Mainstream services

Browse all mainstream services that you might be using. These are services that have known privacy issues and for which we usually recommend alternatives.
Category

129 of 129 mainstream services

Password Manager
1Password

1Password

Privacy concerns

  • Closed source - neither client nor server code is publicly auditable
  • Based in Canada - subject to Five Eyes intelligence sharing
  • Subscription required - no free tier available
  • Cloud sync is the only option - no local-only vault like KeePassXC
Smart Home
Amazon Alexa / Echo

Amazon Alexa / Echo

Privacy concerns

  • Always-on microphone listens for wake word - audio clips sent to Amazon servers
  • Amazon employees have reviewed voice recordings for product improvement
  • Subject to US CLOUD Act - Amazon has provided Alexa recordings to law enforcement
  • Deep integration with Amazon's advertising and shopping ecosystem
  • Third-party skills granted broad access to voice interaction data
AI Assistant
Amazon Alexa AI

Amazon Alexa AI

Privacy concerns

  • Alexa conversations stored on Amazon servers and used for model training by default
  • Subject to US CLOUD Act
  • Amazon employees have reviewed voice interactions for quality improvement
  • Deeply integrated with Amazon's shopping and advertising ecosystem
Music
Amazon Music

Amazon Music

Privacy concerns

  • Integrated with Amazon's advertising and data ecosystem
  • Listening behaviour feeds into Amazon's product recommendation and ad-targeting systems
  • Subject to US CLOUD Act
  • Tied to Amazon account - data shared across Amazon's family of services
Photos
Amazon Photos

Amazon Photos

Privacy concerns

  • Scans photos to feed into Amazon's AI, advertising, and Rekognition facial recognition systems
  • Integrated with Amazon Prime - used as a retention tool to deepen data collection
  • Subject to US CLOUD Act
  • Amazon has provided Ring and Alexa data to law enforcement without warrants
Video Streaming
Amazon Prime Video

Amazon Prime Video

Privacy concerns

  • Owned by Amazon - viewing data integrated with broader Amazon advertising ecosystem
  • Advertising tier added by default - ad-supported viewing now feeds targeted ad profiles
  • Subject to US CLOUD Act
  • Amazon has a pattern of broad government data requests across its services
Phone OS
Android (Google)

Android (Google)

Privacy concerns

  • Owned by Google - device data feeds directly into Google's advertising ecosystem
  • Collects location, app usage, contacts, and device identifiers by default
  • Google Play Services runs persistently in the background with extensive system permissions
  • Subject to US CLOUD Act
  • Advertising ID ties behaviour across all apps to a single persistent profile
  • Many manufacturers ship additional bloatware with their own data collection on top
Phone App Store
Apple App Store

Apple App Store

Privacy concerns

  • Apple collects app download history and purchase data
  • Has complied with government requests to remove apps from regional stores
  • App privacy labels are self-reported by developers - not independently verified by Apple
  • Has complied with government data requests for App Store account information
Calendar
Apple Calendar

Apple Calendar

Privacy concerns

  • Syncs to iCloud - Apple can access calendar data by default
  • Not E2EE unless Advanced Data Protection is enabled
  • Has complied with government data requests
  • Locked into Apple ecosystem for seamless sync
Contacts
Apple Contacts

Apple Contacts

Privacy concerns

  • Syncs to iCloud - not E2EE by default unless Advanced Data Protection is enabled
  • Apple can access contact data under standard settings
  • Has complied with government data requests
  • Locked into Apple ecosystem for seamless cross-device sync
Smart Home
Apple HomePod

Apple HomePod

Privacy concerns

  • Siri interactions processed on Apple servers - tied to your Apple ID
  • HomeKit data synced via iCloud - not fully E2EE under standard settings
  • Has complied with government data requests
  • Locked into Apple ecosystem - limited third-party device compatibility
Email
Apple iCloud Mail

Apple iCloud Mail

Privacy concerns

  • Syncs to iCloud by default - Apple can access unencrypted mail
  • Apple has complied with government data requests
  • Not end-to-end encrypted unless using Advanced Data Protection
AI Assistant
Apple Intelligence

Apple Intelligence

Privacy concerns

  • Tied to Apple ID - interactions logged and associated with your account
  • Server-side processing for complex requests means data leaves the device
  • Private Cloud Compute marketed as privacy-preserving but independently unverifiable
  • Has complied with government data requests
  • Locked into Apple ecosystem
Phone OS
Apple iOS

Apple iOS

Privacy concerns

  • Apple collects device usage, Siri interactions, and app analytics by default
  • iCloud backup not fully E2EE under standard settings - Apple can access device data
  • Has complied with government data requests at scale
  • App Tracking Transparency marketed as a privacy feature but Apple's own ad tracking is exempt
  • Historically locked into Apple ecosystem with no alternative app distribution
Office
Apple iWork

Apple iWork

Privacy concerns

  • Syncs via iCloud - not fully E2EE by default
  • Apple can access documents under standard iCloud settings
  • Has complied with government data requests
  • Locked into Apple ecosystem for collaboration features
Maps
Apple Maps

