Morning Overview

8 phone apps security experts keep urging people to delete

Privacy researchers and digital-rights groups publish recurring lists of the software they consider most invasive on a personal handset. The names on those lists rarely change, because the underlying issue is rarely a single flaw and usually a business model built on collecting far more than the app needs. Here are eight names that keep resurfacing, and the documented practice behind each one.

1. TikTok: The Ownership Question That Will Not Go Away

cottonbro studio/Pexels
<p>cottonbro studio/Pexels</p>

The objection to TikTok has never rested on a single bug. Its parent company, ByteDance, is headquartered in Beijing, and that jurisdictional fact pushed governments to strip the app from official devices: the United States barred it from federal government phones in 2022, and the European Commission, Canada and the United Kingdom added their own staff-device restrictions. India blocked it nationwide in 2020. The company’s privacy policy has also disclosed collecting device identifiers, approximate location and biometric identifiers including faceprints and voiceprints.

Those bans apply to work phones, not personal ones, so the individual question is different: whether that volume of behavioral data is a fair price for a short-video feed. Tightening the app’s permissions is the lighter alternative.

2. Temu: Permissions Beyond a Shopping Cart

Temu — Image Credit: HKvkohsy OoHpital - CC0/Wiki Commons
Image Credit: HKvkohsy OoHpital – CC0/Wiki Commons

Temu’s app has drawn attention less for what it sells than for what it asks to reach. The discount marketplace, operated by PDD Holdings, collects device, network and behavioral information described in its own privacy disclosures, a scope wider than a storefront strictly needs. Context sharpened the concern: PDD’s Chinese shopping app Pinduoduo was suspended from Google Play in March 2023 after malware was identified in versions distributed outside the official store.

That episode involved a different app and Temu itself has not been shown to carry malicious code. The durable point is structural: an aggressive shopping app that lives on a handset year-round accumulates a long behavioral record, and uninstalling it between purchases removes that stream without closing the account.

3. Facebook: The Five-Billion-Dollar Privacy Penalty

Facebook — Image Credit: Pixabay/Pexels
Image Credit: Pixabay/Pexels

Few apps carry a regulatory record as concrete as this one. In July 2019 the Federal Trade Commission imposed a $5 billion penalty on the company over privacy violations, the largest the agency had ever levied in a consumer privacy case, following the Cambridge Analytica episode in which the personal data of tens of millions of users reached a political consultancy without meaningful consent. The order also required new internal privacy oversight.

The app remains a heavy background collector, logging activity across other sites and services through embedded tools even when it sits unopened. Deleting the app does not delete the account, and the mobile browser version offers most of the same functionality with a smaller footprint on the device.

4. Instagram: A Fine Over Teenagers’ Contact Details

Instagram — Image Credit: Brian Ramirez/Pexels
Image Credit: Brian Ramirez/Pexels

The regulatory hit against Instagram came from Dublin. In September 2022 Ireland’s Data Protection Commission fined the Meta-owned platform €405 million over its handling of children’s data, after business accounts operated by teenagers displayed their phone numbers and email addresses publicly and accounts belonging to minors defaulted to public visibility. Meta signaled it would appeal the decision while saying it had already changed the settings involved.

Beyond that case, the app requests access to camera, microphone, photo library and precise location, and its advertising system draws on activity gathered across Meta’s other properties. Removing it from a handset ends the location and sensor access without touching the account, which stays reachable from a browser.

5. CapCut: The Editor That Shares TikTok’s Parent

CapCut — Image Credit: Usertol - CC BY 4.0/Wiki Commons
Image Credit: Usertol – CC BY 4.0/Wiki Commons

CapCut sits on these lists mainly because of who owns it. The video editor is a ByteDance product, the same parent as TikTok, so it inherits the identical jurisdictional questions that drove government-device bans on its sibling app. The terms attached to it have drawn criticism for granting the company a broad, royalty-free licence to content uploaded for editing, which extends the app’s reach past the footage a person chooses to publish.

No enforcement action has singled out CapCut on its own, and the editor is capable, which is why it keeps getting installed. The narrower alternative to removing it is to treat the app as a cloud service rather than a local tool, and to keep sensitive footage out of it.

6. SHEIN: A Breach, Then a State Penalty

SHEIN — Image Credit: DMCGN - CC BY 4.0/Wiki Commons
Image Credit: DMCGN – CC BY 4.0/Wiki Commons

Rare among these entries, SHEIN’s app has an enforcement action attached to a documented breach. In October 2022 New York’s attorney general announced a $1.9 million penalty against Zoetop, the retailer’s former parent, over a 2018 breach that exposed data tied to roughly 39 million accounts, and over the company’s failure to notify most of those users or to require password resets.

That penalty concerns past conduct rather than the current app, and the operating company has since restructured. What keeps the name on caution lists is the combination: a shopping app that requests wide device access, an ownership chain that has moved between jurisdictions, and a documented history of handling a breach badly. Ordering through a browser removes that access.

7. Snapchat: Disappearing Messages, Persistent Location

Snapchat — Image Credit: Freepik
Image Credit: Freepik

The record here starts with a settlement. The Federal Trade Commission settled charges with the messaging company in 2014 over deceptive claims that sent messages disappeared, finding that recipients could save them through several workarounds, and over the app’s transmission of users’ address-book contacts without clear notice. The resulting consent order placed the company under privacy monitoring for twenty years.

The live concern now is location. Snap Map can broadcast a precise position to an entire friend list, updating whenever the app is opened, which turns a social feature into a movement log for anyone who has ever accepted a friend request loosely. Turning on Ghost Mode addresses that without removing the app, but the setting has to be chosen deliberately.

8. WhatsApp: Encrypted Content, Exposed Metadata

WhatsApp — Image Credit: Rahul Shah/Pexels
Image Credit: Rahul Shah/Pexels

WhatsApp is the awkward entry, because its message contents are end-to-end encrypted by default. The objection is what sits around them. In September 2021 Ireland’s Data Protection Commission fined the encrypted messaging service €225 million for failing to explain clearly, under European transparency rules, how it shared user data with other Meta companies, a decision that followed widespread confusion over a 2021 policy update.

Metadata is the residue encryption does not cover: who contacted whom, when, how often and from which device and network. That pattern alone can reconstruct a social graph, which is why some specialists point users toward alternatives that minimise it rather than toward abandoning encrypted messaging altogether.


More from Morning Overview