
It’s not exactly a secret nowadays that Android phones collect user data. In fact, they do so roughly every four and a half minutes—even while sitting untouched in a pocket, sending details like the device’s hardware serial number and phone number.
However, most people think data collection only happens after you’ve installed apps or created accounts. The truth is that even brand-new, out-of-the-box Android phones start tracking your device once you connect it to Wi-Fi. This happens even before you ever download a single app, slot in a SIM card, or touch anything else.
If you care about data privacy, you’re probably asking: What exactly gets sent to Google? How true is this? What can I do about it? Understanding what your phone shares is an important part of protecting your personal information. Other safeguards, including identity theft coverage, may provide additional support if that information is later exposed or misused.
Here’s what you should know.
What Happens at First Boot
The moment your phone connects to the internet, the Google apps (Play Services, Play Store, etc.) and other pre-installed apps may connect to Google’s servers. They check for updates, register the device with Firebase Cloud Messaging (Google’s system for delivering push notifications), and report hardware and software identifiers used for checks like Play Integrity.
None of this requires opening an app since stock Android as an operating system is dependent on Google’s services. It’s not optional. If you use OEM devices from Samsung, Xiaomi, or other Android phone brands, they also connect and send data to their own servers on top of the Google Services connection.
What Gets Sent to Google
This is not speculation by people who are hardcore about privacy. The same research team from Trinity College Dublin published a follow-up paper in 2025, examining exactly what is transmitted between pre-installed Google apps and Google’s servers before the user ever opens them.
The findings:
- Advertising cookies.
- Analytics cookies.
- Click-tracking links.
- Device identifiers.
These were all downloaded and stored on the phone, even on a freshly reset device. No Google app was even opened, no consent was requested, and there is no way to opt out either.
The study also argues that this data transmission by Android’s pre-installed apps is a regulatory blind spot—at least in Europe. They operate in the same way browser tracking cookies do, and the EU’s e-Privacy Directive already requires consent for that kind of tracking on the web.
The study argues that this practice raises questions under the EU’s ePrivacy rules, which regulate storing or accessing information on users’ devices.
What You Can Actually Control
While you can’t separate a stock or Google-certified Android build from Google’s services, there are ways that at least allow you to shrink your footprint:
- Use a de-Googled ROM (GrapheneOS, CalyxOS) if your device supports it. These are privacy-focused, alternative Android operating systems that do not inherently rely on Google apps and services. Note, however, that other apps you install can still be in communication with Google.
- Use the Aurora Store or F-Droid to download apps instead of the Google Play Store.
- Aurora still pulls apps from Google Play’s servers and sends your installed-apps list and device details to Google by default. However, it doesn’t require you to sign in to a Google account.
- F-Droid distributes free and open-source apps independently of the Google Play Store.
- Turn off usage and diagnostics reporting in Settings, even though this only trims part of the traffic.
- Run a local firewall like NetGuard to see (and block) which system components are contacting external servers like Google or your phone brand’s servers (Samsung, Xiaomi, etc.)
- Audit your Google account, as it’s arguably the bigger exposure. Review its connected apps and activity controls regularly.
Android’s openness is arguably its greatest strength—but being open doesn’t equate to being neutral. Google will always want your data, but with the steps above, you can at least cut down how much of it you hand over.







