What a locked phone still shows: lock screen privacy settings that actually matter
Lock your phone and the screen goes dark. That feels like the end of the story: no passcode, no access, nothing to see. In practice, the lock screen is a working surface, not a wall. Operating systems are built to keep being useful to you even while locked, which means they keep showing things, keep broadcasting things, and keep accepting some inputs. None of this is a bug. It is the tradeoff every phone maker makes between convenience and exposure, and most people never look at where that line actually sits.
This isn’t about someone cracking your encryption on the sidewalk. It’s about the much more common scenario: your phone is face up on a table, in someone’s hand for a second, or sitting in a bag next to a stranger on a train. What can they learn or do without ever guessing your passcode?
Notification previews are the biggest leak
This is the one that matters most because it happens constantly and requires zero effort from an attacker. When a message, email, or app alert arrives, both iOS and Android default to showing a preview on the lock screen: sender name, and often the first line or two of content. Two-factor codes are a specific problem here. If a text message with a six-digit login code lands while your phone is locked and face up, that code is readable by anyone glancing at the screen for the two seconds it takes to appear.
The mechanism is simple: the notification system runs at the OS level, below the lock screen, because notifications need to work whether or not you’ve authenticated. The app doesn’t get to decide independently whether its content is sensitive. The OS decides based on a global setting, unless you configure it per-app.
Both platforms let you turn this down without turning notifications off entirely. iOS has a setting to show previews only “when unlocked.” Android’s equivalent hides sensitive content on the lock screen while still showing that a notification exists. Neither requires you to lose notifications altogether, just the free preview of their contents.
Widgets and the today view
Widgets on the lock screen or in the “today view” (swipe left on iOS, or a locked home screen panel on some Android skins) run in a similar category. A calendar widget shows your next meeting’s title and time. A weather widget confirms your general location. A notes widget might show the first few lines of whatever you last typed. None of these need a passcode because widgets, like notifications, are designed to give you a glance of information without requiring you to unlock.
The fix is the same principle as notifications: decide what’s worth the convenience. A weather widget on the lock screen tells someone what city you’re probably in, but the weather app already knows your location anyway. A calendar widget showing “Interview: Jane Smith, 3pm” is a different kind of leak. Go through what’s actually on your lock screen and ask whether each item earns its place there.
What the radios keep doing
This part is invisible, which is exactly why it’s worth knowing about. A locked phone is not radio-silent. Wi-Fi and Bluetooth radios continue their normal background behavior: Wi-Fi periodically probes for known networks so it can reconnect the instant you’re in range, and Bluetooth continues advertising or scanning depending on what’s paired. Apple’s Find My network and Android’s equivalent rely on this: your phone (and AirTag-style trackers) broadcast a low-power Bluetooth signal that nearby devices can relay, even when locked, even sometimes when powered off in newer hardware.
None of this is a targeted attack. It’s ambient signaling that any phone in Bluetooth or Wi-Fi range can technically observe if it’s built to look, the same way a store’s Wi-Fi router can log the MAC addresses of phones that walk past scanning for networks. It’s low-resolution information, mostly useful for tracking device presence rather than reading content, but it’s a real gap between “locked” and “silent.”
On the cellular side, your phone’s baseband is in constant contact with the carrier network to maintain service, independent of the lock screen entirely. This is standard cellular operation, not something the lock screen controls, but it’s worth knowing that “locked” only ever applied to the parts of the phone the OS manages. The radio layer has its own life.
The camera, flashlight, and voice assistant shortcuts
Most phones let you swipe to a camera shortcut or press a button combination to launch the camera without unlocking. This is deliberate: you don’t want to fumble with a passcode to catch a fast-moving photo opportunity. The tradeoff is that anyone holding your locked phone can open the camera, and on some setups, browse recently taken photos from within that camera shortcut before it locks them out of the rest of the gallery.
Voice assistants raise a related question. If “Hey Siri” or “Hey Google” is enabled to work from a locked state, the assistant can read out calendar events, send texts via dictation, or answer questions using data synced to your accounts, all without a passcode, using only your voice or a nearby button. Whether this is a real risk in your case depends entirely on who has physical or audible access to your phone. It’s not a universal problem, but it’s a setting worth actually knowing you have, rather than inheriting the factory default without a decision.
Wallet cards and quick access
Apple Wallet and Google Wallet can be configured to require Face ID, a fingerprint, or a double-press before completing a payment, but the cards themselves are often visible or reachable from the lock screen with a swipe or button press, showing the last four digits of a card and possibly loyalty or transit passes. Transit cards in particular are frequently set to work with zero authentication on purpose, because fumbling for Face ID at a turnstile defeats the point of tap-to-pay transit. That’s a reasonable tradeoff for a transit card. It’s a different tradeoff for a credit card, and the two don’t have to use the same setting.
USB and physical access
Plugging a locked phone into a USB port used to default to allowing data access in some older Android configurations. Modern Android and iOS both restrict data transfer over USB while locked, requiring you to unlock and explicitly approve the connection (“Trust this computer,” or an equivalent Android prompt) before the connected device can see anything beyond charging. This is worth checking rather than assuming, especially on older devices or ones where “USB debugging” was ever turned on for development purposes and never turned back off, since that setting bypasses some of these protections.
What actually adjusting these settings gets you
Locking these things down does not make your phone untraceable and does not stop someone who has your unlock code or a warrant and forensic tools with the time to use them. What it does is close the gap between “locked” and “gives away nothing,” for the much more common situation of a phone left unattended for thirty seconds, glanced at across a table, or picked up by a curious stranger. That’s a realistic threat model for almost everyone, and it’s the one these settings are actually built to address.
Go through notification previews first since it’s the highest-frequency leak, then widgets, then decide deliberately about voice assistant and wallet behavior on the lock screen based on how you actually use your phone. None of this is a single switch that solves the problem. It’s a handful of independent settings, each closing one specific gap, and each worth understanding rather than accepting by default.
If you want more explainers like this on how your devices actually behave, not just what the settings menu calls things, check out the rest of what we cover at The Privacy Wire.