What 40 popular apps say about your browsing history

A link opened from Instagram can feel like a quick detour from the app. You read the page, close it and carry on scrolling. It’s easy to forget that opening a website inside an app may also create data about what you visited.

Surfshark examined the privacy disclosures of 40 popular apps across social media, shopping, messaging and generative AI. Eighteen of them, or 45%, declared that they collect browsing history on iOS, Android or both. Surfshark checked what developers reported in the Apple App Store and Google Play Store; it did not observe those apps browsing through people’s phones. 

Social media accounted for the largest share. Nine of the ten apps Surfshark examined declared browsing history collection on at least one platform. Facebook, Instagram, TikTok, X, YouTube and Pinterest did so on both. Snapchat, LinkedIn and Reddit did so on Android, while Discord did not declare it on either platform. Among the shopping apps, eBay, Shopee and Shopify declared it on both stores; Taobao did so on iOS and AliExpress on Android. 

The differences between the stores need careful reading. A declaration on Android and no equivalent declaration on iOS tells us what each version’s developer reported under that store’s rules. It doesn’t, by itself, explain how the apps behave differently or prove that the version with no declaration gives its owner no useful information about your activity.

The same caution applies to the word browsing. Google defines “Web browsing history” as information about websites a user has visited. Its guidance also says that data collected through a web view opened by an app can fall within an app’s disclosure, depending on how that web view works. Surfshark’s table doesn’t identify the collection method for each app, and a listing that declares browsing history doesn’t establish that the app can read the history in your separate browser. Google says developers are responsible for the accuracy of their Data safety declarations.

The smaller categories are revealing too. Messenger, Rakuten Viber and LINE were the three messaging apps in the sample that declared browsing history collection. Among the ten AI apps, Gemini was the only one. That doesn’t make every other app in those groups private in a broader sense. The study asked one narrow question about one data category.

For users, the useful starting point is the App Privacy or Data safety section on an app’s store listing. Check whether browsing history is declared, then look at the stated purpose and whether collection is optional. If you regularly open sensitive links from a social or shopping app, opening them in your browser gives you a clearer sense of which app you’re using, though it won’t erase information already available to the service or website.

This also connects to a wider question I’ve raised about how much of our behaviour smartphone services need to know to offer convenience. Surfshark’s figures don’t tell us exactly where every visited URL goes. They do show how ordinary browsing has become part of the data that many popular apps say they collect.

Zeen Social Icons