When an app on your iPhone asks to access your photos, most people tap “Allow” without reading the fine print. The app wants to let you set a profile picture, or share a photo in a chat, or import an image. The request seems minimal and specific.
What many people don’t realize is that “Allow Access to All Photos” is a meaningful grant of access — not just to the one photo you’re about to share, but to your entire camera roll. Every photo you’ve ever taken. Every screenshot. Every image saved from a messaging app. The photos from your doctor’s appointment, your tax documents scanned in January, your children’s faces, the location data embedded in thousands of images.
iOS has the controls to prevent this. Most users have never seen them.
The Four Levels of Photo Access in iOS
Starting with iOS 14, Apple introduced granular photo permission controls that go beyond the binary allow/deny. When an app requests photo access, iOS now presents four options:
Select Photos. The app can only see the specific photos you choose to share. You pick individual photos from your library; the app has no visibility into anything else. The selection can be changed at any time.
Allow Access to All Photos. The app gets full read access to your entire camera roll, all albums, all screenshots, and all media saved to your device. This is the least restrictive option.
Add Photos Only. The app can save new photos to your library but cannot read existing ones. This is appropriate for camera apps and some sharing apps.
Don’t Allow. The app has no access to your photos.
The problem is that many apps continue to request “Allow All Photos” access through their own prompts, often with language that makes “Allow All” sound like the normal or necessary choice. And many users who set up their phones years ago, before these granular controls existed, are running on old permissions they’ve never revisited.
What Apps Can Do With Full Photo Access
When an app has full access to your photo library, it can:
Read every photo’s contents. The app sees the image data — not just thumbnails, but the full-resolution file. For a photo editing app, this is necessary. For an app that only needs to let you pick a profile picture, it’s far more than required.
Read EXIF metadata. Every photo taken with your iPhone contains embedded metadata: the precise GPS coordinates where the photo was taken (if location services were active), the exact timestamp, the device model and camera settings. An app with photo access receives this metadata for every photo in your library.
Map your location history. A collection of geotagged photos is a detailed location log. The GPS coordinates in photos from your home, your workplace, your doctor’s office, your children’s school, and your frequent routes are all embedded in the metadata. An app with full photo access can extract this information automatically.
Access sensitive documents. Most people’s camera rolls include photos of documents: passports, driver’s licenses, financial statements, prescription labels, medical appointment summaries, whiteboards with confidential information. An app with full photo access sees all of this.
Access images of people. Your photos contain faces — family members, friends, colleagues — that can be used for facial recognition purposes. An app with full access can perform face detection on your entire library.
How to Audit Your Current Permissions
iOS provides two ways to see which apps have access to your photos.
Method 1: Privacy & Security settings
- Open Settings
- Go to Privacy & Security > Photos
This shows a list of every app that has requested photo access, with its current permission level displayed. You can tap any app to change its permission immediately.
Look through this list carefully. You’ll likely find apps with full photo access that don’t need it — social media apps that were granted access years ago, apps you rarely use, apps whose primary function has nothing to do with photos.
Method 2: App Privacy Report
- Open Settings
- Go to Privacy & Security > App Privacy Report
- Enable the report if you haven’t already
The App Privacy Report shows you which apps have actually accessed your photos in the last seven days, not just which ones have permission to. This is more useful than the permission list alone — it tells you which apps are actively using their access, rather than just holding the permission for potential future use.
Apps that have photo permission but haven’t accessed your library recently are still a risk (they could start at any time, or after an update) but are a lower priority than apps actively reading your photos.
The “Select Photos” Option: More Useful Than Most People Know
The “Select Photos” permission level is significantly underused because most apps request “Allow All” and iOS presents it as the first option.
Here’s why “Select Photos” is often sufficient and worth choosing:
When you grant “Select Photos” access, you pick specific photos from your library. The app can only see those photos. If you need to give the app access to additional photos later, you go back to the permission settings and update your selection — or the app will prompt you to add more photos when you try to share one it doesn’t have access to.
For most common use cases — uploading a profile picture, sharing a photo in a messaging app, adding an image to a form — the “Select Photos” level provides exactly the functionality you need while limiting exposure to the rest of your library.
The limitation is that some apps genuinely need broader access: a photo backup app, a photo editing app that needs to browse your full library, a memories app that you want to organize everything. For these, “Allow All Photos” is functionally necessary. For most apps that request it, it isn’t.
EXIF Metadata: The Data Inside Your Photos
Photo permissions don’t just control access to the images themselves — they control access to the metadata embedded in them.
