Your Phone as a Surveillance Tool

It knows where you’ve been every minute of the last several years. Who you’ve talked to. What you’ve searched for. What you’ve bought. How you’ve slept. How many steps you’ve taken. What your heart rate is. What makes you laugh and what makes you angry — because it sees how you react to content.

This isn’t a bug someone planted on you. It’s the phone you bought yourself. Voluntarily. And that you never turn off.

Today isn’t about fear. It’s about understanding. How exactly this works. What data gets collected. By whom. And what you can actually do about it.

App permissions

Let’s start with what happens when you install an app.

You download an app. You tap install. A list of permissions appears — or it doesn’t, depending on your operating system version. You tap “next.” The app is installed.

In those few seconds, you may have given the app access to things you never thought about.

Let’s break down each permission — what it really means. Not technically. Humanly.

Location. This isn’t just “the app knows where you are.” It’s a complete map of your life. Where you live — determined by where the phone is at night. Where you work — by where you spend your working hours. Which doctors you visit — by the location of medical facilities. How often you go to church, a bar, a casino, protests — all of it is visible from your location history.

Location access comes in three types. Always — the app sees you constantly, even when closed. Only while using — sees you only when the app is open. Never — doesn’t see you.

Most apps request “always.” Most apps don’t need it. A flashlight app doesn’t need location at all. A weather app is fine with “only while using.” Navigation needs constant access.

Microphone. This is the permission that raises the most questions — and the most myths. Let’s be honest.

A proven fact — apps you’ve granted microphone access to can use it while the app is active. This is documented and legal if you’ve given permission.

An unproven but widely discussed claim — constant background listening via the microphone without the app being activated. There’s no direct public evidence for this. But there’s something else.

A proven and more interesting fact — your phone doesn’t need to listen to your microphone to know what you’re talking about. Because it knows who you’re talking to — through call metadata. It knows where you were during the conversation — location data. It knows what you searched for before and after — browser history. From this data, the algorithm draws conclusions that are more accurate than direct eavesdropping.

You discussed buying a car with a friend. Your phone didn’t hear the conversation. But it knows you were at a car dealership yesterday — location data. That you searched for reviews of a specific model — browser history. That your friend was also browsing car websites — social-connection analysis. Car ads start appearing. You think you were being listened to. In reality — your data was just being read.

Camera. An app with camera access can take photos and videos while active. Less obviously — it sees everything that comes into frame while it’s open. Including documents you photograph. Including the faces of people around you.

Contacts. This is a permission most people grant without thinking. The app wants to find your friends — makes sense.

What actually happens. The app receives the full list of everyone in your contacts. Their names, numbers, emails. This data goes to a server. The company now knows your social network — who your friends, colleagues, and relatives are. Even if those people never installed the app, their data is already there.

This is exactly how Facebook built shadow profiles of people who never registered — through the contacts of those who did.

Call history. The app sees who you called, for how long, how often. From this, a graph of your social connections is built. Who matters most in your life is determined by call frequency and duration. This is valuable data for advertisers and data brokers.

Files and storage. Access to all files on the phone. Photos, documents, downloads. An app that requested this permission sees everything you’ve stored.

Bluetooth and WiFi. This is a permission few people take seriously. And that’s a mistake.

By scanning WiFi and Bluetooth networks, an app can pinpoint your location to within a few meters — even without GPS. Even indoors. Shopping malls use this technology to track shoppers’ movements through their stores. Without their knowledge.

Data collected without any permissions

There’s a category of data collected without any permission request at all. You didn’t tap anything. You didn’t agree to anything. The data goes out automatically.

IP address. Every time your phone connects to the internet, it transmits an IP address. From it, an approximate location is determined — city, provider, sometimes even a neighborhood.

Device identifiers. IMEI — a unique number for every phone in the world. Unchangeable. Undeletable. It’s transmitted to the cellular operator with every call and text.

Call and SMS metadata. The operator sees who you called, when, for how long. The content of the conversation is encrypted. The metadata isn’t. And metadata says a great deal. NSA research showed that call metadata alone can be used to reconstruct, with high accuracy, a person’s social network, daily routine, professional connections, and personal relationships.

Advertising identifier. GAID on Android, IDFA on iPhone. We covered this in the post about data brokers. A unique code visible to every app with tracking permission. Through it, they synchronize data about you among themselves.

IMSI catchers. What no one talks about out loud

This is a topic I wanted to cover separately — because it’s discussed either in a conspiracy-theory context, or not at all. But it’s a real technology with real applications.

