Most privacy advice for Android quietly assumes a Pixel. The phone in your hand is far more likely to be a Redmi, a Galaxy M, a Realme, a vivo or a OnePlus, and it shipped with a manufacturer layer between you and Google’s settings — one carrying its own recommendation engine, its own identifiers and a folder of apps you never chose. On top of that sits a threat picture that is genuinely local: instant-loan apps that hoover up your contact list, and OTP interception.
We have ordered this guide by how much risk each change removes, not by where the setting lives. Where a control’s name changes between skins we say so rather than invent a menu path — the fastest route to any setting is the search box at the top of the Settings app.
The four permissions that can actually cost you money
Camera and microphone get the headlines. In India, the permissions that lead to real financial and reputational damage are Contacts, SMS, Accessibility and notification access. Nearly every loan-app harassment case turns on at least two of the four.
Audit them app by app in the permission manager. On near-stock Android, Google documents the path as Settings > Security & Privacy > Privacy > Permission manager. Samsung, Xiaomi, Realme, vivo and OnePlus each reshuffle that tree, so search for Permission manager rather than hunting.
Contacts
A messaging app you use for messaging has a case. A lending app, a wallpaper app, a torch, a photo editor, a game does not. Revoke and watch what breaks; almost nothing does.
SMS and call logs
Google Play policy restricts SMS and Call Log permissions to apps actively registered as the device’s default SMS, Phone or Assistant handler, with narrow exceptions, and requires an app to stop using the permission once it is no longer the default. In practice, one app should hold SMS access. If a shopping app, a lending app or a caller-ID utility holds it, your OTP stream is in someone else’s hands.
Accessibility services
An accessibility service can read what is on screen and act on your behalf. It is a genuinely important feature for users with disabilities and also the most abused capability on Android. Nothing that is not a real screen reader, switch-access tool or well-known password manager needs it. Open Accessibility and turn off every service you cannot name and justify.
Notification access
This lets an app read the content of every notification — including the SMS preview carrying an OTP, even when the app holds no SMS permission. Treat it as seriously as SMS.
On Android 13 and later, Google blocks apps installed from outside the Play Store from receiving accessibility and notification access through the normal flow. If an app tells you to go to Settings > Apps > [app] > three-dot menu > Allow restricted settings, stop. Google’s guidance is not to allow restricted settings unless you trust the developer, and an app pushing you through that door while promising a loan in five minutes has told you everything.
The permission audit, in one table
| Permission or setting | What it exposes | What we set it to |
|---|---|---|
| Contacts | Every name and number you hold — the social graph used for shame-based recovery calls | Dialler and one messaging app only |
| SMS | OTPs, bank alerts, delivery codes | Default SMS app only |
| Call logs | Who you speak to and how often | Default phone app only |
| Notification access | The text of every notification, OTP previews included | Off, unless a smartwatch app you trust |
| Accessibility service | Reads the screen and can tap for you | Off for anything you cannot justify by name |
| Location, precise | Roughly 50 metres or better, per Google’s figures | Approximate for weather, news, shopping, social; precise only for maps and ride-hailing |
| Location, all the time | Movement history while the app is closed | Downgrade to while-using-the-app |
| Photos and videos | Your whole gallery, screenshots of statements included | Select photos and videos, where offered |
| Camera and microphone | Live capture | Ask every time, for occasional apps |
| All-files access | Everything in internal storage | Deny; grant only to a file manager you chose |
| Install unknown apps | Lets a browser or chat app sideload an APK | Off for every app, permanently |
| Advertising ID | Stitches your behaviour together across apps | Delete it |
Two rows need a footnote. Approximate location, in Google’s developer documentation, narrows you to about three square kilometres — plenty for a weather app, useless for locating your flat. And the partial-media option Android introduced in version 14 depends on how each app was built, so it appears for some apps and not others.
Cut the identifiers that follow you between apps
Permissions control what one app can read. The advertising ID controls how easily separate apps agree they are looking at the same person. Google documents the control as Settings > Privacy > Ads, where you can reset the ID or delete it outright; on older versions it sits under Settings > Privacy > Advanced > Ads. Deleting beats resetting — a reset hands you a fresh number that starts building a profile immediately, while deletion makes the ID unavailable to apps that ask.
Then deal with the Google account, which is separate from the phone. Under Data & privacy > History settings sit Web & App Activity, Timeline and YouTube History. Each can be turned off, or left on with auto-delete at the shortest interval offered; turning one off stops new activity being saved but does not remove what is already stored, so use the delete option too. Timeline has also changed shape — Google’s Maps documentation now describes it as saved on your device, with an optional encrypted backup on Google’s servers, and off unless you opt in.
Finally, open myadcenter.google.com and switch personalised ads off. Google states the ads then become non-personalised, chosen from context such as time of day, page topic and current location, and that your saved topic and brand preferences are deleted. You are removing the profile, not the advertising.
While in the Play Store, tap your profile picture, open Play Protect > Settings and confirm scanning is on. Its companion option, improve harmful app detection, sends unknown apps to Google for code-level evaluation.
Loan apps, OTP theft and the permissions that make both possible
The predatory-lending pattern is consistent enough to write as a checklist. The app promises money in minutes with no paperwork. During onboarding it asks for Contacts, SMS, storage and often the camera, framing all of it as verification, and may ask you to enable an accessibility service or notification access to auto-fill your OTP. The loan lands smaller than advertised, the difference taken as fees. When repayment slips, collection begins — not with you, but with the contact list copied on day one, sometimes attached to photos pulled from your gallery. That needs no clever malware, only four taps on Allow, which is why the permission audit sits at the top of this guide.
