The Quiet Ways Apps Track You Even When You're Not Using Them
Background data collection is more common than most people realise. Here's what's actually happening and how to limit it without deleting everything.
Key takeaways
- Apps can collect data even when you are not actively using them, depending on the permissions you have granted.
- Location, microphone, and contact access are among the most commonly misused background permissions.
- Both iOS and Android give you tools to review and restrict what each app can do in the background.
- Revoking a permission does not always mean deleting the app; most apps still function with limited access.
- Third-party SDKs inside apps can transmit data independently of the app developer's own code.
What is actually happening in the background
When you download an app and tap 'allow' on permission requests, you are granting access that can persist long after you close the app. Most of that activity is mundane: an email client checking for new messages, a calendar syncing with a server. But some of it is not mundane at all.
Many apps include third-party code called SDKs, built by advertising networks, analytics companies, or data brokers. When the app runs any background process, that SDK can also run, collecting device identifiers, behavioral patterns, or location data and sending it to servers you have never interacted with. The app developer may have agreed to include that code in exchange for revenue, but you never see that arrangement.
Your everyday digital habits generate far more data than most people expect, and background collection is a large part of why.
iOS and Android handle this differently
Apple introduced App Tracking Transparency in 2021, which requires apps to ask before tracking you across other companies' apps and websites. Android's approach relies more on manual permission management rather than a system-level prompt. Both systems have improved over time, but neither automatically prevents all background data collection. The controls described in this article apply to both platforms, though the exact menu paths differ.
The permissions that matter most
Not all permissions carry the same risk. Location is the most commercially valuable piece of data an app can collect. An app with always-on location access builds a detailed record of where you live, work, shop, and sleep. That data is legally sold to brokers in most US states. For a full picture of how that process works, see how location data gets collected and sold.
Microphone and camera access are a close second in terms of sensitivity. A few categories of apps, such as voice assistants and video callers, genuinely need them. Many others, such as retail apps or flashlight utilities, have no legitimate reason to request them at all.
Contact access is less discussed but equally problematic. When an app reads your contacts, it gets data about people who never agreed to share anything with that app.
Background refresh, the ability for an app to wake itself up and run while you are not using it, is the mechanism that ties this all together. Without it, most passive tracking would not be possible.
What you can do right now
The fastest first step is a permission audit. On iPhone, open Settings, go to Privacy and Security, and work through each category. Location Services shows every app that has location access and at what level. Change anything set to 'Always' to 'While Using' unless you have a specific reason to keep it. On Android, the same audit lives in Settings under Privacy, then Permission Manager.
Turn off background app refresh for apps you do not need to update in real time. On iPhone this is in Settings, then General, then Background App Refresh. On Android, go to each app's settings and restrict background activity or battery use.
Check for apps you rarely open. An app you have not touched in months may still have live permissions and active background processes. Deleting unused apps removes that surface area entirely. The app audit checklist is a good framework for identifying what is worth keeping.
For a more thorough walkthrough of the settings that have the biggest impact, your phone's privacy settings covers the changes that matter most without requiring technical knowledge.
The limits of what you can control
Permission controls reduce passive tracking but do not eliminate it. Apps can still collect data that does not require explicit permission, including the type of device you use, your network information, and behavioral patterns within the app itself. Some of this collection is disclosed in privacy policies, which few people read in full.
Advertising identifiers, called IDFA on iPhone and GAID on Android, let networks link your activity across multiple apps without knowing your name. Apple lets you reset or limit ad tracking in Settings under Privacy and Security, then Tracking. Android has a similar option under Privacy in Settings.
No single action gives you complete control. A combination of permission management, selective app deletion, and a habit of questioning new permission requests gets you meaningfully closer to limiting what is collected about you passively.
Frequently Asked Questions
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.