Privacy

The 5-Minute Privacy Check I Run Before Installing Any New App

I used to install apps the way most people do: search, tap, accept whatever permissions pop up, start using it. Then one day I watched a flashlight app request access to my contacts and location, and I finally asked the obvious question — why does a flashlight need to know who my friends are?

Since then, every app goes through the same five-minute check before it touches my phone or laptop. It has saved me from at least a dozen bad installs, and it’s simple enough that I actually stick to it.

Minute one: who actually makes this?

I look up the developer, not the app. A real company with a website, a physical address in the app-store listing, and a history of other products is a different risk profile than “SuperTools LLC” registered nowhere, publishing forty near-identical utilities.

Red flags I’ve learned to take seriously:

  • The developer’s “website” is a Facebook page or a bare landing page with no contact info
  • The company name in the store doesn’t match the name in the privacy policy
  • Dozens of apps published in a short window — that’s a template farm, and the business model is your data

Minute two: the permission sniff test

Before installing, both major app stores show what an app can access. The question is never “are these permissions scary?” — it’s “does this permission match the job?”

A navigation app asking for location: fine. A PDF reader asking for your microphone: no. A keyboard asking for full network access: that one deserves real thought, because everything you type could travel somewhere.

On desktop the equivalent check is the installer itself. If a simple utility wants admin rights, browser extensions, and a “companion updater service”, I close the installer.

Minute three: skim the privacy policy for three phrases

Nobody reads privacy policies, including me. But you don’t have to read them — you have to search them. I Ctrl+F for three things:

  1. “third parties” — how many, and for what purpose? “Share with partners for marketing” means your data is the product.
  2. “retain” — how long do they keep data after you delete your account? “As long as necessary” with no cap is a bad answer.
  3. “sell” — under CCPA, companies that sell data have to say so. It’s remarkable how often the answer is buried in plain sight.

Ninety seconds of searching tells you more than the star rating ever will.

Minute four: check the exit before you enter

I try to find the account-deletion path before creating an account. If deleting requires emailing support, or the help articles dance around the question, that tells you how the company thinks about your data. Services that respect users make leaving easy.

Minute five: recent reviews, sorted by newest

Star ratings average years of history; an app that went bad after an acquisition can coast on old five-star reviews for a long time. Sorting by newest surfaces the real signal: “started showing ads everywhere after the last update”, “now requires an account”, “battery drain since March”. Three complaints about the same thing in the last month is a pattern, not noise.

What this actually prevents

None of this requires technical skill, and the whole routine fits in the time it takes to make coffee. What it prevents is the slow accumulation of small privacy leaks: the note-taking app that scans your address book, the wallpaper app that pings an analytics server every hour, the free VPN that is free because it resells your browsing data — the most expensive kind of free there is.

The apps that pass the check earn a spot on my devices. The ones that don’t join a long list of things I almost installed — and the best security incident is the one that never gets the chance to happen.