App permissions.
The question is never whether an app asks for something. It is whether the thing it asks for has anything to do with what it does.
Android permissions are the one part of the surveillance stack that is genuinely visible: they are declared in the manifest, listed on the store page, and prompted for at runtime. That visibility is also why they get ignored. A list of twenty entries in a settings screen reads as noise, and the prompt arrives at the moment you are trying to do something else.
The useful lens is fit. A messaging app reading contacts is doing its job. A cash register app asking for the same thing is not. Permission requests also accumulate: features get added, SDKs bring their own requirements, and nothing ever gets removed because removing access is invisible to users and risky for the developer. Bloatware shipped by the manufacturer is the extreme end of this, since those packages are preinstalled with permissions already granted and often cannot be removed at all.
Everything filed under permissions
The Preinstalled Apps You Can Actually Delete (and the Ones That Will Break Your Update Path)
Not all preinstalled apps are bloatware. Here's how to tell which of the 40+ system apps on your phone are safe to remove, disable, or leave alone.
The McDonald's App Asks for 23 Permissions. A Cash Register Needs Zero.
McDonald's app requests 23 Android permissions to sell you a burger. We break down what each one actually does and why fast food needs your location.
The Permission Creep Problem: Apps Request 40% More Access Than They Did Three Years Ago
Apps now request 40% more permissions than in 2023. Why developers over-permission, what it costs users, and how to fight back without deleting everything.
Xiaomi Ships 71 System Apps You Didn't Ask For and Can't Remove
Xiaomi devices come preloaded with 71 system apps on average. Most collect data, many display ads, and you can't uninstall them without root access.
Samsung ships 47 preloaded apps and you can't delete most of them
Samsung Galaxy phones come with 47 preinstalled apps on average. 31 can't be uninstalled. Here's what they're tracking and why carriers love bloatware.
Why does this app need microphone permission?
Why do apps request microphone, location, or contacts access they don't need? A field guide to Android permission creep and how to spot it.
Common questions
Which Android permissions are the risky ones? +
The ones Android itself classifies as dangerous, because they gate access to data about you or to hardware that can observe you: location, camera, microphone, contacts, SMS, call logs, and physical activity. A permission is only meaningful next to what the app is for, though, so the list alone is not a verdict.
Can I just revoke everything and see what breaks? +
Largely, yes, and it is a reasonable habit. Modern Android lets you revoke most dangerous permissions after install, and apps are supposed to degrade rather than crash. What revoking does not touch is the tracking code inside the app, which mostly works from data that needs no permission at all.
Other topics
Check your own apps.
The analysis runs on your device, against the bytecode of the packages you already have installed. No account, no sign-in.
GET IT ON Google Play