Applications developed by Meta have emerged as the most voracious consumers of user data among the five leading technology conglomerates. On average, Meta software explicitly claims to harvest 25 out of a possible 35 distinct categories of personal information. In stark contrast, Google acquires 17, Amazon gathers 12, Microsoft collects a mere eight, and Apple retains only seven. Consequently, the disparity between Meta and the latter two corporations represents a staggering threefold difference. Researchers at Surfshark reached this profound conclusion in a recent study following a meticulous analysis of applications hosted within the App Store.
Analyzing the App Store Landscape
The investigative team scrutinized 171 iOS applications. This comprehensive portfolio included 44 Google programs, 41 Apple utilities, 40 Microsoft applications, 34 Amazon services, and 12 Meta platforms. The specialists rigorously examined privacy disclosures directly on the App Store pages, meticulously tabulating exactly how many data categories developers declared for each respective application.
Meta Dominates Data Harvesting
Unsurprisingly, Meta applications unequivocally dominated the top seven positions regarding the sheer volume of declared data categories. Meta AI seized the primary position, aggressively harvesting 33 out of the 35 potential data types. Furthermore, Meta Horizon, Meta Business Suite, Meta Ads Manager, Messenger, Forum, and Facebook each explicitly indicated the collection of 32 distinct categories.
Every single one of the 12 evaluated Meta applications openly declared the collection of device identifiers, product interaction metrics, performance indicators, and comprehensive crash diagnostics. Nine of these programs specified the tracking of precise geographical locations, while seven actively monitored web browsing histories. The research team specifically highlighted this geolocation tracking, noting that many rudimentary functions operate flawlessly with merely an approximate user location.
Notably, Instagram and WhatsApp evaded inclusion within this specific study. Surfshark selectively analyzed applications exclusively associated with a singular Meta Platforms developer account on the App Store. Because Instagram and WhatsApp operate beneath entirely different account umbrellas, they remained unexamined. Therefore, these findings do not encapsulate the exhaustive product ecosystem of these five corporate behemoths; rather, they reflect a highly specific sampling of 171 applications.
Google and Amazon Data Practices
While Google trailed Meta concerning the average number of data categories, it prominently occupied 29 positions among the 40 applications exhibiting the most expansive declared data harvesting. Google’s highest-ranking programs routinely mandate access to between 18 and 26 distinct types of personal information.
Furthermore, Google maintains undisputed dominance across six distinct App Store categories: photography and video, music, entertainment, utilities, health and fitness, alongside developer tools. For instance, Google Maps, the solitary navigational application within this sampling, audaciously claims 26 discrete data types.
All scrutinized Google applications universally declare the acquisition of device identifiers, diagnostic intelligence, and performance telemetry. A substantial multitude of these programs also harvest search and purchasing histories, personal photographs or videos, email addresses, usernames, and precise location data. Eight specific Google applications, prominently featuring Chrome and Gemini, continuously monitor user web browsing histories.
The Amazon Ecosystem
Excluding the Meta ecosystem, Amazon Alexa secured the premier position by demanding 28 unique data types. On average, Amazon software asserts the necessity for 12 distinct categories. Eleven Amazon applications actively track precise geographical locations, whereas only Amazon Shopper explicitly admitted to monitoring web browsing histories. Device identifiers, email addresses, personal names, performance metrics, application interaction data, and crash reports feature prominently across their portfolio.
Restrained Approaches: Microsoft and Apple
Microsoft and Apple demonstrated the lowest average data consumption metrics. Microsoft predominantly focuses on crash reports, device and user identifiers, email addresses, personal names, diagnostic intelligence, performance metrics, and product interaction data. A mere six Microsoft programs demand precise geolocation, and only two monitor web browsing histories.
Apple averages a remarkably restrained seven data categories per application. Among the company’s 13 utility programs, the average metric rests at a mere six categories, standing in stark contrast to the 17 categories demanded by Google’s comparable utilities. Safari emerged as the singular examined Apple application that actively chronicles web browsing history. Six Apple programs mandate precise location tracking. Other frequently declared categories primarily encompass device identifiers, email addresses, and essential performance telemetry.
Interpreting the Declarations
Crucially, the Surfshark results do not definitively illustrate the actual volume of transmitted information. Moreover, they do not conclusively prove that developers harvest every declared category from every single user. This investigation fundamentally relies upon the self-reported declarations submitted by the developers directly to the App Store. According to Apple’s stringent developer guidelines, software creators must transparently disclose the specific data types collected by their application and any integrated third-party components. They must also perpetually maintain the accuracy of these vital disclosures.
Apple formally defines data collection as the transmission of information beyond the physical device, retaining it longer than strictly necessary to process a real-time request. Data that permanently resides exclusively upon the user’s localized device might not require inclusion within such a formal declaration.
Therefore, this comprehensive ranking primarily illuminates the vast breadth of declared application access to diverse forms of user intelligence, rather than quantifying the actual volume of data continually transmitted to remote servers. The systematic amalgamation of search and purchasing histories, geographical locations, device identifiers, and cross-service activities potentially empowers these corporations to construct immensely detailed and profoundly intrusive user profiles.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.