How to tell if an app is selling your data
How to read App Store privacy labels and Google Play Data safety sections, spot permissions that don't fit the job, and check what an app actually does after install.
Most apps that share your data never "sell" it in the way people imagine. There is no spreadsheet of names changing hands. More often, a flashlight or a recipe app includes an advertising library that reports your device, your location and your habits to a company you have never heard of. The good news is that you can spot most of this in about two minutes, before you install anything.
Read the label before you tap Get
On the App Store, scroll to App Privacy on any app's page. Apple sorts what the developer reports into three groups:
- Data Used to Track You: data combined with information from other companies' apps and websites for targeted advertising or ad measurement, or shared with data brokers. This is the section to read first.
- Data Linked to You: data the app collects and ties to your identity, such as your account or device.
- Data Not Linked to You: data collected without being tied to you, such as anonymous crash reports.
On Google Play, open the app's page and find Data safety. It separates data shared with other companies from data collected by the app, and lists security practices such as whether data is encrypted in transit and whether you can ask for it to be deleted. One useful detail: if an app only uses data on your device and never sends it off, it does not have to list that data as collected.
Both labels are self-reported by the developer, so treat them as a starting point, not a guarantee. But an app that admits to tracking is telling you something plainly.
Permissions that don't fit the job
Every permission request is a small question: does this app need that to do what it says? A scanner needs the camera. A card-night scoreboard does not need your location. A to-do list does not need your contacts.
Check what you've already granted:
- iPhone: Settings, then Privacy & Security, then each category, such as Location Services, Contacts or Photos.
- Android: Settings, then Security & privacy, then Privacy, then Permission manager (the exact names vary slightly by phone maker).
If an app asks to "track your activity across other companies' apps and websites" on iPhone, that is Apple's App Tracking Transparency prompt, and you can say no without losing any app features. To stop the prompts entirely, go to Settings, then Privacy & Security, then Tracking, and turn off Allow Apps to Request to Track.
The quickest privacy check is not reading a policy; it is asking whether each permission matches the one job you downloaded the app to do.
The account-required red flag
Some apps genuinely need an account: banking, messaging, anything with other people on the other end. But when a simple tool, such as a timer, a card maker or a scorekeeper, won't let you in without an email address or a social login, ask why. An account turns you from an anonymous device into a known person, and that is exactly the kind of data that becomes valuable to share.
A related clue is third-party code. Many apps include advertising, analytics or attribution SDKs, and those libraries are where most cross-app tracking comes from. You can't see them directly, but they show up indirectly: in the Tracking section of the label, and in network activity.
Check what an app actually does
iPhone has a built-in tool for this. Go to Settings, then Privacy & Security, then App Privacy Report, and turn it on. After a few days it shows which domains each app has contacted over the past seven days, and when apps accessed your location, camera, microphone, contacts and photos. The report is stored on your device. If a simple offline app is contacting a list of advertising domains, you have your answer.
A second test works on any phone: turn on airplane mode and use the app. If the core feature still works, the important work is happening on your device.
We think the strongest privacy guarantee is an app that has nowhere to send your data, which we wrote about in privacy is an architecture decision. Most of the apps on our apps page are built that way, with no account and nothing that needs to leave the phone.
You don't need to distrust every app. You just need two minutes and the habit of looking before you tap install.
Recent posts
-
How-to
How to make a photo-a-day timelapse of your kid growing up
Oct 03, 2026
-
How-to
How to appeal a denied health insurance claim
Oct 02, 2026
-
How-to
How to settle up money after a poker or card night, fairly and fast
Oct 01, 2026
-
How-to
How to plan a national park road trip that isn't all driving
Oct 01, 2026
-
How-to
How to start strength training at home with no equipment
Sep 30, 2026
-
How-to
Why your espresso tastes sour or bitter, and the one change to make
Sep 29, 2026
0 comments
No comments yet — be the first.
Leave a reply
Sign in with Google to join the conversation. We require a quick sign-in to keep comments spam-free.
Sign in with Google to comment