Rules
Part of Privacy settings: rules, examples and updates for 2027
Privacy settings checklist: facts, examples and context
A new phone privacy checklist in three passes: what to settle before the switch, which permissions to grant during setup, and how to retire the old device.
A new phone is the one moment when every privacy decision is open at once. Permissions are being granted from scratch, apps are asking for your contacts again, and the old device is about to leave your house with several years of your life on it.
Menu names differ between makes and versions, so this checklist describes the setting to look for and why it matters rather than where to tap. Do the first section before you power the new phone on.
What to take away
- Grant the narrowest option that makes the app work, and revisit after a few weeks.
- Permissions are being granted from scratch, apps are asking for your contacts again, and the old device is about to leave your house with several years of your life on it.
- Menu names differ between makes and versions, so this checklist describes the setting to look for and why it matters rather than where to tap.
Before you switch (while the old phone still works)
1. Confirm your recovery details. On your email and your most important accounts, check the recovery address and phone number are current: while you can still receive codes on the old device. This is the step people skip and then spend a week undoing.
2. Deal with your authenticator app first. Two-factor codes do not move by themselves. Use the app's own transfer or export process deliberately, before anything else. Getting locked out of your own accounts is the most common way this transition goes badly.
3. Save your backup codes offline. Print them or write them down. Not in a note on the phone you are about to replace. The reasoning for the factor itself is in CISA's guidance on multi-factor authentication, and the wider account order is in account security.
4. Check what is actually backed up. Photos and app data usually are. Message history often is not, or is only in a backup you have to enable. Find out before the old phone is wiped, not after.
5. List the apps tied to your phone number. If the number is changing, those logins will break. Update them while both devices work.
Moving the data
6. Prefer a direct transfer to restoring an ancient backup. An old backup carries forward years of accumulated permissions, stale sessions, and apps you stopped using. A direct device-to-device transfer is cleaner.
7. Do not bring apps you no longer use. This is the cheapest moment you will ever get to drop them, along with whatever access and background activity they had.
8. Move messaging apps deliberately. Know whether history transfers, whether the backup is encrypted, and whether it lands in a cloud account with weaker sign-in than the app itself.
Sign-in and recovery on the new phone
9. Set a long device passcode. Six digits or more, or a passphrase. Biometrics are the convenience layer on top; the passcode is what actually protects the device, and it is what gets asked for after a restart.
10. Lock down the platform account the phone signs into. It holds your backups, your photos, and your location, and it can often reset other things. Give it the strongest sign-in available and check its trusted-device list.
11. Ask your mobile carrier for a port-out or transfer PIN. Without it, someone who convinces the carrier to move your number receives every text-message code you have.
12. Turn on find-my-device and remote wipe, and check it actually works before you need it.
The lock screen
Everything here is about what a person holding your locked phone can see or do.
13. Hide message content in notifications. Previews on the lock screen show password reset codes, bank alerts, and private conversations to anyone who picks it up. Show that a message arrived, not what it says.
14. Check notification settings for banking and authenticator apps specifically, since these are the ones where a preview is a genuine key.
15. Decide what works while locked. Voice assistant, quick settings, wallet, camera, reply-from-notification, and USB accessory access are usually separately controllable. Convenience and exposure are the same switch.
16. Set a short auto-lock. Most real-world access to phones is opportunistic and brief.
Permissions
Grant the narrowest option that makes the app work, and revisit after a few weeks.
17. Location. Prefer "while using" over "always", and approximate over precise wherever the app does not genuinely need the exact position. Very few apps do.
18. Contacts. The most consequential permission on the phone, because it exposes other people's details, not just yours. Uploading your address book is how you get suggested to people you deliberately avoid. Decline it by default.
19. Photos. Grant access to selected photos rather than the whole library. A single-image share does not require the archive.
20. Camera and microphone. Review which apps hold these and remove the ones that do not obviously need them. Learn what the on-screen indicator looks like on your phone.
21. Local network, Bluetooth, and nearby devices. These are used for proximity and presence tracking as well as for legitimate features. Deny unless a feature you use depends on it.
22. Background activity and refresh. Restricting it for apps you use occasionally reduces both battery drain and how often they phone home.
Background sharing and identifiers
23. Reset and, where possible, disable the advertising identifier. It is the number that ties your activity across apps together.
24. Decline app tracking prompts by default. You can always allow one later for an app you actually care about.
25. Turn off usage and diagnostics sharing you do not want to send, and check personalized advertising in the platform account, which is a separate setting from the device one.
26. Check Wi-Fi and Bluetooth scanning. Many phones keep scanning for location purposes even when the radios appear off, and most support randomising the address the phone broadcasts to networks. Turn randomisation on.
Social apps, set up again from scratch
27. Refuse the contact-upload prompt during setup. Every social app asks again on a new device, and this is the moment people grant it without thinking. If you have granted it before, look for the option to delete the contacts already uploaded.
28. Re-check discovery and message settings. Whether people can find you by phone number or email, and who may send you message requests. A reinstall sometimes restores defaults, and these two settings decide whether unwanted contact reaches you at all. The full pass is in the social media privacy audit.
Retiring the old phone
29. Sign out of your accounts before wiping. Devices left signed in to the manufacturer's account often remain locked to it, which blocks resale and complicates trade-in.
30. Remove the SIM, and delete any eSIM profile.
31. Do a full factory reset, and confirm the device is encrypted so the reset makes the old data unreadable. Manually deleting files is not the same thing.
32. Remove the device everywhere else. Take it off the find-my list and out of the trusted-device list on your accounts, and sign out its sessions in your important apps. A traded-in phone that still appears as an active session is a loose end.
If you are handing the old phone to a family member rather than selling it, do all of the above anyway and set it up as a new device for them. Passing it on with your accounts still on it is how shared-device problems start. Selling it rather than passing it on brings its own set of decisions, which are in marketplace scams.
Keeping the new device current is the part that quietly closes the technical routes, which is the point of CISA's advice on updating software.
Common questions
Do I need to do all of this on day one?
The first section, yes, before you switch. The lock screen and permissions can wait until the evening. Retiring the old phone should not wait long: an unwiped phone in a drawer is still an unwiped phone.
Is a passcode enough, or do I need a fingerprint or face recognition?
Use both. Biometrics make a long passcode practical, which is the point. The passcode is the stronger secret and it is worth making it a real one.
What if I want to keep the old phone as a spare?
Reset it anyway, keep it signed out, and store it somewhere sensible. An old device left logged in is an active session you are not watching.
Should I reuse my old backup to save time?
Only a recent one. A very old backup restores permissions and apps you have since had good reasons to remove, and you will not notice which ones came back. For the reasoning behind the defaults you are choosing, see privacy settings.