87% of Android apps request at least one permission they do not need for their core function, according to NordVPN's mobile app research, published in May 2026 and based on an audit of 103 top apps across 18 categories. iOS apps request fewer unneeded permissions, at 60%, largely because Apple's platform asks for far fewer permissions overall. The gap between what an app needs and what it asks for is the single biggest gap between developer intent and user trust in mobile privacy right now.

What percentage of apps request unnecessary permissions?

87% of Android apps and 60% of iOS apps requested at least one permission not required for the app to function, per NordVPN's May 2026 research. NordVPN's team audited the top 5 apps in each of 18 categories, including shopping, travel, gaming, and health and fitness, for a combined sample of 103 apps, and cross-checked each requested permission against what the app's stated function actually required.

Figure 1: Android apps over-request permissions far more often than iOS apps. Source: NordVPN mobile app research, May 2026 (n=103 apps, 18 categories).

Social networking apps requested the most Android permissions of any category in the sample, while health and fitness apps were the most permission-hungry on iOS, a notable pattern given how sensitive health data is under most state privacy laws. A privacy policy generator built to disclose every requested permission closes the gap between what an app collects and what its privacy policy actually states, which is the first thing app store reviewers and regulators check.

How many permissions does the average app request?

The average Android app requests 19 permissions, and the average iOS app requests only 5, according to NordVPN's May 2026 audit. Of those, Android apps average about 4 unnecessary permissions per app and iOS apps average about 1, meaning roughly 1 in 5 requested permissions on either platform serves no function the app actually performs.

Figure 2: Android apps request nearly four times as many permissions as iOS apps, and more of them go unused. Source: NordVPN mobile app research, May 2026.

Most Android apps ask for permissions they do not need 87% of Android apps requestpermissions they do not need

The platform gap is structural, not accidental. Android's permission model exposes a longer list of discrete hardware and data permissions that developers can request individually, while iOS bundles more capability behind fewer, broader entitlements, which naturally caps how many separate permissions an iOS app can ask for even when a developer wants more access than the app needs.

What share of apps have dangerous or risky permissions?

Beyond simple over-requesting, a separate class of "dangerous" permissions, ones that expose contacts, precise location, camera, or microphone access, shows up even more often in security-focused audits. NowSecure's 2025 assessment of 378,000 Android apps found that 62% requested at least one dangerous permission, and a companion audit of 335,000 iOS apps found nearly 31,000 using risky, often undocumented entitlements.

Figure 3: Nearly two-thirds of Android apps carry at least one dangerous permission. Source: NowSecure enterprise mobile app security assessment, June 2025 (Android n=378,000; iOS n=335,000).

Separately, a CyberNews audit of the top 50 Android apps in Google Play found they require an average of 11 dangerous permissions listed directly in their app manifests, a figure that only covers the most downloaded apps and likely understates the picture for the long tail of smaller, less-scrutinized apps.

How many apps share user data with third parties?

55.2% of apps on the Google Play Store, just over 1 in 2, share user data with third parties, according to Incogni's 2026 analysis of the top 1,000 free and paid apps on the store, based on each app's own Google Play Data Safety disclosure. Free apps in the sample shared roughly 7 times more data points on average than paid apps in the same category, and popular apps with 500,000-plus downloads shared over 6 times more data points than less popular apps.

Figure 4: Just over half of the most-downloaded apps on Google Play share user data externally. Source: Incogni, "Sharing is NOT caring" Android app analysis, 2026 (n=1,000 apps).

Sharing rates are far higher in some categories than others. Social media apps in the same dataset collected the most data of any category, averaging 19.18 distinct data points per app, well above the sample-wide average, which makes social apps the single riskiest category for a privacy policy to under-disclose.

How has App Tracking Transparency changed opt-in rates?

Since Apple's App Tracking Transparency (ATT) framework launched in 2021, requiring an explicit prompt before any app can track a user across other companies' apps and websites, opt-in rates have climbed slowly but never approached a majority. Business of Apps and Adjust's 2025-2026 benchmarks put the global average between roughly 27% and 35%, up from about 21% in 2022, with wide variation by app category and region.

Figure 5: ATT opt-in has crept upward since 2022 but plateaued short of a third of users. Source: Business of Apps ATT opt-in rate tracker and Adjust benchmarks, 2022 to 2026 (figures vary by measurement window; 2026 reflects a mid-range plateau estimate).

