More than you think. Less than should be.

Dozens of actors have access to your device — and few of them are visible.

Transparent smartphone X-ray

On PC: hover with mouse. On mobile: tap.

The operating system controls permissions, network access, location, sensors and updates. It can send data to the manufacturer for diagnostics, personalization or synchronization.

Examples: Google Android, Apple iOS, manufacturer-specific interfaces

Status: Can be completely replaced by free operating systems like GrapheneOS, LineageOS or /e/OS ✅

The main chip is the computing center of the device. The manufacturer supplies reference designs and proprietary features that are not fully transparent — and thus provide deep control over what the device can and does do.

Examples: Qualcomm, Apple, MediaTek, Samsung Exynos, Google Tensor

Status: Hardware currently not transparent or changeable — research on open-source chips is ongoing

The modem keeps in touch with the mobile network. It is often largely proprietary, difficult to audit — and communicates directly with the network, bypassing the operating system.

Examples: Qualcomm Modem, Apple Modem, MediaTek Modem

Status: Currently cannot be replaced by open firmware — one of the biggest open problems

ARM does not supply the finished chip, but the architecture behind it. Who controls the architecture controls the technical foundation — a largely invisible layer of trust.

Examples: ARM CPU architecture, ARM TrustZone, licensed designs

Status: Partially replaceable by RISC-V as an open alternative — not yet mainstream in smartphones

The manufacturer decides on hardware selection, pre-installations, proprietary apps and telemetry. Even with the same operating system, devices can differ greatly here.

Examples: Apple, Samsung, Xiaomi, OnePlus, Motorola

Status: Can be partially circumvented through conscious device choice (Fairphone, Pixel with GrapheneOS)

Before the operating system even starts, the bootloader verifies what gets loaded. It determines whether alternative software is even possible — making it one of the most fundamental control instances.

Examples: Locked bootloader, Secure Boot, manufacturer startup firmware

Status: For some devices (Pixel, Fairphone) unlockable — prerequisite for free operating systems

A shielded area in the chip for biometric data, keys and payments. The idea is protection — but the implementation is proprietary and hardly auditable for users.

Examples: Apple Secure Enclave, ARM TrustZone, Samsung Knox

Status: Currently not openly auditable — no generally available free alternative

The software in the modem itself is usually closed and rarely audited from the outside — even though it has direct access to radio communication and network data.

Examples: Proprietary modem firmware, carrier-specific radio profiles

Status: Currently cannot be replaced by open firmware

Updates come via separate channels for operating system, modem, WiFi chip, security modules. Who controls this infrastructure can change functionality — without users noticing.

Examples: OTA updates, modem firmware updates, Google Play System Updates

Status: Free operating systems use their own update channels without Google dependency ✅

App stores see search queries, downloads, usage, updates and device data. They control through policies which apps are even available.

Examples: Google Play Store, Apple App Store, third-party stores

Status: Free alternatives: F-Droid, Droid-ify, Aurora Store — usable without Google account ✅

Apps are often the most direct data source — depending on permissions granted: contacts, camera, microphone, location, calendar, fitness data and usage behavior.

Examples: Social media apps, messengers, shopping apps, banking apps

Status: Permission management under GrapheneOS/LineageOS much more granularly controllable ✅

These actors track users invisibly across many apps — via ad IDs, SDKs, fingerprinting. The result is detailed behavioral profiles.

Examples: Tracking SDKs, ad IDs, cross-app profiles, attribution trackers

Status: Can be greatly reduced by tracker blockers (DNS, browser add-ons) ✅

Photos, backups, contacts, chats, notes — whoever operates the cloud service gets broad insight into the digital everyday.

Examples: iCloud, Google Drive, Microsoft Azure, app backups

Status: Free alternatives: Nextcloud (self-hosted), Proton Drive, Cryptomator ✅

Location is determined not only via GPS, but via WiFi networks, radio cells, Bluetooth, sensors and IP addresses combined. This makes location data one of the most sensitive data points of all.

Examples: GPS/GNSS, WiFi location, cell location, sensor fusion

Status: Access under GrapheneOS/LineageOS per app granularly controllable — including fake location ✅

Your mobile carrier sees the timing and location of every network connection, metadata and can narrow down location via radio cells — even without GPS.

Examples: Telekom, Vodafone, O2 / Telefónica

Status: Currently difficult to circumvent — VPN partially reduces visible metadata

The SIM identifies the device on the network. With eSIM comes the dependence on central remote management by the provider.

Examples: SIM card, eSIM profile, remote SIM provisioning, IMSI

Status: Physical SIM card provides more control than eSIM — exchangeable for some models ✅

Your WiFi or internet provider sees destination addresses, times and data volumes. Together with DNS queries, a usage profile emerges — even without access to content.

Examples: Home router, WiFi provider, DNS resolver, ISP

Status: Can be greatly reduced through encrypted DNS (DNS-over-HTTPS) and VPN ✅

Government bodies can obtain data through legal requests or technical interfaces — from metadata to deeper communications monitoring, depending on legal status and country.

Examples: Court orders, data retention, network monitoring

Status: Encryption and minimal data traces reduce the attack surface

Many devices send error reports and usage statistics in the background. With incorrect configuration, this can provide very meaningful data.

Examples: Crash reports, telemetry, diagnostic uploads

Status: Disableable under GrapheneOS/LineageOS or not present at all ✅

Fingerprint, facial recognition, microphone, accelerometer, gyroscope — these sensors can reveal usage habits and stay patterns that go far beyond their actual purpose.

Examples: Face ID, fingerprint sensor, microphone, motion sensors

Status: Per-app access controllable — usage voluntary but often difficult to avoid completely

These radio chips constantly send signals and can be recognized by surrounding devices. MAC addresses, known networks and connection times allow conclusions about locations and behavior.

Examples: WiFi scanner, Bluetooth Low Energy, AirDrop, MAC addresses

Status: MAC randomization (GrapheneOS standard) greatly reduces tracking ✅

Push services reveal when a device is online and which apps are active — inconspicuous for users, but technically very revealing.

Examples: Apple Push Notification Service, Firebase Cloud Messaging

Status: Under GrapheneOS, apps can operate without Google push services ✅

Often an app with too many permissions is enough — camera, microphone, contacts, location. Even an innocent app can reveal a lot with the wrong permissions.

Examples: Microphone access, contacts access, movement/fitness data

Status: Free operating systems offer granular permission management — down to sensor level ✅

The browser sees search queries, visited sites, cookies and interactions. Through synchronization, passwords and autofill, a detailed usage profile emerges.

Examples: Chrome, Safari, Firefox, tracking via cookies and fingerprinting

Status: Free browsers: Brave, Firefox with uBlock Origin, Vanadium (GrapheneOS) ✅

Smartwatches, headphones, car systems and IoT devices pair with the smartphone and extend the data landscape through additional connections between everyday life, location and behavior.

Examples: Smartwatch, Bluetooth headphones, car infotainment, fitness tracker

Status: Can be reduced through conscious device choice and minimal pairing

When you know the actors and understand the system, you can make conscious decisions. And eventually it is no longer a decision, but becomes a statement of who you are.

Journey with us →

How transparent is your smartphone

Check your phone

free • anonymous • independent