The Quick Read
Your phone is being tracked online through at least four overlapping systems, and none of them are the same one your existing privacy guide covers. The advertising identifier follows you across apps. In-app browsers in Facebook, Instagram, and TikTok inject tracking scripts into every link you tap. Third-party tracking SDKs sit inside the apps you installed and call home every time you open them. Wi-Fi and Bluetooth radios broadcast identifiers into every passing scanner.
Cutting each layer takes a few minutes in Settings. None of them require an app purchase, a custom ROM, or carrier-level intervention. The settings below are the documented paths from the vendors themselves: Apple, Google, and DuckDuckGo.
The Advertising Identifier Is the Spine of Mobile Tracking
Both iOS and Android ship a single device-level identifier whose entire purpose is to let ad networks correlate your activity across apps. Apple calls this the advertising identifier, or IDFA. Google calls it the Google advertising ID, or GAID. The two are the same idea with different branding: a per-device token that the OS hands to any app that asks, and that the ad network then uses to stitch a profile across every app on your phone that loads the same network.
Apple's developer documentation describes what happens when the user opts out at the system level: "If the user has limited ad tracking at the system level, this property returns `false`, and advertisingIdentifier returns a string of zeros (`00000000-0000-0000-0000-000000000000`)." [4] In other words, the OS hands the app a deliberately useless ID, and the app can tell from the value whether the user opted out.
The zero string is the same for every device that opts out. For any app that respects Apple's API, there is nothing to correlate against.
iPhone: Ask Apps Not to Track, and Reset the IDFA
Apple's App Tracking Transparency policy lives in the Privacy & Security area of the Settings app. There is a single app-level toggle called Allow Apps to Request to Track.
Apple's own description is specific: "If you turn off 'Allow Apps to Request to Track' in Privacy & Security settings, you won't get prompts from apps that want to track your activity. Each app that asks for permission to track while this setting is turned off will be treated as if you tapped Ask App Not to Track." [5]
The same Apple support page confirms what this changes for advertisers: "While this setting is turned off, each app that requests to track is unable to access the advertising identifier (IDFA)." [5]
Turning that one toggle off is the strongest single change an iPhone user can make. Every app you have ever installed, every app you will install, and every prompt that ever tries to come up is muted by it.
You can additionally cut what Apple itself uses to personalize ads in the App Store, Apple News, Stocks, and Apple TV. Apple's documentation says: "You can turn off Personalized Ads on your iOS, iPadOS, or visionOS device by going to Settings > Privacy & Security > Apple Advertising and tapping to turn off Personalized Ads." [1]
The same Apple page explains what the toggle actually does: "Turning off Personalized Ads will prevent Apple from using this information for ad personalization. It may not decrease the number of ads you receive, but the ads may be less relevant to you." [1] Apple's own identifier is described as "a random identifier not tied to your Apple Account," and on Maps specifically as "a session identifier that rotates multiple times per hour." [1] That is meaningfully better than the IDFA your average ad SDK hands around, but it is still Apple's profile.
Android: Opt Out of Ad Personalization and Reset the Advertising ID
Android's advertising ID lives in Google Play Services, not the OS itself. The exact path on a current Android phone is Settings, then Google, then Services, then the All Services tab, then Privacy and security. [6]
Google's own help text for the setting reads: "Opt out of ad personalization or reset your advertising ID." [6] The exact wording is the entire description Google ships with the toggle.
Opting out does not delete the advertising ID entirely. Apps that already have a copy still have a copy. Resetting does not delete it either; it just issues a new random one. The next time an app checks the ID, it gets the new value and the profile restarts from scratch.
This is meaningfully weaker than Apple's iPhone privacy rules. On iOS, opting out means the OS hands out a literal zero string. On Android, the OS hands out a real, fresh random ID. The shift makes life harder for cross-app correlation but does not eliminate it.
In-App Browsers Are Tracking You Without Tabs
When you tap a link inside Facebook, Instagram, TikTok, or Messenger, the link usually opens in a browser panel inside the app. That panel is not Safari and not Chrome. It is an in-app browser that the app controls. Every site you visit through it loads through the app's embedded WebView, meaning the app can inject JavaScript into every page you load, read every form field, and log every URL with your user identifier attached.
