Every app on your child's phone or tablet has a privacy policy. That policy describes what data the app collects, how it uses that data, and who it shares it with. Very few parents — or adults in general — read these policies in full, and that's part of what app developers are counting on. An app audit is the process of systematically reviewing what data the apps your child actually uses are collecting, without needing to read a 40-page legal document to do it.

The 10-Minute Audit Checklist

You don't need to audit every app on the device — start with the five or six your child actually uses daily. For each one, walk through:

  • Permissions granted — camera, microphone, location, contacts, photos. Does the app need this to function?
  • Location access type — "While Using" is generally lower-risk than "Always," which lets an app track location even when closed.
  • Data-sharing disclosure — check the app's privacy label (see below) for whether data is shared with third parties or advertisers.
  • Account necessity — does this app require an account at all, and if so, how much personal information did it ask for at signup?
  • Business model — is the app free, ad-supported, or subscription? Free-and-ad-supported apps generally rely on data collection to generate revenue.

Start with the App Permissions

On both iOS and Android, you can see exactly what permissions each app has requested and been granted. Go to Settings > Privacy & Security (iOS) or Settings > Apps > Permissions (Android, exact wording varies by manufacturer) to see which apps have access to your camera, microphone, location, contacts, and photos. Any app with permissions you didn't knowingly grant, or permissions that seem excessive for what the app actually does — a simple game asking for microphone access, for instance — is worth a closer look.

Review the App Store Data Labels

Apple's App Store requires developers to disclose their data practices in a standardized "App Privacy" section on every app's listing page, covering what data is collected and whether it's linked to your identity or used for tracking. Google Play has a comparable "Data safety" section on Android app listings. Neither disclosure format is independently audited by the platform in real time — they rely on developer self-reporting — so treat them as a useful starting signal rather than a guarantee, and cross-check against the app's actual behavior (the permissions it requests) where something looks inconsistent.

A Simple Red / Amber / Green Scorecard

To keep the audit fast, sort each app into one of three buckets rather than agonizing over every detail:

  • Green: Permissions match the app's obvious function, data-sharing disclosure is minimal, and there's a clear reason the app needs an account (if it has one).
  • Amber: One or two permissions seem broader than necessary, or the data-sharing section mentions advertising partners — worth a conversation, not necessarily a deletion.
  • Red: Permissions clearly exceed what the app needs to function, extensive third-party data sharing is disclosed, or the app has no real business model other than data collection. Worth seriously reconsidering.

The Three-Question Test

For any app that lands in amber or red, ask: Does this app genuinely need this data to function? What does the company disclose doing with the data it collects? Is there a privacy-preserving alternative that does the same job? Free apps are often free because user attention and data are the actual product being monetized — when your child is the user, that calculation deserves more scrutiny than it typically gets. A repeatable habit — even 10 to 20 minutes reviewing the apps your child uses most, run quarterly or whenever a new app becomes a regular part of their routine — is a meaningful, low-effort step toward protecting their digital footprint over time.