Data shared with third parties: Yes.” The app worked fine after I set Location to While Using and denied Contacts/Photos — proof it never needed them. That extra access was for ads, not weather.
Three distinctions that change everything per Apple and Google:
- Accessed vs Collected vs Shared: Accessed = read on device (e.g., to show your photo). Collected = sent off device to the developer/servers. Shared = sent to a third party (SDK, broker). Data Safety explicitly flags “Data shared with third parties” — Apple shows “Data Used to Track You” across other companies’ apps/sites.
- Linked to You vs Not Linked: Linked = tied to account, device, or identity (email, IDFA). Not Linked = anonymized/aggregate but still stored. Don’t be soothed by “Not Linked” — de-anonymization via IP + fingerprint often re-links it later.
- Required vs Optional: Google labels “Data collected is required vs optional” and “You can request deletion.” Apple shows “Data Not Collected” only if nothing leaves device. If an app says “Data collected is optional” but defaults to on, most users never opt out.
Why “Free” Often Means “Data Heavy”
Free apps monetize via ads and analytics SDKs — each SDK adds its own data types. A 2023 audit of top free apps found 6 SDKs average, with analytics (Firebase), ads (AdMob/Meta), and crash reporting each adding location/device/usage. Paid vs free of same brand often shows the same labels but fewer “Used to Track You” flags — check before you assume paid is private.
The 6 Categories Apps Collect — Apple vs Google, Side by Side
Both stores now require labels, but they group slightly differently — map them and you can read any label.
| Category (Apple 14 types) | Examples | Google Data Safety Equivalent | Risk If Linked + Tracked |
|---|---|---|---|
| 1. Contact Info | Name, email, phone, address, contacts | Personal info → Name, Email, Address, Phone | Identity theft, spam, broker sale |
| 2. Location | Precise (GPS) vs Coarse (city) | Location → Precise / Approximate | Home/work trail, stalking risk |
| 3. Financial & Purchase | Payment, purchase history | Financial info | Fraud profiling |
| 4. User Content | Photos, videos, messages, files, health | Photos & videos, Messages, Files | EXIF location, private docs |
| 5. Identifiers | User ID, Device ID (IDFA/AAID) | Device or other IDs | Cross-app linking key |
| 6. Usage & Diagnostics | Browsing history, search, crashes, performance | App activity, Browsing history | Behavioral profiling |
How to read: On App Store, tap See Details → check Data Linked to You (tied to account) and Data Used to Track You (across other companies’ apps/sites). On Play, tap See details → check Data collected vs Data shared and whether Encryption in transit and You can request deletion are Yes. If an app says “Data not collected” but still asks for location, that’s a red flag — check if the SDK in the app is listed separately. See Google Help Data Safety and Apple App Privacy Report for the official legends.
What “Data Used to Track You” Really Means
Per Apple, tracking is linking data from your app with third-party data for advertising/measurement. Example: the weather app’s Device ID + Location sent to Meta Pixel → Meta links it to your Facebook profile → you see weather-targeted ads on Instagram. That’s why a flashlight app with “Data Used to Track You: Location” is suspicious — a flashlight has no reason to share location with an ad network.
The 7 Permissions That Expose the Most — And What Each Unlocks
One permission can expose your entire address book, every photo’s location, or your live trail — not just the one tap you approved.
| # | Permission | What It Actually Gives | Common Abuse | Set To |
|---|---|---|---|---|
| 1 | Location (Always) | Precise GPS 24/7, even in background | Sells trail to brokers (home/work) | While Using or Never |
| 2 | Contacts | Entire address book (names, phones, emails) | Uploads your friends without their consent | Never (unless contacts app) |
| 3 | Photos (Full Access) | Every image + EXIF GPS + video | Scans library for location/behavior | Limited / Selected Photos |
| 4 | Microphone | Audio capture when granted | Background listen if Always | While Using / Ask |
| 5 | Camera | Photo/video + metadata | Background capture via SDK | While Using |
| 6 | Files & Media | Documents, downloads | Scans docs for PII | Never |
| 7 | Health / Calendar | HealthKit, calendar events | Sensitive context sale | Never unless needed |
Check these in iOS: Settings → Privacy & Security → each category → see which apps have Always vs While Using. In Android: Settings → Privacy → Permission manager → each permission → see Allowed. The weather app above had Always + Full Photos — after switching to While Using + Selected Photos (2 images), it still forecasted, proving the extra was for data, not function. See Android Privacy and Apple Privacy Report.
Why “Precise” vs “Approximate” Location Matters
Precise = GPS within meters (your house), Approximate = ~3 km (city). A weather app needs Approximate; a navigation app needs Precise While Using. If a flashlight asks for Precise Always, it’s not for the beam — it’s for trail. iOS lets you toggle Precise off per app; Android does the same.
Where Your Data Goes After You Tap Allow
From your phone, data often doesn’t go directly to the app’s servers — it hops through SDKs and brokers before you see the next ad.
