Privacy News
5,000 Apps, One Privacy Audit: What Your Phone Is Actually Sharing
September 2026
Most privacy stories are about one company at a time. This one is broader: IT Asset Management Group (IT-AMG) went through the self-reported privacy disclosures of more than 5,000 apps in Apple's App Store, looking for patterns in what apps actually admit to collecting. Combined with separate research from SafetyDetectives on kids' apps and Incogni on foreign-owned apps, the numbers add up to a fairly clear picture of where data collection is worst — and where it's surprisingly restrained.
The headline numbers
5,000+
App Store privacy disclosures analyzed by IT-AMG
70%
of studied kids' apps collected identifying information (SafetyDetectives)
50%+
of studied kids' apps shared child data with third parties
30+
data types collected by each of Meta's five apps
90%+
of collected data used just for "basic functions" on some social apps
12+
data categories Amazon and Google each admit to, despite not disclosing cross-app tracking
The kids' app problem
The most concerning finding sits with apps built for children. SafetyDetectives analyzed 20 popular kids' apps and found that every subscription app in the study posed a privacy risk of some kind. 70% collected identifying information, and more than half shared user or child data with third parties.
Two apps stood out. Reading Eggs, a literacy tool, collects audio and photo data directly from children's devices and uses that data for advertising and personalization. ABCMouse, an early childhood learning app, shares device data with third parties and was flagged by researchers as difficult to cancel or delete once you're subscribed.
Social apps: the least surprising list
Meta's apps — Facebook, Instagram, Messenger, Threads, and Business Suite — each collected more than 30 types of data in the IT-AMG analysis, much of it linked directly back to individual users. Some social apps in the dataset used over 90% of the customer data they collect just to perform basic functions like messaging or finding new contacts — a reminder that "basic functionality" can be defined very broadly.
One notable omission: Amazon and Google don't appear on IT-AMG's list of apps that track users across other apps and websites — but only because neither company filled out that specific disclosure section. Both still admit to collecting data across at least 12 categories that link back to your identity. Self-reported labels can only reflect what a company chooses to disclose.
Where an app is built from matters too
Separate research from data broker removal service Incogni looked at apps built by foreign-owned companies and found that Chinese-owned apps — including Alibaba, Temu, and TikTok — consistently collected sensitive information such as home addresses or approximate location. Alibaba was the standout case, requesting access to users' documents, files, phone numbers, photos, and videos.
Same job, wildly different appetite for data
Comparing apps that do the same job shows just how much this varies by company, not category. Delivery and ride-hailing apps need your location to function — that part isn't controversial. But a side-by-side of three delivery-style apps found DoorDash limiting its tracking data to contact information, identifiers, location, purchases, and usage — while Grab collected all of that plus search history, phone diagnostics, financial information, and browsing history. Lyft, doing essentially the same job as both, wasn't flagged as invasive at all. Same category, same core function, very different amount of data collected.
Where Offgrid Studio's apps land on this
Every app we've built — OffgridStem, OffgridScribe, OffgridVox, and OffgridCam — carries an App Store privacy label of "Data Not Collected." That's not a claim we're making in marketing copy; it's the same self-reported disclosure system this whole analysis is based on, and it's checkable by anyone in the App Store's own privacy section before they download anything.
We also ran our own network audit to verify what our apps actually send over the network, rather than asking anyone to take the label on faith alone.
What to actually do with this
- Before downloading any app, check its App Store or Google Play privacy section — labels are self-reported, but they're the most transparent signal available
- Be especially cautious with subscription-based kids' apps — this is where the SafetyDetectives study found the highest risk concentration
- Don't assume two apps in the same category collect the same amount of data — compare before choosing, the way DoorDash and Grab differ
- Periodically delete apps you haven't opened in the past month — an unused app on your phone is still a live data-collection surface
Frequently asked questions
How many apps were included in the privacy analysis?
IT Asset Management Group (IT-AMG) analyzed self-reported privacy disclosures from more than 5,000 apps in Apple's App Store. Separately, SafetyDetectives analyzed 20 popular kids' apps, and Incogni researched data collection patterns among apps developed by foreign-owned companies.
What percentage of kids' apps share data with third parties?
According to SafetyDetectives' analysis of 20 popular kids' apps, all subscription apps in the study posed privacy risks. 70% of the apps collected identifying information, and more than half shared user or child data with third parties.
Do social media apps collect more data than other categories?
Yes, based on the IT-AMG analysis. Meta's apps — Facebook, Instagram, Messenger, Threads, and Business Suite — each collected more than 30 types of data and linked much of it back to specific users. Some of these apps used more than 90% of collected customer data just to perform basic functions like messaging.
Does an app's country of origin affect how much data it collects?
Research from data broker removal service Incogni found that apps developed by Chinese-owned companies, including Alibaba, Temu, and TikTok, collected sensitive information such as addresses or approximate locations. Alibaba stood out for requesting access to users' documents, files, phone numbers, photos, and videos.
Is it possible to know exactly what an app collects before downloading it?
App Store and Google Play privacy labels give a good starting signal, but they're self-reported by the companies that build the apps. A company could fail to disclose certain data collection or classify it in a way that appears less invasive, so the labels are a useful check, not a guarantee. See our Privacy Policy for how we approach this ourselves.
More from Offgrid Studio
We Ran Our Own Network Audit. Here's What We Found. · Best Baby Monitor Apps for iPhone in 2026 · Otter.ai vs Google vs Rev: What Actually Happens to Your Recordings?