Metlivi Blog

Verify privacy layer by layer on every device

Privacy settings rarely travel as one bundle. An account-level choice may follow you to a new phone, while microphone access, photo access, notifications, browser permissions, downloaded files, and active sessions can remain local to each device or browser profile. Build a device-by-setting matrix instead of trusting the label “synced.” Put devices across the top and five layers down the side: account preferences, in-app local controls, operating-system permissions, notification and browser access, and sessions or connected services. Record the observed state, where it was changed, when it was verified, and whether the service explicitly says it syncs. Then change one harmless setting, check every device, and restore the intended state. Consistency means each device matches your chosen boundary, not that every switch must have the same technical value.

August 27, 20268 min readHome, Safety, Pets & Sustainable LivingBy Metlivi Editorial Team
Section 1

Inventory devices, browser profiles, and sessions

Start with every place that can open the account: current phone, tablet, work or home browser profile, desktop app, shared computer, old handset, replacement device, and any connected service. Distinguish a physical device from a browser profile and from an account session; one laptop can hold several independent browser profiles, while one phone can show both an app session and a web session. Record device name in your own neutral words, platform and version, app or browser version, account identifier, last observed use, and whether you still control it. Google Account guidance illustrates why session review matters: devices and sessions can be inspected and unfamiliar or unnecessary sessions signed out. Use the companion service’s own current session page when it provides one, and leave the cell unknown when it does not.

Section 2

Split privacy controls into five layers

Layer one is the service account: history, personalization, training or improvement choices, discovery, sharing defaults, retention, and connected services. Layer two is local app behavior such as an on-device lock, downloaded media, cached previews, local history, or an app-specific notification toggle. Layer three is the operating system: microphone, camera, photos, contacts, location, files, and background access. Layer four covers notification previews and browser site permissions, downloads, cookies, and autofill. Layer five contains active sessions, integrations, share links, exports, and files already outside the app. Put every relevant control in exactly one row. If the same label appears in two layers, retain two rows; a service microphone toggle and the phone’s microphone permission are different controls with different owners.

Section 3

Set the intended boundary before comparing screens

Write the desired result for each row before opening settings. Examples are “microphone only on the phone used for voice input,” “no lock-screen message preview on any shared device,” “history choice applied to this account,” or “old tablet signed out and local export removed.” This prevents visual sameness from becoming the goal. A tablet that is never used for voice should not be granted microphone access merely to match a phone. Mark each cell as verified-on, verified-off, not applicable, unknown, or blocked, and add the exact menu and date. Never infer a device state from another device’s screen. Product wording can be similar even when one switch is stored in an account and another in local application data.

Section 4

Run a one-setting propagation test

Choose a reversible, low-impact setting and harmless test content. Capture the initial state on all devices without recording private conversation text. Change the setting on one device, close and reopen the app, refresh web sessions, and observe whether other cells change. Do not toggle several settings at once, reinstall the app, or use sensitive content, because you will not know which event caused a difference. Restore the selected boundary and verify again. The test reveals only the current account, versions, and routes you observed. It does not establish a universal product rule. Record the result as account-synced, device-local, browser-profile-local, unclear, or not applicable, and repeat only after a relevant version or account change.

Section 5

Review operating-system and browser permissions separately

Apple and Android both provide system locations for reviewing app access, but the available choices depend on device, operating-system version, and permission category. On every device, open the current system page and check contacts, photos, microphone, camera, location, files, notifications, and background access only when relevant to features you actually use. In each browser profile, inspect camera, microphone, notifications, downloads, saved sign-in, and site data through that browser’s current controls. Revoking a system permission changes future access on that device; it does not prove that data already uploaded, downloaded, exported, cached, or shared was removed. Those objects stay in their own rows with their own deletion or review action.

Section 6

Close the loop when replacing, sharing, or losing access to a device

Before retiring a device, confirm the replacement independently rather than copying an old checklist as truth. Sign out the old session through the service’s documented path, remove local downloads and exports you no longer need, clear browser profiles according to the device owner’s process, and verify that notification previews and saved sign-in no longer appear. Do not remotely erase or alter a device you do not own or lack authority to manage. For a shared computer, use the approved account and browser sign-out route and ask its owner or administrator about local cleanup. Reopen the device matrix after an app reinstall, major operating-system update, password or recovery change, new integration, browser-profile migration, or lost-device event. A dated matrix makes drift visible without pretending settings can never change.

Related questions

Common questions

If a privacy switch appears on every device, is it automatically synchronized?

No. Record where each value is stored and test one reversible setting across the current devices.

Should every permission have the same value on every device?

No. The intended boundary can differ when a device does not use a feature; consistency means each cell matches its purpose.

Does signing out remove downloaded chats or exports?

Not necessarily. Sessions and local files are separate layers and need separate verification.

Related reading

Keep exploring this topic