Skip to content

Excessive permissions

In plain terms

Nothing was hacked: a perfectly legal app asked for access to your contacts, your location and your microphone, and you said yes so you could use it.

Definition

Excessive permissions refers to data collection made possible by permissions granted to an app that are disproportionate to the function it performs.

How it works

The request arrives at the worst possible moment for reflection: the app has just been opened, the user wants to use it, and refusing seems to block the feature. It's often phrased to sound necessary — access to contacts "to find your friends", location "to improve your experience". Once granted, the permission is permanent and silent: nothing signals later access, and the app can collect data in the background. The harm isn't an intrusion but an accumulation, often resold to data brokers, where information from several apps is cross-referenced to reconstruct habits, movements and a social circle.

Warning signs

  • Permission requested with no relation to the function: microphone for a flashlight, contacts for a game
  • Request made at launch rather than when the relevant feature is actually used
  • App refusing to work without a non-essential permission
  • Location granted "always" rather than "while using the app"
  • Old apps still holding permissions you no longer use

How to verify

Mobile systems offer a view by permission rather than by app: open "location", then "microphone", then "contacts", and look at who's in each list. This is more revealing than going through apps one by one, and it surfaces the forgotten ones.

What to do

Grant permissions when you actually use the feature rather than at install time, prefer "while using the app" over "always" for location, and decline what isn't necessary — an app that then stops working has just told you something about its business model. Do a periodic review, starting with apps you no longer open.

If it already happened

Remove unnecessary permissions, uninstall unused apps, and reset the phone's advertising identifier, which is what links this data collection together. You can exercise your right of access and erasure with the publishers concerned.

Frequently asked questions

Is this really an attack, if it's legal?
The practice isn't always illegal, and that's what makes it durable. It appears here because the outcome for you is the same as non-consensual collection: data you wouldn't have given if the request had been phrased clearly.
Does refusing a permission break the app?
Rarely for actual features: recent systems allow refusal without blocking. An app that becomes unusable after refusing a permission tied to a secondary feature is telling you that collection, not the service, is what it's selling.

Official sources

This article is part of the Phones and connected devices family. Last updated: 2026-09-03.