Apple Maps

Privacy concerns

  • Collects location data tied to Apple ID and iCloud account
  • Apple has complied with government data requests
  • Not fully E2EE - location search history accessible to Apple under standard settings
  • Limited data portability outside the Apple ecosystem
Music
Apple Music

Apple Music

Privacy concerns

  • Syncs listening history to iCloud - Apple can access data under standard settings
  • Integrated with Apple's broader ecosystem and device data collection
  • Has complied with government data requests
  • Limited data portability outside the Apple ecosystem
Notes
Apple Notes

Apple Notes

Privacy concerns

  • Syncs to iCloud - not fully E2EE by default unless Advanced Data Protection is enabled
  • Apple can access note contents under standard iCloud settings
  • Locked into Apple ecosystem with limited export options
  • Has complied with government data requests
Photos
Apple Photos

Apple Photos

Privacy concerns

  • Not E2EE by default - Apple can access photos under standard iCloud settings
  • Apple has complied with government data requests
  • Previously deployed on-device CSAM scanning (later paused) raising broader surveillance concerns
  • Locked into Apple ecosystem for seamless library sync
2FA Authenticator
Authy

Authy

Privacy concerns

  • Owned by Twilio, a US communications company
  • Cloud backup mandatory - cannot use Authy without creating an account
  • Subject to US CLOUD Act
  • Twilio suffered a significant breach in 2022 affecting Authy user phone numbers
  • Closed source - cannot be independently audited
Search Engine
Bing

Bing

Privacy concerns

  • Owned by Microsoft - search queries tied to Microsoft account and advertising profile
  • Subject to US CLOUD Act
  • Queries increasingly feed Microsoft's Copilot AI training pipeline
  • Deep integration with Microsoft's broader data ecosystem
Maps
Bing Maps

Bing Maps

Privacy concerns

  • Owned by Microsoft - location queries tied to Microsoft account and advertising profile
  • Subject to US CLOUD Act
  • Integrated with Microsoft's broader advertising and data ecosystem
  • Usage data feeds into Microsoft's Copilot AI training pipeline
AI Assistant
Bixby

Bixby

Privacy concerns

  • Collects voice interactions and device usage data
  • Subject to South Korean legal jurisdiction and government data requests
  • Privacy policy permits broad data sharing with Samsung's advertising and analytics partners
  • Processes data through Samsung's cloud infrastructure with limited transparency
Web Hosting
Bluehost

Bluehost

Privacy concerns

  • Owned by Newfold Digital (formerly Endurance International Group)
  • US-based, subject to CLOUD Act
  • Parent company owns dozens of hosting brands - significant market concentration
  • Has experienced security incidents affecting customer data
  • Aggressive upselling and confusing pricing structures
  • Privacy policy permits broad data sharing across Newfold's portfolio of brands
Calendar
Calendly

Calendly

Privacy concerns

  • US-based scheduling tool, subject to CLOUD Act
  • Collects meeting metadata, attendee information, and usage patterns
  • Shares data with third-party integrations (Zoom, Salesforce, HubSpot, etc.)
  • Privacy policy permits broad data use for marketing and analytics
AI Assistant
ChatGPT

ChatGPT

Privacy concerns

  • US-based, subject to CLOUD Act - all conversations stored on OpenAI's servers
  • Conversation history used to train future models by default unless opted out
  • Microsoft is a major investor - deep integration with Microsoft's data ecosystem
  • Free tier users have significantly reduced data controls compared to paid tiers
  • Has faced regulatory investigations across multiple jurisdictions
Computer OS
ChromeOS

ChromeOS

Privacy concerns

  • Owned by Google - entire OS experience tied to Google account
  • All activity feeds into Google's advertising ecosystem
  • Subject to US CLOUD Act
  • Designed to keep data in Google's cloud rather than local storage
  • Limited offline functionality by design - deep cloud dependency
AI Assistant
Claude

Claude

Privacy concerns

  • US-based (Anthropic), subject to CLOUD Act
  • Anthropic has received major investment from Google and Amazon - creating ties to large tech data ecosystems
  • Conversations stored server-side; Anthropic staff can access them for safety and trust review
  • No E2EE - Anthropic has full access to conversation contents
DNS
Cloudflare 1.1.1.1

Cloudflare 1.1.1.1

Privacy concerns

  • US-based - subject to CLOUD Act
  • Retains query logs for up to 25 hours by default
  • Privacy policy permits data sharing with Cloudflare's network partners
  • WARP VPN product bundles DNS with full traffic routing through Cloudflare's infrastructure
Domain Name
Cloudflare Registrar

Cloudflare Registrar

Privacy concerns

  • US-based, subject to CLOUD Act
  • Cloudflare sits between your website and all its visitors - significant traffic visibility
  • Has faced criticism for providing services to extremist and harmful websites
  • Business model built on being infrastructure for a large portion of the internet - significant data concentration
Video Streaming
Dailymotion

Dailymotion

Privacy concerns

  • Owned by Vivendi, a French media conglomerate
  • Ad-supported model with extensive tracking and third-party data sharing
  • Limited transparency over data retention practices
  • Collects detailed viewing and engagement data for advertising purposes
Password Manager
Dashlane