This is the part most readers do not realize. Tapping a link in Facebook is not the same as opening the URL in Safari. It looks identical in the moment. It is fundamentally different in what Facebook gets to see.
The workaround takes two seconds per link: long-press the link in Facebook, Instagram, TikTok, or Messenger, then choose Open in Safari (iPhone) or Open in Chrome (Android). The link opens in your real browser, outside the app's control. The trade-off is a small convenience loss: you leave the app to read the page.
The deeper fix is to use your phone's built-in browser by default for any link that matters. On Android, install a browser like Brave, Firefox Focus, or Chrome and stop tapping links in social apps from their native interface. On iPhone, do the same with Safari, Firefox Focus, or Brave.
App SDKs Track You Even When You Do Not Tap Anything
The third layer is the hardest one to see. The app on your screen is one piece of code. Bundled inside it is a second piece of code from an analytics or advertising vendor, and that second piece makes its own network calls to its own servers with its own copy of your device identifier. You never see the calls. You never agreed to them. They happen on launch, on screen change, on every meaningful event the SDK has been told to track.
Apple's App Tracking Transparency and Android's opt-out are supposed to cut this, but enforcement is uneven. Apps still load SDKs, and SDKs still make calls, regardless of whether the user denied tracking.
The single tool that addresses this directly on Android is DuckDuckGo's App Tracking Protection. It is a feature in the DuckDuckGo Private Browser for Android that runs locally on the device and intercepts the network traffic of every other app on the phone. DuckDuckGo describes it as a feature that "helps block 3rd-party trackers in your apps, even when you're not using them." [7]
The same DuckDuckGo documentation explains what it actually does: it "detect[s] when other apps on your phone are about to send data to any of the 3rd-party tracking companies in our list of app trackers, and block[s] most of those requests." [7] DuckDuckGo maintains a public list of blocked tracking companies on GitHub, and the local block list updates from that source.
DuckDuckGo is explicit that this is not a VPN. Their help page compares the two directly: "App Tracking Protection is different from a VPN" and "works locally on your device, sitting between your apps and the servers they talk to." A VPN, by contrast, "works by establishing a secure, encrypted connection (VPN tunnel) between your device and one of its servers." [8] The block is local, no remote tunnel, no third party sees your traffic.
You turn it on by installing DuckDuckGo Private Browser for Android, opening it, and toggling App Tracking Protection under the More from DuckDuckGo section. Android will then ask you to confirm a VPN configuration permission, which is the OS asking permission for any local traffic interceptor, not DuckDuckGo actually shipping your traffic anywhere.
There is no exact equivalent on iPhone. Apple's tighter rules around background execution, local network interception, and the App Store review process prevent the same kind of system-wide blocker from shipping through the App Store. The closest iPhone equivalent is a combination of App Tracking Transparency, restrictive app permissions, and limiting which apps you install.
Wi-Fi and Bluetooth Radios Leak Your Activity in Real Time
Every modern phone broadcasts two persistent identifiers into the air at all times: its Wi-Fi MAC address and its Bluetooth MAC address (or the modern equivalent, a Bluetooth LE random address that still rotates on a schedule). Stores, malls, airports, advertisers with beacon networks, and street-level sensor grids use these to count visits, log dwell time, and re-identify returning devices.
Apple describes this explicitly. Their Location Services page states: "Location Services allows Apple and third-party apps and websites to gather and use information based on the current location of your iPhone or Apple Watch. Your device will continue to transmit location data, including to Apple, until you turn off Location Services for all apps and system services." [2] Apple's location system uses "GPS and Bluetooth (where those are available), along with crowd-sourced Wi-Fi hotspot and cell tower locations." [2] The Bluetooth and Wi-Fi scanning that powers location is also the scanning that powers retail tracking.
iPhone ships with a randomized MAC address for each Wi-Fi network by default, which means a scanner cannot use the MAC to follow you between networks. The setting is per-network and is exposed by the iPhone as Private Wi-Fi Address. To check it: Settings, then tap the connected network, then look for the Private Wi-Fi Address toggle.
