Same App, 12 Phones, Completely Different Stories: What Your Device Manufacturer Isn't Telling You
Here's something that doesn't get talked about nearly enough in mobile tech circles: when you download an app, you probably assume it behaves the same way no matter what phone you're using. Same icon, same interface, same app store listing — same experience, right?
Wrong. Very, very wrong.
We spent several weeks loading identical apps onto 12 different devices — a mix of Android flagships, mid-rangers, older OS builds, and a couple of iPhones — and then we watched what those apps actually did. The data collection patterns we uncovered weren't just slightly different between devices. In some cases, they were so far apart it was hard to believe we were looking at the same application.
The Test Setup
We're not going to pretend this was a clinical lab study with a six-figure budget. But we were methodical. The device lineup included phones running Android 11, 12, 13, and 14, from four different manufacturers — Samsung, Google, OnePlus, and Motorola — plus two iPhones running iOS 16 and iOS 17. Every device was freshly reset. Every app was downloaded fresh from the official store. We used network traffic monitoring tools and permission logging software to track what each app reached out for, and when.
The apps we tested covered the usual suspects: a major social media platform, a popular weather app, a well-known fitness tracker, and a retail shopping app that most Americans have on their phones right now. We're keeping the specific names vague in a few places because this isn't about calling out individual companies — it's about the system that lets this happen in the first place.
Android Fragmentation Is a Privacy Wild Card
If you've been in the Android world for a while, you've heard the word "fragmentation" used to describe why your phone might not get updates as fast as a Pixel does. But fragmentation isn't just an update problem — it's a privacy problem.
On the Samsung devices we tested, several apps were able to access device identifiers that were significantly harder to reach on the stock Android (Pixel) phones. Samsung's custom Android skin, One UI, includes manufacturer-level APIs and background process permissions that third-party apps can tap into — and some of them absolutely do. One of the apps we tested pinged advertising-adjacent endpoints at nearly three times the rate on the Samsung device compared to the Pixel running the same Android version.
Motorola's near-stock Android experience was considerably cleaner in comparison. The same apps, on Motorola hardware, generated noticeably less outbound traffic to third-party data brokers. That doesn't mean Motorola phones are inherently more private — but it does suggest that manufacturer customization creates real, measurable differences in how much data leaves your device.
The OnePlus device sat somewhere in the middle, which honestly felt about right given how OxygenOS has evolved over the years.
Older Android Versions Are a Different Problem Entirely
We included a device still running Android 11 specifically because a lot of Americans are still using phones that haven't been updated past that point. According to distribution data, tens of millions of active Android devices in the US are running versions that are two or more years behind the current release.
The results on that older OS build were sobering. Several apps that behaved relatively quietly on Android 13 and 14 — where Google has tightened permission scoping, background location access, and sensor access rules — ran noticeably louder on Android 11. One app accessed the device's precise location in the background during a testing window when we hadn't opened the app in over six hours. On the Android 14 device? It couldn't do that. The newer OS simply wouldn't allow it.
This is the part that should make you uncomfortable: the app didn't change. The developer didn't flip a switch to be more aggressive on older phones. The platform just let it happen because the guardrails weren't there yet.
iOS Isn't Off the Hook
Before any iPhone users feel smug, let's talk about what we saw on the iOS side.
Apple's permission model is genuinely more consistent across its devices — that's a real advantage, and it showed in our testing. The two iPhones behaved more similarly to each other than any two Android devices in our lineup did. But iOS has its own quirks.
The retail shopping app we tested requested tracking permission (the ATT prompt Apple introduced in iOS 14.5) on both iPhones. When we denied it, the app's behavior changed — but it didn't stop. It shifted to a different data collection strategy, using what researchers sometimes call "probabilistic fingerprinting" signals: screen resolution, time zone, language settings, and other device characteristics that, when combined, create a surprisingly accurate identifier even without the explicit tracking permission. This isn't unique to iOS, but Apple's reputation for privacy made seeing it in action feel like a particular kind of disappointment.
What Manufacturer Bloatware Does to the Equation
One angle we didn't fully anticipate going into this project was how pre-installed manufacturer apps interact with the apps you download yourself. On the Samsung devices, several pre-installed Samsung apps maintained persistent background processes that, in at least two cases, appeared to be sharing device state information with the apps we were testing — almost like a handshake that the app on a Pixel couldn't initiate because there was no equivalent Samsung service to shake hands with.
This isn't necessarily malicious. Some of it is Samsung's ecosystem doing what Samsung designed it to do. But from a data privacy standpoint, it means that downloading the same app on a Samsung versus a Pixel isn't an apples-to-apples situation. The Samsung device hands that app more surface area to work with.
What You Can Actually Do About This
We know "just buy a Pixel" isn't advice most people are going to act on — and honestly, it's not a complete solution anyway. But there are real, practical steps worth taking regardless of what device you're carrying.
Audit your permissions regularly. Both Android and iOS let you see which apps have access to location, microphone, camera, and contacts. Most people set these once during installation and never revisit them. Make it a quarterly habit.
Check your Android version and push for updates. If your phone is still on Android 11 or earlier, you're missing meaningful privacy protections that Google has built into later versions. If your carrier or manufacturer has stopped supporting your device, that's a legitimate reason to consider an upgrade.
Use a DNS-based ad and tracker blocker. Apps like NextDNS or similar services work at the network level, which means they catch outbound tracking requests regardless of which app is making them or what phone you're on. It's one of the few protections that cuts across the fragmentation problem.
Don't assume the permission prompt tells the whole story. As our iOS testing showed, declining a tracking request doesn't always mean tracking stops. It sometimes just means it gets more creative.
The Bigger Picture
What this investigation really exposed is that "the app" is kind of a fiction. What you're actually running is the app plus your OS version plus your manufacturer's customizations plus whatever pre-installed software is running alongside it. That combination is different on every device, and it produces meaningfully different privacy outcomes.
Until the mobile industry — Google, Apple, and the manufacturers — decides to make consistent baseline privacy protections a non-negotiable standard across the entire ecosystem, the phone you happen to own will keep determining how much of your data walks out the door. And most people will never know the difference.