privacy: Mention non-sandboxed apps can always use camera/microphone/GPS

These toggles only apply to the portal system, so only restrict access
for sandboxed apps. Non-sandboxed apps (installed into `/usr/bin`) can
always access these resources on typical distributions.

In future, perhaps integration with a MAC (like SELinux) could restrict
access to the camera/microphone/GPS for non-sandboxed applications —
but we invented sandboxing to avoid having to do that, so it seems
unlikely that’s ever going to be implemented. If it is, this wording
can change again.

Signed-off-by: Philip Withnall <>

Fixes: #741
7 jobs for 741-privacy-system-apps in 4 minutes and 9 seconds (queued for 1 second)
Status Name Job ID Coverage
passed build #974593


passed test #974594


manual asan #974596
privileged allowed to fail manual
manual flatpak #974595
allowed to fail manual
manual msan #974599
allowed to fail manual
manual tsan #974597
allowed to fail manual
manual ubsan #974598
allowed to fail manual