Shadow Logging: The Quiet Compliance Risk Sitting in Every Employee’s Pocket
Everyone has had the moment. When you casually mention you’ve taken up Paddle, and the next morning your phone slaps an add for Paddle gear on your feed. “My phone is listening to me.” It’s the most persistent myth in tech — and as the BBC explains, it’s almost always wrong.
Here’s the uncomfortable truth: your phone doesn’t need to hear you. It already knows. Your searches, your location, the Wi-Fi you’re on, the apps you share with the people around you — that data quietly stitches together a profile far more accurate than any snippet of overheard conversation. The microphone was never the microphone. The *data* was the microphone.
Even the people running the apps say so. In October 2025 the Head of Instagram, Adam Mosseri, publicly debunked the idea that the app listens to you — while acknowledging that Instagram works with advertisers who share who visited their websites, so the app can then show you related content. That’s the real mechanism: not eavesdropping, but data-matching on a scale that can feel like mind-reading.
At iGO, security and compliance sit at the centre of everything we do — and mobile device data security is exactly the kind of quiet risk we help businesses get on top of. So we want to pull back the curtain on what your devices are really recording, give you the settings that shut it down, and show you why the biggest data risk isn’t while a phone is in use. It’s what happens to that data at the *end* of the device’s life.
What is shadow logging?
Turn on one setting and you can see it for yourself. On any modern iPhone, go to Settings → Privacy & Security → App Privacy Report and switch it on. Leave it running for a week, and it logs every time an app touches the microphone or camera, and — the revealing part — every domain your apps quietly talk to in the background.
What people find is rarely a rogue app recording them. It’s worse in a subtler way: a shopping app pinging dozens of tracking domains, a weather app sharing precise location, a browser session matched across apps into a single advertising profile. None of it feels like surveillance. All of it is. That constant, invisible trail is what we mean by shadow logging — and every app on the device is adding to it.
For an individual, that’s a privacy annoyance. For a business handing that same handset to an employee, it’s something else entirely.
Why is shadow logging a compliance risk, not just a privacy one?
Every device in your fleet is a data-collection surface. It carries location history, network information, app activity and — depending on the role — customer data, credentials and communications. When third-party apps siphon that off to tracking domains, you’ve lost visibility over where your organisation’s data is going. For anyone with data-protection obligations, “we don’t know which third parties our staff devices share data with” is not a comfortable sentence to say to a regulator or an auditor.
The UK has some of the strongest data laws in the world — the Data Protection Act and UK GDPR — and, as the government’s own Department for Science, Innovation and Technology reminds people, they require organisations to keep personal data safe, use it only fairly, and delete it when it’s no longer needed. Unmanaged device data sits awkwardly against all three.
The exposure shows up in three places:
- In use. Over-permissioned apps leak location, contacts and activity to parties you never vetted. Multiply that across a fleet and it becomes a genuine data-governance gap.
- Voice and assistants. This isn’t hypothetical. Apple agreed to a $95 million settlement in the Lopez v. Apple case over allegations that Siri captured recordings without consent and that contractors reviewed them — a case a judge approved and which began paying out in 2026 (Apple denied any wrongdoing). Whatever the legal nuance, the lesson for a business is simple: assistant and “improvement” features should be a conscious choice, not a default left switched on across every device you own.
- At end of life. This is the one most organisations underestimate. A phone that looks wiped is not necessarily a phone that is wiped. Retired, resold, or returned devices that haven’t been securely erased are one of the most common — and most avoidable — routes for business data to walk out the door.
How do you stop shadow logging?
It’s the same lesson as an overheating handset: a device’s behaviour is usually down to its settings, not its hardware — the difference is that here the stakes are your data, not your battery.
As the government’s DSIT puts it plainly, apps “can only access parts of your phone that you give them permission to use… You can say no or change these permissions in your phone’s settings.” That’s the whole game — the permissions are yours to control.
Whether you’re configuring a handful of devices or standardising a whole fleet (ideally enforced through an MDM), this is the checklist we’d run on every iPhone before it reaches a user:
- Audit microphone and camera access.
Settings → Privacy & Security → Microphone (and Camera). Revoke everything that isn’t a genuine calls, voice-notes or video tool. A photo editor or a game does not need your mic. - Turn on the App Privacy Report.
Settings → Privacy & Security → App Privacy Report → On. You can’t manage what you can’t see; this is your visibility layer. - Kill cross-app tracking.
Settings → Privacy & Security → Tracking → switch “Allow Apps to Request to Track” → Off. This is the master switch: every app’s cross-app tracking request is auto-denied, fleet-wide. - Turn off personalised ads.
