NetGuard

The self-hosting community has spent the last year saying the same thing about apps: stop installing every new thing you see. The same lesson applies to a phone that has been passed from hand to hand across four years and three moves. Every app is another permission that once made sense and probably does not anymore. The best Android app permission audit apps take the phone through a proper spring-clean, one permission at a time, and shut down the trackers that stuck around after you stopped using the apps that shipped them.

We stress-tested nine tools on a well-worn Android phone with two hundred and thirty installed apps. The seven picks below reveal, revoke, or block permissions in ways the built-in Android permission manager cannot on its own. Each is safe on unrooted devices, and most work better without root than with it.

What to look for in a permission audit app

Quick comparison

App Best for Free plan Root required Open source
NetGuard Per-app network firewall Yes No Yes
Bouncer Grant permissions once, revoke automatically Trial No No
Exodus Privacy Tracker inventory per app Yes No Yes
AppOps Fine-grained runtime permissions Yes No, uses Shizuku Yes
TrackerControl Block trackers system-wide Yes No Yes
Aurora Store Install without Google Play trackers Yes No Yes
Warden Ad and tracker inventory scanner Yes No Yes

The apps

1. NetGuard, best for a per-app firewall

NetGuard by Marcel Bokhorst is the tool that gets recommended in every “how do I stop this app phoning home” thread. It builds a local VPN loop that intercepts app traffic on-device, then lets you allow or block per app, per Wi-Fi, and per mobile network. The Pro version adds domain-level filtering, which is where the real audit happens. Turning on the request log for a day shows exactly which apps talk to which trackers, which is the receipt half the permission audit relies on.

Where it falls short: uses the VPN slot, which conflicts with real VPNs unless the paid tier’s split-mode is enabled.

Pricing: free with core features. Pro one-time around $10 unlocks domain filtering and the request log.

Platforms: Android.

Download: Aptoide · Google Play · F-Droid

Bottom line: the single most useful tool in an audit workflow. Install first.

2. Bouncer, best for grant-then-revoke workflows

Bouncer by Samuel Rustan is a one-trick app in the best way. Grant an app the location, camera, or microphone permission it needs to do a task, and Bouncer revokes it a few minutes later. That is closer to how iOS handles “allow once”, but on Android and with configurable timers. The audit angle is powerful: watching Bouncer log the apps that keep asking for reinstatement tells you which install is over-reaching.

Where it falls short: not open source and paid up front. The bet is a one-time purchase for a specific feature.

Pricing: free trial. One-time around $2 to keep it.

Platforms: Android.

Download: Aptoide · Google Play

Bottom line: the one paid pick worth making. Two dollars for a permanent good habit.

3. Exodus Privacy, best for tracker inventory

Exodus Privacy analyses an APK’s declared permissions and the third-party analytics SDKs it contains. On the phone it scans installed apps against the Exodus community database and produces a report for each: how many trackers it ships, what they do, and what permissions the app requests. The report gives you the map from installed app to real-world data exfiltration and lets you decide which apps deserve to stay.

Where it falls short: static analysis. It sees what the APK declares, not what the runtime does. Pair with NetGuard for the runtime picture.

Pricing: fully free, non-profit.

Platforms: Android, web.

Download: Aptoide · Google Play · F-Droid

Bottom line: the app that changes what you install next month by showing what last month’s install cost you.

4. AppOps, best for surgical runtime revocation

AppOps exposes Android’s internal AppOps permission model, which is a superset of the user-facing permission manager. With Shizuku or an ADB command run once from a laptop, you can revoke fine-grained permissions Android hides from the Settings UI, including notification listener access and specific system-provider reads. This is where you neutralise an app you cannot uninstall but do not fully trust.

Where it falls short: needs Shizuku or ADB. Not one-tap, though the setup takes ten minutes.

Pricing: free, open source.

Platforms: Android.

Download: Aptoide · F-Droid · GitHub releases

Bottom line: the tool for anyone who takes ADB and Shizuku for granted.

5. TrackerControl, best for system-wide tracker blocking

TrackerControl is NetGuard’s cousin in spirit: a local VPN loop that classifies outbound traffic against a tracker database and blocks the domains you decide against. Where NetGuard focuses on network firewalling per app, TrackerControl focuses on the tracker-domain inventory across the whole phone. The two coexist by running one at a time or by using TrackerControl’s filter lists inside NetGuard Pro.

Where it falls short: also uses the VPN slot, so pair carefully with a real VPN.

Pricing: free, open source.

Platforms: Android.

Download: Aptoide · F-Droid

Bottom line: the audit-plus-blocking tool for anyone happy to configure a filter list.

6. Aurora Store, best for installing without the Google Play trackers

Aurora Store installs apps from the Google Play catalogue without the Play Services account, which is the difference between “Google knows every app you have” and “you know every app you have”. Paired with a permission audit, Aurora is the way to reinstall an app after uninstalling its trackier siblings. The 2026 build supports Google Play’s fine-grained device-signature check, so most apps run without complaint.

Where it falls short: not every DRM-protected app installs cleanly. Banking apps and some games still want the vendor account.

Pricing: fully free, open source.

Platforms: Android.

Download: Aptoide · F-Droid

Bottom line: the store-side half of a real permission audit.

7. Warden, best for a one-shot tracker scanner

Warden by ubuntudroid scans installed apps and lists trackers, permissions, and telemetry endpoints in a compact report. It is less flexible than Exodus but faster to run and easier to hand to a family member for their annual privacy check. The results can be exported as JSON for anyone who wants to keep a history.

Where it falls short: no runtime blocking. Warden is a scanner, not a firewall.

Pricing: free, open source.

Platforms: Android.

Download: Aptoide · F-Droid

Bottom line: the audit tool to hand a non-technical relative once a year.

How to pick the right one

FAQ

Are Android permission audit apps safe to run on an unrooted phone? Yes. Every pick above works without root on modern Android. The only tool that needs an ADB command is AppOps, and only once at setup.

Can I use two firewall apps at the same time? No, they share the local VPN slot. Alternate between NetGuard and TrackerControl, or use NetGuard Pro’s filter list feature instead of installing both.

Do trackers survive an app uninstall? The tracker SDK inside the APK goes with the app. Any accounts or identifiers it uploaded remain with the vendor.

What is the best free permission audit app for Android? Exodus Privacy for scanning. NetGuard for blocking. Both are open source with zero paid features hidden behind a wall.

How often should I audit permissions? Every three months on active phones, and always after installing anything from an unfamiliar source.