Dashlane

Privacy concerns

  • US-based - subject to CLOUD Act
  • Encrypted vaults stored on Dashlane's servers - trust depends on their security practices
  • Privacy policy permits data collection for analytics and product improvement
  • Free tier severely limited - business model creates incentives that may deprioritise privacy
Video Streaming
Disney+

Disney+

Privacy concerns

  • Ad-supported tier introduced - ad-tier data is shared with third-party advertisers
  • Owned by Disney - subject to US CLOUD Act
  • Viewing data used for content licensing decisions and audience profiling
  • Privacy controls limited to opt-outs rather than genuine data minimisation
Cloud Storage
Dropbox

Dropbox

Privacy concerns

  • US-based, subject to CLOUD Act
  • Has previously granted employee access to user files without consent
  • Collects extensive usage metadata and device information
  • Privacy policy permits broad data sharing with third-party partners
Notes
Evernote

Evernote

Privacy concerns

  • Notoriously updated privacy policy in 2016 to allow employee access to notes
  • Ownership transferred to Italian company Bending Spoons in 2023 - data handling continuity unclear
  • Has experienced security breaches historically
  • Free tier has very limited encryption controls
VPN
ExpressVPN

ExpressVPN

Privacy concerns

  • Acquired by Kape Technologies in 2021 - Kape has a history rooted in adware distribution
  • CEO previously worked for a UAE government surveillance contractor
  • US-adjacent jurisdiction via Kape's Israeli and UK ownership
  • Kape also owns CyberGhost, Private Internet Access, and ZenMate - significant VPN market consolidation
Social Media
Facebook

Facebook

Privacy concerns

  • Owned by Meta - one of the most comprehensive advertising surveillance platforms in existence
  • Tracks users across the web and apps via Meta Pixel even without an account
  • Has been fined billions across multiple jurisdictions for privacy violations
  • Facial recognition deployed at scale; data used to train Meta AI models
Photos
Facebook / Instagram

Facebook / Instagram

Privacy concerns

  • Meta uses uploaded photos to train facial recognition and AI models
  • Photos feed directly into Meta's advertising profile on you
  • Meta has been fined billions for unlawful facial recognition data collection
  • Deleted photos have historically remained on Meta's servers long after removal
Messaging
Facebook Messenger

Facebook Messenger

Privacy concerns

  • Owned by Meta, deeply integrated into Meta's advertising profile
  • Default chats are not end-to-end encrypted - stored on Meta's servers
  • Extensively used by Meta to build behavioural ad profiles
  • Has complied with law enforcement data requests at massive scale
Photos
Flickr

Flickr

Privacy concerns

  • Owned by SmugMug after Yahoo divestiture - limited transparency on data practices
  • Photos used in datasets for AI model training without explicit opt-in
  • US-based, subject to CLOUD Act
  • Privacy controls are complex and non-obvious for casual users
Email
Gmail

Gmail

Privacy concerns

  • Google scans email content to power its advertising and AI products
  • Deep integration across Google's data ecosystem (Search, Drive, Ads, etc.)
  • Subject to US CLOUD Act - data can be compelled by US authorities
  • Has a history of complying with government data requests and FISA orders
Domain Name · Web Hosting
GoDaddy

GoDaddy

Privacy concerns

  • US-based, subject to CLOUD Act
  • Suffered multiple major breaches including a 2021 incident exposing 1.2 million customer records
  • Aggressive upselling and dark patterns throughout registration, checkout, and account management
  • Privacy policy permits broad data sharing with advertising and analytics partners
  • WHOIS privacy sold as a paid add-on despite being a basic privacy necessity
  • Owns a significant portion of shared hosting globally - major infrastructure concentration risk
2FA Authenticator
Google Authenticator

Google Authenticator

Privacy concerns

  • Added cloud sync in 2023 - TOTP secrets now uploaded to Google's servers by default
  • Synced secrets tied to Google account and subject to US CLOUD Act
  • Google account compromise exposes all 2FA codes simultaneously
  • No end-to-end encryption of synced secrets confirmed at launch of sync feature
Calendar
Google Calendar

Google Calendar

Privacy concerns

  • Deeply integrated with Google account and advertising ecosystem
  • Event data (titles, locations, attendees) feeds into Google's profile on you
  • Subject to US CLOUD Act
  • Shares event data with third-party apps granted calendar access
Browser
Google Chrome

Google Chrome

Privacy concerns

  • Owned by Google - browsing history feeds directly into Google's advertising profile
  • Syncs browsing history, bookmarks, and passwords to Google servers by default
  • Subject to US CLOUD Act
  • Privacy Sandbox initiative rebrands tracking rather than eliminating it
  • Third-party cookie deprecation repeatedly delayed under advertiser pressure
Contacts
Google Contacts

Google Contacts

Privacy concerns

  • Fully integrated with Google account and advertising ecosystem
  • Contact data (names, emails, phone numbers, relationships) feeds into Google's profile on you
  • Subject to US CLOUD Act
  • Third-party apps granted contact access frequently over-share data with Google
Cloud Storage
Google Drive

Google Drive

Privacy concerns

  • Scans file contents to power Google's advertising and AI products
  • Deep integration across Google's data ecosystem
  • Subject to US CLOUD Act - data can be compelled by US authorities
  • Has complied with government data requests and FISA orders
AI Assistant
Google Gemini