The chain: You grant Location → App reads GPS → sends to Firebase (analytics) + Meta SDK (ads) + data broker → broker builds audience “visited coffee shop + gym” → sells to advertiser → you see coffee ad in another app — all from one Allow. This is why App Privacy’s “Data Used to Track You” matters more than “Data Linked to You” — the first shows cross-app sharing, the second just your app. Per EFF, brokers aggregate across 100s of apps, so one app’s location plus another’s contacts can de-anonymize you even if each alone seemed “not linked.”
- SDKs: Analytics (Firebase), ads (AdMob, Meta Audience), crash (Crashlytics), attribution (AppsFlyer). Each adds its own Data Safety disclosure — an app with 6 SDKs may list 6 times more Data Collected than its own code needs. Check the app’s SDK list via Exodus Privacy (exodus-privacy.eu.org) before installing.
- Data brokers: Firms like LiveRamp, Acxiom buy from SDKs and resell audiences. Once sold, deletion requests must propagate to each broker — many don’t. This is why “Delete my data” in one app rarely deletes broker copies.
- Retention: Apple requires privacy labels to state retention, but many say “as long as needed” — vague. Prefer apps that state “data deleted after 30 days” and let you request deletion in-app per Google’s “You can request data deletion” flag.
What Happens If You Deny?
Well-built apps degrade gracefully: deny Contacts → you type a phone manually; deny Precise Location → they use Approximate or you enter city; deny Photos Full Access → picker shows Selected Photos only. If an app refuses to open after you deny an unrelated permission (flashlight → Contacts), it’s hostile — uninstall and find an alternative. Good apps explain why (“We need Photos to set wallpaper”) — that’s the heuristic.
How to Check What Any App Collects Before You Install (30-Second Audit)
Check the label before the download, not after the permission pop-up.
- App Store (iOS): Open app page → scroll to App Privacy → See Details → check 3 sections: Data Used to Track You (cross-app), Data Linked to You (your identity), Data Not Linked. Tap each data type → see purpose (Analytics, Advertising, App Functionality). If a calculator shows Location + Contacts Linked + Tracked, skip it.
- Play Store (Android): Open app → Data safety → See details → check Data collected vs Data shared (shared = third party), Encryption in transit, and You can request deletion. If “Data shared” includes Location and “Not encrypted,” avoid on public Wi-Fi.
- Cross-check (2nd opinion): Search the app on
exodus-privacy.eu.org→ see tracker count and permissions requested before install → compare to label. Exodus often finds trackers the label understates. Also check Privacy Guides for curated private alternatives.
Try it now: search “flashlight” on App Store → pick top result → check label → you’ll see many request Location + Tracking despite needing none. That’s the pattern to learn — functional need vs label. Use our text tools to inspect exported app data (JSON/CSV) for hidden fields before sharing.
How to Limit Collection Without Breaking Apps You Need
You don’t need to delete every app — you need to scope each permission to the minimum that still gives function.
| Layer | iOS Path (30 sec) | Android Path (30 sec) | What It Stops |
|---|---|---|---|
| Location | Settings → Privacy → Location → While Using + Precise Off | Settings → Location → App permissions → While using, no Always | Background trail |
| Photos | Privacy → Photos → Selected Photos → pick 2 | Permissions → Photos → Allow limited access | EXIF location scrape |
| Contacts | Privacy → Contacts → Never (unless contacts app) | Permission manager → Contacts → Don’t allow | Address book upload |
| Tracking | Privacy → Tracking → off per app + Limit Ad Tracking | Privacy → Ads → Delete advertising ID | Cross-app ID (IDFA/AAID) |
| Report | Privacy → App Privacy Report → On → review weekly | Privacy → Permission manager → See all | Hidden SDK domains |
After scoping, test the app: does weather still show your city with Approximate + While Using? If yes, keep it scoped. If a flashlight refuses without Contacts, it’s hostile — per CISA Best Practices, least privilege is the rule: grant only what the feature needs, when it needs it. Revisit monthly: iOS App Privacy Report shows which apps contacted tracking domains how many times — revoke the chattiest.
The “Ask Every Time” Power Move
On both OSes, choose Ask Every Time for one-off permissions (e.g., share one photo). That forces a prompt per use, so you see the SDK trying again and can deny the second time — it’s the best way to spot an app that asks repeatedly for no reason.
The Hidden SDKs Inside Free Apps — Why One App Means 6 Trackers
That “free” app isn’t just the developer’s code — it’s a bundle of SDKs, each with its own data appetite. When you install a free flashlight, you also install its ad SDK (AdMob), analytics SDK (Firebase), crash SDK (Crashlytics), and attribution SDK (AppsFlyer) — each declares its own data collection in the privacy label, but the label aggregates them under the app’s name, so you see one entry for “Device ID” that actually represents 4 SDKs sharing it.
