Suspicious apps

7 Popular Apps Under Privacy Investigation Right Now — What the Lawsuits and Regulators Actually Found

TikTok, CapCut, Temu, Shein, AliExpress, Bigo Live and Likee have all faced real privacy probes, fines, or lawsuits. Here’s what’s documented — and what isn’t.

I spent a weekend going through court filings, FTC press releases, and regulatory decisions from South Korea, Switzerland, and Vietnam after a friend sent me one of those “delete these 7 apps immediately” videos. Some of the claims in those videos check out. Some are wildly overstated. A few are just made up.

So instead of repeating the scary version, I pulled the actual paperwork. Lawsuits, fines, technical audits, the works. Below is what regulators and researchers have actually found about seven apps that show up on almost everyone’s phone — TikTok, CapCut, Temu, Shein, Bigo Live, Likee, and AliExpress — plus what you can do about it without throwing your phone into a lake.

Why “where does the data go” actually matters

Here’s the part most videos skip past too fast to be useful. China’s National Intelligence Law, passed in 2017, requires Chinese organizations to support national intelligence work when asked. That’s a real law, and it’s part of why lawmakers in the US, EU, and several Asian countries keep circling back to apps owned by Chinese companies.

But “a company is incorporated in China” and “this specific app is sending your data to Chinese intelligence services” are two very different claims. The first is a legal fact. The second needs actual evidence — a lawsuit, an audit, a regulatory finding. That’s the bar I held every app on this list to.

7apps reviewed
5+countries with active regulatory action
$1.4M+in confirmed fines (AliExpress alone)
200M+CapCut users named in the BIPA lawsuit

TikTok: what’s documented vs. what’s just chatter

TikTok app icon on a smartphone home screen

TikTok is the app everyone already half-expects to see on a list like this, so I’ll keep this section tight and focus on what’s changed recently rather than rehashing 2023 headlines.

The big one: in August 2024, the FTC and the Department of Justice filed a lawsuit alleging TikTok and ByteDance knowingly let children under 13 use the platform without parental consent, in violation of the Children’s Online Privacy Protection Act. The complaint says ByteDance was aware of its 2019 consent order obligations and continued collecting data from underage users that was used for ad targeting, without notifying parents.

Then there’s the structural change. In a deal that closed in January 2026, TikTok’s US operations transitioned to a majority American-owned entity called TikTok USDS Joint Venture LLC, with ByteDance retaining a minority stake and Oracle and Silver Lake among the new American investors. That came with an overhaul of the app’s terms of service, and the new policy reportedly explicitly permits TikTok to process “sensitive personal information,” including health details or religious beliefs, if a user discloses them in a video.

Outside the US, enforcement keeps coming. Vietnam’s competition regulator fined TikTok roughly $33,500 in January 2026 for misleading users and violating data privacy and consumer protection rules, and the same statement noted TikTok lacked a mechanism for users to exercise privacy rights over data used for advertising.

What I’d actually do

If you use TikTok, the practical move isn’t necessarily deleting it — it’s going into Settings > Privacy and turning off personalized ads, location access, and “Suggest your account to others.” Five minutes, no drama.

What I liked

  • The US ownership restructuring is a genuine, verifiable change — not a rumor.
  • TikTok’s in-app privacy controls are actually fairly granular if you dig into them.

What concerns me

  • The COPPA lawsuit involves real allegations about children’s data, not hypotheticals.
  • “Sensitive personal information” being permitted under the new policy is worth reading carefully if you post about health or personal life.

Want a cleaner way to manage what you post and edit before it ever reaches TikTok? See the editing tools I actually use below.

Compare Editing Tool Alternatives

CapCut: the biometric data lawsuit nobody talks about enough

CapCut video editing app interface on a phone

This one surprised me more than TikTok, honestly, because CapCut feels like “just a video editor.” But it’s owned by ByteDance, and in July 2023 a group of users filed a nationwide class-action lawsuit in the Northern District of Illinois.

The lawsuit claims CapCut gathers significant amounts of private data, including facial scans, from its more than 200 million active users, and that users are not told about or asked to consent to this collection. One plaintiff says they began using CapCut as a seventh grader without ever setting up an account, viewing a privacy policy, or getting parental consent.

According to the attorneys who filed the case, CapCut allegedly harvests geolocation, addresses, messaging information, and biometric data such as facial measurements, and uses it for marketing and targeted advertising. The suit also accuses CapCut of collecting device-level identifiers like MAC addresses and SIM serial numbers.

