7 Phone Privacy Settings Most Indians Have Never Opened and Should Change Today
Microphone Access: The Permission You Gave Every App
Open your phone's app permissions list and count how many apps have microphone access. On most Indian users' phones, the number is between eight and fifteen, and at least half of those apps have no reason to ever record audio. Shopping apps, utility apps, games. The microphone permission exists for voice calls and voice search. Everything else is optional at best, and you can revoke it without breaking the app's core function. On Android: Settings -> Privacy -> Permission Manager -> Microphone. On iOS: Settings -> Privacy & Security -> Microphone. Go through the list. Toggle off anything that isn't a calling or recording app. If an app stops working without it, you'll know immediately, and then you can decide whether that tradeoff is worth it.
Precise Location vs Approximate Location
Most people know they've given location access to certain apps. Fewer know there's a middle setting between "always on" and "never", and it's the most useful one. Approximate location shares a general area (roughly a 3-kilometre radius) without pinpointing your exact address. A weather app doesn't need to know which floor of your building you're on. A food delivery app needs your address only when you're placing an order, not running in the background all day. On Android 12 and above, and iOS 14 and above, you can switch any app from precise to approximate location. On iOS: Settings -> Privacy & Security -> Location Services -> tap each app -> select "Approximate Location." On Android: Settings -> Location -> App Permissions -> tap the app -> toggle "Use precise location" off. Do this for every app that isn't navigation or a cab service.
Ad Tracking and Personalised Ads
Both Google and Apple give you a setting to limit how advertisers build a profile from your behaviour. Apple's App Tracking Transparency, introduced with iOS 14.5, requires every app to ask permission before tracking you across other apps and websites. If you said yes to any of those prompts without reading them, you can reverse those decisions. On iOS: Settings -> Privacy & Security -> Tracking -> toggle "Allow Apps to Request to Track" off. On Android, Google's equivalent lives at Settings -> Google -> Ads -> "Delete advertising ID." Deleting the advertising ID doesn't stop ads, it stops personalised tracking. You'll still see ads; they just won't follow you from a Flipkart search into a news app twenty minutes later.
Clipboard Access
Every time you copy something, a password, a UPI PIN, a bank account number, an OTP, it sits in your clipboard. On iOS 14 and above, Apple added a notification that appears whenever an app reads your clipboard without you pasting anything into it. Several major apps were caught doing this, including TikTok and LinkedIn, after the notification exposed the behaviour. The fix on iOS is passive: the notification tells you when it's happening, and you can then decide whether to keep the app. On Android, clipboard access is less transparent, but Android 12 introduced a similar notification. Check your clipboard history settings at Settings -> General Management -> Clipboard on Samsung devices. Clear it regularly. Never copy a password and then open an unrelated app before pasting it.
Lock Screen Notifications
This one costs nothing and takes thirty seconds. By default, most phones show the full content of notifications on the lock screen, which means anyone who picks up your phone sees your OTPs, your bank alerts, your messages. The setting is under Notifications on both platforms. On iOS: Settings -> Notifications -> Show Previews -> select "When Unlocked." On Android: Settings -> Notifications -> Sensitive Notifications, or on Samsung, Settings -> Lock Screen -> Notifications -> select "Hide content." The phone still shows you that a notification arrived. It just doesn't display what it says until you've unlocked the screen. Given how often phones are left on desks, in autos, or handed to someone to make a quick call, this is the most underused security setting on any Indian user's device.
Google Account Activity Controls
Google stores a detailed log of everything you search, every YouTube video you watch, every place you visit with location history on, and every voice command you've made to Google Assistant. This data is stored in your Google account, not just on your device, which means it survives a phone reset. Go to myactivity.google.com. You'll see a timeline that may go back years. Under "Data & Privacy" in your Google account settings, you can turn off Web & App Activity, Location History, and YouTube History individually. You can also set auto-delete to 3 months, so the data doesn't accumulate indefinitely. Most Indian users who check this page for the first time are surprised by how granular the record is, not just search terms, but the exact second each search happened, the device used, and the IP address.
Background App Refresh and Mobile Data Access
Apps that run in the background aren't just draining your battery, they're sending and receiving data when you're not using them. On iOS: Settings -> General -> Background App Refresh. Turn it off globally, or selectively for apps that don't need real-time updates. On Android: Settings -> Apps -> select the app -> Mobile Data & Wi-Fi -> toggle "Background data" off. The practical effect: a news app you opened three days ago stops pinging its servers every few minutes. A shopping app stops refreshing your browsing history in the background. This setting doesn't prevent the app from working when you open it. It only stops the app from doing things while your screen is off and you're not watching. Chanakya wrote in the Arthashastra that an unguarded resource is an invitation, the principle applied to statecraft, but the logic holds for data: what runs unobserved operates without accountability.
The seven settings above each address a different entry point, audio, location, identity, clipboard, visibility, history, background activity. But they share a single mechanism: permissions granted once, during setup or in a moment of impatience, that continue running indefinitely without a second prompt. Your phone never asks again. It only asks the first time.