Second, you can cut the active Bluetooth scanning when you are not using it. Apple's Significant Locations feature on the same Settings > Privacy & Security > Location Services > System Services screen uses Bluetooth and Wi-Fi scans to "places you have recently been, how often and when you visited them, and the routes you take to get there, in order to learn places and routes that are significant to you." [2] That feature can be disabled; the location services data is "synced between your devices using end-to-end encryption and cannot be read by Apple." [2] End-to-end does not mean uncollected. Disable it if you do not want the local scan history.
On Android, the randomized MAC setting is exposed per saved Wi-Fi network and is on by default on most current builds. The exact path differs by phone maker and Android version; the toggle is typically under the network detail screen in Wi-Fi settings under a label that names "privacy" or "MAC randomization." To cut the Bluetooth beaconing, turn Bluetooth off in quick settings when you are not actively using it.
Your Browser Also Leaks the Whole Site You Visited
The browser is its own tracking layer, and it operates even with the advertising ID and SDKs cut. Every site you load gets your IP address, your user agent, and any cookies already set for its domain. If the site embeds a third-party tracker (a Google Analytics tag, a Facebook pixel, a Criteo banner), the third party also gets your IP and user agent.
iCloud Private Relay is Apple's answer for Safari users. Apple's documentation describes it as "part of an iCloud+ subscription" that "helps protect your privacy when you browse the web in Safari." [3] The mechanism uses two separate relays operated by different entities: "Your IP address is visible to your network provider and to the first relay, which is operated by Apple. Your DNS records are encrypted, so neither party can see the address of the website you're trying to visit." [3]
The second relay "generates a temporary IP address, decrypts the name of the website you requested, and connects you to the site." [3] Apple summarizes the trust model in plain language: no single party, not even Apple, can see both who you are and what sites you're visiting. [3]
On Android, the equivalent is a VPN or a Tor browser. Apple's iCloud Private Relay is Safari-only and iOS/iPadOS/macOS-only. There is no exact same-product equivalent for Chrome on Android.
The Bottom Line
Mobile tracking is layered because no single cut kills it. Disable the advertising ID and the in-app browsers still track you. Use Private Relay and the SDKs still phone home. Run DuckDuckGo's blocker and the BLE radio still pings the storefront.
If you only have ten minutes, do these in order:
- iPhone: Settings > Privacy & Security > Tracking, turn off Allow Apps to Request to Track. [5]
- Android: Settings > Google > Ads, opt out of ad personalization, then reset your advertising ID. [6]
- Android: Install DuckDuckGo Private Browser and turn on App Tracking Protection in settings. [7]
- iPhone: Settings > Privacy & Security > Apple Advertising, turn off Personalized Ads. [1]
- Both: When a link matters, long-press it and open in Safari or Chrome instead of letting Facebook, Instagram, or TikTok open it in their own browser.
- iPhone: Subscribe to iCloud+ and turn on Private Relay in iCloud settings. [3]
None of these stop a state-level adversary or a sophisticated stalker. They do stop the bulk of commercial phone tracking that follows you between apps, between sites, and between stores.
What This Does Not Stop
Cutting the advertising ID, the in-app browser, the third-party SDKs, and the radio beacons does not stop a determined adversary. A stalker with access to your carrier account can request cell-tower location records. A nation-state actor with access to your carrier's lawful-intercept system can capture your calls and messages. A law enforcement subpoena to Apple, Google, or your app vendor can pull what those vendors still store.
The settings in this article stop the bulk of commercial tracking. They do not stop targeted surveillance. Those are two different threat models with two different tool stacks. If you are facing a targeted threat, you need a different guide.
References
- Apple Legal: Apple Advertising & Privacy
- Apple Legal: Location Services & Privacy
- Apple Support: iCloud Private Relay
- Apple Developer: ASIdentifierManager
- Apple Support: Allow Apps to Request to Track
- Google Account help: Manage your advertising ID
- DuckDuckGo: What is App Tracking Protection
- DuckDuckGo: Is App Tracking Protection a VPN?