18 of 40 top apps log the sites you visit

09.09.2026 6 min 7

Nearly half of the most popular mobile apps collect browsing history, and they say so themselves on their own store pages. Surfshark read the privacy labels of 40 top Android and iOS apps and found 18 of them, 45%, declaring that they gather information about the websites you visit. This is not a leak or a hack. It is a line the developers filled in and published, and almost nobody reads it.

In short

  • Surfshark checked App Store and Google Play labels for 40 leading apps across four categories. 18 declare that they collect browsing history.
  • Social apps lead: 9 of 10. Facebook, Instagram, TikTok, X, YouTube and Pinterest declare it on both platforms.
  • Shopping apps: 5 of 10. Messaging: Viber, Messenger and LINE. Of ten generative AI apps, only Google Gemini.
  • The usual mechanism is the built-in browser: you tap a link and the app, not your browser, opens the page.

What was actually measured

The study, published on 1 September 2026, did not intercept any traffic. The researchers took 40 apps, ten each in generative AI, social media, e-commerce and messaging, mostly from Cloudflare's ranking of the world's most used internet services, and looked at one field in each store listing: whether the App Store label reports "Browsing History" and whether the Google Play label reports "Web browsing history".

Apple's own definition of that field is worth reading twice: "Information about content the user has viewed that is not part of the app, such as websites." It is not about what you do inside the app. It is about the web outside it. An app that ticks this box is telling Apple that it records pages that have nothing to do with its own service.

18 of 40apps declare browsing history collection
9 of 10social apps do it on at least one platform
1 of 10AI apps: only Google Gemini

Who ticked the box

Among social apps, Facebook, Instagram, TikTok, X, YouTube and Pinterest declare the collection on both platforms, while Reddit, LinkedIn and Snapchat declare it on Android only. Discord was the single social app that declares it on neither. In e-commerce, eBay, Shopee and Shopify declare it on both stores, Taobao on iOS only, AliExpress on Android only. Messaging is quieter, with Rakuten Viber, Messenger and LINE. Browsers were counted separately, outside the 40: Chrome, Safari and Edge collect browsing history, Firefox, Aloha and DuckDuckGo do not.

The split between platforms is the detail worth noticing. The same company, the same brand, two different answers depending on which store you open. A label describes a specific build and the paperwork behind it, not a law of nature, and it is a declaration rather than the result of an audit. That is the honest caveat on the whole study, and it cuts both ways: a careless label can overstate as easily as it can understate.

Why an app wants your web history

The reason is unglamorous. The more a service knows about where you go online, the better it targets ads and the more precisely it shapes your feed. Surfshark's lead system engineer Karolis Kaciulis, quoted by TechRadar, points at the delivery mechanism: apps increasingly route links through their own embedded browsers, so the moment you tap a link inside the feed, the host app can see what you search for and what you read. None of the social or shopping apps in the list need that history to work. It is collected because it is worth money.

What a VPN does not do here: a tunnel hides your traffic from the network and your provider and changes the address sites see. It does nothing about an app you installed yourself, granted permissions to, and are now browsing through. Encryption protects the channel, not the endpoint that you agreed to trust.

How to check your own phone in two minutes

  1. Open the app's page in the App Store and scroll to "App Privacy", or its Google Play page and open "Data safety". Look for Browsing History or Web browsing history in the collected data.
  2. Stop reading the web inside apps. Press and hold a link to get the option to open it in your own browser, or use "Open in browser" from the built-in browser's menu.
  3. Where an app has a switch for its internal browser, turn it off. Telegram has one on Android under Settings, Chat Settings, In-App Browser.
  4. Set a browser that does not report this collection as your default. Firefox and DuckDuckGo declare no browsing history collection, and Firefox on iOS now ships an ad blocker of its own.

The wider point is not about any single app. Data collection is now declared out loud, in a standard form, on a page anyone can open, and it still goes unnoticed because nobody scrolls that far. We saw the same pattern in hardware when LG televisions turned out to listen and scan the home network with the screen off. The label is not the problem. The habit of never reading it is.

Does this mean apps read my browser history?
No. They do not reach into Safari or Chrome. The label covers web pages you view through the app, above all in its built-in browser, plus whatever its trackers see on sites that embed them.
The study comes from a VPN company. Can it be trusted?
Its data is public. Every number here comes from App Store and Google Play labels, so you can open the same pages and check any app on the list yourself. That is the useful part: this is verifiable, not an insider claim.
Will a VPN stop it?
No. A VPN hides your traffic from the network you are on and swaps the IP address that sites see. The app on your phone is on the inside of the tunnel and still sees what you open in it.
How do I stop it without deleting the app?
Take your reading out of the app. Open links in your own browser, turn off the internal browser where the app allows it, and on iOS keep "Ask App Not to Track" on, which limits cross-app ad tracking but does not stop the app's own logging.

surfsharkprivacysocial mediaapplegooglefacebookinstagramtiktokyoutubegeminidata protection

Read also