Here’s the part that matters most for where this stands now: in March 2025, a federal judge partially granted ByteDance’s motion to dismiss, but allowed certain privacy and biometric data claims under California privacy law to proceed, noting that how much users actually understood about CapCut’s privacy terms remained unclear.

This isn’t a “the case was thrown out” situation, and it isn’t a “proven in court” situation either. It’s an active lawsuit where a judge has already said the core privacy claims are strong enough to keep going.

What surprised me

I didn’t expect a video editor to be the one facing a Biometric Information Privacy Act claim in Illinois — that law is usually associated with facial-recognition security systems, not filters and auto-captions.

Who should pay attention here

If you use CapCut’s AI face filters, auto-caption voice features, or beauty effects regularly — or if your kids do — this is the section worth re-reading. The lawsuit specifically calls out features that process facial geometry and voiceprints.

FeatureData type involvedStatus
AI face filtersFacial geometry / biometricNamed in active lawsuit
Voice-based captions/effectsVoiceprintNamed in active lawsuit
Standard cut/trim editingVideo file metadata onlyNot specifically flagged

Prefer an editor with a clearer privacy track record for everyday cuts and captions?

See Video Editor Alternatives

Temu: what the Swiss audit found (and what it didn’t)

Temu shopping app on a smartphone screen

Temu gets thrown around a lot in “spyware” conversations, so I went looking for the most rigorous independent technical analysis I could find. That turned out to be a report from Switzerland’s National Test Institute for Cybersecurity (NTC), released in December 2024.

The headline finding people quote is alarming-sounding, but the actual conclusion is more measured. The NTC report does not directly accuse Temu of malicious behavior, but it identifies two technical issues that could, if exploited, turn the app into a vector for attacks. Temu’s own response points out that the NTC’s 60-person-day analysis concluded there were no critical security risks or unauthorized surveillance found.

On permissions specifically, an earlier review found Temu requests 24 permissions, including Bluetooth and Wi-Fi network access, which it called a cause for concern even though Temu is less aggressive in its data requests than its sister app Pinduoduo.

It’s also worth noting that a separate technical review found Temu, AliExpress, and Shein all request location permissions, similar to how Amazon does — so location access alone isn’t unique to Chinese-owned shopping apps.

Where the heavier scrutiny is coming from is policy bodies, not just security labs. The US-China Economic and Security Review Commission has called for the FTC to investigate Temu for deceptive practices including privacy violations, false advertising, and forced labor links, while acknowledging this would require formal investigation, not assuming guilt outright.

What I liked

Temu responded publicly to the Swiss report instead of ignoring it, and pointed to the audit’s own conclusion that no critical surveillance was found. That’s more transparency than I expected.

What I didn’t like

24 requested permissions for a shopping app is genuinely a lot, and “could be exploited” findings — even when not malicious by design — are still worth fixing.

Pros

  • Independent 60-person-day audit found no critical security risks.
  • Company responded publicly with context rather than silence.

Cons

  • 24 permissions requested, several with unclear retail justification.
  • Two technical anomalies identified that researchers say could theoretically be exploited.
  • Subject of an ongoing US policy-level call for FTC investigation.

Shein: where the regulatory pressure is actually coming from

Shein fast fashion app browsing screen

Shein doesn’t have the same headline-grabbing lawsuit as CapCut, but it’s been the primary subject of a detailed US-China Economic and Security Review Commission issue brief covering data risks, sourcing, and trade practices across Chinese fast-fashion platforms.

That brief states plainly that Shein is the first-mover platform about which the most data is available, with Temu discussed as a rapidly expanding secondary case, and that both raise concerns about data risks, sourcing violations, and exploitation of trade loopholes.

South Korea has been the most active regulator here. Its Personal Information Protection Commission opened investigations into both AliExpress and Temu in late 2023 amid a surge of customer complaints, eventually developing into what looks like a broader crackdown on China-based e-commerce platforms operating in Korea. Shein has faced similar scrutiny from the same regulatory wave, alongside antitrust concerns over pricing and labeling across all three platforms.

The honest take

I couldn’t find a Shein-specific lawsuit or fine on the scale of AliExpress’s $1.4 million penalty (more on that below). What I found instead is a pattern: Shein keeps coming up as “platform one” in broader Chinese e-commerce scrutiny, which tells you regulators consider it a bellwether — not that it’s been individually convicted of anything specific yet.

