Cyberlium

Android › Module 2 › Lesson 2

BeginnerModule 2Lesson 2/6

Mobile Privacy Settings

Tighten location, ads, notifications, and app permissions on modern Android

15 min+50 XP3 quiz
Module progress2 of 6
Location · Permissions · Ads

Opening

Defaults favor convenience. Fifteen minutes in Settings shrinks a year of leftover tracking.

Out of the box, modern Android is usable: maps navigate, photos back up, ads personalize, notifications peek on the lock screen. Those defaults also mean precise location in the background, a stable advertising ID, and OTP banners visible to anyone who can see the glass — or to any app you already granted notification access in the last lesson. This walk is on a phone you own. Paths differ by OEM (Pixel's Settings tree is not Samsung's, Xiaomi's is not Motorola's). You will learn the mechanisms — while-using versus always location, scoped photos, ad-ID reset, lock-screen notification privacy, permission-manager audit — then find the same ideas under whatever labels your skin uses. You will not remotely change someone else's phone "to help." You will not dump another person's location history. You will not bypass Play Protect or hide root to keep a bank app quiet.

1. Location: while using is a session; always is a tracker you forgot you hired

Android splits location into when and how precise. "While using the app" means the app may read location when it is visible (and, on recent versions, for a short time after you leave — still not "all night in a pocket"). "Allow all the time" / background location means it may read while you sleep, commute, and sit in meetings. Precise is GPS-class coordinates. Approximate is a coarse area, often enough for weather or a regional news app. The mechanism is not "maps are evil." Navigation, rideshare while you are in the trip, and Find My Device (a Google/OEM feature you chose) have honest jobs for location. A flashlight, a puzzle game, a PDF reader, and most shopping apps do not need Always + Precise. Background location is also how a stalkerware-class app (Module 1) keeps a trail after you think you closed it. Deny Always unless you can name the job in a sentence you would say to a friend without embarrassment.

On Pixel-class Android, think Settings → Location → App location permissions (or Privacy → Permission manager → Location). On Samsung, think Settings → Location and Settings → Privacy. The labels move; the questions do not: who has Always, who has Precise, who can live on Approximate or While using. Revoke unused. You can grant again the next time you actually navigate. Do not "test" a tracking APK. Do not export someone else's Timeline.

2. Photos and media are scoped now — "all files" is the old over-grant

Older Android let a gallery or a "cleaner" ask for storage and receive the whole shared tree: every photo, every download, every WhatsApp image. Newer releases push selected photos, photo pickers, and media-specific grants (Images, Video, Audio) so an app sees what you picked, not the entire camera roll. That is least privilege for memories and documents — the same idea as Topic 1's PoLP, applied to a roll of family pictures. A camera app needs Camera while you shoot, not your contacts. A social app that uploads one picture should use the picker, not "allow management of all files." All-files / All files access is a special grant meant for genuine file managers, backup tools you chose, and some document scanners — not for a theme pack. If an app cannot work without seeing every file, ask whether you still want that app. Do not grant All files so a "booster" can "scan junk." Junk-scan is a classic excuse to read everything.

Microphone and camera are sensors, not "media." Review them in the same Permission manager pass. A video-call app you use weekly can keep mic and camera. A forgotten shopping app from 2023 should not. One-time grants (Allow this time) exist so a QR scan does not become a permanent camera key. Prefer one-time or while-using over Allow all the time for sensors you only need in a session.

3. Advertising ID and lock-screen banners: identifiers and secrets on glass

The Google advertising ID is a resettable identifier apps use to join your behavior across apps for ads. It is not your name, but it is a stable handle until you reset or delete it. Settings → Google → Ads (or Privacy sandbox / Ads — OEM wording varies) lets you reset the ID, delete it where the UI offers that, and turn down ad personalization. Resetting does not make you invisible. It breaks a long-lived join. That is enough to be worth doing when you harden a daily driver, the same way Topic 4 treated cookie partitions: shrink correlation, do not claim a cloak. This is not a license to fraudulently reset IDs to evade bans on games you cheated. It is your identifier on your account. Leave other people's devices alone.

Lock-screen notification content is a privacy control and a 2FA control. "Show sensitive content" on a lock screen means an OTP, a bank balance, a medical reminder, or a message preview is readable without the PIN, password, or biometric — by a shoulder, a photo, or a thief who has the glass but not the credential. Set lock-screen notifications to hide sensitive content or to show no content until unlock (wording: Privacy, Lock screen, Notifications on lock screen). Combined with the last lesson: even hidden banners can still be read by an app with notification access. Lock-screen hide is necessary and not sufficient. You still empty the listener list.

4. Permission manager is the monthly audit — unused grants are keys you forgot you cut

Permission manager (Privacy dashboard on some skins) groups Camera, Mic, Location, Contacts, Phone, SMS, Photos, and more by who has them and when they were last used. Unused + still granted is the interesting set: an app you have not opened in months still holds a key. Revoke. Uninstall if you do not use it. Apps you no longer want still receive network access and still appear in Special app access if you never cleaned them. Also review accounts: Settings → Passwords, passkeys and accounts / Accounts. Remove leftover work profiles and old personal logins you do not use. Autofill should be the password manager you chose in Topic 4, not a random "autofill assistant" from a blog APK. This audit is on your device. Do not demand a partner's phone "for their safety" as a surprise search; that is a relationship and legal line this course does not cross. Offer to walk them through their own Settings if they ask.

