BRYME TECH
SEPTEMBER 2026 · THE TOOL DESKPractical technology. No theatre.
THE BRYME

Practical guide · verified against the real thing

The Android privacy settings worth changing (a one-time pass)

In one line: Ten minutes in Settings that outlast every app decision: the permission manager, the advertising ID, lock-screen leaks, and the network settings people forget exist.

App-by-app permission audits catch the worst offenders, but Android's privacy posture is set one level higher — in device settings most people open once and never again. This is the one-time pass, in the order that matters most. It takes about ten minutes, survives app installs, and needs repeating only when the OS has a major update.

1. The permission manager: by permission, not by app

Settings, then Privacy, then Permission manager (on some skins: Apps, then Special app access). The inversion is the point: instead of asking "what does this app have?", review by permission — Camera, Microphone, Location, Contacts — and see every app holding each. Two sweeps per permission: anything you can't explain gets revoked, and anything set to "Allow all the time" gets a hard question (location all-the-time is legitimate for exactly one or two apps — maps, a safety app — and nobody else). This is the device-wide version of the per-app permission audit; the two together are the full picture.

2. The advertising ID: reset it, then consider deleting it

Android assigns an advertising ID that apps and ad networks use to link activity across apps. Settings, then Privacy, then Ads: Delete advertising ID (or Reset on older versions). Resetting gives you a new random identifier; deleting removes the identifier entirely on current versions — apps fall back to weaker, less accurate signals. Neither stops advertising; both weaken cross-app tracking, which is the part worth weakening. The economics of why that matters are in what free apps do with your data.

3. The lock screen: what it shows before you unlock

Settings, then Lock screen: decide what notifications reveal when the phone is locked — hide sensitive content (message previews are the leak), or show nothing. While there: confirm the screen lock itself is a six-digit PIN at minimum (pattern or four digits fall to shoulder-surfing and smudges far too easily), and that fingerprint/face unlock is set. The login-failure checklist is less funny when the device holding your 2FA apps is behind a four-digit pattern.

4. The network corners

Two settings with outsized value. Private DNS (Settings, then Network, then Private DNS): pointing the phone at a DNS-over-TLS resolver encrypts name lookups device-wide — a one-line change with real effect on public Wi-Fi, and the reason it works is in what DNS does. Wi-Fi permissions per app: apps don't need location to scan for networks — the "Wi-Fi control" permission exists; revoke it from apps that don't manage connectivity. And when mobile data itself misbehaves after all this tweaking, that diagnosis has its own ladder: mobile data, diagnosed.

5. The forgotten two

Notification history (Settings, then Notifications): enable it — a rolling log of dismissed notifications that rescues the swipe you regret, and doubles as evidence when an app is vibrating without telling you why (the quiet-notification failure mode has its own piece: why notifications go missing). Google Play Protect (Play Store, profile, Play Protect): confirm it's on — it scans installed apps continuously and is the baseline malware defence; it is not a reason to install recklessly, which is the pre-install checklist's job.

Next

Related on this desk.