# Remove unnecessary permissions?

**URL:** <https://community.thunkable.com/t/remove-unnecessary-permissions/226188>\
**Category:** Questions about Thunkable X\
**Created:** [September 14, 2019, 8:52am UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188 "2019-09-14T08:52:19Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![wrybread](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wrybread](https://community.thunkable.com/u/wrybread)\
**Post date:** [September 14, 2019, 8:52am UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/1 "2019-09-14T08:52:19Z")

</div>

I’m trying to remove unnecessary permissions from my Android Thunkable app. By default the Play Store is telling me my app is requesting this:

android.permission.CAMERA  
android.permission.RECORD\_AUDIO  
android.permission.READ\_PHONE\_STATE  
android.permission.READ\_CONTACTS

My app simply plays a few sounds, so these are completely unnecessary. Any advice on removing them?

---

<div class="post-metadata">

**Author:** ![kartik14](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/kartik14/32/44782_2.png) [@kartik14](https://community.thunkable.com/u/kartik14)\
**Post date:** [September 14, 2019, 8:55am UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/2 "2019-09-14T08:55:18Z")

</div>

Hi,  
What components have you used?

> [@wrybread](#):
>
> CAMERA

Seems you used **Camera**

> [@wrybread](#):
>
> RECORD\_AUDIO

Seems you used **Sound Recorder (Voice Recognizer)**

> [@wrybread](#):
>
> READ\_PHONE\_STATE

Seems you used **Photo Album**

* * *

> [@wrybread](#):
>
> My app simply plays a few sounds

From where?  
Have you taken them in assets?

# Thanks!

---

<div class="post-metadata">

**Author:** ![wrybread](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wrybread](https://community.thunkable.com/u/wrybread)\
**Post date:** [September 14, 2019, 9:09am UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/3 "2019-09-14T09:09:42Z")

</div>

> Seems you used **Camera** , sound recorder, etc

That’s odd, I haven’t done any of those things, at least not intentionally.

My app is just a bunch of buttons that trigger sounds (a “soundboard”), nothing more. The sounds are just MP3s that I imported into the files section.

---

<div class="post-metadata">

**Author:** ![wrybread](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wrybread](https://community.thunkable.com/u/wrybread)\
**Post date:** [September 15, 2019, 7:50am UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/4 "2019-09-15T07:50:54Z")

</div>

I figured out how to remove the permissions manually, in manifest.xml. Using APK Studio it’s possible to open the manifest.xml file and remove these permissions:

```
<uses-permission android:name="android.permission.CAMERA"/>
<uses-permission android:name="android.permission.READ_CONTACTS"/>
<uses-permission android:name="android.permission.READ_CALENDAR"/>
<uses-permission android:name="android.permission.WRITE_CALENDAR"/>
<uses-permission android:name="android.permission.RECORD_AUDIO"/>

```

Two questions:

- can anyone see a disadvantage to manually removing these permissions from manifest.xml? (assuming of course that my app doesn’t use the above features of Thunkable)? Am I likely to break anything internally?

- Is there any way to remove these permissions in the Thunkable IDE? If not, I’d humbly suggest that it would be a nice option… I would never install an app that asks for access to my contacts without good reason.

---

<div class="post-metadata">

**Author:** ![kartik14](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/kartik14/32/44782_2.png) [@kartik14](https://community.thunkable.com/u/kartik14)\
**Post date:** [September 15, 2019, 8:13am UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/5 "2019-09-15T08:13:22Z")

</div>

I wonder how these silly permissions even got into your app… 🤔

> [@wrybread](#):
>
> I figured out how to remove the permissions manually, in manifest.xml

So, is your Problem solved for now?  
If yes, Mark [**this**](http://community.thunkable.com/t/remove-unnecessary-permissions/226188/4) (Click this to see the post 😅) post as the Solution! ✅

It will clear this topic from the unsolved topics, and move his to solved topics. 😉

# Thanks! 😊

---

<div class="post-metadata">

**Author:** ![wrybread](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wrybread](https://community.thunkable.com/u/wrybread)\
**Post date:** [September 15, 2019, 8:30am UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/6 "2019-09-15T08:30:20Z")

</div>

> [@kartik14](#):
>
> I wonder how these silly permissions even got into your app… 🤔

It looks like Thunkable adds these permissions into every app? I just created a new app and inserted a single button, then built the APK and examined it’s manifest.xml, and it created all of the above permissions too, including the need to read my contacts…

Does anyone know why that is?