Google Gemini

Privacy concerns

  • Owned by Google - conversations feed directly into Google's advertising and data ecosystem
  • Integrated with Google account - queries tied to your broader Google profile
  • Subject to US CLOUD Act
  • Human reviewers annotate conversations for model improvement
  • Deeply embedded in Google Workspace - processes documents, emails, and calendar data server-side
Smart Home
Google Home / Nest

Google Home / Nest

Privacy concerns

  • Always-on microphone feeds into Google's advertising and data ecosystem
  • Google employees have reviewed audio recordings without clear user disclosure
  • Subject to US CLOUD Act
  • Nest devices collect home occupancy patterns, temperature preferences, and daily routines
  • Data shared across Google's ecosystem including advertising platforms
Notes
Google Keep

Google Keep

Privacy concerns

  • Directly integrated with Google account and advertising profile
  • Note contents scanned and used to improve Google's AI products
  • Subject to US CLOUD Act
  • No meaningful encryption at rest beyond standard Google account protection
Maps
Google Maps

Google Maps

Privacy concerns

  • Location history feeds directly into Google's advertising profile
  • Builds a detailed record of everywhere you go, including home, work, and daily routines
  • Location data has been provided to law enforcement via geofence warrants
  • Subject to US CLOUD Act
  • Timeline feature stores years of precise movement history by default
Video Conferencing
Google Meet

Google Meet

Privacy concerns

  • Integrated with Google account - data feeds into Google's ad profile
  • Meeting metadata collected and retained
  • Transcripts and recordings stored on Google servers
Password Manager
Google Password Manager

Google Password Manager

Privacy concerns

  • Credentials stored in your Google account - tied directly to Google's advertising ecosystem
  • Subject to US CLOUD Act
  • A single Google account compromise exposes all stored passwords simultaneously
  • No independent audit of encryption implementation
Photos
Google Photos

Google Photos

Privacy concerns

  • Scans photo and video contents using AI to build detailed profiles including faces, locations, and objects
  • Deep integration with Google's advertising and data ecosystem
  • Subject to US CLOUD Act - images can be compelled by US authorities
  • Previously offered unlimited free storage as an incentive to harvest photo libraries at scale
Phone App Store
Google Play Store

Google Play Store

Privacy concerns

  • Collects app download history, search queries, and usage patterns for advertising
  • Subject to US CLOUD Act
  • Has complied with government requests to remove apps and hand over developer data
  • Review and rating data used to build commercial intelligence products
DNS
Google Public DNS

Google Public DNS

Privacy concerns

  • Operated by Google - all DNS queries feed directly into Google's data infrastructure
  • Logs and uses query data to improve Google's services
  • Subject to US CLOUD Act
  • Gives Google comprehensive visibility into every domain you visit regardless of browser or device
Search Engine
Google Search

Google Search

Privacy concerns

  • Every query tied to your Google account and advertising profile
  • Builds detailed interest, intent, and behavioural profiles sold to advertisers
  • Subject to US CLOUD Act - search histories have been subpoenaed in legal cases
  • Has complied with government data requests for search histories at massive scale
  • Has changed its search to be primarily AI-driven since May 2024 (AI Overviews), which will increase data collection and profiling
Office
Google Workspace

Google Workspace

Privacy concerns

  • Document contents scanned and used to improve Google's AI products
  • Deep integration with Google's advertising ecosystem
  • Subject to US CLOUD Act
  • Third-party add-ons granted broad access to document contents by default
AI Assistant
Grok

Grok

Privacy concerns

  • Owned by Elon Musk's xAI - deeply integrated with X/Twitter
  • Conversations and X activity used to train Grok models
  • Privacy policy permits broad data use with limited user controls
  • US-based, subject to CLOUD Act
  • Limited independent scrutiny of data handling practices
Maps
HERE Maps

HERE Maps

Privacy concerns

  • Owned by a consortium including automotive giants BMW, Daimler, and Audi
  • Collects precise location data from connected vehicles and mobile devices at scale
  • Sells anonymised (but re-identifiable) location data to third-party commercial partners
  • Privacy policy permits broad data sharing across the automotive and logistics industries
Web Hosting
HostGator

HostGator

Privacy concerns

  • Owned by Newfold Digital - same parent company concerns as Bluehost
  • US-based, subject to CLOUD Act
  • Significant service quality decline noted since Newfold acquisition
  • Privacy policy permits broad data sharing across parent company's brand portfolio
  • Customer data potentially shared across all Newfold-owned properties
Video Streaming
Hulu

Hulu

Privacy concerns

  • Majority owned by Disney - aggressive ad targeting even on paid tiers
  • Sells user viewing data and demographics to advertising partners
  • Subject to US CLOUD Act
  • Ad-heavy experience with minimal data minimisation options for subscribers
Cloud Storage
iCloud Drive

iCloud Drive

Privacy concerns

  • Apple can access files not covered by Advanced Data Protection
  • Apple has complied with government data requests
  • Encrypted in transit but not fully E2EE by default
  • Locked into Apple ecosystem
TV Reviews
IMDb