Settings → Privacy & Security → Apple Advertising → Personalised Ads → Off. - Switch off Significant Locations.
Settings → Privacy & Security → Location Services → System Services → Significant Locations → Off. Left on, the device keeps a timestamped diary of everywhere it — and its user — has been. - Tighten location app by app.
In Location Services, set anything that isn’t maps or delivery to “Never,” and turn off Precise Location for the rest. Most apps have no business knowing exactly where a device is. - Opt out of Siri “improvement.”
Settings → Apple Intelligence & Siri (also under Privacy & Security → Analytics & Improvements) → turn off “Improve Siri & Dictation.” Given the settlement above, this is an easy call.
Fifteen minutes per device, and the shadow log goes dark. But — and this is the part that matters most for a business — settings only govern the device while you control it.
What’s the one risk you can’t fix in the settings menu?
You can lock a handset down perfectly for three years, and then undo all of it in the thirty seconds it takes to hand that device on without a certified wipe.
Device data security isn’t a moment; it’s a lifecycle — and it cuts both ways. A device leaving your business without a proper wipe leaks your data outward; a refurbished device arriving into your business without one means you could be inheriting someone else’s.
Which is exactly why who you source your devices from matters just as much as how you retire them.
This is precisely where iGO comes in, and why we take it as seriously as we do.
How iGO keeps every device we supply secure
Security isn’t a bolt-on for us — it’s built into how we supply. Every device we supply arrives clean, secure and ready to deploy: professionally graded, fully tested, and securely data-wiped to a verified known-good state, with a 12-month warranty as standard.
You’re never inheriting someone else’s data, and your team starts from a clean, predictable baseline.
That same rigour runs across the device lifecycle:
- Every supplied device, verifiably clean. Certified wiping and grading before dispatch, so the refurbished phones and tablets you receive are genuinely clean — not just factory-reset.
- Full IMEI tracking from the moment a device enters our process to the moment it reaches you, so everything is accounted for and auditable.
- Pre-configuration to your spec, where you want it, so devices arrive locked down and standardised rather than something your IT team has to harden by hand.
- And when devices come back the other way — trade-ins, upgrades or end-of-life returns — we handle secure data destruction and reverse logistics too, giving you a documented, compliant route for retiring old hardware as well as sourcing new.
The result: refurbished phones and tablets that make commercial and compliance sense, supplied by a partner who treats your data trail as carefully as you do — with trade-in and secure retirement there when you need them, not as the whole story.
Let’s build something — become a hardware partner
If you’re an insurer, retailer, distributor or repair network, here’s the direct invitation:
Partner with iGO for your device fulfilment and data destruction, and let us take the risk out of your hardware lifecycle.
Whether you want to buy refurbished phones and tablets in bulk, plug our fulfilment and secure-wiping into your existing operation, or set up a repeatable ordering pipeline through our system integration and API, we’ll build the right programme around your volumes, grades and compliance needs.
Start here → iGO Fulfilment
Talk to us directly → [email protected]
Tell us what you’re moving and how often, and we’ll come back with a plan to make your device supply cleaner, greener, fully tracked, and genuinely secure — end to end.
Frequently asked questions
Is my phone really listening to my conversations?
Not in the way people fear. Phones listen passively for wake words like “Hey Siri,” but there’s no evidence your conversations are recorded to target ads — even the Head of Instagram has publicly said the app doesn’t listen.
The ads come from data: your searches, location, network and shared app activity. As the BBC sets out, it’s data-matching, not eavesdropping.
What is shadow logging?
It’s the constant, invisible trail of data your apps share in the background — tracking domains, location, cross-app activity — even when nothing is obviously recording.
Turn on Settings → Privacy & Security → App Privacy Report to see it for yourself.
How do I stop apps tracking me on my iPhone?
Turn off “Allow Apps to Request to Track,” switch off Personalised Ads and Significant Locations, set location access to “Never” or “While Using” app by app, and opt out of “Improve Siri & Dictation.”
Around fifteen minutes per device.
Does this matter for my business, not just me personally?
Yes.
Every staff handset carries location history, network data and often customer information, and the UK’s Data Protection Act and UK GDPR require you to keep that data safe and delete it when it’s no longer needed.
Unmanaged apps and un-wiped end-of-life devices are two of the most common ways it leaks.
How does iGO keep device data secure?
Every device that passes through us gets secure data destruction and certified wiping, full IMEI tracking, and documented reverse logistics — so your data never becomes someone else’s asset.
See iGO Fulfilment or email [email protected].
Security and compliance aren’t a feature at iGO. They’re the whole point. Send one email to [email protected] and let’s map out your device lifecycle together.

Leave A Comment