Two defences are worth building before you need them. First, verify the lender rather than the app: the Reserve Bank of India runs the Sachet portal at sachet.rbi.org.in, where you can look up entities registered with the financial regulators and file or track a complaint about an unregistered one. A slick Play Store listing is not registration.
Second, understand the OTP path on your own phone. A code leaves your device three ways: you read it to a caller, an app with SMS permission reads it, or an app with notification access reads the banner. You control all three. No bank, delivery agent or KYC-update caller has a legitimate reason to ask for an OTP, and no honest app needs notification access to fill one — Android’s SMS Retriever lets a developer receive a verification code without ever holding SMS permission.
If money has moved, report fast. The National Cyber Crime Reporting Portal at cybercrime.gov.in, run by the Ministry of Home Affairs, accepts complaints under financial fraud, crimes against women and children, and other cybercrime, and lets you search a repository of suspect numbers, URLs and accounts. The national cyber-fraud helpline is 1930. Call first, file afterwards.
The ads your phone manufacturer installed
On several skins sold in India, some advertising is not from apps you installed — it sits inside the system apps. Xiaomi’s HyperOS and the MIUI builds before it are the most discussed case, where the file manager, cleaner, security app and app installer have carried recommendation panels at various points. Realme, OPPO’s ColorOS and vivo’s Funtouch ship comparable features. One UI, Motorola’s near-stock builds and Nothing OS are lighter, though Samsung has its own customisation and marketing-consent options.
Because these controls get renamed and moved with almost every release, we will not publish menu paths that expire at the next update. Instead, open Settings, use the search box, and run these words one at a time — recommendations, ads, personalised, marketing, customisation service, user experience programme, and autostart. Turn off every switch those surface. Then open the system apps themselves — file manager, security or phone manager, themes, the app store — and check each one’s own settings menu, because several keep a separate recommendation toggle there.
The autostart search matters for a second reason: most Indian skins add an aggressive background-launch manager on top of Android’s own rules, so denying autostart to preinstalled apps you never open stops them waking to phone home. Anything preinstalled you do not use should be disabled rather than ignored — hold the icon, open App info, and use Disable where Uninstall is unavailable.
Reading a Play listing before you install
Every Play listing carries a Data safety section declaring what the app collects, what it shares, and whether collection is optional. Use it, but know its limit: Google’s documentation is explicit that these are developer declarations, that the section covers only apps distributed on Play, and that an independent security review badge does not verify their accuracy. A torch app declaring contacts, location and financial information is a plain warning; an empty section is unverified, not clean.
Then turn on Android’s housekeeping: under unused app settings in the Apps section, enable pausing activity for unused apps, and Android revokes permissions and stops background work for anything you have not opened in months.
Setting up a phone for a child or an elderly parent
This is about phones you configure with the person’s knowledge, at their request or as their guardian. We do not cover monitoring another adult’s device.
For a child’s phone the account matters more than the toggles: a supervised account through Google’s Family Link tools gives install approval and screen-time controls that survive a factory reset better than any setting. India’s Digital Personal Data Protection Act, 2023 backs this up — it requires verifiable parental consent before a child’s personal data is processed, and prohibits both behavioural tracking of children and advertising targeted at them. That is a right you can cite in a complaint, not merely a preference.
For an elderly parent the failure mode is different. They will not be tricked by a game; they will be called by someone claiming to be from the bank. Install nothing from outside the Play Store and leave install-unknown-apps off everywhere. Grant SMS to the default messaging app only. Turn off every accessibility service. Use a Google account they control, with recovery details written on paper kept at home. Then have one specific conversation: nobody legitimate ever asks for an OTP, a PIN or a screen-sharing session, and the correct response is to hang up and ring you. Screen-sharing apps are the favourite tool for this scam, so if one is not installed, leave it that way.
The rights the DPDP Act gives you
Under the Digital Personal Data Protection Act, 2023, consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose — which is why a lending app demanding your entire gallery is not merely rude. You must also be given notice, in English or another scheduled language, of what is collected and why.
As a data principal you can request a summary of the data processed about you and who it was shared with; ask for correction, updating and erasure; and nominate someone to exercise these rights if you die or become incapacitated. The Act requires companies to run a grievance mechanism and requires you to exhaust it before approaching the Data Protection Board — so your complaint starts with an email to the app’s grievance officer, and you keep a copy.
A ten-minute pass worth repeating each quarter
- Recheck Contacts, SMS, call logs, location, microphone and camera in the permission manager. Anything unfamiliar loses it.
- Recheck Accessibility and notification access. Same rule.
- Delete the advertising ID again after any major system update, which sometimes restores it.
Questions readers keep asking us
Does deleting my advertising ID break anything?
No. Apps that used it for tracking simply do not get it; they keep working. You will still see ads, just less well aimed.
If I deny Contacts to a loan app, will my loan be rejected?
A regulated lender assesses you on credit information, not your address book. If contact access is a condition of the loan, your contact list is the product being bought.
The setting you named is not on my phone. What now?
Use the Settings search box and try alternative wording — one skin’s Permission manager is another’s App permissions or Privacy protection. If a control genuinely does not exist on your build, the Google account controls at myadcenter.google.com and under Data & privacy still apply.
I already gave a suspicious app everything. What order do I fix it in?
Uninstall it; change passwords for anything you opened while it was installed; check your bank and UPI apps for unrecognised transactions; then confirm no accessibility service or notification access is still enabled, because those sometimes outlive the app that requested them. If money moved, call 1930 and file at cybercrime.gov.in the same day.
None of this needs technical skill. It needs a willingness to say no to an Allow dialog engineered to make no feel like the harder option. For how we research and check pieces like this, see our editorial standards and our about page.