IMDb

Privacy concerns

  • Owned by Amazon - ratings, watchlists, and viewing history are directly linked to your Amazon account
  • Film and TV preferences cross-referenced with Prime Video watch history and Amazon shopping behaviour
  • Data used to serve personalised advertising across Amazon's ad network
  • Subject to US CLOUD Act surveillance law
Messaging
iMessage

iMessage

Privacy concerns

  • End-to-end encrypted between Apple devices only
  • iCloud backup of messages is not E2EE by default - Apple can access them
  • Locks you into Apple ecosystem
  • Metadata collected by Apple
Photos
Instagram

Instagram

Privacy concerns

  • Owned by Meta - every photo uploaded feeds facial recognition, ad targeting, and AI training at scale
  • Photos used to build detailed demographic and interest profiles sold to advertisers
  • Meta has been fined billions for unlawful facial recognition data collection without consent
  • Deleted photos have historically remained on Meta's servers long after removal
Social Media
Instagram

Instagram

Privacy concerns

  • Owned by Meta, feeds directly into Meta's advertising profile
  • Collects precise location, device data, browsing behaviour, and contact lists
  • DMs are E2EE by default for personal chats (rolled out Jan 2024) - Meta has proposed removing this encryption in 2026
  • Used to build psychographic profiles for targeted advertising
DNS
ISP Default DNS

ISP Default DNS

Privacy concerns

  • Your ISP can see and log every domain you visit via DNS queries
  • DNS data frequently sold to advertising partners and data brokers
  • Subject to government surveillance and mandatory data retention laws
  • Queries transmitted in plaintext by default - no encryption
Messaging
KakaoTalk

KakaoTalk

Privacy concerns

  • Dominant South Korean messaging app owned by Kakao Corp
  • Messages stored on servers and accessible to South Korean authorities
  • Has handed over user data in domestic law enforcement cases
  • Collects extensive device and usage metadata
Password Manager
Keeper

Keeper

Privacy concerns

  • US-based - subject to CLOUD Act
  • Has pursued legal action against security researchers who disclosed vulnerabilities
  • Collects usage metadata and device information
  • Enterprise editions marketed with admin vault access features
Music
Last.fm

Last.fm

Privacy concerns

  • Owned by Bauer Media Group (acquired 2021) - listening data remains a commercial asset
  • Scrobbling model means detailed long-term listening history accumulated on their servers
  • US-based, subject to CLOUD Act
  • Limited modern privacy controls despite handling years of historical listening data
Password Manager
LastPass

LastPass

Privacy concerns

  • Suffered a catastrophic breach in 2022 - encrypted vaults stolen along with URL metadata in plaintext
  • Has experienced multiple prior security incidents over its history
  • US-based - subject to CLOUD Act
  • Ownership has changed hands multiple times (LogMeIn, GoTo) raising continuity and trust concerns
2FA Authenticator
LastPass Authenticator

LastPass Authenticator

Privacy concerns

  • Tied to LastPass account - inherits all of LastPass's security and privacy problems
  • Suffered exposure in the same 2022 breach as the password manager
  • US-based, subject to CLOUD Act
  • Cloud backup depends entirely on LastPass infrastructure security
Social Media
LinkedIn

LinkedIn

Privacy concerns

  • Owned by Microsoft - harvests professional and personal data for advertising
  • Tracks users across the web via LinkedIn pixels
  • Data used to train Microsoft AI models
Computer OS
macOS

macOS

Privacy concerns

  • Apple collects app usage, Siri interactions, and device analytics by default
  • Gatekeeper and notarisation system means Apple knows every app you run
  • Has complied with government data requests
  • iCloud integration means documents, desktop, and downloads synced to Apple servers by default
  • Not fully E2EE under standard iCloud settings
Cloud Storage
Mega

Mega

Privacy concerns

  • Founder Kim Dotcom's troubled legal history raises trust concerns
  • Based in New Zealand but infrastructure spans multiple jurisdictions
  • Client-side encryption claims have not been independently audited end-to-end
  • Has faced questions over ownership and potential undisclosed access
AI Assistant
Meta AI

Meta AI

Privacy concerns

  • Owned by Meta - conversations feed into Meta's advertising profile
  • Integrated across Facebook, Instagram, WhatsApp, and Messenger
  • Subject to US CLOUD Act
  • Trained on years of Facebook and Instagram user data without explicit consent
  • No meaningful separation between AI interactions and Meta's advertising infrastructure
TV Reviews
Metacritic

Metacritic

Privacy concerns

  • Owned by Fandom (formerly CBS Interactive) - a large media and advertising company
  • User data shared across Fandom's network of entertainment and gaming sites
  • Heavy advertising and third-party tracker presence on the platform
  • Subject to US CLOUD Act surveillance law
Office
Microsoft 365

Microsoft 365

Privacy concerns

  • Subject to US CLOUD Act - all documents stored on Microsoft servers
  • Copilot AI features process document contents server-side
  • Workplace surveillance features built into admin dashboards (Productivity Score)
  • Has faced regulatory scrutiny in the EU over data transfers and telemetry
2FA Authenticator
Microsoft Authenticator

