The short answer

Read the store permission panel and the developer privacy policy, then compare each requested permission to the app’s advertised features. On Android XR, inspect the APK/AndroidManifest when available. Refuse background camera, always‑on mic, continuous sensor streams or overlay/accessibility access that aren’t explicitly documented; install with one‑time or foreground permissions and test.

Time needed about 30–60 minutes, split between quick checks and a short test

Key takeaways
  • A camera or mic on your face makes ordinary phone permissions a much higher recording risk.
  • You can verify most claims before install by checking the store permission panel, the developer privacy policy and, for Android, the APK/AndroidManifest.
  • Background camera, persistent microphone, continuous sensor streams and overlay/accessibility requests are red flags unless the developer documents a clear technical need.
  • Install with one‑time or 'only while using' permissions, then test core features immediately with minimal privileges.
  • If a developer omits a privacy policy or permissions don’t match features, avoid the app and report it to the store and device vendor.
  • Use GlassesApps device pages for notes about how an app behaves on specific hardware like XREAL, Vision Pro or Ray‑Ban Meta.
Before you start
  • Your glasses paired, powered on and connected to the companion phone or host device.
  • Access to the store used by your device (Google Play for Android XR, App Store for Vision Pro, or the vendor/companion store).
  • A web browser on your phone or laptop to open the developer’s privacy policy and the GlassesApps listing (/apps).
  • Optional (Android): ability to download an APK or access an APK inspector if the app is not distributed through Play.

The steps

  1. Open the app page in the storeNavigate to the app’s listing on the device store (Google Play, App Store or vendor store) and scroll to the permissions or privacy section.You should see: You see a permissions summary or an 'App privacy' label and a link to the developer privacy policy on the same page.
  2. Read the developer privacy policyOpen the privacy policy linked on the store page and read sections about data collection, camera/microphone use and background processing.You should see: The policy names the types of data collected and explains whether audio/video or background sensor data is recorded, stored or shared.
  3. Match each permission to a featureList the app’s core advertised features and, one by one, ask why each permission is needed for those features.You should see: Every permission has a plausible explanation tied to a feature; any permission without a clear match is flagged.
  4. Check GlassesApps and vendor notesSearch the GlassesApps directory (/apps) for the app and open device pages (for example, /devices/xreal-air-2-ultra) for known issues.You should see: You find curator notes or community reports that confirm or question the app’s behaviour.
  5. Inspect the APK or manifest (Android only)If the app is available as an APK, open it in an APK inspector and view AndroidManifest.xml for requested permissions and background Service entries.You should see: You see an explicit list of permissions and any background Service declarations that indicate continuous operation.
  6. Install with minimal privilegesInstall only if permissions match features; on install choose one‑time or 'only while using' options and deny background access.You should see: The OS permission prompts show foreground/one‑time options and the app installs without background permissions granted.
  7. Test core features immediatelyOpen the app, use the advertised features for a short session, then put the app in the background and observe indicators and behaviour.You should see: The app performs core tasks while open and does not continue to access camera/mic/sensors in the background unless documented.
  8. Revoke and report if behaviour is unexpectedIf you observe unexplained background access or recording, revoke the permission in settings, uninstall the app and report it to the store and device vendor with your observations.You should see: Permissions are revoked, the app stops functioning and you have submitted a store report or vendor ticket.

Check permissions on your XREAL Air 2 Ultra before installing

On XREAL Air 2 Ultra start at the Play Store permission panel and the developer privacy policy linked on the app page. Match each requested permission to a concrete advertised feature. If the app requires background camera, persistent mic or continuous sensors without explaining why, do not install.

Why glasses permissions are riskier

Glasses put cameras and microphones closer to other people and run overlays next to your view. That turns routine phone permissions into continuous recording or tracking risks. Treat every permission by asking whether the feature truly needs continuous or background access, not whether the feature sounds plausible.

Five-minute pre-install checklist

Run these checks in order: open the store permission panel, read the developer privacy policy, look up the app on GlassesApps, and compare each permission to an advertised feature. Stop if anything is unexplained; a clear explanation must be on the store page or developer site before you proceed.

  • Open the app page on the store and read the permissions panel.
  • Open the developer’s privacy policy linked on the store page.
  • Search the app on the GlassesApps listing (/apps) for curator notes or reports.
  • Compare each permission to a specific advertised feature and ask what it enables.

How to evaluate common permissions

For each permission ask two questions: which specific feature needs it, and does that feature require continuous or background access? Prefer one‑time or foreground access. Require a documented explanation for any background operation, including where data is stored and who can access it.

  • Necessity: tie the permission to a named feature on the store page or support site.
  • Scope: does the app need continuous streams or only on-demand access?
  • Data flow: where does captured data go and for how long is it retained?
  • Documentation: background use must be described in the privacy policy or support pages.

When a permission is reasonable or a red flag

Judge permissions by feature and operation mode. Camera and mic are reasonable for active AR, video calls or on‑demand voice control. They are red flags if requested for idle/background operation or when the app has no visible reason to capture audio or video.

  • Camera — reasonable: live AR view, visual search, telepresence; red flag: camera requested without any live‑camera feature or for background recording.
  • Microphone — reasonable: on‑demand voice commands or live calls; red flag: always‑on voice detection or background audio capture with no logging disclosure.
  • Location/sensors — reasonable: turn‑by‑turn navigation or motion tracking; red flag: a static utility that asks for continuous motion or location streams.
  • Overlay/accessibility — reasonable: assistive tools that alter input or show captions; red flag: casual apps requesting overlay without an explanation.

Device-specific verification: Android XR, XREAL, Ray‑Ban Meta, Vision Pro

Stores and tools differ by device. On Android XR and XREAL use the Play Store page and, when possible, inspect the APK/AndroidManifest. For Apple Vision Pro read the App Store privacy label and the app support pages. For vendor stores and companion apps check the vendor listing and the GlassesApps device page for notes.

  • XREAL Air 2 Ultra: check Play Store permissions, the developer policy and the device page on GlassesApps (/devices/xreal-air-2-ultra).
  • Apple Vision Pro: read the App Store privacy label and the app’s support documentation; consult the Vision Pro device page (/devices/apple-vision-pro).
  • Ray‑Ban Meta and vendor stores: review the companion app permissions and vendor listing; see the device page (/devices/ray-ban-meta) for patterns.
  • Android XR: if an APK is available, inspect AndroidManifest.xml for permissions and background Service entries; see /devices/android-xr for guidance.

After install: grant minimal privileges and test

Install with one‑time or 'only while using' permissions and deny background access. Use the app for the advertised features while watching for recording indicators and unexpected network activity. Revoke any permission that the app uses when it should not and test again.

  • Grant camera/mic as 'only while using' or one‑time, then make a short call or capture to verify.
  • Deny background location and background sensor access unless documented.
  • Watch for recording lights or OS privacy indicators and confirm they activate when the app uses sensors.
  • Use companion app or device settings to view active sensors and revoke permissions immediately if behaviour is unexpected.

Recover from a bad install

If you discover unexplained background recording or uploads, revoke the app’s permissions, uninstall it and report the behaviour. If sensitive accounts were used while the app ran, rotate tokens or unlink devices that were exposed.

  • Revoke camera/microphone and background permissions in settings immediately.
  • Uninstall the app and note timestamps, screenshots or logs that show the behaviour.
  • Report the app to the store and the device vendor so they can investigate or block the app.

Report red flags and who to contact

Report apps that lack privacy policies, request unrelated background permissions, or have community reports of covert recording. Use the store‑side reporting tool and notify the device vendor; if the app was sideloaded report it to the source and the vendor so other users can be warned.

  • Use the store’s report function on Google Play or the App Store and include concise evidence.
  • File a report with the device vendor so they can warn users or remove the app from a companion store.
  • If sideloaded, report the source and avoid reinstalling until the issue is resolved.

What to do now

Open the app’s store page, read the permissions panel and the developer privacy policy, then compare each permission to a stated feature. Search the GlassesApps directory (/apps) for curator notes. Install only with foreground/one‑time permissions and run a short test with people aware you are testing.

Where this usually goes wrong

  • App keeps recording audio when you think it’s closedThe app was granted background microphone or declared a background service not disclosed on the store page.Revoke microphone and background permissions, uninstall the app, and report it to the store. Check the GlassesApps listing before reinstalling.
  • An app requests motion and location but is only a document viewerPermissions are excessive; the developer requests broad access for analytics or reused code requires sensors.Do not install. Contact the developer for an explanation; if none is provided, report the app and search GlassesApps for alternatives.
  • You installed without checking and later discover uploads to unknown serversBackground permissions were granted and the privacy policy did not disclose data sharing.Uninstall immediately, revoke account tokens if used, rotate or unlink sensitive accounts and report the behaviour to the store and vendor.
  • The app asks for accessibility/overlay and behaves like a keyloggerOverlay or accessibility permissions allow reading UI or input and a malicious app can misuse them.Revoke accessibility/overlay access immediately, uninstall, and report the app. Limit accessibility access to known, reputable apps only.

The checklist

  • Open the app page in the store
  • Read the developer privacy policy
  • Match each permission to a feature
  • Check GlassesApps and vendor notes
  • Inspect the APK or manifest (Android only)
  • Install with minimal privileges
  • Test core features immediately
  • Revoke and report if behaviour is unexpected

Frequently asked questions

Can I check all permissions before installing an Android XR app?

Yes. The Play Store lists requested permissions on the app page. If you can obtain the APK, inspect AndroidManifest.xml with an APK inspector to see every declared permission and background Service entries. Compare those entries to the app’s feature list and privacy policy; avoid APKs that declare background or dangerous permissions without a clear justification.

What if the app needs the camera for core features but I don’t want continuous recording?

Grant camera access only while you actively use the feature and deny background camera access. Test the feature with camera access granted, then revoke it to confirm the app cannot record in the background. If the app requires background access to function, decide whether that trade‑off is acceptable before you continue using it.

How do I report an app that abuses permissions on my glasses?

Report it to the store where you installed it using the app’s report function and include concise evidence: which permissions were requested and what behaviour you observed. Also notify the device vendor so they can warn users or investigate. Keep screenshots and timestamps to support your report.

Are vendor companion stores safer than Google Play or the App Store?

Not automatically. Vendor stores may curate for a device but they still require the same checks. Inspect permissions and the privacy policy regardless of store and consult vendor notes and the GlassesApps directory (/apps) for curator and community insight before trusting a vendor‑distributed app.

Find apps that work on your glasses

Every app in the directory lists the glasses it runs on, how it works on each, and the official source that proves it.

Browse the app directory