AI App Permissions: What to Allow and What to Deny

AI App Permissions: What to Allow and What to Deny

An AI chat app needs very few permissions to work. Photo or camera access lets you ask about a picture, and microphone access is only needed for voice features. Contacts, location, calendar and tracking almost never need to be switched on for a chatbot. Give each app the least access that makes the feature you actually use work, pick “selected photos” instead of your whole library, and deny everything else. You can always grant more later.

That’s data minimization, the same principle privacy laws ask companies to follow, applied from your side of the screen.

What permissions do AI apps ask for, and do they need them? #

PermissionLegitimate reasonWhen to say no
PhotosAttaching a picture to ask aboutAlways choose selected photos, not full library
CameraSnapping a photo of a menu, sign or formIf you never ask about photos
MicrophoneVoice chat or dictation inside the appIf you only type
ContactsRarely any for a chatbotAlmost always
LocationLocal answers like weather or nearby placesDeny, or allow “While Using” with approximate location
Calendar, email, cloud driveAssistants that act on your schedule or inboxUnless you rely on that feature
Tracking (iPhone) / advertising ID (Android)Personalized adsAlways safe to decline
NotificationsReminders and repliesYour call; low risk
Accessibility or screen readingAssistants that read or control other appsOnly for apps you trust completely

Two rows deserve extra care.

Accessibility access lets an app see and interact with whatever’s on your screen, in every app. It’s powerful and meant for assistive tools. An AI app that asks for it can read your messages and banking screens, so grant it only when you know exactly why.

Connected accounts such as email, calendar or cloud storage are permissions too, just granted inside the AI service instead of your phone’s settings. Anything connected can be read by the AI, and by extension exposed to hidden instructions in the content it reads. We explain that risk in what is prompt injection.

Photos: share a few, not your whole library #

Photo access is the permission AI apps ask for most, and the one most worth limiting.

  • On iPhone, when an app asks for photo access you can choose to share only selected photos. You can change it later in Settings → Privacy & Security → Photos, where each app shows Full Access, Limited Access or None.
  • On Android, newer versions include a system photo picker that hands an app only the images you pick. When an app asks for broad media access, look for the option to allow selected photos, or pick “Don’t allow” and use the share sheet instead.

Limited access means an app you forgot about can’t browse years of pictures of your kids, your IDs and your screenshots. For what cloud chatbots do with images you upload, see is it safe to upload photos to ChatGPT.

How to review AI app permissions on iPhone #

  1. Open Settings → Privacy & Security.
  2. Tap a permission such as Microphone, Camera, Contacts or Location Services to see every app that has it, and switch off the ones that don’t need it.
  3. Or go to Settings, scroll to the app itself, and review everything it has in one place.
  4. Under Privacy & Security → Tracking, turn off apps you don’t want tracking you across other companies’ apps and sites.
  5. Turn on App Privacy Report in the same menu to see when apps actually used your camera, microphone and location.

How to review AI app permissions on Android #

  1. Open Settings → Apps, pick the app, and tap Permissions.
  2. Set each one to Allow only while using the app, Ask every time or Don’t allow.
  3. For a bird’s-eye view, open the Permission manager under Security & privacy (the menu name varies by brand) to see every app with a given permission.
  4. Leave on the option that removes permissions from apps you haven’t used in a while.
  5. Under Settings → Privacy → Ads, delete your advertising ID if you don’t want personalized ads.

Third-party AI keyboards: be careful with Full Access #

AI keyboards are the permission trap people miss. On iPhone, a third-party keyboard can only send what you type to its servers if you turn on Allow Full Access. Many AI keyboards need it for their features to work, which means every message, search and password field you type in could pass through them. Our guide to keyboard privacy covers which keyboards process text on the device.

What permissions does Personal LLM ask for? #

Personal LLM runs AI models entirely on your phone, so it doesn’t need access to your accounts, contacts or location. It asks for access to your photos, or your camera, only when you want to attach a picture for a vision model to read. It has no voice input, so it has no reason to use your microphone. There’s no account to create.

Two things do use the network: downloading a model file once from Hugging Face, and ads from Google AdMob in the free version. On iPhone, the app asks for App Tracking Transparency permission, and if you decline, ads are non-personalized. On Android, ads use the standard advertising ID, which you can delete in settings. Your chats, the photos you attach and your settings stay on the phone.

Before you install an AI app #

  1. Read the store privacy label. It shows what’s collected and whether it’s linked to you. See AI app privacy labels explained.
  2. Watch the first-launch prompts. A chatbot asking for contacts or precise location before you’ve typed a word is a warning sign.
  3. Deny first, grant later. If a feature needs a permission, the app will ask again when you try to use it.
  4. Delete apps you stop using, along with the access they still hold.

Frequently asked questions #

Should I give ChatGPT access to my photos? #

Only if you want to ask about pictures, and then choose selected photos rather than your full library. Anything you attach is uploaded to OpenAI’s servers, so avoid photos of IDs, documents with account numbers or other people in private moments.

Is it safe to give AI apps microphone access? #

It’s reasonable for apps with voice features you use, set to allow only while the app is open. Your phone shows an indicator whenever the microphone is active. If you only type, deny it. Our guide to whether your phone is listening to you shows how to check which apps use it.

Why does an AI app want my location? #

Usually for local answers like weather, nearby restaurants or directions, or for ads. If you don’t use those features, deny it. If you do, allow it only while using the app and turn off precise location.

What happens if I deny a permission? #

The app keeps working without the feature that needed it. If you later try something that requires it, such as attaching a photo, the app asks again or points you to settings.

Do on-device AI apps need fewer permissions? #

Usually. A model that runs on your phone doesn’t need an account or a connection to your other services to answer. It still needs photo or camera access if you want it to look at pictures, and it needs the internet to download the model once.