How to check and revoke camera & mic permissions
The fast route: Settings → Privacy → Permission manager → Camera, then Microphone. Set anything that doesn't need the sensor to Don't allow, and everything else to Only while using the app. Ten minutes, and it's the highest-value privacy change most people can make to their phone.
The average phone has somewhere between forty and a hundred apps on it, and most were granted permissions in a hurry during setup, years ago, and never reviewed since.
Permissions are the actual control surface for phone privacy. An app that cannot open the camera cannot use the camera — no amount of bad intent gets around it. Everything else is downstream of this list.
Here's how to audit it properly.
Step 1: open the permission manager
- Open Settings
- Tap Privacy — on Samsung this is Security & privacy, then Privacy
- Tap Permission manager
You'll see permissions grouped by type — Camera, Microphone, Location, Contacts, Files and so on — each with a count of how many apps hold it. If you can't find it, search Settings for "permission".
Manufacturer note: on Xiaomi and Redmi it's under Settings → Privacy protection → Permission manager; on OnePlus and Oppo, Settings → Privacy → Permission manager. The screens differ slightly, the logic doesn't.
Step 2: audit the camera
Tap Camera. Apps appear in four groups:
- Allowed all the time — can use the camera even in the background. Very few apps should be here.
- Allowed only while in use — only when the app is open and on screen. This is the correct setting for almost everything.
- Ask every time — prompts on each use.
- Not allowed — cannot open the camera at all.
Go down the list and ask one question per app: does this app's core purpose require a camera?
A camera app, a video-call app, a QR scanner, a banking app that scans cards — yes. A game, a torch, a keyboard, a weather app, a note-taking app, a launcher, a wallpaper app — no. Tap anything in the second category and choose Don't allow.
Be strict. If you can't immediately articulate why an app needs the camera, revoke it. You lose nothing.
Step 3: audit the microphone
Back to Permission manager, then Microphone. Same exercise, and this list is usually worse — microphone permission gets requested by more apps than plausibly need it.
Legitimate: calling and messaging apps, voice recorders, voice assistants, music identification, video recording, translation. Questionable: social apps that don't record, shopping apps, games, utilities, anything advertising-funded that doesn't record anything.
The group to look at hardest is Allowed all the time. Background microphone access, screen off, is the strongest capability on your phone. Almost nothing needs it.
Step 4: what "Don't allow" actually does
The common worry is that revoking will break something. It won't — since Android 6, apps are required to handle a denied permission gracefully.
Concretely: the feature that needs the sensor stops working, and the app asks again the next time you tap that feature. Nothing is uninstalled, no data is lost, no settings are reset. If you revoke camera access from a messaging app and later want to send a photo, it prompts and you grant it in one tap.
This makes the audit almost risk-free. Revoke aggressively; re-grant on demand.
Step 5: turn on automatic removal
Android can revoke permissions from apps you've stopped using, which quietly solves the problem of an audit going stale.
- Settings → Apps → See all apps
- Tap an app → scroll to Pause app activity if unused (older versions: Remove permissions if app isn't used)
- Turn it on
Newer Android versions enable this by default for apps targeting recent API levels, but it's worth confirming on the apps you care about.
Step 6: add the system kill switches
Android 12 added two global toggles most people have never seen, and they're the bluntest and most effective controls available.
- Pull down the notification shade twice to open Quick Settings
- Tap the pencil or edit icon
- Drag Camera access and Mic access into your active tiles
Switching either off cuts that sensor for every app on the phone. Apps that request audio receive silence rather than an error, so nothing crashes. Emergency calls are unaffected.
Useful in specific moments: a sensitive meeting, a medical appointment, or overnight. Turn the microphone off when you don't need it and the whole question of who might be listening stops applying.
Step 7: check what's been used already
Permissions tell you what an app could do. They don't tell you what it has done.
For the last 24 hours, Android will show you:
- Settings → Privacy → Privacy Dashboard
- Tap Camera or Microphone
Do this after your audit. It's a useful sanity check, and it often surfaces one app you'd have sworn was harmless.
Then note the ceiling: 24 hours, no durations, no lock-screen context. We went through those limits in detail here.
A quick reference
| App type | Camera | Microphone |
|---|---|---|
| Camera / photo app | While in use | While in use (video) |
| Video calling | While in use | While in use |
| Messaging | While in use | While in use |
| Social media | While in use | While in use, or deny |
| Games | Deny | Deny unless voice chat |
| Utilities, torch, weather | Deny | Deny |
| Keyboards | Deny | While in use, if you dictate |
| Anything unrecognised | Deny | Deny |
Where permissions stop being enough
A permission audit is the right first move, and it's genuinely the highest-leverage thing on this list. But it has a structural limit: it's a snapshot of capability, not a record of behaviour.
After the audit you'll still have a handful of apps that legitimately need your camera and microphone. For those, the useful question isn't "can it?" — you've already answered that — but "how often does it, and when?" A video app using your microphone during a call is expected. The same app using it at 4am with the screen locked is not.
Android won't answer that. Its record lasts a day, omits duration, and ignores lock state.
Spytrap keeps the log that's missing: every camera and microphone access, which app, exact timestamp, how long it lasted, and whether your screen was locked — as history you can go back through. Each app gets a trust score from its real behaviour, alerts fire the moment a sensor opens, and you can revoke access in one tap straight from the alert instead of walking back through Settings.
One-time $0.99 on Google Play. No account, no cloud, nothing collected. It detects that a sensor was activated — it never sees your photos, video or audio.
Get Spytrap on Google Play — $0.99 →