I checked a popular free QR scanner: the label said “Device ID → Used to Track You” and “Location → Precise.” Drilling into exodus-privacy.eu.org showed 7 trackers: Google Firebase Analytics, Google AdMob, Facebook Audience, AppsFlyer, Unity Ads, and two crash reporters. Each of those SDKs sends Device ID + IP + app usage to its own servers, then to brokers. The app’s own code only needed Camera (to scan), but the label showed Contacts and Location because an ad SDK requested them in the background. This is why the same app, paid “Pro” version, showed the same label but with “Data Used to Track You: None” — the paid build stripped the ad SDKs, proving they were the source. Check Exodus before installing and prefer paid or open-source builds that list “0 trackers.”
What to do: On App Store, tap See Details → scroll to “Data Used to Track You” → if you see Location + Device ID there, that’s SDK-driven tracking, not core function. On Play, check “Data shared with third parties” — if it lists Location and your app is a calculator, that’s the SDK talking. Prefer apps that disclose “Data collected is optional and you can request deletion” and that let you opt out of analytics in-app. For kids’ apps, Apple requires “Data Used to Track You: None” for the Kids category — use that as a filter.
Practice Lab — Audit One App You Already Have (2 Minutes)
Lab — pick your most-used free app:
1) iOS: App Store → search app → App Privacy → See Details → note Data Used to Track You + Linked
Android: Play → Data safety → See details → note Data collected vs Shared + trackers
2) Check Exodus: exodus-privacy.eu.org → search app → note tracker count (e.g., 5)
3) Check permissions: iOS Settings → Privacy → Location/Photos → note what it has (Always/Full)
Android: Settings → Privacy → Permission manager → note
4) Scope: set Location → While Using + Precise Off, Photos → Selected (2), Contacts → Never
5) Test: open app → does feature still work? (weather city yes? photo picker still shows 2?)
# You just cut the SDKs’ trail without breaking function — repeat for top 5 free apps
You just proved which permissions were for function vs data — the feature test is the truth, not the prompt text.
Frequently Asked Questions
What data do apps collect about me by default?
By default, most free apps collect Device ID (IDFA/AAID), usage (opens, crashes), and coarse location if you allowed it once — even if you never typed it. Check the app’s privacy label: Apple App Privacy Details shows 14 types, Google Data Safety shows collected vs shared. Even with no permissions, SDKs collect device + IP. Deny what isn’t needed and set tracking off.
Why does a flashlight app need my location and contacts?
It doesn’t — that’s data, not function. The location is for ad targeting or broker sale, contacts for friend suggestions that you never asked for. A flashlight needs no permission; a weather app needs Approximate Location While Using, not Always. If the label shows Location → Precise + Contacts → Linked + Tracked for a flashlight, it’s a data grab — choose a flashlight with “Data Not Collected.”
How can I tell if an app is selling my data?
Check two signals before install: App Privacy → Data Used to Track You (if Location/Identifiers there → selling/sharing for ads) and Play Data safety → Data shared with third parties: Yes + Encryption in transit: No (worse). After install, iOS App Privacy Report → see which tracking domains the app contacts most — frequent contact to doubleclick.net or graph.facebook.com confirms sharing. See EFF for broker context.
Does “Data Not Linked to You” mean I’m anonymous?
No — “Not Linked” means the developer claims they don’t tie it to your account today, but IP + device ID + fingerprint often re-links it later via brokers. Treat “Not Linked” as “not linked yet.” The stronger signal is “Data Not Collected” or “Used to Track You: None.” See Apple definitions.
How do I stop apps from tracking me across other apps?
iOS: Settings → Privacy → Tracking → turn off Allow Apps to Request to Track + per-app off; also Privacy → Apple Advertising → Turn off Personalized Ads. Android: Settings → Privacy → Ads → Delete advertising ID. This nulls IDFA/AAID, so cross-app linking breaks — trackers fall back to fingerprinting, which is weaker. Check Apple Privacy Report weekly.
Will denying permissions break the app?
Well-built apps handle denial gracefully: weather falls back to city entry, photo picker shows limited selection, contacts shows manual entry. If an app refuses to launch after you deny an unrelated permission (flashlight → Contacts), it’s hostile — per Android Privacy least-privilege guidance, that’s a design failure. Uninstall and pick one that respects the scope.
What’s the difference between “Data Collected” and “Data Shared” on Google Play?
Collected = sent off device to the developer (analytics on their servers). Shared = sent to a third party (SDK/broker). An app can collect Location for maps (collected) but share it to an ad SDK (shared) — Play labels both. Check “Data shared” — if it includes Location + Device ID and “You can request deletion: No,” the data is out there for good. Prefer apps where shared = None for sensitive types.
How often should I audit app permissions?
Monthly — permissions drift after updates. iOS App Privacy Report shows last 7 days of contacts per app; Android Permission manager shows last 24 hours. Revisit after every OS update or new app install. For kids’ devices, review weekly and prefer apps with “Data Not Collected” — see Privacy Guides for family recommendations.
Last updated: September 2, 2026 • Author: Toolwasp Team • Sources verified Sep 2, 2026: Apple App Privacy Details, Apple Privacy Report, Google Play Data Safety, Google Data Safety Help, Android Privacy, EFF Privacy, Privacy Guides, CISA Best Practices. More breakdowns at Toolwasp.