A new iPhone app called Loupe shows which device signals apps can read without your permission, and the list is longer than most users expect.
Loupe is an iOS app that surfaces data points any app on your phone can quietly read: language and region settings, battery level and state, installed apps, and persistent device identifiers. These signals are accessible through standard APIs with no special permissions required. Individually they seem mundane, but combined they form a reliable fingerprint that can identify and track you across apps and sessions without triggering any privacy prompt.
Apple has spent years building a privacy brand around App Tracking Transparency, which requires apps to ask permission before tracking users across apps and websites. Fingerprinting sidesteps that requirement entirely, assembling a profile from signals Apple never restricted. Loupe makes this gap between Apple's privacy pitch and reality visible to ordinary users, not just security researchers.
Apple's developer guidelines technically prohibit fingerprinting, but enforcement is another matter - and Loupe's existence suggests the underlying signals remain wide open.
