Practical guide · verified against the real thing
What 'free' apps are actually doing with your data
In one line: The price of a free app isn't zero — it's you. Here's the trade, in the industry's own disclosure language, and the controls most people never open.
Free apps are free the way broadcast TV is free: the product is audience attention, and increasingly, audience information. The industry discloses what it does — in privacy policies and the standardized data-safety labels app stores now require — and the disclosure, read plainly, describes four businesses running under the icon you tapped. Here's what's actually going on, and the controls that exist.
The four businesses inside a free app
Advertising: the visible one — ads shown in-app, targeting built from whatever the app's SDKs can see: your device identifiers, approximate location, the other apps installed, sometimes the screen you're on. Data brokerage: many apps pass information to third-party data companies who assemble it across thousands of apps into profiles — the privacy-policy phrase is "sharing with partners", and the partners are the tell. Analytics: usage measurement, legitimately useful to developers and rarely limited to the minimum. And the model-training era: the newest line in modern privacy policies — user content and interactions "used to improve our services", which increasingly means training machine-learning systems on your photos, documents or prompts. Each of these can be legitimate; the pattern to notice is that they're all incentives to collect more than the app needs to function.
How to read the labels honestly
Both major app stores now carry standardized data labels, and the reading order matters. On Apple's "App Privacy" labels: "Data Linked to You" is the identity-attached collection; "Data Not Linked to You" is aggregate-but-still-collected; "Data Used to Track You" is the one that feeds cross-app advertising. On Google's "Data safety" section: the reveals are in the questions it answers — does the app share data with third parties, can you request deletion, is data encrypted in transit. The label that matters most is the absence: an app collecting contacts, location and photos while offering nothing but a torch function has told you its business model in one screen.
The controls that actually exist
Platform settings have quietly become powerful: permission review (Android and iOS both let you grant location "only while using", strip background access, and see which apps touched sensitive permissions — the Android walkthrough is on this desk); tracking controls — iOS's App Tracking Transparency (the "ask not to track" switch), Android's ad-ID reset and deletion tools; account-level dashboards — Google and Facebook both offer activity controls and ad-personalisation switches that turn down, though not off, the profiling; and the nuclear-but-effective option — paid alternatives, which convert you from product to customer for a few pounds a month.
The working rule
Match the data to the function: a maps app needs location; a game does not. Prefer apps whose business you can see (paid, subscription with a visible service) for the categories that touch your life most — photos, messages, documents, health. And treat "free" as a pricing question with a hidden currency: not "what does this cost", but "what does this cost per photo, per contact, per location ping, for as long as I use it?" Once the trade is visible, most people start choosing deliberately — which is the entire point of the disclosure.
Sources: app-store data-label documentation (Apple App Privacy labels; Google Play Data safety); platform privacy-control documentation. Reviewed September 2026 — label formats evolve; the reading order survives.
Sources
Next