Meta AI Tops List of Most Data-Hungry Apps in 2026

Meta AI declares 33 of 35 possible data types, topping a 2026 Surfshark analysis of how much information major apps collect about their users, according to a report by Cybersecurity Insiders. cybersecurity-insiders

Key facts

  • The study: Surfshark's 2026 analysis covered 171 apps from major technology companies cybersecurity-insiders

  • Top collector: Meta AI, declaring 33 of 35 data types cybersecurity-insiders

  • Company averages: Meta's apps collected an average of 25 of 35 data categories; Google apps averaged 17 cybersecurity-insiders

  • Top non-Meta app: Amazon Alexa, declaring 28 data types cybersecurity-insiders

  • What to do: Review app permissions and revoke access apps don't obviously need

Which apps collect the most data?

The report's ten notable examples: Meta AI, Facebook, Instagram, Messenger, TikTok, Amazon Alexa, Google Maps, WhatsApp, Pinterest and Duolingo. TikTok's collection can include identifiers, contact information and location; earlier research found Facebook collected all 32 data points in Apple's privacy framework at the time. cybersecurity-insiderscybersecurity-insiders

The Duolingo entry is the useful surprise: even educational apps can collect considerable information — extensive data collection isn't limited to social media. cybersecurity-insiders

Is your phone secretly tracking you?

"Secretly" overstates it. These apps generally disclose their practices in privacy policies and app-store privacy labels — the real problem is that users rarely read them or understand what permissions mean. Collection also isn't automatically spying: apps may need data for legitimate features, performance, personalization or advertising. And privacy labels describe what developers say they collect — they don't measure frequency or independently verify disclosures. cybersecurity-insiderscybersecurity-insiders

The pattern worth understanding: encryption doesn't equal privacy. WhatsApp messages are end-to-end encrypted, but the broader app can still involve identifiers, contacts and usage data. End-to-end encryption is when only the sender and recipient can read a message — it protects content, not the metadata around it. cybersecurity-insiders

How do you limit app data collection?

Review app permissions regularly, disable unnecessary access to location, contacts and other sensitive data, and think before granting permissions an app doesn't obviously need. On both iOS and Android, permission settings can be reviewed per-app in under a minute — location is the highest-value one to lock down, since it reveals routines, workplaces and habits. cybersecurity-insiders

Source: Cybersecurity Insiders, citing Surfshark's 2026 Big Tech privacy analysis.