Learn › How tracking works

What app permissions actually mean

Last reviewed 2026-07-20

Permissions are the doors an app can open on your phone. Most are ordinary and necessary. A few are powerful enough that monitoring software specifically wants them — those are the ones worth understanding. Jump to Accessibility, Notification access, or Device admin if a report sent you here.

The everyday permissions

These are requested by huge numbers of legitimate apps. Their risk is about which app holds them and whether it needs them — not the permission itself.

Accessibility services — the powerful one

Accessibility exists so screen readers and assistive tools can help people with disabilities. To do that job, it can read everything on your screen and act as if it were you — see text in any app, capture what you type, and tap buttons automatically.

That is enormous power, and stalkerware wants it precisely because it bypasses the protection of individual apps: an app with accessibility can read your messages inside an encrypted messenger, because it reads the screen after the app has decrypted them. Very few apps legitimately need it — genuine accessibility tools, some password managers, some automation apps. If an app you don’t recognize (or a “system update”-sounding app) holds accessibility access, that is worth investigating. Check under Settings → Accessibility on Android.

Notification access

This lets an app read every notification you receive — including message previews from other apps. A monitoring app with notification access can capture incoming texts and chat messages without opening those apps at all. Legitimate uses exist (smartwatch companions, some automation), but like accessibility, it’s a permission worth accounting for. Android lists holders under Settings → Notifications → Device & app notifications (wording varies by phone).

Device administrator

Device admin was designed for workplace management — letting an IT department enforce a passcode or remotely wipe a lost work phone. Stalkerware misuses it for a simpler reason: an app with device-admin rights is harder to uninstall, and can sometimes lock or wipe the phone. If you find a device-admin app you didn’t set up (and you’re not on a managed work phone), treat it seriously — but revoke it only after reading Safety first, because on a monitored phone that action can be noticed.

Other capabilities worth knowing

How to review your permissions

  1. Android: Settings → Privacy → Permission manager shows every permission and which apps hold it. The Privacy dashboard shows recent access. Check Accessibility and Special app access separately — the powerful permissions live there, not in the normal list.
  2. iPhone: Settings → Privacy & Security lists each capability and the apps granted it. iOS 16+ Safety Check reviews sharing in one place.
  3. Both: revoke what doesn’t fit the app’s purpose. If something powerful looks wrong and you suspect monitoring, read Safety first before changing it.

What DeSpy checks for

DeSpy reads each app’s requested, granted, and denied permissions and translates them into plain language — flagging the powerful combinations above (accessibility, notification access, device admin, sideloading, always-on VPN) and explaining why each matters. It separates ordinary platform apps holding normal permissions from apps whose configuration actually looks like monitoring.