No Kings: Vote Early! October 17! We showed up. We built a movement. Now, we turn people power into voter power.
Movement · National Find your chapter

How to protect your device, your accounts, your contacts, and other people connected to your activism.

Your phone is one of the most information filled objects you carry. If you’re an active-activist, it carries organizer names, group chats, volunteer info, photos, documents, calendar info, passwords, account recovery access, and years of location, message, and photo history. More importantly, you’re not only putting yourself at risk if your phone is compromised, it’s the contacts and groups you’re associated with that are at risk.

We keep us safe.

Useful phone security starts with: 1. Attack Surface and 2. Blast Radius.

  • Attack surface is every place information is accessed, from your physical phone and its apps to the cellular provider, cloud backups and connected laptops.
  • Your blast radius is how much of your organization and contacts becomes exposed when compromised.

EFF’s Security Planning guide recommends digital security through identifying what you need to protect, who could realistically want it, how they might obtain it and what happens if they succeed. For activists specifically, EFF also maintains a detailed Attending a Protest guide covering device security around protesting.

50501.co phone security graphic showing a smartphone with privacy, messaging, cloud, and location icons, emphasizing that phone security is organizing security for activists and protest organizers.

Strong Protection = Carry Less Information

Encryption, passcodes, and secure messaging help but data minimization is one of the few security controls that keeps working when other safeguards fail.

  • If a volunteer spreadsheet never existed on your phone, a person who unlocks the phone can’t retrieve it.
  • If an organizer doesn’t have access to a chapter account, stealing their credentials has less value.
  • If you remove unnecessary cloud storage apps before an action, the accounts are no longer sitting one authentication step away from whoever is holding the device.

Before a protest, look through your phone.

Check: Contacts, Notes, Files, Photos, Downloads, email attachments, calendars, cloud drives, browser tabs, password managers and social-media accounts.

Privacy Guides Protesters’ Guide to Smartphone Security recommends minimizing stored data and (if possible) carrying a separate device containing what’s necessary. A “burner” phone isn’t automatically anonymous either. Carrying it with your normal phone, signing it into accounts or repeatedly using it at home can reconnect it to your identity.

EFF similarly warns that the locations of two phones carried together can potentially be correlated.

For organizers, this should extend beyond major actions like big protests. Do you really need the entire volunteer database stored on a phone? What about permanent downloads of sensitive documents? Reducing the amount of information accessible through a single phone lessens the consequences of losing it.

Your Weather App = Possible Surveillance Problem

A less obvious phone security risk comes from basic apps and the advertising industry.

On August 27, 2026, the Committee to Protect Journalists published an investigation into the surveillance capabilities created by online advertising. Researchers pointed out that commercially available datasets contain approximately 100 million location points associated with roughly one million devices. Journalists examining data were able to identify individuals from their movement patterns. A journalist also discovered that a weather application he permitted to access location data was connected to a information database that tracked him.

The federal government documented how powerful this information can be. In an enforcement case involving Gravy Analytics and Venntel, the FTC alleged that location data obtained by data suppliers could expose visits to sensitive locations and be used to infer political activities. The FTC said Gravy claimed to process more than 17 billion location signals from roughly a billion devices daily.

This is why organizers should periodically performing an app surveillance audit.

  • On iPhone, App Privacy Report shows what apps have accessed location, contacts, photos, the camera or microphone during the previous 7 days and what internet domains the apps contacted.
  • On Android, review the Privacy Dashboard and each app’s permissions. CPJ’s newly updated ad-tech security guide walks you through how to disable and limit advertising-identifiers, reduce personalized advertising and inspect apps for embedded tracking technology using tools such as Exodus Privacy and App Microscope.

Location tracking keeps going even when you turn off GPS permission

There are several different kinds of “location” on a smartphone and GPS is only one of them. A powered-on cell phone communicates with cellular networks so the network can provide service. EFF’s guide to mobile-phone location tracking talks about the four main pathways:

  1. Cell towers
  2. Cell site simulators
  3. Wi-Fi
  4. Bluetooth signals, and location information leaked by applications / websites.

Turning off Instagram’s location permission doesn’t stop your cell phone carrier from knowing different parts of its network your phone is using.

A more specialized risk involves cell-site simulators, sometimes called Stingrays or IMSI catchers and these systems imitate cellular-infrastructure and can cause phones in an area to communicate with them.

