Running in the Dark: What Your Apps Are Doing When You Are Not Looking
Photo: James Nash (aka Cirrus), CC BY-SA 2.0, via Wikimedia Commons
There is a reasonable assumption most smartphone users carry with them: when you close an app, it stops. You swipe it away, you lock your screen, and you move on with your day. The app, presumably, does the same.
That assumption is incorrect — and the gap between what users believe and what is actually happening represents one of the most underappreciated privacy vulnerabilities in modern mobile computing.
Background app activity is not a fringe concern reserved for security researchers and privacy advocates. It is a routine feature of the mobile ecosystem, one that app developers rely on extensively and that operating systems permit with varying degrees of transparency. For the average American smartphone user, the consequences range from a mysteriously depleted battery to the quiet, continuous exfiltration of location data, contact lists, and behavioral patterns.
What Background Permissions Actually Allow
When an app requests permission to run in the background, it is asking for the ability to execute processes even when the user is not actively engaging with it. On both Android and iOS, this can encompass a wide range of activities: refreshing content feeds, syncing data to remote servers, monitoring device sensors, tracking location, and logging usage behavior.
Some of these functions are genuinely useful. A navigation app that loses your position the moment you switch to your music player would be frustrating and potentially dangerous. A messaging app that cannot deliver notifications without being actively open would defeat its own purpose.
The problem arises when these permissions are granted broadly and then exploited beyond their stated function. A weather app that requests background location access to deliver local forecasts may, in practice, be transmitting your precise GPS coordinates to advertising networks dozens of times per day. A retail app with background refresh enabled may be cataloging your purchasing patterns and device identifiers long after your last transaction.
The technical architecture that enables this behavior is largely invisible to users. Neither Android nor iOS provides a real-time dashboard showing exactly what each app is transmitting at any given moment. What users see instead are vague permission categories and occasional prompts that are easy to dismiss without fully understanding their implications.
The Apps Most Likely to Overreach
Not all apps behave the same way in the background. Research consistently identifies several categories as particularly aggressive in their background data collection practices.
Social media platforms are among the most active background operators. Applications in this category frequently request access to location, contacts, microphone, and camera, and many retain background refresh permissions that allow continuous data synchronization. Independent analyses have documented these apps transmitting device data at intervals measured in minutes rather than hours.
Free utility and productivity apps — including certain flashlight tools, battery optimizers, and file managers — have historically been among the worst offenders. Because their primary function requires minimal ongoing data collection, aggressive background behavior is particularly difficult to justify on functional grounds. Several apps in this category have been removed from major app stores following investigations into unauthorized data harvesting.
Mobile games with advertising integrations represent another high-risk category. The advertising software development kits embedded in many free games are designed to collect behavioral and location data to serve targeted advertisements. These SDKs often operate independently of the game itself, continuing to collect data according to their own logic rather than the stated purpose of the host application.
Navigation and ride-sharing apps occupy a more complicated position. Their core functionality is genuinely location-dependent, but the scope of background location access they request frequently extends well beyond what their features require.
Why the Settings Are Designed to Confuse You
Both Apple and Google have made incremental improvements to background permission controls over the years. iOS introduced the option to allow location access only while using an app. Android added granular permission management in later versions of the operating system. These are meaningful steps.
However, the permission management interfaces on both platforms continue to present information in ways that obscure rather than illuminate the actual risks. Permission categories are labeled in functional terms — "location," "contacts," "background app refresh" — without explaining what specific data is being collected, where it is being sent, or how long it is retained.
The default settings on many devices also favor permissiveness. Apps installed from major stores frequently arrive with background permissions pre-enabled, and the process of reviewing and adjusting those permissions requires navigating multiple layers of system settings that most users never visit.
There is also a deliberate friction asymmetry at work. Granting a permission typically requires a single tap on a prompt that appears at a convenient moment. Revoking that same permission requires locating the app in the device's settings menu, finding the relevant permission category, and manually toggling it off — a process that assumes the user knows to look in the first place.
How to Audit and Restrict Background Activity
Regardless of whether you are using an iPhone or an Android device, a systematic review of your background permissions is a practical and achievable security measure. The following steps apply broadly across current operating system versions, though specific menu labels may vary.
Start with location permissions. On both iOS and Android, you can view which apps have been granted location access and under what conditions. For any app that does not have a clear, ongoing need for your precise location, revoke background location access entirely. Many apps function perfectly well with location access limited to active use only, or disabled altogether.
Review background app refresh settings. iOS users can find this option under General settings, where individual apps can be toggled off. Android handles background activity through battery optimization settings, which allow you to restrict apps from running processes when not in active use. Disabling background refresh for apps that do not require real-time updates — shopping apps, games, news aggregators — yields both privacy and battery benefits.
Examine data usage by app. Both operating systems provide breakdowns of mobile data consumption by application. An app that is consuming significant data in the background relative to your actual usage of it warrants scrutiny. Unusually high background data consumption is a reliable indicator that an app is transmitting information beyond what its stated function requires.
Audit contact and sensor permissions. Many apps request access to your contact list, microphone, or camera without a clear functional justification. Reviewing these permissions and revoking unnecessary access reduces the volume of personal data available for collection.
Consider uninstalling rather than restricting. For apps that require aggressive permissions to function — and for which no privacy-respecting alternative exists — removal is often the most effective option. An app that is not installed cannot collect data regardless of permission settings.
The Broader Principle
Background app behavior illustrates a fundamental tension in the current mobile ecosystem: the interests of app developers and the advertising networks they serve are not always aligned with the interests of users. Permissions that appear reasonable in isolation — location access for a weather app, contact access for a social platform — can aggregate into a comprehensive profile of a user's movements, relationships, and habits when combined across dozens of applications over months or years.
The responsibility for managing this risk has been placed, largely by default, on individual users. That placement is imperfect. The tools available to consumers are less intuitive than they should be, and the volume of information required to make fully informed permission decisions is rarely provided at the moment of consent.
What is within reach, however, is a more deliberate and informed approach to the permissions already granted on your device. A single afternoon spent auditing background access across your installed applications is not a complete solution to mobile privacy risk — but it is a meaningful one, and it begins with the recognition that closed does not mean stopped.