The privacy settings worth ten minutes
Forty one items. That was the length of a privacy checklist somebody forwarded me last month, and each item on it was defensible on its own.
The person who sent it had done four. Two of those were defaults the phone had changed by itself in an update, so the honest number was two.
That is what a long list produces. Avoidance, mostly, because nobody voluntarily reopens a document that makes them feel behind.
So here is the short one. Five settings, about ten minutes, and the sequence carries as much weight as the contents do.
Where I am sitting: I run mobile data lines commercially, SIM cards in modems rented by the month, and a fair share of the businesses renting them are doing data collection work with them. I have watched what a handset gives up from the network side, which is the only reason I have a view on which of these toggles is load bearing.
One thing I am not going to redo here. Working out what you actually care about is a separate exercise, four questions on a single page, and I have written it up properly on its own. This piece assumes you skipped that, like almost everyone does, and want to know what to press.
The five, in order
Switch off the tracking permission and reset the advertising identifier.
Move every location permission from always to while using.
Read the microphone and camera lists, and revoke whatever surprises you.
In the two or three accounts you genuinely use, turn personalisation off and shorten how long activity is retained.
Open the security page of your main email account and revoke everything connected to it that you do not recognise.
The ordering is the argument. Each buys less than the one above it, and the drop is steep. Stop after three and you have collected most of what was on offer.
Why the identifier sits at the top
Every phone carries an advertising identifier. One string, readable by every app on the device, and identical in all of them.
That is the entire mechanism. A weather app and a shopping app are unrelated companies with unrelated databases. The only thing connecting their two records of you is a value they can both read off the handset.
Switching off tracking stops that value being handed out. Resetting it cuts loose whatever was already filed against the old one. Apps carry on working, each keeps its own record, and what they lose is the join.
From my side of the wire, the tell is how much effort goes into controlling that field when somebody is running a hundred devices for commercial data work. It is the first thing they have to fix, because it is what collapses a hundred separate personas back into one machine in a single query. That is a fair proxy for what it is worth.
An honest caveat. The industry adapted, and there are matching techniques that never touch the identifier at all. Those are worse in the sense of being harder to see and harder to refuse, and they are also less accurate. Taking the accurate method away still costs the buyer something real.
Always is the default answer to a question nobody reads
Almost every app that requests location requests always. Very few of them need it.
Always means the app can locate you while it is closed. A supermarket app showing you the nearest branch does not need to know where you sleep, and it will ask for always regardless, because asking is free.
Set everything to while using. You will break a small number of things and you will find out inside a day. Background navigation is the genuine case. A run tracker with the screen off is the other.
Location earns the second slot on how identifying it is. Two points will do it. Where a handset rests overnight and where it rests during the working day picks a person out of a city this size with no name attached to the file anywhere.
The permission lists are a memory test
Find the screen listing which apps hold the microphone, then the one for the camera.
Read them for surprises, not for spies. The useful question is why a document scanner asked for the microphone, and whether you have opened it since the month you installed it.
Mine had a keyboard I stopped using, a utility with no plausible reason to be on there, and one entry I could not identify from the name.
The realistic risk is duller than the recording fantasy. A grant you made in 2022 is still live, attached to an app that has changed owners since, and you have no idea who is behind it now. Small apps get bought quietly and the permissions travel with the install base.
Revocation costs nothing. If an app truly needs it, it asks again, with the app open in front of you, which is a much better place to make the decision than a first launch screen.
Two accounts properly beats eleven half done
Pick the services you use daily. For most people that is a search engine, a video site, and one social account.
Each has a personalisation setting, and separately a setting for how long activity is kept. They are rarely on the same page, and the retention one is usually further down.
Personalisation off with retention untouched is the common half finished state, and it is the weaker half. Personalisation governs what gets shown back to you. Retention governs how much of you exists to be handed to an advertiser, a legal request, or whoever owns the company in five years.
Cap it at the accounts you actually use, because this step is tedious and it is where people abandon the whole exercise.
There is a cost. Recommendations get worse for a fortnight, and a video feed with no history behind it is genuinely poor for a while. Some people switch it back on, which is fine as long as the decision was deliberate.
The list almost nobody opens
This one outranks its position. It sits fifth because when it goes first, people skip it.
Open the security section of your main email account and look at what is connected to it.
Every service you signed into with that account. Every extension you approved. Every device still holding a session, including the handset you sold.
That mailbox is the recovery route for everything else you own. Bank, government portal, work login. They all post reset links there, and anything holding a live token on the account has a chair in the room where those links land.
Mine listed eleven. I recognised four. One was a calendar integration from a job I left in 2021, still holding read access to the mailbox.
Three minutes, and it is the best three minutes on this page. While you are in there: if the password is one you also use elsewhere, that is the job a password manager does, and it has its own piece. If there is no second factor, add one, and which kind you pick is also its own piece. The tools I use for both are here, tested rather than ranked by payout.
No menu paths, on purpose
I am not going to write settings, then privacy, then fourth item down.
Instructions in that shape expire inside a year. Screens get renamed, items get promoted to their own page, and a reader following a dead path decides the setting no longer exists and stops.
Search the settings app for the words instead. Tracking. Location. App permissions. Activity, or history. Connected apps, or third party access, depending on who wrote the screen.
What items six through forty one are worth
They are real, and each returns less than the one before it. Somewhere around item twenty you are spending an hour closing a gap that was never going to be the thing that hurt you.
Somebody who does five is in better shape than somebody who read forty one and did none, and the second person is the common case.
There is a repeat problem too. New phone, new account, an update that flips a default back on. A five step routine survives being run again in two years. A forty one step one gets attempted once and never revisited.
I do not accept the counterargument that all of this is theatre because zero is unreachable. Zero was never the target. The question is whether the cheap moves are worth making, and they are, because they are cheap.
The part I got wrong
For about three years I did this as an annual purge. One sitting, revoke everything, feel virtuous, forget about it.
The flaw is that the grants that matter are the ones made after the purge. Every app I installed over the following year asked for something at install time, and at install time the answer is yes, because the prompt is standing between you and the thing you just downloaded.
So I cleaned up twelve months of saying yes, then went and manufactured another twelve months of it.
Moving the decision to the install prompt is what fixed it. No, or while using, and if the app truly needs more it tells me by failing. It almost never fails.
The annual pass now takes about ten minutes, because there is hardly anything left in there to find.
I had the ordering wrong for years as well. I spent that time on browser settings and cookie banners, which is where the visible part of this subject lives, while the connected apps list on my email account sat untouched with a token from a job I had already left. One of those was a hole. The other was tidying.