Skip to main content

Morning Overview

9 phone apps that quietly collect the most personal data about you

Every smartphone user grants a long list of app permissions without much thought, and a handful of the most popular apps rank among the most data-hungry on any phone. Regulators on both sides of the Atlantic have fined, sued or settled with several of these companies over exactly what gets collected and how. Here are nine apps that have drawn regulatory scrutiny over the personal data they gather.

1. Facebook: A Broad Permissions List

Facebook — Image Credit: Pixabay/Pexels
Image Credit: Pixabay/Pexels

Meta’s Facebook app lists permissions for contacts, precise location, camera access and browsing activity in its own app-store disclosure, the exact categories the FTC’s app privacy guidance tells phone owners to scrutinize before approving. In 2019 the company agreed to pay the FTC $5 billion to settle charges that user data had been mishandled and shared with outside app developers, among the largest privacy penalties any tech company has paid.

Permissions granted years earlier often stay active long after the original reason for allowing them has passed, so a periodic review of what the app can still see remains the simplest way to limit what continues to be collected going forward.

2. Instagram: A Nine-Figure Privacy Fine

Instagram — Image Credit: Brian Ramirez/Pexels
Image Credit: Brian Ramirez/Pexels

Instagram, owned by Meta, collects location, contacts, browsing behavior and advertising identifiers as part of its standard data practices, and its regulatory history includes a 405 million euro fine from Ireland’s Data Protection Commission in 2022 over how the platform handled teenage users’ contact information and email addresses.

The fine centered on default account settings that made minors’ contact details visible on public business profiles rather than any single leak, a reminder that a platform’s defaults can matter as much as what gets actively published or shared with advertisers.

3. TikTok: The Children’s Data Penalty

TikTok — Image Credit: greenwish _/Pexels
Image Credit: greenwish _/Pexels

TikTok, then operating as Musical.ly, paid the FTC $5.7 million in 2019 to settle charges that it had illegally collected names, email addresses and location data from children under 13 without parental consent, the largest civil penalty the agency had obtained in a children’s privacy case at the time, per TikTok’s regulatory record.

The Justice Department and FTC returned in 2024 with a fresh lawsuit alleging continued violations of the same children’s privacy law, arguing the platform still gathers device and behavioral data at a scale regulators consider excessive for underage users.

4. WhatsApp: A Data-Sharing Settlement

WhatsApp — Image Credit: Rahul Shah/Pexels
Image Credit: Rahul Shah/Pexels

WhatsApp links a phone number, device information and message metadata to parent company Meta under a 2021 privacy policy that drew a 225 million euro fine from Ireland’s Data Protection Commission, the largest such penalty issued by that regulator at the time, according to WhatsApp’s regulatory history.

Message content stays encrypted, but the surrounding metadata, who a person messages, how often, from which device and at what time, was the category regulators said had not been disclosed with enough transparency to users signing up, a gap regulators said left users unable to meaningfully consent.

5. Snapchat: The Disappearing Message Deception

Snapchat — Image Credit: Freepik
Image Credit: Freepik

Snapchat settled with the FTC in 2014 over charges that it had misrepresented how thoroughly its messages actually disappeared while also collecting contacts and location data beyond what its privacy policy described, according to Snapchat’s settlement record, which found find-friends data had been transmitted without adequate notice. The order placed the company under outside privacy monitoring for twenty years.

Snap Map still gathers precise location for its social features today, and the Lenses tools behind its camera filters process facial geometry data pulled directly from a phone’s camera feed in real time.

6. Uber: The God View Problem

Uber — Image Credit: Dllu - CC BY-SA 4.0/Wiki Commons
Image Credit: Dllu – CC BY-SA 4.0/Wiki Commons

Uber tracks precise trip and location history for every ride, data an internal tool nicknamed “God View” once let employees watch in real time for individual riders, a practice that helped trigger a 2017 FTC settlement over misrepresented privacy and security protections, according to Uber’s regulatory history.

The agency later reopened that settlement after learning the company had concealed a 2016 breach exposing 57 million riders’ and drivers’ records rather than disclosing it, adding a twenty-year independent audit requirement to the revised order, one of the strictest privacy consent decrees the agency has issued.

7. Amazon: The Alexa Recordings Fine

Amazon — Image Credit: Sagar Soneji/Pexels
Image Credit: Sagar Soneji/Pexels

Amazon’s shopping app logs detailed purchase and browsing profiles across its retail business, and a related 2023 FTC settlement required the company to pay $25 million over Alexa devices that had retained children’s voice recordings indefinitely despite parents’ deletion requests, according to Amazon’s regulatory record.

A companion settlement covering Ring doorbell cameras added a further $5.8 million after the FTC found employees and contractors had accessed customer video footage without authorization for years, sometimes for entertainment rather than any business purpose, according to the FTC complaint that accompanied the settlement.

8. LinkedIn: The Scraped Profile Incident

LinkedIn — Image Credit: Bastian Riccardi/Pexels
Image Credit: Bastian Riccardi/Pexels

LinkedIn builds a detailed professional graph from job history, connections, endorsements and browsing activity across its network, and in 2021 the public profile data of roughly 700 million members was scraped and offered for sale on a hacking forum, according to LinkedIn’s incident history, which also lists a separate 2016 breach of stored account credentials.

LinkedIn maintained the scraping violated its terms of service rather than exposing any private data, though the episode showed how much profile detail, employer history, location and contact patterns among them, sits exposed to automated collection by default.

9. X: The Two-Factor Data Fine

X — Image Credit: Department of Homeland Security - Public domain/Wiki Commons
Image Credit: Department of Homeland Security – Public domain/Wiki Commons

The app formerly known as Twitter collects broad usage and location data, and in 2022 its operator paid the FTC $150 million after regulators found phone numbers and email addresses collected for two-factor authentication had instead been used to target advertising, according to Twitter’s settlement record.

The case argued that data given for account security is not the same as data given for marketing, a distinction the platform’s own security prompts had blurred for millions of users, and the order required a new comprehensive privacy program.


More from Morning Overview