← All Guides

Notifications and Permissions

Every app on your phone is a request engine. It asks for access to your location, your contacts, your microphone, your files — and most people tap "Allow" without reading. On GrapheneOS, you have more granular control over these requests than on any stock Android device, including tools that do not exist elsewhere. This guide covers how to use them.

Why it matters

Permissions are the boundary between an app doing what you installed it for and an app surveilling your life. A weather app does not need your contacts. A messaging app does not need your location at all times. A game does not need your microphone.

Stock Android gives you basic permission toggles. GrapheneOS goes further with network permission controls, Contact Scopes, and storage isolation that let you define exactly what each app can and cannot access. But these tools only work if you use them — and review them regularly.

Reviewing and configuring permissions

  1. Open the permission panel for any app. Go to Settings > Apps > select the app > Permissions. You will see a list of every permission the app has requested, grouped by what is currently allowed and what is denied.
  2. Review each permission category. The key categories are: Location, Microphone, Camera, Contacts, Phone, SMS, Storage, Sensors, and Nearby Devices. For each one, ask whether the app genuinely needs this access to function. If not, set it to "Don't allow" or "Ask every time."
  3. Configure Contact Scopes for apps that demand contacts access. Go to Settings > Apps > select the app > Permissions > Contacts. When you grant contacts access, GrapheneOS offers Contact Scopes — a feature that lets you expose only specific contacts to the app rather than your full address book. If a ride-sharing app demands contacts to share your trip status, you can limit it to two or three people instead of handing over everyone you have ever saved.
  4. Review the network permission. GrapheneOS adds a network access toggle that stock Android does not have. Go to Settings > Apps > select the app > Permissions. You will see a network access toggle. Revoking this completely blocks the app from accessing the internet — both Wi-Fi and mobile data. This is useful for apps that work offline (calculators, note-taking apps, some games) where network access serves only the developer's analytics or advertising.
  5. Configure lock screen notification privacy. Go to Settings > Notifications > Notifications on lock screen. You have three options: Show all notification content, Hide sensitive notification content, or Hide all notifications on lock screen. At minimum, select "Hide sensitive content." This prevents message previews, banking alerts, and other private information from being visible to anyone who glances at your locked screen.
  6. Review sensitive notifications setting. Go to Settings > Notifications > Sensitive notifications. This controls whether notification content from apps marked as sensitive is displayed when the device is locked. Disable this if you want an additional layer of lock screen privacy.
  7. Configure background activity per app. Go to Settings > Apps > select the app > Battery > Battery optimization. Three options exist: Unrestricted means the app can always run in background and will never be paused. Optimized is the default — the system manages background activity normally. Restricted means the app has almost no background activity and will not run unless you open it.
  8. Exempt sandboxed Google Play from battery optimization. If you use sandboxed Google Play Services for push notifications, it needs to run in the background reliably. Go to Settings > Apps > Google Play Services > Battery and set it to Unrestricted. Without this, push notifications for apps that rely on Google's Firebase Cloud Messaging may arrive late or not at all.

Best practices

  • Audit permissions monthly. Set a recurring reminder. Apps request new permissions after updates, and the system may grant them based on previous consent patterns. A five-minute review once a month catches permission creep before it accumulates.
  • Default to "Ask every time" for location. Very few apps need constant location access. Setting location to "Ask every time" means you consciously approve each request and can deny it when the context does not justify it.
  • Use Contact Scopes as your default contacts strategy. Rather than choosing between "full access" and "no access," Contact Scopes lets you give apps exactly the contacts they need. This is particularly useful for messaging apps where you want to find specific people without exposing your entire address book.
  • Restrict background activity for apps you use infrequently. There is no reason for an app you open once a week to run in the background consuming resources and potentially communicating with servers.
  • Keep notifications hidden on lock screen for messaging and finance apps at minimum. Even if you trust the people around you, screen visibility in public spaces is a real exposure vector.

Common mistakes

  • Granting all permissions at install time. Many people tap "Allow" through every prompt just to get the app working. Take thirty seconds to evaluate each request. You can always grant a permission later if the app genuinely needs it.
  • Never reviewing permissions after initial setup. Your permission decisions at install time are a starting point, not a final state. Apps change. Your usage changes. Review regularly.
  • Not knowing Contact Scopes exists. This is one of GrapheneOS's most useful privacy features, and many users never discover it. If you have been giving apps full contacts access because the alternative was breaking the app, Contact Scopes is your solution.
  • Setting everything to Unrestricted battery. This defeats the purpose of background activity management. Only exempt apps that genuinely need persistent background access — primarily sandboxed Google Play Services and apps where real-time notifications are critical.
  • Ignoring the network permission toggle. Revoking network access for offline-capable apps is one of the simplest and most effective privacy measures available. A calculator with no internet access cannot send telemetry. An offline note app with no network cannot sync your private thoughts to a server.

Reality check

Permissions are not a one-time configuration. They are an ongoing practice. Apps update, new permissions get added, and your own usage patterns change. The tools GrapheneOS provides — Contact Scopes, network toggles, granular permission controls — are more powerful than what any stock device offers, but they require you to engage with them.

No permission system can protect you from an app that is fundamentally designed to collect data. If an app's core business model depends on harvesting your information, restricting permissions may break it or degrade it to the point of being unusable. In those cases, the right move is finding an alternative, not trying to tame a hostile app with toggles.

Permissions are where your privacy intentions become actual device behaviour. GrapheneOS gives you controls that do not exist on stock Android — network permission toggles, Contact Scopes, and profile-level isolation. Use them deliberately, review them regularly, and treat every permission request as a question that deserves a considered answer rather than an automatic approval.

Take control of what your apps can access — starting with a device built for privacy.

Browse secure devices or ask us on WhatsApp.