Microsoft Authenticator

Privacy concerns

  • Cloud backup syncs secrets to Microsoft account
  • Subject to US CLOUD Act
  • Collects usage metadata and device information
  • Microsoft account compromise exposes all stored credentials and 2FA secrets
AI Assistant
Microsoft Copilot

Microsoft Copilot

Privacy concerns

  • Owned by Microsoft - conversations tied to Microsoft account
  • Subject to US CLOUD Act
  • Deeply integrated across Microsoft 365 - processes documents, emails, and Teams conversations
  • Workplace deployments give admins visibility into employee Copilot usage
  • Built on OpenAI models - data subject to both Microsoft and OpenAI privacy policies
Browser
Microsoft Edge

Microsoft Edge

Privacy concerns

  • Built on Chromium but adds Microsoft-specific telemetry and data collection
  • Syncs browsing data to Microsoft account by default
  • Subject to US CLOUD Act
  • Bing AI sidebar processes page contents server-side
  • Has been caught sending visited URLs to Microsoft's SmartScreen service without clear disclosure
Photos
Microsoft OneDrive

Microsoft OneDrive

Privacy concerns

  • Scans photos for 'safety' purposes and to power Microsoft's AI products
  • Integrated with Microsoft's broader data ecosystem
  • Subject to US CLOUD Act
  • Recall feature (Windows 11) raised serious concerns about continuous screen capture tied to file activity
Cloud Storage
Microsoft OneDrive

Microsoft OneDrive

Privacy concerns

  • Integrated with Microsoft's data ecosystem and advertising platform
  • Subject to US CLOUD Act
  • Scans files for 'safety' purposes - including personal documents
  • Recall feature raised major concerns about local content surveillance
Notes
Microsoft OneNote

Microsoft OneNote

Privacy concerns

  • Integrated with Microsoft 365 and OneDrive ecosystem
  • Content scanned for 'safety' and used across Microsoft's AI products
  • Subject to US CLOUD Act
  • Copilot AI features process note contents server-side
Video Conferencing
Microsoft Teams

Microsoft Teams

Privacy concerns

  • Deep data collection across Microsoft's ecosystem
  • Workplace surveillance features built in
  • Subject to US CLOUD Act
Video Streaming
Netflix

Netflix

Privacy concerns

  • Detailed granular viewing data collected - including pause, rewind, and chapter-by-chapter retention
  • Subject to US CLOUD Act
  • Has shared viewing data with law enforcement in response to legal requests
  • Ad-supported tier adds real-time advertising data collection and targeting on top
VPN
NordVPN

NordVPN

Privacy concerns

  • Based in Panama but operated by Nord Security, which has Lithuanian ownership ties
  • Suffered a server breach in 2018 that was not disclosed for over a year
  • Aggressive marketing claims of 'military-grade encryption' are misleading
  • Owned by the same parent company as Surfshark - raises consolidation concerns
  • Heavy influencer and affiliate marketing model incentivises promotion over honest review
Notes
Notion

Notion

Privacy concerns

  • US-based, subject to CLOUD Act
  • All note content stored on Notion's servers without application-layer encryption
  • AI features process document contents via third-party model providers
  • Workspace admins have broad visibility into all member content
Browser
Opera

Opera

Privacy concerns

  • Majority owned by a Chinese investment consortium since 2016
  • Built-in VPN is operated by Opera itself - a conflict of interest
  • Subject to Chinese national security laws via ownership structure
  • Has been found to request excessive permissions on mobile versions
  • Privacy policy permits broad data sharing with third-party partners
Email
Outlook

Outlook

Privacy concerns

  • Microsoft scans email content for advertising and 'safety' purposes
  • Deep integration with Microsoft's data ecosystem
  • Subject to US CLOUD Act - data can be compelled by US authorities
Calendar
Outlook Calendar

Outlook Calendar

Privacy concerns

  • Integrated with Microsoft 365 data ecosystem
  • Subject to US CLOUD Act
  • Copilot AI features process calendar contents server-side
  • Workplace deployments give admins broad visibility into employee calendars
Contacts
Outlook Contacts

Outlook Contacts

Privacy concerns

  • Integrated with Microsoft 365 and LinkedIn data ecosystems
  • Subject to US CLOUD Act
  • Contact data used to enrich Microsoft's organisational graph and AI products
  • Workplace deployments give admins visibility into employee contact networks
Social Media
Pinterest

Pinterest

Privacy concerns

  • Ad-supported, tracks users across the web
  • Collects browsing data via Pinterest buttons on third-party sites
  • Shares data with advertising partners extensively
Social Media
Reddit

Reddit

Privacy concerns

  • Sells user data to AI companies for training
  • Collects browsing behaviour and usage patterns
  • US-based, subject to CLOUD Act
  • Recent API changes designed to lock in data monopoly
Smart Home
Ring (Amazon)

Ring (Amazon)

Privacy concerns

  • Owned by Amazon - footage and data integrated into Amazon's ecosystem
  • Amazon has provided Ring footage to law enforcement without user consent or warrants
  • Partnerships with hundreds of police departments built into Ring's infrastructure
  • Subject to US CLOUD Act
  • Neighbours app creates a community surveillance network feeding data back to Amazon
TV Reviews
Rotten Tomatoes