Utilities and finance apps tend to see the highest opt-in rates in these benchmarks, while gaming and entertainment apps underperform the global average, which the industry generally attributes to users trusting a finance app's tracking request more than a game's. Regional gaps are also wide: France has reported opt-in rates near 51% in some Adjust breakdowns, well above Germany's roughly 47%, underscoring that ATT compliance alone does not guarantee a high consent rate, and app publishers should not assume a single global number applies to their specific audience.

Do children's apps handle data any differently?

Not meaningfully, and in some measurements the picture is worse. Pixalate's Q2 2025 GDPR-K and UK Children's Code report found that 97% of 253 EU- and UK-registered, child-accessible apps carrying programmatic ads transmitted unlawfully obtained personal data, including location data, in the advertising bid stream; the same report found 91% failed to disclose how they process children's personal data at all. That sample was narrow, drawn from 15,417 child-accessible ad-enabled apps and filtered down to the subset flagged for likely violations, so the 97% figure describes a specific at-risk population rather than the full population of children's apps, but it lines up with Incogni's separate 2026 review of 74 popular children's Android apps, which found 46% collected some user data and 28% actively shared it with third parties.

The Bottom Line

Every dataset in this post points the same direction: mobile apps ask for more access than they use, and users rarely have a clear, current picture of where that data goes afterward. 87% of Android apps over-request permissions, 55.2% of top Google Play apps share data externally, and fewer than 4 in 10 iPhone users actively consent to cross-app tracking when asked directly. For a developer or business publishing an app, the practical fix starts with the same document regulators and app store reviewers check first: an accurate, current privacy policy that names every permission requested, every category of data shared, and every third party it goes to. A privacy policy generator built around app store disclosure requirements keeps that document aligned with what the app actually does, not what it did at launch.

Frequently Asked Questions

What percentage of Android apps request unnecessary permissions? 87% of Android apps request at least one permission they do not need for their core function, according to NordVPN's May 2026 mobile app research, which analyzed 103 top apps across 18 categories. iOS apps requested unneeded permissions less often, at 60%.

How many permissions does the average app request? Android apps request an average of 19 permissions each, of which about 4 are not required for the app to function, per NordVPN's May 2026 research. iOS apps request far fewer, averaging 5 permissions total, with roughly 1 unneeded.

What percentage of apps share your data with third parties? 55.2% of apps on the Google Play Store, just over 1 in 2, share user data with third parties, according to Incogni's 2026 analysis of the top 1,000 free and paid Android apps.

How many people opt in to App Tracking Transparency on iPhone? Roughly 27 to 35% of iOS users opt in to cross-app tracking when Apple's App Tracking Transparency prompt appears, depending on the measurement window, according to 2025 and 2026 industry benchmarks from Adjust and Business of Apps. The rate has climbed slowly from about 21% in 2022 but has not come close to a majority.

Where the Numbers Come From

  1. NordVPN. (2026). "Mobile privacy: What do your apps want to know?" Research Lab report, 103 apps audited across 18 categories, published May 2026.
  2. NowSecure. (2025). "How Dangerous Mobile App Permissions Threaten Enterprise Security." Android n=378,000 apps, iOS n=335,000 apps, published June 4, 2025.
  3. Incogni. (2026). "Sharing is NOT caring: Android apps that can't get enough of you." Analysis of the top 1,000 free and paid apps on Google Play.
  4. Incogni. (2026). "1 in 2 popular apps collect data: an in-depth analysis of data collection in children's Android apps." n=74 unique children's apps across 59 countries.
  5. Pixalate. (2025). "Pixalate Research Finds 253 EU & UK-Registered Mobile Apps Likely Violating GDPR-K & UK Children's Code." Q2 2025 report, published September 4, 2025.
  6. Business of Apps. (2026). "App Tracking Transparency Opt-In Rates." Aggregated industry benchmark tracker, 2022 to 2026.
  7. Adjust. "ATT opt-in rates by app category and region." Global and regional opt-in benchmarks, 2025 data.

Note: All figures verified as of July 2026. App Tracking Transparency opt-in rates vary meaningfully by measurement source and time window; treat the 27 to 35% range as the current best estimate rather than a single fixed figure. This post's headline statistics are refreshed at least twice a year to track new NordVPN, Incogni, and Pixalate report editions.