You've installed a handful of apps, granted a few permissions, and now you wonder: which of those apps actually need the access they've been given? Over‑privileged permissions can expose your location, contacts, microphone, or even your SMS messages to apps that don't need them. This tutorial shows you a concrete, repeatable workflow to audit every permission on your device and trim the excess, using only the built‑in Permission Manager and, when you need more detail, the Android Debug Bridge (ADB).
Since Android 6.0 (Marshmallow) most permissions are runtime – the system asks you each time an app tries to use a sensitive feature. However, a few permissions are still granted at install time, and many users simply click “Allow” without reviewing the request. Over time, the cumulative effect is a device that knows far more about you than you intended.
Auditing permissions helps you:
Two optional prerequisites make the process smoother, but the core UI‑only steps work on any modern Android device.
Settings → About phone and tap Build number seven times.Settings → System → Developer options and toggle USB debugging on.On Windows, macOS, or Linux you can download the platform‑tools zip, extract it, and add the folder to your system PATH.
If you prefer to stay entirely on the phone, skip the ADB section and continue with the built‑in Permission Manager.
All stock Android builds (Pixel, AOSP, and most OEM skins) include a central place to view permissions per app.
Settings.Privacy → Permission manager. On some devices the path is Apps → Permission manager or Settings → Apps → Advanced → Permission manager. The exact wording may vary, but the function is the same.Use the filter dropdown (usually labelled “Allowed”, “Denied”, or “All”) to focus on the Allowed column – those are the permissions you’ve granted.
Not all permissions are equal. Focus first on the groups that can reveal personal data or incur costs:
For each app listed under these groups, ask yourself: Does this app truly need this access to function? If the answer is “no”, revoke the permission.
The UI view is convenient, but it hides two useful details:
android.permission.* name (useful for scripting).READ_PHONE_STATE on older apps).ADB lets you extract a full permission list, filter it, and even batch‑revoke permissions.
adb devices
If your device appears with the word device next to it, you’re ready. If it shows unauthorized, check the phone for a prompt to trust the computer and accept it.
adb shell pm list packages -3
The -3 flag limits the output to third‑party apps (excluding system packages). Copy the list into a text editor for later reference.
Replace com.example.app with the package name you obtained above.
adb shell dumpsys package com.example.app | grep granted=true
The command prints lines like:
android.permission.ACCESS_FINE_LOCATION granted=true
These are the permissions currently granted to that app.
Run the following one‑liner to create a CSV‑style file that you can open in a spreadsheet:
adb shell pm list packages -3 | cut -d':' -f2 | while read pkg; do
echo -n "$pkg,";
adb shell dumpsys package $pkg | grep granted=true | cut -d' ' -f1 | tr '\n' ';' ;
echo;
done > permission_report.csv
The resulting permission_report.csv contains one line per app, with a semicolon‑separated list of granted permissions. Sort, filter, and highlight any permission that looks out of place.
Use the exact permission string from the report. Example: revoking location from com.example.map.
adb shell pm revoke com.example.map android.permission.ACCESS_FINE_LOCATION
ADB will respond with Success if the operation succeeded. Some permissions cannot be revoked because they are classified as “system” or “privileged” – attempting to revoke those will return an error like Permission revocation failed: Not a runtime permission.
If you have identified a set of apps that should never have a particular permission (e.g., no app should have READ_SMS unless it’s a messaging app), you can script a batch revocation:
#!/bin/bash
TARGET_PERMISSION=android.permission.READ_SMS
adb shell pm list packages -3 | cut -d':' -f2 | while read pkg; do
if adb shell dumpsys package $pkg | grep -q $TARGET_PERMISSION; then
echo "Revoking $TARGET_PERMISSION from $pkg"
adb shell pm revoke $pkg $TARGET_PERMISSION
fi
done
Save the script, make it executable (chmod +x revoke_sms.sh), and run it. Always review the list first; batch actions can break apps that legitimately need the permission.
After revoking, double‑check that the permission is truly gone:
granted=true list.If an app crashes or stops working, you’ll see a notification that a required permission is missing. In that case you can either re‑grant the permission or uninstall the app if it’s not essential.
platform-tools folder is in your system PATH, or invoke it with the full path (e.g., ~/android-sdk/platform-tools/adb).By following this workflow you gain a clear, repeatable picture of what each app on your Android device can see and do. Regular audits keep your personal data under your control without the need for rooting or third‑party privacy suites.









