Mobile Privacy
Mobile phone security
Your mobile is with you everywhere. Is it safe to use with regards to your personal privacy. Maybe....
For the average user the short answer is no. It is not secure or very private.
Both Google and Apple are data hoarders and you should automatically assume what ever you do, where ever you go, whom ever you communicate with is fair game for their servers to log, and where profitible, sell without your knowledge or permission. Just read TOS. They make much of their income selling your personal information to others.
Each app you use will come with it's own privacy rules and TOS. If you download an app from either's services they know what you installed.
There are secure messaging apps to be sure but those also have their own set of risks to consider.
Some basics.
- Your phone knows where you are when it is on network. GPS and Tower triangulation.
- Your phone tells your carrier where you are.
- Your apps may collect data about where you are and where you go.
- You have no option to deny how that data is saved, used or sold. This applies to the OS as well as most 3rd party apps.
- If you use Gmail you can assume you have zero privacy.
If you must use a phone for activism there are secure messaging apps but don't install from PlayStore or Apple Store. Download from the publishers site directly or check out sites like APKPure.com where you can bypass the spy stores.
Use only apps that do not require you to provide your phone number. Set them up using an encrypted email service, never your Apple or Gmail accounts.
This is not perfect but it is a step in the right direction.
If your an activist where being such puts you at risk your best bet is to ditch your phones OS and install an alternative. One such alternative is MicroG. It is technical. It has the potential to ruin your phone if not done right. Even if your just average Joe you may prefer to keep your private life private from the data vulchers.
A de-Googled phone is also a good candidate for a burner
A cheap, secondhand phone flashed with a MicroG-based ROM (or similar de-Googled projects like GrapheneOS, LineageOS, or /e/OS) makes a genuinely strong burner device - it never phones home to a Google or Apple account in the first place, which is exactly the leak a normal burner phone still has even after you've done everything else right. Pair it with the same rules covered in our Off Grid and Social Media articles - buy it with cash, don't register it with your real identity, and set up any accounts through an encrypted email service - and you've got a burner that isn't quietly reporting back to the two biggest data brokers on the planet the whole time you're using it.
One real limitation to know before you commit: most banking apps, and some other high-security apps (payment services, some government apps), will refuse to run at all on a de-Googled phone. They check for Google's Play Integrity attestation to confirm the device hasn't been modified, and a custom ROM without Google's proprietary services fails that check by design - not a bug, an intentional block. Fine for a device that's purely a burner for messaging and browsing; don't count on it for anything that needs your actual bank.
Bottom line, as long as you use any mobile device with an OS provided by Google or Apple you really cannot hide.
You can and should install a VPN on your mobile device.
Unless you need it turn location and GPS off.
Note even when off sometimes Google can know where you are anyway. Watch this.
A word on "Stingrays" (IMSI catchers)
Unlike a license-plate camera, a device sometimes called a "Stingray" (after one popular brand) or IMSI catcher targets your phone directly, over the cellular network itself.
What it is. An IMSI catcher is a device that impersonates a real cell tower. Every phone nearby automatically tries to connect to whichever tower has the strongest signal, and phones aren't able to verify a tower is legitimate before connecting - so the fake tower can trick every phone in range into connecting to it instead of the real network.
What it can capture. At minimum, an IMSI catcher can log the unique identifiers (IMSI/IMEI) of every phone that connects, which reveals who was present in a given area at a given time - not just a specific target. More capable models can also pinpoint a phone's precise location, and some can force a phone to downgrade from encrypted 4G/5G to older, weaker 2G service, at which point calls and texts may be interceptable. It affects every phone in range, not just the person being targeted - that's the core privacy concern.
Who uses them, and why. Originally military and intelligence technology, IMSI catchers are now used by federal agencies and many state and local police departments, typically to locate or track a specific suspect's phone. ICE is a documented user - ACLU FOIA records and a DHS Inspector General report confirmed ICE has deployed cell-site simulators, including vehicles specifically outfitted with fake cell towers, often without following their own legal-process rules. Their use has also been documented at protests and demonstrations, which is where most of the privacy controversy comes from - everyone else's phone in range gets swept up too, usually without a warrant covering bystanders and often without public disclosure that the device was deployed at all.
How they're deployed. IMSI catchers range from suitcase-sized units carried in a vehicle, to aircraft-mounted versions that can sweep a wide area, to smaller handheld units. Effective range varies widely by model, from a couple hundred feet to a couple of miles.
Countermeasures (realistic, not perfect):
- Prefer encrypted messaging apps (Signal, for example) over standard SMS/voice calls - those still route over the cellular network itself and can be more exposed to interception if a device is forced onto 2G.
- If your phone allows disabling 2G (an option on many recent Android and iOS devices, sometimes under a "Lockdown"/advanced network setting), turning it off blocks the specific downgrade trick some IMSI catchers rely on.
- Use WiFi calling/messaging over a trusted network when you have the choice, rather than relying on the cellular network for sensitive communication.