An IMSI catcher is a device that imitates a cellular tower. Your phone searches for the nearest tower — and connects to the catcher, thinking it’s a legitimate operator tower.

What this gives whoever operates the catcher.

IMSI — International Mobile Subscriber Identity — a unique identifier for your SIM card. The catcher obtains it. Now it knows that you — a specific subscriber — are within the device’s coverage area.

Call and SMS metadata — who you’re calling, who’s calling you. Depending on the device type — sometimes even the content of unencrypted calls.

Location accurate to within a few dozen meters — because the device sees how the signal level changes as the phone moves.

Who uses IMSI catchers

Law enforcement — as part of lawful operations with court authorization. This is legal and regulated.

Intelligence agencies — for intelligence-gathering purposes. Documented in many countries.

Private organizations — this is a gray area. In a number of countries, selling and using catchers privately is illegal. In others, it’s weakly regulated. Cases of use by private investigation firms and corporate security services have been documented.

At mass events — demonstrations, conferences, political rallies — the presence of IMSI catchers has been recorded by researchers in several countries. The devices collected the IMSI of everyone present — effectively creating a list of people who attended the event.

How to tell if a catcher is operating nearby

The phone unexpectedly switches from 4G or 5G to 2G — catchers often operate on the 2G standard because it’s less secure. The battery drains faster than usual. Calls drop or call quality suddenly degrades for no apparent reason.

Apps for detecting IMSI catchers exist — AIMSICD for Android, SnoopSnitch. They don’t guarantee 100% detection, but they flag suspicious network patterns.

Airplane mode. Why it doesn’t make you invisible

This is one of the most widespread myths about phone privacy.

“I turned on airplane mode — so I’m not being tracked.”

Not quite.

What airplane mode actually turns off. Cellular connectivity — calls and texts via the operator. WiFi — if you haven’t turned it back on separately afterward. Bluetooth — likewise.

What airplane mode doesn’t stop.

GPS. This is important to understand. GPS is a passive technology. The phone receives signals from satellites — but transmits nothing. Airplane mode doesn’t disable GPS signal reception. Apps that have location access and run in the background continue to record your whereabouts. Once the phone reconnects to the internet, that data gets transmitted.

Local data recording. Apps continue running locally. They log activity. They prepare data packets to send. As soon as airplane mode is turned off, the data goes out.

Hardware identifiers. The IMEI doesn’t go anywhere. It’s simply not transmitted while there’s no connection.

There’s one more level discussed among security researchers.

The baseband processor — a separate processor in the phone that manages radio communication. It operates independently of the main operating system. There are documented cases where this processor remained active even in airplane mode — at a level the user doesn’t control.

This isn’t conspiracy theory — it’s a documented architectural vulnerability of modern phones. It doesn’t pose a direct threat to the average user. But it’s important to understand that airplane mode isn’t absolute protection.

What actually provides full isolation. Only physically disconnecting from power. Or putting the phone in a special shielding case — a Faraday cage. This is a metal case that blocks all radio signals. Used by journalists and lawyers working with confidential sources.

How apps track each other

There’s a mechanism rarely discussed — cross-app tracking, inter-app surveillance.

You’ve installed ten apps. Each of them sees your phone’s advertising identifier — GAID or IDFA. Through this identifier, they all know they’re dealing with the same device. Data collected by App A can be linked to data collected by App B.

A meditation app knows you meditate at 11 PM. A food delivery app knows you order pizza at that same time. A news app knows you read after midnight. An advertising platform connects all of this — and draws conclusions about your sleep patterns and self-control.

Each app on its own collects seemingly harmless data. Together, they build a detailed psychographic profile.

In 2021, Apple introduced App Tracking Transparency — ATT. Now apps on iPhone must ask permission before tracking you across other apps. Most users tap “don’t track.” This has significantly reduced cross-app tracking on iOS.

On Android, a similar system is less strict. Google — an advertising company — isn’t in a hurry to restrict the tracking that underpins its business model.

Cellular operators. The most underrated source of data

We talk a lot about apps and platforms. Almost never about operators. And that’s a mistake.

Your cellular operator sees more than any single app. Because everything you do through your phone passes through its infrastructure.

What the operator sees.

Every call — who, when, how long. Every text — who, when, how much data. Every internet connection — which sites you visited, when, for how long. Location — via tower triangulation, accurate to within a few hundred meters in a city. Tower handoffs — which allow your movement routes to be reconstructed.

What operators do with this data.

They sell aggregated data — for example, to city administrations for traffic analysis. They hand it over on lawful requests from law enforcement. In a number of countries, they sell it to data brokers.

