The android/app/src/main/AndroidManifest.xml you can read is not the one that ships: Gradle 19,597 's manifest merger adds every library's manifest. Installing expo-notifications quietly brought POST_NOTIFICATIONS, RECEIVE_BOOT_COMPLETED, WAKE_LOCK, Firebase 1 's c2dm.permission.RECEIVE and, through a badge-counter library, fifteen more for Samsung, HTC, Sony, Huawei and other launchers. aapt2, in the SDK's build-tools folder, reads the final list from the APK:
APK=android/app/build/outputs/apk/debug/app-debug.apk
aapt2 dump permissions $APK | grep -c uses-permission
aapt2 dump permissions $APK | grep "name='android.permission" | cut -d"'" -f229 android.permission.SYSTEM_ALERT_WINDOW android.permission.INTERNET android.permission.READ_EXTERNAL_STORAGE android.permission.VIBRATE android.permission.WRITE_EXTERNAL_STORAGE android.permission.ACCESS_NETWORK_STATE android.permission.ACCESS_WIFI_STATE android.permission.RECEIVE_BOOT_COMPLETED android.permission.POST_NOTIFICATIONS android.permission.WAKE_LOCK android.permission.READ_APP_BADGE
In app.json, android.permissions adds entries and android.blockedPermissions makes prebuild write tools:node="remove" entries that beat any library. BookNest blocked the overlay and the two storage permissions. After npx expo prebuild --platform android and a rebuild, the same commands printed 27, and the storage permissions were gone, but SYSTEM_ALERT_WINDOW remained: the template's android/app/src/debug/AndroidManifest.xml declares it again for the debug build's developer overlays, and a build type's manifest outranks the main one. Check the release APK, which is what Google Play 1 's Data Safety form describes (Publishing). Prebuild also regenerated android/ and reset a hand edit in gradle.properties (this project builds only x86_64); keep such settings in a config plugin (Config Plugins).