Metlivi Blog

Companion-App Privacy Mode: Uses, Scenarios, and Limits

“Privacy mode” is not a standard technical promise. One companion app may use the label for an app-opening passcode. Another may hide selected chats, blur the recent-app preview, suppress message text, change an online-status indicator, or move the entire app into an operating-system private space. These features solve different problems. A lock can help when you lend an unlocked phone briefly; a hidden icon can reduce casual discovery; notification controls can keep text off a shared display. None automatically changes the provider's cloud storage, an export already saved to Photos, an active session on another device, or the security of the account password. Translate the product label into exact surfaces before relying on it. Test only your own device and account through ordinary settings—never try to bypass a lock. The useful question is not “Is privacy mode on?” but “Which visible path is covered, when does it lock, and what remains available elsewhere?”

August 30, 20268 min readHome, Safety, Pets & Sustainable LivingBy Metlivi Editorial Team
Section 1

Translate the label into one or more concrete controls

Look for separate switches: Require authentication to open, Hide app, Lock chat, Hide notification content, Blur preview, Disable presence, or Use private space. Write what object each switch controls: the whole app, selected conversation, icon and search result, notification payload, task-switcher image, or activity signal. Record the authentication method, automatic relock trigger, recovery path, and whether the setting is device-specific or account-wide. Apple distinguishes locking an app from hiding a downloaded app in a locked folder. Android private space is a separate locked environment. Signal Screen Security addresses previews and screenshots. Similar-sounding labels therefore should not be compared as if they provide the same boundary.

Section 2

Match the feature to a real scenario

For briefly handing an unlocked phone to someone, fast relock and notification hiding matter more than a hidden icon. On a shared household tablet, separate device accounts or private space may be more relevant than a chat archive. During screen sharing, task previews, notification banners, and app-switching matter. In a crowded place, shoulder visibility and lock-screen previews matter. When ending access on an old device, session management matters more than the local icon. Pick one scenario, name the observer, and define the desired result—for example, “The borrowed-phone user cannot open the companion app after I switch away.” Avoid vague goals such as “No one can ever know I use it,” which no single device feature can verify.

Section 3

Run a five-step test on your own device

Enable the feature and use a harmless test conversation. First, Discovery: check the home screen, app library or drawer, search, recent suggestions, and share sheet without trying to circumvent anything. Second, Opening: follow the ordinary tap path and observe the authentication request. Third, Notification: send a neutral test message and view the locked device, wearable, and connected desktop you own. Fourth, Preview: switch apps and inspect the recent-app card. Fifth, Other device: check an already authorized device or web session. Record pass, partial, or not covered, along with the relock event—immediate, screen lock, timeout, or app exit. Delete the test message afterward. This matrix gives a repeatable result without exposing real content.

Section 4

Check lock timing, recovery, and failure states

A privacy feature is only useful if its trigger matches the moment you need it. Test what happens after the screen sleeps, after the app goes to the background, after a phone restart, and after biometric recognition is unavailable. Read the documented passcode fallback rather than guessing. Confirm that recovery does not silently use a shared email inbox or device credential another household member knows. If private space uses a separate account, record which account installs and updates the companion app. Android warns that private-space availability and behavior depend on device support and configuration. Do not deliberately trigger repeated authentication failures or attempt another person's device. A normal, owner-authorized state test is enough.

Section 5

List the surfaces privacy mode does not own

Check provider-cloud history, device backups, exported screenshots, downloaded media, shared links, notification history, keyboard learning, and sessions on other devices. A local app lock does not sign out a web session. Hiding the icon does not encrypt an export already in Photos. Blurring a task preview does not remove notification text from a watch. A locked chat may still be included in provider retention or account export. Review account password, multifactor authentication, active sessions, OS permissions, cloud sync, and backup settings through their own controls. Also remember that an external camera can photograph a displayed screen. Do not claim a native screenshot restriction guarantees that content cannot be retained.

Section 6

Choose the smallest combination and document it

Most scenarios need two or three aligned controls, not every available switch. A borrowed-phone setup might use immediate app authentication, hidden notification content, and disabled lock-screen previews. A shared tablet may need separate device accounts, app approval, and no remembered browser session. A screen-share setup may use notification suppression, preview shielding, and a prepared window. Write the scenario, controls, relock event, recovery owner, uncovered paths, and next test date on one card. Repeat after a major OS or app update and on every device separately, because a privacy setting may not sync. Remove a control whose cost exceeds the scenario once you have evidence; complexity that causes frequent disabling is not a durable boundary.

Related questions

Common questions

Does privacy mode encrypt all companion-app data?

Not necessarily. The label may cover opening, discovery, a chat, notifications, or previews. Provider storage, backups, exports, and other sessions require separate checks.

Is hiding an app the same as locking it?

No. Hiding changes discovery, while locking requires authentication to open. Some operating systems combine them in a private folder, but their exact scope and exceptions still differ.

Should I test whether a privacy lock can be bypassed?

No. Test only documented, ordinary owner flows: discovery, opening, notifications, previews, relock, recovery, and your own authorized devices.

Related reading

Keep exploring this topic