Rotten Tomatoes

Privacy concerns

  • Owned by Fandango, a joint venture of NBCUniversal - your taste data feeds into a major media conglomerate's advertising ecosystem
  • No data export option - your ratings and watchlist are locked in
  • Shares user data with Fandango's ticketing and streaming partners
  • Subject to US CLOUD Act surveillance law
Browser
Safari

Safari

Privacy concerns

  • Owned by Apple - browsing metadata collected and tied to Apple ID
  • iCloud syncs browsing history across devices - accessible to Apple under standard settings
  • Locked into Apple ecosystem for seamless sync features
  • Has complied with government data requests
  • Intelligent Tracking Prevention is marketed as privacy-friendly but Apple retains metadata
Contacts
Samsung Contacts

Samsung Contacts

Privacy concerns

  • Syncs to Samsung Cloud, operated with third-party infrastructure partners
  • Privacy policy permits data sharing with Samsung's advertising and analytics partners
  • Data subject to South Korean legal jurisdiction and government requests
  • Limited transparency around encryption practices in Samsung Cloud
Phone App Store
Samsung Galaxy Store

Samsung Galaxy Store

Privacy concerns

  • Collects app download history and device usage data
  • Subject to South Korean legal jurisdiction and government data requests
  • Has distributed apps found to contain malware on multiple occasions
  • Privacy policy permits broad data sharing with Samsung's advertising partners
Browser
Samsung Internet

Samsung Internet

Privacy concerns

  • Developed by Samsung - syncs data to Samsung Cloud and Samsung account
  • Collects browsing metadata and usage patterns
  • Privacy policy permits data sharing with Samsung's advertising and analytics partners
  • Subject to South Korean legal jurisdiction and government data requests
Phone OS
Samsung One UI

Samsung One UI

Privacy concerns

  • Adds Samsung-specific data collection on top of Google's Android telemetry
  • Samsung account syncs device data to Samsung Cloud
  • Bixby and Samsung AI features process data server-side
  • Subject to South Korean legal jurisdiction and government data requests
  • Pre-installed apps cannot be removed without root access
Smart Home
Samsung SmartThings

Samsung SmartThings

Privacy concerns

  • Collects home device usage patterns, occupancy data, and automation routines
  • Subject to South Korean legal jurisdiction and government data requests
  • Privacy policy permits broad data sharing with Samsung's advertising partners
  • Hub-dependent architecture routes all device data through Samsung's cloud
Photos
Snapchat

Snapchat

Privacy concerns

  • Collects biometric data from photos and videos including face geometry
  • Images and videos pass through Snap's servers - ephemeral deletion is not independently verified
  • Extensive location data tied to photo metadata
  • Ad-supported model built on harvesting visual and behavioural data
Messaging
Snapchat

Snapchat

Privacy concerns

  • Collects extensive location data including precise GPS
  • Owned by Snap Inc, ad-supported business model
  • My AI feature stores conversations by default
  • Has shared user data with law enforcement extensively
Music
SoundCloud

SoundCloud

Privacy concerns

  • Headquartered in Berlin but US-incorporated, subject to CLOUD Act
  • Collects listening history, upload metadata, and social interaction data
  • Ad-supported free tier shares data with a broad network of advertising partners
  • Has experienced financial instability raising concerns about data handling continuity
Music
Spotify

Spotify

Privacy concerns

  • Collects extensive listening history, playlist data, and behavioural patterns
  • Uses listening data to build detailed psychological and mood profiles for advertisers
  • Microphone access requested on mobile - privacy policy permits voice data collection
  • US-listed company, subject to CLOUD Act despite Swedish origins
VPN
Surfshark

Surfshark

Privacy concerns

  • Merged with Nord Security in 2022 - same parent company as NordVPN
  • Subject to EU legal jurisdiction and data retention directives following merger
  • Aggressive marketing and influencer sponsorship model
  • Free trial requires payment details upfront - dark pattern designed to capture billing information
  • Privacy policy permits data sharing with Nord Security's broader portfolio of products
Messaging
Telegram

Telegram

Privacy concerns

  • Not end-to-end encrypted by default - only in Secret Chats
  • Group chats and regular chats stored on Telegram servers unencrypted
  • Closed source server code - cannot be independently audited
  • Based in Dubai, unclear legal jurisdiction
Social Media
Threads

Threads

Privacy concerns

  • Owned by Meta - collects same data as Instagram and Facebook
  • Designed to feed into Meta's advertising profile
  • Requires an Instagram account - cannot be used independently
Music
Tidal

Tidal

Privacy concerns

  • Majority owned by Square / Block (Jack Dorsey) after Jay-Z acquisition
  • US-based, subject to CLOUD Act
  • Collects listening history, device data, and usage metadata
  • Privacy policy permits data sharing with third-party analytics partners
Social Media · Video Streaming
TikTok

TikTok

Privacy concerns

  • Owned by ByteDance, a Chinese company - subject to Chinese national security laws requiring data access on demand
  • Confirmed that China-based staff accessed US and EU user data
  • Collects biometric data including faceprints and voiceprints in some jurisdictions
  • Extensive behavioural profiling via watch time, scrolling behaviour, and interaction patterns
  • Subject to ongoing regulatory bans and scrutiny across multiple countries
Maps
TomTom