And if there isn’t already a way to disable that, maybe it would make a good feature request?

> [@kartik14](#):
>
> So, is your Problem solved for now?

It’s more of a workaround than a solution I think, but I’m glad to mark it solved if you think that’s appropriate.

---

<div class="post-metadata">

**Author:** ![doctorsof](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/doctorsof/32/30099_2.png) [@doctorsof](https://community.thunkable.com/u/doctorsof)\
**Post date:** [September 15, 2019, 12:18pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/7 "2019-09-15T12:18:51Z")

</div>

@Mark will help and solve i hope it will be great.  
Thanks

---

<div class="post-metadata">

**Author:** ![Mark](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/mark/32/18133_2.png) [@Mark](https://community.thunkable.com/u/Mark)\
**Post date:** [September 16, 2019, 4:46pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/8 "2019-09-16T16:46:09Z")

</div>

We know about this. Given our product architecture it’s a bit more complex to deal with than we’d like, so it might take a while. For the most part, it doesn’t interfere with the actual working of your apps, but I appreciate that you (and your users) don’t want to see unneeded permissions in the list.

-Mark

---

<div class="post-metadata">

**Author:** ![wrybread](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wrybread](https://community.thunkable.com/u/wrybread)\
**Post date:** [September 16, 2019, 5:00pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/9 "2019-09-16T17:00:06Z")

</div>

Thanks for the explanation. I still don’t understand why access to contacts would ever be required, given the available widgets? Of all the requested default permissions that seems like the most alarming to users.

And maybe the ability to turn these off in app settings?

---

<div class="post-metadata">

**Author:** ![wrybread](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wrybread](https://community.thunkable.com/u/wrybread)\
**Post date:** [September 16, 2019, 5:37pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/10 "2019-09-16T17:37:34Z")

</div>

And by the way @mark (and all the devs) thanks massively for the amazing work you do! Hopefully it’s clear the above is all meant constructively.

---

<div class="post-metadata">

**Author:** ![Mark](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/mark/32/18133_2.png) [@Mark](https://community.thunkable.com/u/Mark)\
**Post date:** [September 16, 2019, 6:20pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/11 "2019-09-16T18:20:10Z")

</div>

> [@wrybread](#):
>
> I still don’t understand why access to contacts would ever be required, given the available widgets? Of all the requested default permissions that seems like the most alarming to users.

Yeah, I think it’s worth us looking into that one specifically.

-Mark

---

<div class="post-metadata">

**Author:** ![Mark](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/mark/32/18133_2.png) [@Mark](https://community.thunkable.com/u/Mark)\
**Post date:** [September 16, 2019, 6:21pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/12 "2019-09-16T18:21:06Z")

</div>

> [@wrybread](#):
>
> And by the way @mark (and all the devs) thanks massively for the amazing work you do! Hopefully it’s clear the above is all meant constructively.

Thanks, @wrybread! We appreciate your appreciation!

-Mark

---

<div class="post-metadata">

**Author:** ![edgoscpl](https://avatars.discourse-cdn.com/v4/letter/e/bb73d2/32.png) [@edgoscpl](https://community.thunkable.com/u/edgoscpl)\
**Post date:** [September 27, 2019, 5:41pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/13 "2019-09-27T17:41:59Z")

</div>

I am not sure how this will manifest itself, in the App Listing, or just requiring a Privacy Policy, can someone explain, since we do not use any of there permissions? Also, would thunkable in an important case will willing to review the App and remove these from any manifests?