EXIF (Exchangeable Image File Format) metadata is technical information embedded in photo files when they’re taken. On an iPhone, this typically includes:
- GPS coordinates, if Location Services were active when the photo was taken
- Timestamp, accurate to the second
- Device model (iPhone model and iOS version)
- Camera settings (focal length, aperture, ISO, shutter speed)
- Orientation data
The GPS data is the most sensitive for most people. A photo taken at home contains the GPS coordinates of your home. A photo at a medical facility contains coordinates that reveal where you sought medical care. Photos from your children’s school contain the school’s location. Photos taken over years of daily life constitute a granular location history.
An app with full photo access receives all of this metadata along with the image data. The metadata retrieval requires no special permission beyond photo access — it’s embedded in the files.
To check whether your photos contain GPS data:
- Open a photo in the iOS Photos app
- Swipe up on the photo to see details
- If a map appears, the photo has GPS coordinates embedded
If you’re planning to share a photo and want to remove the location data, the Photos app allows this: tap the Share button, then look for “Options” at the top of the share sheet, where you can toggle location data off before sharing.
What iOS Does (and Doesn’t) Protect You From
Apple has built meaningful privacy controls into iOS for photo access. Worth being clear about what these controls do and don’t cover.
What they protect: Third-party apps running on your device are limited by the permission level you set. An app that has been granted “Select Photos” cannot access the rest of your library. Apps are sandboxed — they can’t access each other’s data or bypass the permission system.
What they don’t protect: If an app collects photos or metadata and transmits them to its servers, the privacy of that data is then governed by the app’s privacy policy and security practices, not by iOS. The permission system controls what the app can access on your device; it doesn’t control what the app does with data once it has it.
Apple’s own processing: If iCloud Photos is enabled, your photos sync to iCloud. Apple performs server-side processing for features like face recognition, scene detection, and Memories. Apple’s processing occurs on-device where technically possible (the neural engine is used for some of this work), and Apple’s privacy documentation outlines how their cloud-based processing works. This is a separate consideration from third-party app permissions.
App Privacy Report limitations: The Privacy Report shows which apps accessed your photos. It doesn’t show what the apps did with the photos after accessing them — whether they transmitted them, what they extracted, or how long they retained the data.
Changes to Make Right Now
If you haven’t audited your photo permissions recently, here’s a practical checklist:
Step 1: Open Settings > Privacy & Security > Photos. Review every app listed. For any app with “All Photos” access that you don’t clearly need to browse your full library, change it to “Selected Photos.”
Step 2: Enable App Privacy Report. Settings > Privacy & Security > App Privacy Report. Check it after a week of normal use to see which apps are actively using their photo access.
Step 3: Review camera access separately. Settings > Privacy & Security > Camera. Camera access and photo library access are separate permissions. An app with camera access can take photos during active use but doesn’t automatically have access to your existing library.
Step 4: Check Location Services for the Camera app itself. Settings > Privacy & Security > Location Services > Camera. The Camera app can be set to “Never,” “Ask Next Time,” or “While Using.” If location tagging in photos concerns you, setting this to “Never” stops new photos from being geotagged at capture, which addresses the issue at the source.
Step 5: Before sharing photos, use “Remove Location Data.” When using the share sheet to send a photo to someone, tap “Options” and disable location before sending. This strips the GPS coordinates from the copy that leaves your device.
The Broader Pattern
Photo permissions are one instance of a broader iOS privacy pattern: the controls exist, they’re granular, and they’re under-used because the default prompts favor app convenience over user control.
The “Allow Access to All Photos” option is prominently placed for a reason — apps want it, and the permission prompt is designed to make it easy to grant. The more protective options — “Select Photos,” “Don’t Allow” — are available but take deliberate engagement to choose.
Taking twenty minutes to go through your photo permissions, check which apps are actively reading your library, and switch “All Photos” grants to “Selected Photos” where appropriate is one of the highest-leverage privacy actions available on iOS. The controls work. They just need to be used.
Storing Photos Privately Outside the Camera Roll
If you’re taking photos or scanning documents specifically for private record-keeping — medical documents, financial paperwork, personal archives — storing them in a dedicated private service keeps them separate from the general camera roll that any app with photo access can see.
daftei is designed for this use case: photos and files stored with AES-256 encryption at rest and TLS 1.3 in transit, without AI training on your content and without advertising. Files in daftei aren’t part of your iOS camera roll, so they’re outside the scope of any photo permission grant you make to other apps. Storage starts at 5 GB free, with unlimited on the Pro plan.
The permission audit described above makes your camera roll meaningfully more private. For content that needs stricter isolation — sensitive health records, identity documents, private memories — a dedicated private storage tool adds an additional layer beyond what permission controls alone can provide.