In the US in 2019, a scandal broke out. It turned out that the largest American operators — AT&T, T-Mobile, Sprint — were selling their subscribers’ real-time location data to private companies. Including companies that resold it to anyone. Including private investigators and bounty hunters.

For money. Data on where you are right now. Sold by the operators. Without your knowledge.

The FTC fined the operators. The practice was stopped — officially. What happens unofficially is unknown.

In Europe, the GDPR restricts such practices far more strictly. But operators still collect and retain metadata — as required by data-retention laws for law-enforcement purposes.

What actually works. Practical steps.

What to do: minimal effort

Level one — minimal effort, maximum impact.

Check the permissions of every app right now.

Android: Settings → Apps → select an app → Permissions. Or: Settings → Privacy → Permission Manager — check by category. Location, microphone, camera, contacts — who has access.

iPhone: Settings → Privacy & Security. There, by category — location, microphone, camera, contacts, photos.

A rule that works. If you can’t explain why an app needs a given permission, revoke it. A flashlight doesn’t need a microphone. A calculator doesn’t need location. A game doesn’t need contacts.

Switch location access from “always” to “only while using” for every app except navigation.

Turn off your advertising identifier.

Android: Settings → Google → Ads → Delete advertising ID. In newer Android versions, this is available directly.

iPhone: Settings → Privacy → Tracking — turn off “Allow Apps to Request to Track.” Settings → Privacy → Apple Advertising — turn off personalized ads.

This won’t make you invisible. But it removes the main tool for cross-app tracking.

Level two — conscious app selection.

Before installing any app — thirty seconds of checking. Go to the app’s page in the store. Find the “Privacy” or “App Data” section. Look at what data is collected and who it’s shared with.

Google Play and the App Store now require developers to disclose this information. It’s there — nobody just looks at it.

Alternative apps that collect less.

Browser — Firefox or Brave instead of Chrome. Chrome is a product of Google, an advertising company. Firefox and Brave are built by organizations with a different business model.

Messenger — Signal instead of WhatsApp. Signal is a nonprofit organization. End-to-end encryption. Minimal data collection. WhatsApp is owned by Meta and shares metadata with its parent company.

Search — DuckDuckGo or Brave Search instead of Google. They don’t build a profile from your queries.

Keyboard — this is a permission many people grant to third-party keyboards without thinking. A keyboard sees everything you type. Passwords, messages, search queries. Use your operating system’s default keyboard.

Level three — for those who want to go deeper.

VPN. Hides your real IP address from sites and apps. Your traffic goes through the VPN provider’s server. Important — you’re now trusting the VPN provider with what you used to trust your internet provider with. Choose a provider with a verified no-logs policy — Mullvad, ProtonVPN.

DNS over HTTPS. Technically encrypts DNS queries, which are normally transmitted in plain text. Your provider sees that you’re accessing the internet, but not which specific sites. This is configured in your phone’s WiFi settings.

A separate phone for sensitive activity. This is a level not everyone needs. But journalists, lawyers, and activists use two phones. One for everyday use. Another — only for confidential work, with no personal accounts and a minimum of apps.

Your rights regarding phone data.

The GDPR applies here too.

Apps that collect your data are required to provide access to it on request. Article 15. They’re required to delete it on request. Article 17. They’re required to stop processing for advertising purposes upon objection. Article 21.

A cellular operator is also a data controller. You can request what data it holds about you. Call history, texts, the location data it retains. That’s your right.

If an app uses your data in a way you didn’t expect and didn’t authorize — that’s grounds for a complaint to the AKI [Estonian data protection authority].

One practical check, right now.

Go to settings.google.com if you have Android or a Google account. Section “Data & Privacy.” There — “Location History.” Tap “Manage Location History.”

Look at what’s there.

You’ll most likely see a map of your movements. Over months. Over years. Accurate to the street level. Every day is marked. You can look at a specific day — where you were, at what time, for how long.

That’s what Google keeps on your movements.

You can delete it. And set it to auto-delete every three months. Right there on the same page.

This will take five minutes. And it’s the first conscious step toward making your phone work for you — not against you.

One last thing.

The phone is an amazing tool. It gives access to knowledge, people, and opportunities that no generation before us has had.

It’s also the most detailed surveillance tool that has ever existed. Voluntarily carried. Constantly powered on. Never turned off.

That’s not a reason to give it up. It’s a reason to understand what you’re dealing with.

A person who understands how their phone works makes different decisions. Which apps to install. Which permissions to grant. What to turn on and what to turn off.

Not paranoia. Literacy.

The same kind of literacy as reading a contract before signing it.

← All journal entries