EFF cautions that there’s not much concrete evidence demonstrating routine use of these systems against protesters or organizers, however, a good precaution is disabling older 2G connectivity if your phone supports it because some fake-base-station attacks attempt to downgrade phones to weaker 2G networks.

Android’s new Advanced Protection system include 2G network protection on supported devices with additional security controls. EFF’s protest guide goes into more detail: The reasoning behind disabling 2G.

Airplane Mode is useful, but it doesn’t make your phone invisible. Your phone still retains locally collected information and uploads it later when you turn off airplane mode. If you’re trying to stop the phone from communicating with other networks, completely turning it off is the better option.

A locked phone has different levels of “locked”

A very useful concept is knowing the difference between Before First Unlock (BFU) and After First Unlock (AFU).

A phone that just restarted but hasn’t been unlocked is in BFU state.
At that point, a portion of the device’s private information remains protected by stronger encryption.

After the phone is unlocked, the device enters AFU state.
Even after the screen is locked again, more cryptographic material is usually available to the operating system.

This makes a big difference in forensic tools attempting to extract photographs, messages, web history, location information, stored passwords and app data.

Restarting a phone doesn’t make it impossible to search and forensic tools can exploit vulnerabilities but knowing the difference between BFU and AFU helps explain recommendations that sound arbitrary. Keep your phone updated, use a strong password/code, minimize data you carry, and consider powering down your phone before entering a high-risk situation.

Android’s Advanced Protection can automatically reboot a supported device after it remains locked for 72 hours, returning protected user data to a state requiring a fresh unlock. On some Pixel devices it can block new USB data connections while the screen is locked, reducing the avenue for unauthorized access.

If a phone has been seized and if it leaves your possession and is later returned under suspicious circumstances, do NOT automatically factory reset it before consulting a digital-security expert. Resetting the phone might destroy evidence that could help determine what happened to the device.

Secure the accounts behind your phone

A secure phone can still expose your group or chapter if the accounts connected to it are weak.

For important movement related accounts, prioritize phishing-resistant authentication instead of relying on just SMS codes. Google has a free Advanced Protection Program for those at elevated risk such as activists, journalists and political campaign staff. It uses passkeys or security keys and adds another layer of account protection. Groups and chapters should occasionally review active sessions and connected devices, especially when someone leaves an admin role.

This also applies to Signal. End-to-end encryption protects messages but an unlocked or forgotten endpoint can expose conversations. Review Linked Devices, remove old computers or tablets, and enable Screen Security to reduce message exposure in app previews. Disappearing messages can help reduce how much conversation history is available, but still can’t prevent participants from saving what they received.

Photos and posts expose more than you think

Photos reveal who attended, where people gather, what vehicles were present, and what locations or individuals are connected to hosting or organizing an event. Image files can include embedded location data, which Apple allows users to review / remove, but visuals can be just as, if not more, revealing. For example: Street signs, name badges, tattoos, license plates, reflections, computer screens, and recognizable homes and work locations.

Before an event, establish expectations beforehand like who keeps the original pictures, who is allowed to publish them, what should be blurred or cropped, and if posts should wait until participants are safely away from the event/location.

Know when you need stronger protection

Many organizers never face sophisticated spyware or targeted phone attacks, but people with unusually visible roles or sensitive information should know stronger protections are available to you.

Apple’s Lockdown Mode restricts certain phone features to reduce the targeted attacks available to highly sophisticated threats. Android’s Advanced Protection combines several strong device safeguards while Intrusion Logging can create encrypted security logs that can help a trusted specialist investigate suspicious activity.

If Apple, Google or another trusted provider sends a genuine sophisticated-threat warning, don’t assume a consumer spyware scanner can prove the device is clean. Access Now’s spyware guidance recommends preserving evidence and seeking expert help. Its free, 24/7 Digital Security Helpline assists activists, journalists and civil-society organizations dealing with account compromise, malware and advanced surveillance.

Reducing the blast radius is the goal, not perfection.

Keep less unnecessary information, limit access by role, protect important accounts with strong authentication, review permissions and active sessions, and establish a plan for lost, stolen or seized devices.

For continued learning, bookmark EFF’s Surveillance Self-Defense library, CPJ’s advertising-surveillance guide, and Access Now’s Digital Security resources.

50501.co phone security graphic asking organizers what sensitive information, accounts, contacts, and locations could be exposed if their phone were compromised.

← All posts