
Meta AI Tops List of Most Data-Hungry Apps in 2026
Meta AI declares 33 of 35 possible data types, topping a 2026 Surfshark analysis of how much information major apps collect about their users, according to a report by Cybersecurity Insiders. cybersecurity-insiders
Key facts
The study: Surfshark's 2026 analysis covered 171 apps from major technology companies cybersecurity-insiders
Top collector: Meta AI, declaring 33 of 35 data types cybersecurity-insiders
Company averages: Meta's apps collected an average of 25 of 35 data categories; Google apps averaged 17 cybersecurity-insiders
Top non-Meta app: Amazon Alexa, declaring 28 data types cybersecurity-insiders
What to do: Review app permissions and revoke access apps don't obviously need
Which apps collect the most data?
The report's ten notable examples: Meta AI, Facebook, Instagram, Messenger, TikTok, Amazon Alexa, Google Maps, WhatsApp, Pinterest and Duolingo. TikTok's collection can include identifiers, contact information and location; earlier research found Facebook collected all 32 data points in Apple's privacy framework at the time. cybersecurity-insiderscybersecurity-insiders
The Duolingo entry is the useful surprise: even educational apps can collect considerable information — extensive data collection isn't limited to social media. cybersecurity-insiders
Is your phone secretly tracking you?
"Secretly" overstates it. These apps generally disclose their practices in privacy policies and app-store privacy labels — the real problem is that users rarely read them or understand what permissions mean. Collection also isn't automatically spying: apps may need data for legitimate features, performance, personalization or advertising. And privacy labels describe what developers say they collect — they don't measure frequency or independently verify disclosures. cybersecurity-insiderscybersecurity-insiders
The pattern worth understanding: encryption doesn't equal privacy. WhatsApp messages are end-to-end encrypted, but the broader app can still involve identifiers, contacts and usage data. End-to-end encryption is when only the sender and recipient can read a message — it protects content, not the metadata around it. cybersecurity-insiders
How do you limit app data collection?
Review app permissions regularly, disable unnecessary access to location, contacts and other sensitive data, and think before granting permissions an app doesn't obviously need. On both iOS and Android, permission settings can be reviewed per-app in under a minute — location is the highest-value one to lock down, since it reveals routines, workplaces and habits. cybersecurity-insiders
Source: Cybersecurity Insiders, citing Surfshark's 2026 Big Tech privacy analysis.