- For situations where you specifically don't want your phone's presence logged at all (e.g. attending a sensitive event), a Faraday bag blocks all radio signals in and out - the most reliable option, since it doesn't rely on detecting anything.
- If you're leaving a phone unattended somewhere - a vehicle, a motel room - and it has a removable battery, pull the battery. "Powered off" isn't always the same as "can't transmit"; a phone can't do anything at all with the battery physically out of it. Worth knowing this is increasingly a moot point on modern phones, since most current iPhones and Android devices have sealed, non-removable batteries - this really only applies to older or ruggedized devices that still offer one.
- IMSI-catcher "detector" apps exist, but treat their results skeptically - most rely on spotting suspicious tower behavior and can produce false positives/negatives; they're a signal, not proof.
- The most dependable countermeasure remains the simplest: leave your phone at home, or use a separate burner device, for situations where you need to ensure your presence and identity aren't logged.
Does a separate "app number" (Hushed, Burner, Google Voice, etc.) protect you from a Stingray?
No, and it's worth understanding why - it's a common and understandable mix-up. An IMSI catcher works at the cellular radio level: it captures your IMSI (tied to your SIM) and IMEI (tied to your phone's hardware) the moment your device's cellular radio registers with a tower, real or fake. That happens independently of whatever calling app or phone number you're using on top. A second number from an app like Hushed, Burner, MySudo, or Google Voice is a software-layer identity - it changes what number shows up when you call someone, but it's invisible to a Stingray. If your phone's cellular radio is on and registered to a network at all, it's still broadcasting its real IMSI/IMEI regardless of what app or number you're using to place the call.
What actually works: airplane mode, then turn WiFi back on. Airplane mode disables cellular, WiFi, and Bluetooth together - but both iOS and Android let you re-enable WiFi independently while cellular stays off. Do that, and use a calling app over WiFi (most, including Signal, work fine without any cellular connection at all), and you get both things you actually wanted: a separate number, and a phone that isn't broadcasting on the cellular band for a Stingray to catch in the first place.
Two honest caveats: this trusts the OS to actually power the radio down, and there have been rare, documented cases (mostly baseband firmware bugs, or nation-state-level exploitation) where it didn't - not a practical concern for routine surveillance, but not an absolute guarantee against the most sophisticated adversaries either. And it protects against remote/over-the-air capture, not physical seizure - the SIM is still sitting right there in the device if someone takes the phone itself.
An even cleaner version: a phone with no SIM card in it at all, WiFi only. Rather than trusting airplane mode to toggle a radio off, a phone that never has a SIM inserted has nothing for a cellular radio to register with in the first place - no IMSI to broadcast, no carrier connection, period. Pair that with a calling app (Google Voice, for example) over WiFi, and you've got a working phone number with essentially no cellular footprint at all. One narrow technical caveat for completeness: most phones are required to support emergency (911) calling even with no SIM inserted, which means the baseband can still briefly power up and search for a tower for that purpose alone - in theory this could expose the phone's IMEI even without a SIM. That's a narrow, resource-intensive technique that matters against a targeted, well-resourced adversary, not routine surveillance.
Worth separating two different things this setup does and doesn't protect, though: it's excellent at the cellular/carrier layer, but it does nothing about the calling app or account itself. Google Voice specifically runs through a Google account, and Google logs who you called, when, and the IP address (and therefore roughly the location) you connected from - the device isn't leaking cellular data, but the service is still logging plenty, just through the account instead of the SIM. A WiFi-only phone can also still be roughly located through WiFi-based positioning databases (the same ones our Google Spy article's "_nomap" note covers) even with zero cellular radio active at all.
As with everything in this section, this is about the best available precautions, not a guarantee - short of the phone being at the bottom of a river, nothing is 100%. This setup gets about as close as a phone you can actually use gets.
Activists at protests
If you're attending a protest, consider leaving your primary phone at home or in your vehicle rather than carrying it with you - it's both a location-tracking risk (see above) and a target if things get chaotic. If you want to document what happens, a small, inexpensive dedicated video recorder (even a basic dash cam) can work well as an alternative - it's not an obvious "phone held up recording" that draws attention the way a cell phone does. One legal note: recording police performing public duties in public is well-established protected activity in the US. The sensitivity is more about bystanders' private conversations being picked up - a number of states require all-party consent to record audio. That mostly hinges on whether there's a reasonable expectation of privacy, not simply location, so a loud public conversation is generally treated differently than two people speaking quietly off to the side - but the line is genuinely blurry and varies by state, so check your own state's current law before recording anyone's conversation besides your own interactions with police. This isn't blanket advice to secretly record everyone around you, just a practical alternative to carrying a phone.
More reading: Princeton's study on the security and privacy risks of phone number recycling - an old number still listed on an account you've forgotten about can end up back in a stranger's hands. Worth pairing with a periodic check of haveibeenpwned.com to see if any of your accounts have turned up in a known data breach - see our Privacy Resources article for more on that.