How to check that an Android app has no internet permission (and how we check ours)
SHORT ANSWER
Can an Android app without the INTERNET permission send data over the network?
Not by itself. An Android app can only open network connections if its manifest declares the INTERNET permission, which is granted automatically at install. You can list an app's declared permissions with aapt2. HostSpica Identity 1.0.0 declares no INTERNET permission, so the app's own code cannot send data over the network.
Key takeaways
- INTERNET is a "normal" permission: Android grants it at install with no prompt, so an app that declares it can use the network without ever asking you.
- Because there is no prompt, the Settings permission screen is not a reliable place to check. Read the app's manifest instead.
- No INTERNET permission stops the app's own network access. It does not stop things you choose to do through other apps, such as opening a link in your browser.
- You can verify any app in about a minute with adb and aapt2. We publish the exact commands and our results below.
Why the INTERNET permission matters
On Android, an app's ability to open sockets depends on a permission declared in its manifest: android.permission.INTERNET. It is classed as a normal permission, so the system grants it automatically when the app is installed and never shows a dialog. That is exactly why its absence is meaningful: an app that does not declare it has no way to make its own network requests, regardless of what its code tries to do.
For apps that hold secrets — one-time-code seeds, passkeys, saved passwords — this is the cleanest privacy property you can check yourself. There is no analytics SDK to trust and no server to breach, because the app has no path to one.
How to check any app yourself
You need a computer with adb and the Android SDK build-tools (for aapt2), and the app installed on a phone with USB debugging on.
- Find the APK path on the phone:
adb shell pm path <package-name>. For apps from Google Play this prints one or more paths; the one ending inbase.apkholds the manifest. - Copy it to your computer:
adb pull <path-to-base.apk> app.apk. - List the declared permissions:
aapt2 dump permissions app.apk. - Look for
android.permission.INTERNETin the output. If it is not there, the app does not declare it.
adb shell pm path com.hostspica.identity
adb pull /data/app/.../base.apk app.apk
aapt2 dump permissions app.apk
# or, with more detail:
aapt2 dump badging app.apk | grep uses-permissionWhat we found: HostSpica Identity 1.0.0
We ran the check above on the release build of HostSpica Identity 1.0.0 (package com.hostspica.identity) on 3 October 2026. The merged manifest declares these permissions and no others that grant data access:
| Permission | Why it is there |
|---|---|
| CAMERA | Scan QR codes on screen: adding a 2FA account, pairing a sign-in, approving a sign-in. The camera feed is processed on the device and not stored. |
| USE_BIOMETRIC, USE_FINGERPRINT | Fingerprint or face check to open the app, approve sign-ins and use passkeys. |
| BLUETOOTH_ADVERTISE, BLUETOOTH_CONNECT | Android 12 and newer: the direct, short-lived connection to a nearby browser for passkey sign-in and sign-in approval. |
| BLUETOOTH, BLUETOOTH_ADMIN (up to Android 11) | The same Bluetooth connection on Android 10 and 11, which use the older permissions. |
| WRITE_EXTERNAL_STORAGE, READ_EXTERNAL_STORAGE (Android 9 and below only) | Limited by maxSdkVersion to Android 9 and below. Used to save an exported QR image on those versions; no newer version is affected. |
| DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | An app-private permission that AndroidX adds automatically to protect the app's own broadcast receivers. It does not give access to any data. |
android.permission.INTERNET and ACCESS_NETWORK_STATE are not in the list. We also checked the release builds of HostSpica Authenticator and HostSpica Passkey in our build tree: neither declares INTERNET either. We repeat this check on every release, and the live Google Play build of any version can be checked with the steps above.
Things that look like network use but are not our app
- Opening a link. The "Privacy policy" button in Identity's Settings hands the address to your browser. The browser makes the request; the app does not.
- Google Play updates and review prompts. The in-app update and review features are performed by the Play Store app already on your phone. Our app only receives the result.
- Backups. You choose where to save a backup file through Android's file picker. If you pick a folder that a cloud-drive app syncs, that app uploads the file — your choice, and the file is encrypted with your password first.
What this check does not prove
For what we do to protect secrets once they are on the device, see the security overview.
Frequently asked questions
Does "no INTERNET permission" mean the app can never share my data?
It means the app itself cannot send data over the network. You can still share things through other apps, for example by saving a backup into a synced folder or copying a password and pasting it elsewhere.
Can an app get the INTERNET permission later without me knowing?
A new version can declare it, and because it is a normal permission Android would grant it automatically on update without a prompt. That is why the check should be repeated after updates, and why we state the permission list per version.
How do I check the app installed from Google Play?
Install it, then follow the steps above with the real package name: find the APK path with adb, pull base.apk, and run aapt2 dump permissions on it.
References
Review status
Last technical self-review by the author on 3 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED