Android App Permissions Explained: Normal, Dangerous and Special

Android App Permissions Explained: Normal, Dangerous and Special

Android permissions are the rules that decide what an app may do beyond its own sandbox, such as using the camera, reading contacts or drawing over other apps. They fall into three kinds, normal, runtime (also called dangerous) and special, and only the last two ask you for a decision.

Key takeaways
  • Normal permissions are granted automatically at install and carry little risk; runtime ("dangerous") permissions need your approval; special permissions are switched on in system settings.[1]
  • A permission list shows what an app can ask for, not what it does with the access.
  • Since Android 11 you can grant location, microphone and camera access "Only this time", and unused apps have sensitive permissions reset automatically.[2]
  • Red flag: an app asking for access its purpose does not need, such as a flashlight app that wants contacts.

Why Android has permissions at all

Every Android app runs in its own sandbox, isolated from other apps and from your data. Permissions are the controlled doors in that wall. An app declares the doors it wants in its manifest, and Android decides whether to open them automatically or to ask you first.

That is why the same list appears in two places you can check: the app's Google Play listing and the AndroidManifest.xml inside its APK. App Checker reads both.

The three kinds of permission

TypeWho decidesExamples
Normal (install-time)Granted automatically when the app is installedInternet access, vibration, network state
Signature (install-time)Granted only to apps signed with the same certificate as the app that defines itSystem-level or same-developer features
Runtime ("dangerous")You approve it in a promptCamera, microphone, location, contacts, SMS
SpecialYou switch it on in a Settings screenDraw over other apps, install unknown apps, usage access

Android's documentation describes normal permissions as access that extends beyond an app's sandbox but presents very little risk to the user's privacy, while runtime permissions are "also known as dangerous permissions" because they give access to restricted data or actions that more substantially affect the system and other apps.[1] Special permissions correspond to particularly powerful operations, such as drawing over other apps, and are toggled from the Special app access page in system settings.[1]

The controls you get as a user

Special app access: the permissions to watch

Special permissions guard the most powerful operations, so they are worth a second look:

The Accessibility Service is not a permission in this list, but it is similarly powerful; see our accessibility guide.

How to read an app's permission list

  1. Match permissions to purpose. A navigation app wanting location makes sense; a calculator wanting contacts does not.
  2. Focus on the runtime and special ones. Most apps declare many normal permissions, such as internet access, and that is expected.
  3. Look at the combination. Contacts plus SMS plus accessibility in a simple utility is a stronger signal than any one alone.
  4. Compare similar apps. If two flashlight apps differ by ten permissions, ask why.

App Checker's Play Store check and APK analyzer both label permissions that require a runtime prompt as "Dangerous", so you can scan a long list quickly.

What a permission list cannot tell you

A permission shows what an app can ask for, not what it does with that access. A legitimate messaging app and a spyware app can request the same permissions.

Treat permissions as one piece of evidence, alongside the developer's reputation, the app's age rating and privacy policy, and where you got the file. OWASP's MASVS-PRIVACY controls expect apps to minimize the data they access and be transparent about it.[4]

Frequently asked questions

What is the difference between normal and dangerous permissions?

Normal permissions are granted automatically and carry little risk, such as internet access. Dangerous (runtime) permissions give access to sensitive data or actions, such as the camera or contacts, so Android asks you to approve them.

Are dangerous permissions always bad?

No. The label means the permission is sensitive, not that the app is malicious. A camera app needs camera access. The question is whether the permission fits what the app is for.

What does "Only this time" mean?

It grants an app location, microphone or camera access for the current session only. The permission is removed once you leave the app, and the app has to ask again next time.

Why did an app lose a permission I gave it?

Android automatically resets sensitive runtime permissions for apps targeting Android 11 or higher that have not been used for a few months. Open the app and grant the permission again if you still want it.

What are special permissions?

They guard particularly powerful actions, such as drawing over other apps. You do not approve them in a pop-up; you switch them on in the Special app access section of system settings.

How do I see which apps have a permission?

Open Settings and look for the permission manager, usually under Privacy or Apps. Choose a permission such as Camera to see every app that can use it and change each one.

Why does a free app ask for so many permissions?

Some are normal and harmless, and some serve advertising or analytics libraries. Compare the list to what the app does, and prefer an alternative that asks for less.

Can I deny a permission and still use the app?

Often yes. Well-built apps work with reduced features when a runtime permission is denied. If an app refuses to work without an unrelated permission, treat that as a red flag.

Where can I see an app's permissions before installing it?

On its Google Play listing, or by searching it in App Checker, which shows the permission list from the live listing. For a file you already have, upload the APK to the analyzer.

References
  1. Permissions on Android — Android Developers — normal, signature, runtime ("dangerous") and special permission types.
  2. Permissions updates in Android 11 — Android Developers — one-time permissions and auto-reset of permissions for unused apps.
  3. Manifest.permission reference — Android Developers — REQUEST_INSTALL_PACKAGES definition.
  4. OWASP MASVS — MASVS-PRIVACY — data minimization and transparency controls.

Check an app →

App Checker FAQ

What is Paxio App Checker?

App Checker is a free tool that shows what an Android app declares before you install it. Search any app to see its Google Play permissions, ads, age rating and privacy policy, or upload an APK to see its manifest: permissions, exported components, deep links and certificate pinning.

Is App Checker free, and do I need an account?

Yes, it is free and there is no signup or account. Searches and APK uploads are rate-limited so the service stays available for everyone.

Where does the data come from?

Play Store results are fetched live from the app's current Google Play listing, not from a curated database, so they reflect what the developer has published right now. APK results are parsed directly from the file you upload.

Is my uploaded APK stored or shared?

No. An uploaded APK is analyzed for that single request and deleted immediately afterward. It is not stored, shared or kept for later.

Does App Checker scan my child's phone?

No. It never touches a device. It reads an app's public Play Store listing or a file you choose to upload, and nothing is installed or run.

Does a result mean an app is safe or unsafe?

No. App Checker reports what an app declares: the permissions it can request, whether it shows ads, its age rating. That is useful evidence, but it is not a review, an endorsement or a safety guarantee, and a permission shows what an app can ask for, not what it does with it.

How is App Checker different from the Paxio app?

App Checker is a standalone lookup tool and does not require the Paxio app. Paxio is a separate parental control app for Android that sets screen time limits, blocks apps and filters content on a child's own device.

Who builds App Checker, and how do I report a problem?

It is built by the team behind Paxio. Write to support@paxio.in with anything that looks wrong and, if you can, the app name or package ID.

See all questions, including APK analysis →