TomTom

Privacy concerns

  • Sells location and mapping data to third parties including advertisers and governments
  • Connected devices transmit real-time location data back to TomTom servers
  • Has supplied mapping data to companies with questionable data practices
  • Privacy policy permits data sharing with a broad network of commercial partners
Social Media
Tumblr

Tumblr

Privacy concerns

  • Sells user data to AI companies for model training
  • Ad-supported with third-party tracking throughout
  • History of data handling issues following ownership changes
Social Media · Video Streaming
Twitch

Twitch

Privacy concerns

  • Owned by Amazon - viewing habits, device data, and payment information feed into Amazon's advertising ecosystem
  • Suffered a massive data breach in 2021 exposing streamer income and platform source code
  • Subject to US CLOUD Act
  • Extensive chat and behavioural tracking for advertiser targeting
Social Media
Twitter / X

Twitter / X

Privacy concerns

  • Owned by X Corp - privacy policy significantly weakened post-2022 acquisition
  • Biometric data and employment/education history now collected per updated policy
  • Has complied with government data requests and handed over DMs to authorities
Messaging
Viber

Viber

Privacy concerns

  • Owned by Rakuten, a Japanese e-commerce company
  • Collects location data, contacts, and usage metadata
  • Privacy policy allows sharing data with third parties
  • End-to-end encryption implementation not independently audited
Video Streaming
Vimeo

Vimeo

Privacy concerns

  • US-based, subject to CLOUD Act
  • Collects detailed viewing metadata and user interaction data
  • Uses third-party advertising and analytics tools with broad data access
  • Privacy controls exist but require active management to limit data sharing
Maps
Waze

Waze

Privacy concerns

  • Owned by Google since 2013 - all location and routing data feeds into Google's ecosystem
  • Collects real-time location, speed, and driving behaviour continuously while active
  • Subject to US CLOUD Act
  • User-reported data aggregated and shared with municipal governments and advertisers
Video Conferencing
Webex

Webex

Privacy concerns

  • Owned by Cisco - US-based, subject to CLOUD Act
  • Has had significant security vulnerabilities
  • Collects meeting metadata and content
Messaging
WhatsApp

WhatsApp

Privacy concerns

  • Owned by Meta - metadata (contacts, group membership, timestamps) shared with Facebook's ad ecosystem
  • Messages are end-to-end encrypted by default, but non-encrypted cloud backups (iCloud/Google Drive) can expose message history
  • Requires a phone number tied to your identity
  • Metadata subject to law enforcement requests
Computer OS
Windows

Windows

Privacy concerns

  • Microsoft collects extensive telemetry by default - cannot be fully disabled without enterprise tools
  • Recall feature captures continuous screenshots of activity
  • Subject to US CLOUD Act
  • Copilot AI deeply integrated - user activity increasingly processed server-side
  • Advertising ID tracks behaviour across apps and Microsoft services
  • OneDrive backup enabled by default - documents automatically uploaded to Microsoft servers
Office
WPS Office

WPS Office

Privacy concerns

  • Developed by Kingsoft, a Chinese company
  • Privacy policy permits data collection and transfer to Chinese servers
  • Has been flagged by security researchers for excessive data collection
  • Subject to Chinese national security laws requiring data access on demand
Email
Yahoo Mail

Yahoo Mail

Privacy concerns

  • Notoriously breached - 3 billion accounts compromised in 2013
  • Actively scans emails for advertiser data
  • Previously built custom surveillance tool for US intelligence agencies
Search Engine
Yahoo Search

Yahoo Search

Privacy concerns

  • Powered by Bing under the hood - shares the same underlying data collection
  • Owned by Apollo Global Management after Verizon divestiture
  • Ad-supported with extensive third-party tracker network on results pages
  • Additional Yahoo-specific data collection layered on top of Bing's
Video Streaming
YouTube

YouTube

Privacy concerns

  • Owned by Google - every watch, search, and pause tracked and fed into advertising profiles
  • Watch history used to serve personalised ads across all Google services
  • Subject to US CLOUD Act - viewing history has been subpoenaed in legal cases
  • Metadata collection is pervasive even when logged out via fingerprinting and cookies
Music
YouTube Music

YouTube Music

Privacy concerns

  • Owned by Google - listening history feeds directly into Google's advertising profile
  • Deep integration with Google account and data ecosystem
  • Subject to US CLOUD Act
  • Tracks listening behaviour across devices and ties it to your broader Google profile
Office
Zoho Docs

Zoho Docs

Privacy concerns

  • Indian company with servers across multiple jurisdictions
  • Privacy policy permits broad data use for product improvement and analytics
  • Collects extensive usage metadata and document interaction data
  • Free tier users have significantly reduced data controls and retention limits
Video Conferencing
Zoom

Zoom

Privacy concerns

  • Previously routed calls through China
  • Used meeting content to train AI models without clear consent
  • Stores recordings and transcripts on their servers
  • Has had multiple significant security vulnerabilities