5. OEM paths differ — Pixel vs Samsung is the same questions under different trees

Stock-ish Pixel / AOSP-near skins cluster many of these under Settings → Security & privacy (or Privacy). Location is often its own top-level item. Special app access lives under Apps. Google Ads lives under Google settings. Samsung uses Settings → Privacy, Settings → Security and privacy, Settings → Notifications, and Settings → Location; "Permission manager" may sit inside Privacy. Other OEMs invent names (safety, permission controller, special permissions). Do not memorize one screenshot from a 2022 blog and declare your phone "missing" the control. Search in Settings for: Location, Permission, Notification, Ads, Lock screen, Accessibility, Device admin. The mechanism names from this lesson are the map. The OEM is the street signs. If a work profile is managed by your employer, some toggles are grey — that is MDM policy, not a puzzle to jailbreak. Do not try to break a managed profile. Use a personal device for personal hardening when policy blocks a change.

6. Wrong vs right: leaving Always Precise and lock-screen OTPs vs a settings pass you can repeat

Worked failure — same daily driver, opposite correlation and shoulder-surf risk. Right is never "spy on someone else's location to practice."

  • Wrong

    Grant every app Always + Precise because maps asked once and you tapped the top option. Leave All files on a cleaner. Keep sensitive OTP and bank banners on the lock screen. Never open Permission manager. Reset an ad ID to evade a game ban. Remotely locate a partner's phone without their consent. Disable Play Protect so an app "stops complaining." Those enlarge tracking and theft. This course forbids the non-consensual and the bypass.

  • Right

    Prefer While using and Approximate unless navigation or a find-my-device feature you chose needs more. Use photo pickers instead of all-files for one-off uploads. Reset or delete your advertising ID on your account; hide sensitive lock-screen content. Audit Permission manager and Special app access on YOUR phone. Search Settings when OEM labels differ. Next lesson is Safe App Installation — Play Protect, unknown sources, and a checklist before every new package.

7. Practical: walk YOUR Settings — notes file, no one else's device

Spend one sitting on a phone you own. You will not hit every OEM pixel-perfect path. You will answer the mechanism questions and write the answers. If a control is missing, write "not found / OEM name" rather than sideloading a "privacy tool" APK to replace Settings. Settings is the lab. Third-party "boosters" are how Module 1 threats arrive.

Privacy walk checklist — own device, OEM paths vary

# YOUR phone only. Search Settings if labels differ (Pixel vs Samsung vs others).
# Do NOT audit someone else's device without their request and presence.
# Do NOT sideload "privacy cleaner" APKs. Do NOT bypass Play Protect.

mkdir -p "$HOME/cyberlium-lab"
NOTES="$HOME/cyberlium-lab/android-privacy-walk.txt"

{
  echo "date: $(date -Iseconds 2>/dev/null || date)"
  echo "oem_skin: Pixel / Samsung / other (name it)"
  echo "ethics: own device — no non-consensual location, no live malware"
  echo ""
  echo "=== LOCATION ==="
  echo "apps_with_ALWAYS:"
  echo "apps_with_PRECISE_that_could_be_approximate:"
  echo "revoked_or_set_to_while_using:"
  echo ""
  echo "=== PHOTOS / FILES / SENSORS ==="
  echo "all_files_access_apps:"
  echo "camera_mic_unused_revoked:"
  echo ""
  echo "=== ADS ==="
  echo "ad_id_reset_or_deleted: yes/no"
  echo "ad_personalization_limited: yes/no"
  echo ""
  echo "=== LOCK SCREEN + PERMISSION MANAGER ==="
  echo "sensitive_notification_content_hidden: yes/no"
  echo "unused_grants_revoked:"
  echo "accounts_removed_leftovers:"
  echo ""
  echo "still_open: next = safe install (Play Protect, unknown sources)"
} > "$NOTES"

chmod 600 "$NOTES"
# Windows: WSL / Git Bash, or restrict the file in your user profile.

# Typical search terms (not a single OEM gospel):
#   Location | Permission manager | Notifications | Ads | Lock screen
#   Special app access | Privacy dashboard

# NEVER: dump another person's Timeline or photos into NOTES
# NEVER: install a random APK that promises a "one-tap privacy score"

Mission: complete the privacy walk on a phone you own

1) Set leftover location to While using / Approximate unless you can name a real job for Always + Precise. 2) Hide sensitive lock-screen notification content; reset or delete your advertising ID where the UI allows. 3) Use Permission manager to revoke unused Camera, Mic, Photos, Contacts, SMS. Write the pass to $HOME/cyberlium-lab/android-privacy-walk.txt (chmod 600). Own device only. OEM paths may differ — search Settings.

Stuck? Ask Cyberlium AI Mentor

If Samsung vs Pixel menus still feel like different operating systems, ask for a hint — not a third-party APK. Try: "Hint only: what is the mechanism difference between While using and Always location, and which Settings search terms find lock-screen notification privacy and the ad ID on a non-Pixel phone — without me installing a cleaner?" You still tap the menus yourself.

You now treat location, photos, ad IDs, and lock-screen banners as leftover keys, not as factory furniture you must keep. While using beats Always for most apps; pickers beat all-files; hiding sensitive notification content pairs with the last lesson's listener audit. OEM skins change labels, not the questions. Next — Safe App Installation — you put Play Protect on, keep unknown sources off per source, and run a checklist before every install so a new package does not undo this walk.

Knowledge Check

1

APPLY: A weather app still has Always + Precise location. You open it twice a week. What is the matched grant?

Multiple choice

Knowledge Check

2

APPLY: True or False: Hiding sensitive notification content on the lock screen is unnecessary if you already denied SMS, because OTPs cannot appear as banners.

True or False

Knowledge Check

3

APPLY: Your Samsung menus do not match a Pixel screenshot in a blog. Correct move?

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)