Device and installation manual · adults 18+

App permissions for AI companions: grant less, verify more

Permissions are device gates, not trust badges. Text interaction usually needs network access but not your camera, contacts, precise location, microphone or full photo library. Media features may need one narrow path. This guide maps each common prompt to the user action that can justify it, then shows how to revoke access without overstating what revocation can accomplish.

Reviewed and updated

App permissions for AI companions: grant less, verify more: decision table
PermissionPossible user-initiated reasonSafer first responseWhat it does not prove
Photos/mediaChoose an existing uploadSelected item or limited accessUploaded copy was deleted
CameraTake a new pictureAllow only during deliberate captureNo server copy exists
MicrophoneRecord voice inputOne-time/while using if availableAudio is processed locally
NotificationsReceive alertsHide previews and choose categoriesEmail alerts are disabled
Location/contactsFeature-specific use must be explainedDeny for ordinary chatService cannot infer coarse location
Controlled setup

Run this device check in order

  1. 01

    Begin text-only with optional permissions denied.

  2. 02

    Trigger only the feature you intend to test.

  3. 03

    Read the OS prompt and identify requesting app or browser.

  4. 04

    Select one-time, while-in-use or selected-item access when available.

  5. 05

    Cancel broad access when the purpose is unclear.

  6. 06

    Review the permission panel immediately after the task.

  7. 07

    Document local revocation separately from provider-side controls.

01

Build a purpose-to-permission map

Every prompt should connect to an action you just initiated. Choosing Upload can justify a photo picker. Choosing Record can justify microphone access. Choosing Take photo can justify camera access. Ordinary typed conversation does not explain contacts or precise location. If timing and purpose do not match, deny and inspect the feature documentation.

A service may technically function with broader access, but convenience is not the same as necessity. Grant the narrowest option supported by the OS and app. If limited access fails, decide whether the feature is worth broader exposure rather than tapping through automatically.

02

Photo picker versus library permission

Modern operating systems can let you choose a specific file without giving an app ongoing access to the whole library. The exact wording differs. On iOS, Selected Photos may appear. On newer Android versions, selected photos and videos may be offered. Browser file pickers can grant a chosen file through a separate path.

After selection, assume the chosen file can be transmitted if you complete the upload. Revoking later access limits future library browsing; it does not retract the selected upload. Check the provider’s current interface and policy for uploaded-file controls.

03

Microphone and camera indicators

iOS and Android provide indicators when the microphone or camera is active, subject to version. Use them as real-time signals. Close the recording feature and confirm the indicator clears. Then inspect the permission page. If access appears while you did not initiate capture, stop using the service and investigate.

Keyboard dictation, voice calls, browser recording and native-app recording may involve different applications. Identify which software owns the indicator. Do not claim that an indicator proves how audio is processed or retained after transmission.

04

Contacts and location deserve a high bar

A fictional text companion normally does not require an address book or precise GPS location to exchange messages. If a current feature requests either, read the adjacent explanation and provider documentation. Deny unless you understand and want the exact function. Approximate location can still be inferred from an IP address or regional settings, so denying GPS is not an anonymity guarantee.

Contacts access can reveal information about people who never chose the service. Avoid granting it merely to simplify invitations or sharing. Use the operating system share sheet without contact access when possible, and verify recipients before sending sensitive material.

05

Notification permission is only one layer

Allowing notifications lets the app or website request delivery through the OS. Message content, email alerts, browser push, badges and connected-device mirroring remain separate. Configure preview privacy first and inspect in-service alert settings where visible.

Denying push does not stop account emails. Allowing push does not guarantee timely delivery under Focus, Battery Saver, network loss or background restrictions. Test a harmless message and label the result as device-specific.

06

Revoke cleanly and troubleshoot narrowly

On iPhone, use Privacy & Security and the per-app Settings page. On Android, use App info > Permissions. Browsers add site-level controls. Change one permission, retry one harmless action and note the result. Resetting every permission and clearing all data at once destroys useful evidence and can create a login problem unrelated to the original failure.

After revocation, inspect whether cached previews or downloaded files remain. Those are storage issues, not permission failures. Account or uploaded-content removal is a provider-side question.

07

Field note: audit permission drift after updates

Permissions are not a one-time setup. Operating-system updates can add narrower choices, an app update can request a new capability, and unused-app features can revoke access automatically. Keep a small baseline listing the permissions you intentionally allowed and the action that justified each one. After an update, compare the current panel with that baseline before using camera, microphone or media upload again. A newly visible permission is a reason to inspect the current feature and documentation, not proof of misuse; an unexplained prompt is a reason to deny until the purpose is clear.

Browser use requires two baselines. The operating system can allow the browser to use camera or microphone, while the browser independently allows or blocks a particular site. When troubleshooting, identify both states and change the narrower site setting first. For photo uploads, note whether the service uses a system picker, selected-library access or a broad library grant. End the audit by locking the phone, closing the feature and confirming any camera or microphone indicator has cleared. This tests local access control only and makes no claim about files already transmitted.

Evidence boundary

What product documentation and the current interface can confirm

Use the provider’s official pages and the version open on your device. Record only what is stated or visible now. A screen can confirm that a control is presented to this account; it cannot prove behavior for every region, plan, operating system or future release.

  • Which software generated the OS prompt
  • The permission choices available on this device
  • The feature that stops or works after one controlled change
  • Current browser site permissions where relevant
  • Provider documentation for any unusual permission purpose

Version caveat: Permission labels and limited-access choices depend on OS release, app implementation and browser. A permission result describes this device, not provider retention.

Continue the setup

Related device checks

Device questions

Frequently asked questions

Does typed chat need microphone access?

No. Deny microphone access unless you deliberately use a voice or recording feature.

What if the upload picker works while Photos permission is denied?

The system picker may authorize only the selected file. That is different from ongoing library access.

Does revoking a permission delete earlier uploads?

No. It limits future device access. Use provider controls and documentation for uploaded data.

Optional next step

Apply the device checks to a current product surface

Only continue after you know which access method, permissions and notification settings you will accept. These links are sponsored; verify the current official interface and terms yourself.

Open the full product access directory

These are access links, not feature endorsements. Complete the compatibility checklist and verify the current product screen before granting permissions.

Girlfriend GPT logoGirlfriend GPTDarLink logoDarLinkGet-Harder logoGet-HarderSecrets logoSecretsCandy logoCandyDondi logoDondiFantasy logoFantasyJoi logoJoiLovescape logoLovescapeMyLovely logoMyLovelyOurDream logoOurDreamPromptchan logoPromptchanSwipey logoSwipeyXotic logoXotic