← All Guides

Why Normal Smartphones Are Not Private

Every stock Android and iOS device collects data continuously, silently, and by design. This is not a bug. It is the business model. Understanding what happens behind the screen is the first step toward doing something about it.

Data collection is constant

Your phone does not wait for you to open an app before it starts transmitting data. Background services run continuously, syncing location history, Wi-Fi access points, Bluetooth beacons, app usage patterns, and device identifiers to remote servers. Studies have shown that a stock Android phone contacts Google servers thousands of times per day, even when idle and not actively in use.

iOS behaves similarly. Apple collects device analytics, Siri usage data, location data, and app telemetry. Opting out of analytics in settings reduces some collection, but does not eliminate it. Core system services continue to transmit regardless of user preferences.

Background services you cannot disable

Both platforms include services that cannot be fully disabled through settings. Google Play Services on Android handles push notifications, location services, device authentication, and app licensing. It runs with system-level privileges and cannot be uninstalled on a stock device. It has access to your contacts, calendar, location, network state, and more.

On iOS, system daemons handle similar tasks. iCloud syncing, Find My, Siri processing, and diagnostics all operate below the user-facing settings layer. Turning off individual toggles does not stop the underlying processes from running.

Google and Apple telemetry

Google's telemetry includes your search history, voice recordings (if Assistant is enabled), location timeline, app install history, advertising identifier, and device fingerprint. This data is tied to your Google account and used for ad targeting, product development, and compliance with law enforcement requests.

Apple's telemetry is less advertising-focused but still substantial. Device diagnostics, Siri audio samples, Maps usage, and App Store behaviour are all collected. Apple's privacy marketing emphasises on-device processing, but significant data still leaves the device, particularly when iCloud is enabled.

Why settings do not fix it

Privacy settings on both platforms are designed to give users a sense of control without fundamentally changing how the operating system works. You can disable location history, but the device still records cell tower connections. You can turn off ad personalisation, but the advertising identifier still exists. You can deny an app camera access, but the OS itself retains full hardware access at all times.

The problem is architectural. These operating systems were built to collect data. Adjusting settings is like closing curtains in a glass house. The structure itself is the issue.

What this means for you

If your work, personal circumstances, or principles require genuine privacy, settings-level changes on a stock device are insufficient. You need a system that was designed from the ground up to not collect data in the first place. That means a different operating system, not just different settings.

What a privacy-first architecture looks like instead

The alternative is not "the same phone with different settings" — it is an operating system built without the vendor's telemetry layer in the first place. GrapheneOS ships with no Google Play Services baked into the system, no advertising ID, and no background sync to a vendor account by default. Apps that genuinely need Google's compatibility layer (some banking apps, Maps) can still run it — but sandboxed as an ordinary app you install and can remove, not as a system-level component with permanent access to the device.

That architectural difference is why disabling a setting on a stock phone and removing the collection layer entirely are not the same category of change. One asks the vendor to stop; the other removes the vendor from the loop.

If you require real control, you need a system designed for it.

Browse secure devices built on GrapheneOS, or talk to us on WhatsApp about your requirements.

Frequently asked questions

Can I fix this with privacy settings on my current phone?

Only partially. Settings-level toggles reduce some collection but do not remove system-level services (Google Play Services on Android, core daemons on iOS) that continue running with elevated access regardless of user preferences.

Does turning off ad personalisation stop tracking?

No. It stops some ad targeting based on the data collected, but the advertising identifier and the underlying data collection typically continue. The identifier still exists; only its use for ad personalisation is affected.

What actually removes the collection instead of just limiting it?

An operating system that never includes the vendor telemetry layer in the first place, such as GrapheneOS — rather than a stock OS with settings adjusted after the fact.