Browse privately on your phone

Reduce what your phone reveals about you, and understand the network layer that no app or setting can hide.

Difficulty
Advanced
Time
About 30 minutes
Platforms
Android, iOS

You can harden a laptop carefully and then undo all of it by doing the same research on an ordinary phone. Phones are built to be identified. They announce themselves to the mobile network, run dozens of chatty applications and know where you are. If anonymity matters to you, the phone is where most people quietly fail.

Start with one uncomfortable fact.

The layer you cannot change with an app

As soon as your phone has a SIM and a signal, the mobile network knows which device is connected, which subscriber it belongs to, and roughly where you are, based on the towers in range. No browser, VPN or private-browsing setting touches this. It happens in the network itself, below the applications.

The only real defences at that layer are physical: aeroplane mode, leaving the phone behind, or using a device with no SIM connected to you. For most people that is disproportionate. But if your threat model is serious, understand that a powered-on phone is a location beacon regardless of what is on the screen.

Everything below concerns the layers you can control. This guide is a companion to Browse the web anonymously, and uses the same three tiers.

Tier 1: Everyday phone privacy

Sensible defaults that reduce tracking substantially for very little effort. These apply to both iPhone and Android.

  • Turn off the advertising identifier. On iOS, disable “Allow Apps to Request to Track” and personalised advertising. On Android, delete or reset the advertising ID. This alone breaks a great deal of cross-app profiling.
  • Audit application permissions. Revoke location, microphone and camera access from anything that does not strictly need them. Prefer “while using” over “always” for location, and deny background location widely.
  • Use encrypted DNS. Android has a built-in private DNS setting; iOS requires a configuration profile or an application from the provider.
  • Set a tracker-blocking browser as the default, and add a content blocker where the platform supports one.
  • Consider a system-wide tracker blocker. On Android, a local VPN-based blocker can filter tracker domains outside the browser as well as inside it.
  • Reduce your application set. Every application is a data collector. Where a service works acceptably in the browser, prefer the website to the app.

Tier 2: Anonymous browsing on mobile

For sessions that should not be linkable to you, rather than merely untracked.

  • Android: use the official Tor Browser for Android, or route selected applications through Tor with Orbot. Raise the security level and do not customise the browser.
  • iPhone and iPad: use Onion Browser, which the Tor Project recommends for iOS. Because all iOS browsers use Apple’s WebKit engine, it offers somewhat weaker protection than Tor Browser does on other platforms. That is acceptable for most needs but not for the highest-risk work.
  • The desktop rules still apply. Do not sign in to real accounts during an anonymous session, do not add extensions and do not mix identities.
  • For a signup that should not lead back to you, pair this with Set up anonymous email and payments.

Tier 3: High-risk mobile setups

If discovery carries real danger, harden the whole device, or better, carry a separate clean one.

  • A Pixel running GrapheneOS is the strongest widely available option. GrapheneOS hardens Android, removes Google telemetry and provides per-application network and sensor permissions, so an application can be cut off from the internet or from the accelerometer entirely. A recent Pixel with a strong passphrase rather than a six-digit PIN, and the smallest possible set of applications, is the standard high-security build.
  • An iPhone with Lockdown Mode is the easier mainstream option. It reduces the attack surface targeted by mercenary spyware by disabling some web technologies and blocking unknown FaceTime requests and attachment previews. It is far less configurable than GrapheneOS but it is a genuine improvement behind a single toggle.
  • Consider a dedicated device. A clean phone used only for sensitive work, never signed in to your real accounts, is safer than trying to compartmentalise one everyday phone.
  • CalyxOS on a Pixel is a middle path. It removes Google’s core telemetry while keeping more everyday applications working than GrapheneOS does.

What still leaks

  • Cloud backups. An encrypted phone that backs up to a cloud account registered to you can undo the whole arrangement. Check what is syncing.
  • Notifications. Notification content and metadata can pass through platform servers.
  • Biometrics compared with a passphrase. Face and fingerprint unlock are convenient, but in some jurisdictions they can be compelled more easily than a memorised passphrase. Understand the trade-off where you live.
  • Sensor and behavioural data. Motion sensors, typing patterns and the timing of your activity can correlate a clean device with you.

Sources and further reading

Operating system features, default settings and hardware options change with every release. Re-verify the specific settings and device recommendations against the official documentation above before relying on them.

This page was last reviewed on 27 July 2026