Ed

---

<div class="post-metadata">

**Author:** ![eoinparkinson](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/eoinparkinson/32/143769_2.png) [@eoinparkinson](https://community.thunkable.com/u/eoinparkinson)\
**Post date:** [September 27, 2019, 5:59pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/14 "2019-09-27T17:59:55Z")

</div>

These permissions are default installed. It is much simpler and means there is less chance of a mess up with the code if you add a component then remove it. Everything is pre imported. Just make a privacy policy with [Free Privacy Policy](https://www.freeprivacypolicy.com/).

---

<div class="post-metadata">

**Author:** ![wrybread](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wrybread](https://community.thunkable.com/u/wrybread)\
**Post date:** [September 27, 2019, 6:16pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/15 "2019-09-27T18:16:46Z")

</div>

> [@eoinparkinson](#):
>
> Just make a privacy policy with [Free Privacy Policy](https://www.freeprivacypolicy.com/).

If I’m understanding the suggestion, you’re suggesting keeping all permissions (including access to contacts), and assume that users will seek out a privacy policy to see how their information will be used? And to trust the app creator to abide by that privacy policy?

---

<div class="post-metadata">

**Author:** ![eoinparkinson](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/eoinparkinson/32/143769_2.png) [@eoinparkinson](https://community.thunkable.com/u/eoinparkinson)\
**Post date:** [September 27, 2019, 6:19pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/16 "2019-09-27T18:19:36Z")

</div>

If you app tries to actually access contacts, location, etc, Android/iOS will prompt the user with an Alert asking to give permissions. Otherwise no permissions are given. By default Android has all permissions set to false. So your users will not have to worry about you reading their contacts or viewing their location, unless of course your app does that.

---

<div class="post-metadata">

**Author:** ![edgoscpl](https://avatars.discourse-cdn.com/v4/letter/e/bb73d2/32.png) [@edgoscpl](https://community.thunkable.com/u/edgoscpl)\
**Post date:** [September 27, 2019, 6:54pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/17 "2019-09-27T18:54:15Z")

</div>

To be more specific, our app does not use any of these, very simple. I understand since we do not use these, it wont ask for permission while the app is running, unless I am wrong. Will the user be prompted for any of these permissions on installation? Really wish since we do not use these they were not there.

---

<div class="post-metadata">

**Author:** ![wrybread](https://avatars.discourse-cdn.com/v4/letter/w/c89c15/32.png) [@wrybread](https://community.thunkable.com/u/wrybread)\
**Post date:** [September 27, 2019, 9:31pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/18 "2019-09-27T21:31:13Z")

</div>

It prompted me to grant those permissions.

It’s just an XML file (manifest.xml), it should be easy enough to have Thunkable selectively grant those permissions depending on which modules are used, no?

---

<div class="post-metadata">

**Author:** ![chapapptivellc](https://avatars.discourse-cdn.com/v4/letter/c/54ee81/32.png) [@chapapptivellc](https://community.thunkable.com/u/chapapptivellc)\
**Post date:** [October 5, 2021, 6:01pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/19 "2021-10-05T18:01:12Z")

</div>

Yes, it would be very helpful to have Thunkable creators opt out of unnecessary permissions. My app as permissions listed that it does not use.

 ![Screen Shot 2021-10-05 at 1.59.08 PM](https://us1.discourse-cdn.com/flex015/uploads/thunkable/original/3X/9/d/9dbf608a95edb24cd783dc77ef8ab85fb18dcb66.png)

This is undesirable and undercuts some of the advantages of Thunkable.

😀

---

<div class="post-metadata">

**Author:** ![tatiang](https://sea1.discourse-cdn.com/flex015/user_avatar/community.thunkable.com/tatiang/32/55482_2.png) [@tatiang](https://community.thunkable.com/u/tatiang)\
**Post date:** [October 5, 2021, 6:06pm UTC](https://community.thunkable.com/t/remove-unnecessary-permissions/226188/20 "2021-10-05T18:06:44Z")

</div>

As you can see from some of the responses above, these permissions often depend on the components you are using in your project. Which of these have you used? I believe the permissions can remain **even if you add and then remove a component**.

[Next page](https://community.thunkable.com/t/remove-unnecessary-permissions/226188.md?page=2)
