Security

Managing App Passwords and Connected Apps on Android

That game you logged into with Google three years ago still has access. Here's how to find and revoke it.

Adrián Vega

By Adrián Vega

Published 6 December 2025 · Updated 24 June 2026 · 6 min read

Person reviewing accounts

I distinctly remember the first time I realized how many random apps had an open door to my Google account. I was trying out a new photo editor on my Pixel 7, and it asked to "Sign in with Google." Without thinking, I tapped yes. Three months later, I found out that app hadn't been updated in forever, yet it still had permission to view my entire Google Drive. It’s an easy trap to fall into because hitting that blue button is so much faster than creating a new password. We trade our long-term privacy for three seconds of convenience. This guide is about taking those keys back and making sure only the apps you actually use have a seat at the table.

Finding the connected-apps list

Finding the connected-apps list
Illustration — Finding the connected-apps list. Stock photograph, not an actual device screenshot.

Most of us have dozens of these connections lurking in the background. To find yours, you don't need a computer; you can do it right from your phone. Open Settings, scroll down to Google, and then tap Manage your Google Account. From there, slide the top tabs over to Security. Scroll down quite a bit until you see a section titled Your connections to third-party apps & services. Tap "See all connections."

On my phone, the first time I did this, I found 42 apps. Forty-two! Some were games I hadn't played since 2021, and one was a "smart" lightbulb app for a brand I'd already thrown in the trash. Samsung users might see a slightly different layout if they go through the Samsung Settings menu, but the Google path is universal for any Android 13, 14, or 15 device. It's a sobering list. You’ll likely see names you don't even recognize, which is exactly why we're doing this.

What each scope means

Google breaks down permissions into "scopes." When you click on an app in that list, it tells you exactly what it can access. It’s rarely just "your name." You’ll often see "See your primary Google Account email address" or "See your personal info, including any personal info you've made publicly available."

Low-level access

Most apps just want your email and name to create a profile. This is generally fine, though it does mean if that app's database gets leaked, your email is now associated with whatever service they provide. It’s the "Sign in with Google" basic package.

Sensitive access

This is where things get dicey. If an app says it has "Full account access," stop everything. Almost no third-party app should ever have this. Other risky ones include "Read, compose, and send emails from your Gmail" or "See, edit, create, and delete all your Google Drive files." I once saw a basic "PDF converter" app asking for full Drive access. There is no reason for a converter to see every document I own; it should only see the one file I upload. If an app asks for more than it needs to function, it's a red flag.

Revoking access

Cleaning this up is oddly satisfying. Once you're in that "All connections" list, tap an app you don't use anymore. You'll see a big button that says Delete all connections you have with [App Name]. Google will ask you to confirm. When you hit confirm, that app is effectively logged out and its "token" (its digital key) is destroyed.

I recommend being aggressive here. If you haven't used the app in the last month, revoke it. If you need it again later, you can always sign back in. It’s better to spend ten seconds re-linking an app once a year than to let a defunct startup keep a permanent window into your data. One small caveat: if you used "Sign in with Google" to create an account for a paid service (like a streaming site or a subscription tool), revoking access might make it tricky to log back in until you reconnect. It won't cancel your subscription or delete your data on their end; it just cuts the bridge between Google and them.

Samsung account equivalent

Samsung account equivalent
Illustration — Samsung account equivalent. Stock photograph, not an actual device screenshot.

If you're on a Galaxy S23 or S24, you probably have a "Galaxy" life running parallel to your "Google" life. Samsung has its own version of this. Go to Settings, tap your name at the very top (Samsung Account), and look for Security and privacy. Inside, you'll find Connected services.

Samsung tends to link with things like Microsoft (for OneDrive syncing), Spotify (for the clock app), and various smart home platforms via SmartThings. It's the same principle: if you see a service you no longer use, tap it and disconnect. I found that Samsung likes to hold onto permissions for "Partner services" long after you've uninstalled the related app. Checking both the Google and Samsung lists is the only way to be sure your phone isn't leaking data from two different directions.

OAuth basics

The tech behind this is called OAuth. Think of it like a valet key for a car. You don't give the valet your actual house keys; you give them a specific key that only starts the car and doesn't open the trunk. When you "Sign in with Google," Google doesn't give your password to the app. Instead, it gives the app a "token."

The problem is that unlike a valet key, these digital tokens don't usually expire on their own. They stay "active" until you manually kill them. This is why you can find apps from five years ago still on your list. They aren't "hacking" you—they're using a key you gave them and never asked back. This is also why changing your Google password doesn't always kick these apps out. Thousands of people change their passwords thinking they've secured their account, while 30 third-party apps still have valid OAuth tokens that bypass the password entirely.

Audit schedule

This isn't a one-and-done task. I've set a recurring reminder on my calendar for the first Sunday of every quarter. It takes me about three minutes now because I keep the list lean. If you’re a heavy app-tester, you might want to do it once a month.

Here’s a realistic goal: try to keep your "Total Connections" under 15. For most people, that covers the essentials—maybe Spotify, a fitness app, Zoom, and a couple of work tools. If you're at 50+, you're statistically likely to be sharing data with at least one company that has either gone out of business or been sold to a data broker. It’s annoying that we have to babysit our accounts like this, but until Google starts auto-revoking tokens for inactive apps, it's the only way to keep your digital footprint from growing out of control.

Key takeaways

  • Finding the connected-apps list is where you start — it's the fastest win.
  • What each scope means: don't skip this — it's where most users leave settings at risky defaults.
  • Revoking access: don't skip this — it's where most users leave settings at risky defaults.
  • Samsung account equivalent: don't skip this — it's where most users leave settings at risky defaults.
  • Recheck these settings quarterly; OEM updates can reset toggles.

Frequently asked questions

Does changing these settings break apps?
Almost never. Modern Android apps must handle a denied permission or restricted access gracefully — they either skip the feature or prompt again when needed.
Will this drain my battery?
No. If anything, restricting background access and disabling tracking pipelines reduces battery and data usage.
Do these steps apply to Android 13, 14 and 15?
Yes. The menu paths shift slightly between versions and OEM skins (Pixel/stock, Samsung One UI, Xiaomi HyperOS), but the underlying controls behave the same.

References & further reading

Continue reading

Related guides