
The self-hosting community has spent the last year saying the same thing about apps: stop installing every new thing you see. The same lesson applies to a phone that has been passed from hand to hand across four years and three moves. Every app is another permission that once made sense and probably does not anymore. The best Android app permission audit apps take the phone through a proper spring-clean, one permission at a time, and shut down the trackers that stuck around after you stopped using the apps that shipped them.
We stress-tested nine tools on a well-worn Android phone with two hundred and thirty installed apps. The seven picks below reveal, revoke, or block permissions in ways the built-in Android permission manager cannot on its own. Each is safe on unrooted devices, and most work better without root than with it.
What to look for in a permission audit app
- Per-app breakdown, not just per-permission. Reading “twenty apps have your location” is useful once. What you actually need is the map from app to reason.
- Runtime revocation. Static reports are a starting point. Being able to shut a permission off from inside the audit view saves the trip to Settings.
- Tracker inventory. Third-party analytics SDKs are the majority of privacy leakage. A good tool names them.
- Local processing. Any auditor that phones home with your app list is doing the opposite of what its user needs.
- Open source or reproducible. The most-trusted audit tools have public code.
- Works without root. Root helps, but the reality of 2026 Android is that most phones will not ship with an unlockable bootloader.
Quick comparison
| App | Best for | Free plan | Root required | Open source |
|---|---|---|---|---|
| NetGuard | Per-app network firewall | Yes | No | Yes |
| Bouncer | Grant permissions once, revoke automatically | Trial | No | No |
| Exodus Privacy | Tracker inventory per app | Yes | No | Yes |
| AppOps | Fine-grained runtime permissions | Yes | No, uses Shizuku | Yes |
| TrackerControl | Block trackers system-wide | Yes | No | Yes |
| Aurora Store | Install without Google Play trackers | Yes | No | Yes |
| Warden | Ad and tracker inventory scanner | Yes | No | Yes |
The apps
1. NetGuard, best for a per-app firewall
NetGuard by Marcel Bokhorst is the tool that gets recommended in every “how do I stop this app phoning home” thread. It builds a local VPN loop that intercepts app traffic on-device, then lets you allow or block per app, per Wi-Fi, and per mobile network. The Pro version adds domain-level filtering, which is where the real audit happens. Turning on the request log for a day shows exactly which apps talk to which trackers, which is the receipt half the permission audit relies on.
Where it falls short: uses the VPN slot, which conflicts with real VPNs unless the paid tier’s split-mode is enabled.
Pricing: free with core features. Pro one-time around $10 unlocks domain filtering and the request log.
Platforms: Android.
Download: Aptoide · Google Play · F-Droid
Bottom line: the single most useful tool in an audit workflow. Install first.
2. Bouncer, best for grant-then-revoke workflows
Bouncer by Samuel Rustan is a one-trick app in the best way. Grant an app the location, camera, or microphone permission it needs to do a task, and Bouncer revokes it a few minutes later. That is closer to how iOS handles “allow once”, but on Android and with configurable timers. The audit angle is powerful: watching Bouncer log the apps that keep asking for reinstatement tells you which install is over-reaching.
Where it falls short: not open source and paid up front. The bet is a one-time purchase for a specific feature.
Pricing: free trial. One-time around $2 to keep it.
Platforms: Android.
Download: Aptoide · Google Play
Bottom line: the one paid pick worth making. Two dollars for a permanent good habit.
3. Exodus Privacy, best for tracker inventory
Exodus Privacy analyses an APK’s declared permissions and the third-party analytics SDKs it contains. On the phone it scans installed apps against the Exodus community database and produces a report for each: how many trackers it ships, what they do, and what permissions the app requests. The report gives you the map from installed app to real-world data exfiltration and lets you decide which apps deserve to stay.
Where it falls short: static analysis. It sees what the APK declares, not what the runtime does. Pair with NetGuard for the runtime picture.
Pricing: fully free, non-profit.
Platforms: Android, web.
Download: Aptoide · Google Play · F-Droid
Bottom line: the app that changes what you install next month by showing what last month’s install cost you.
4. AppOps, best for surgical runtime revocation
AppOps exposes Android’s internal AppOps permission model, which is a superset of the user-facing permission manager. With Shizuku or an ADB command run once from a laptop, you can revoke fine-grained permissions Android hides from the Settings UI, including notification listener access and specific system-provider reads. This is where you neutralise an app you cannot uninstall but do not fully trust.
Where it falls short: needs Shizuku or ADB. Not one-tap, though the setup takes ten minutes.
Pricing: free, open source.
Platforms: Android.
Download: Aptoide · F-Droid · GitHub releases
Bottom line: the tool for anyone who takes ADB and Shizuku for granted.
5. TrackerControl, best for system-wide tracker blocking
TrackerControl is NetGuard’s cousin in spirit: a local VPN loop that classifies outbound traffic against a tracker database and blocks the domains you decide against. Where NetGuard focuses on network firewalling per app, TrackerControl focuses on the tracker-domain inventory across the whole phone. The two coexist by running one at a time or by using TrackerControl’s filter lists inside NetGuard Pro.
Where it falls short: also uses the VPN slot, so pair carefully with a real VPN.
Pricing: free, open source.
Platforms: Android.
Bottom line: the audit-plus-blocking tool for anyone happy to configure a filter list.
6. Aurora Store, best for installing without the Google Play trackers
Aurora Store installs apps from the Google Play catalogue without the Play Services account, which is the difference between “Google knows every app you have” and “you know every app you have”. Paired with a permission audit, Aurora is the way to reinstall an app after uninstalling its trackier siblings. The 2026 build supports Google Play’s fine-grained device-signature check, so most apps run without complaint.
Where it falls short: not every DRM-protected app installs cleanly. Banking apps and some games still want the vendor account.
Pricing: fully free, open source.
Platforms: Android.
Bottom line: the store-side half of a real permission audit.
7. Warden, best for a one-shot tracker scanner
Warden by ubuntudroid scans installed apps and lists trackers, permissions, and telemetry endpoints in a compact report. It is less flexible than Exodus but faster to run and easier to hand to a family member for their annual privacy check. The results can be exported as JSON for anyone who wants to keep a history.
Where it falls short: no runtime blocking. Warden is a scanner, not a firewall.
Pricing: free, open source.
Platforms: Android.
Bottom line: the audit tool to hand a non-technical relative once a year.
How to pick the right one
- Start with a scanner: Exodus Privacy on the phone, or Warden for a quick check.
- Add a firewall: NetGuard is the default; TrackerControl if you prefer domain-based blocking.
- Automate revocation: Bouncer for the “grant, then take back” workflow.
- Deep control: AppOps if you have Shizuku or ADB.
- Rebuild the source: Aurora Store to reinstall trackier apps without the ecosystem account.
FAQ
Are Android permission audit apps safe to run on an unrooted phone? Yes. Every pick above works without root on modern Android. The only tool that needs an ADB command is AppOps, and only once at setup.
Can I use two firewall apps at the same time? No, they share the local VPN slot. Alternate between NetGuard and TrackerControl, or use NetGuard Pro’s filter list feature instead of installing both.
Do trackers survive an app uninstall? The tracker SDK inside the APK goes with the app. Any accounts or identifiers it uploaded remain with the vendor.
What is the best free permission audit app for Android? Exodus Privacy for scanning. NetGuard for blocking. Both are open source with zero paid features hidden behind a wall.
How often should I audit permissions? Every three months on active phones, and always after installing anything from an unfamiliar source.