AppDocumented permission concernsFormal fine/lawsuit?
SheinNamed in USCESRC data-risk briefNo individual fine confirmed (as of writing)
Temu24 permissions, NTC technical flagsKorean PIPC fine of ~$970,000 (2025)
AliExpressData shared with 180,000+ overseas sellersKorean PIPC fine of ~$1.4M (2024)

If you shop on fast-fashion apps and want to know which AI tools can help you spot deals or compare prices safely first — check this out.

Read: Are Cracked AI Tools Safe?

Bigo Live: the live-streaming privacy trade-off

Bigo Live streaming app on a smartphone

Live-streaming apps are a different beast from shopping or editing apps, because the core function requires real-time camera and microphone access by design. That’s not a hidden behavior — it’s the product.

Common Sense Media, which evaluates apps against published privacy policies, gave Bigo Live a “Warning” rating, noting issues around creating user profiles not tied to any educational purpose, sharing personal information for third-party marketing, and displaying personalized advertisements based on data profiles.

A separate independent review put it more bluntly: a 48 out of 100 privacy rating reflects serious concerns about unencrypted data transmission and third-party marketing sharing, alongside the observation that Bigo collects substantial personally identifiable information including location data and shares it with third parties for marketing.

On the regulatory side, the clearest signal is the wave of youth social media restrictions sweeping multiple countries in 2026. Under new rules announced in several countries, platforms including YouTube, TikTok, Facebook, Instagram, Threads, X, Bigo Live, and Roblox would not be allowed to have under-16 accounts, as part of a broader push by regulators to address platforms that could expose minors to addictive design, scams, and harmful content.

What I’d tell a friend

Bigo Live isn’t uniquely “spyware” compared to other live platforms — but its privacy rating is genuinely below average, and the same review that flagged this also pointed out that Bigo’s privacy controls for hiding location and disabling the “Nearby” feature are actually stronger than some competitors, even if the overall data-sharing picture is weaker.

Pros

  • Comprehensive privacy controls: location hiding, private rooms, screenshot prevention.
  • Fast moderation response time reported by independent reviewers.

Cons

  • “Warning” privacy rating from Common Sense Media.
  • Reported unencrypted data transmission in places.
  • Caught up in new under-16 social media restrictions in multiple countries.

Likee: why parents specifically should look at this one

Likee short video app interface

Likee comes from the same parent company as Bigo Live (Joyy Inc.), and functions as a short-video platform with a younger user base than most of the other apps on this list.

I’ll be straightforward here: I could not find an independent technical audit or regulatory fine specific to Likee on the scale of what exists for AliExpress, Temu, or CapCut. What I did find is that Likee falls into the same general pattern flagged for short-video apps with large teenage user bases — the kind of platform increasingly named in the youth social media restrictions discussed above for Bigo Live.

Given that the same parent company operates both apps, and that Bigo Live’s privacy practices have been independently rated, the privacy concerns documented for Bigo Live (third-party marketing sharing, personalized ad profiles, “Warning” rating from Common Sense Media) are a reasonable proxy for what to check on Likee too — rather than assuming something separately documented for Likee itself.

Who should pay closer attention

Parents of teenagers using Likee. Not because of a proven Likee-specific scandal, but because the broader regulatory direction — restricting under-16 access to short-video and live platforms — applies to exactly this category of app, and the parent company’s other product has documented privacy weaknesses.

Looking for safer creative tools your teens can use for video editing instead?

Browse Family-Friendly Editing Alternatives

AliExpress: the $1.4 million fine that’s actually confirmed

AliExpress shopping app on a smartphone screen

Out of every app on this list, AliExpress has the clearest paper trail. In July 2024, South Korea’s Personal Information Protection Commission fined AliExpress about $1.4 million for transferring the personal information of roughly 180,000 customers to overseas sellers in China and other countries without proper notice or consent.

The investigation found specific, concrete violations: AliExpress failed to notify users about which country their personal information was being transferred to, didn’t disclose the names and contact details of the overseas recipients, and made the account-deletion process difficult to find. On top of that, AliExpress displayed its account-deletion page only in English, which made it harder for Korean users to exercise their right to unsubscribe.

This wasn’t a one-off. In 2025, South Korea’s antitrust regulator separately fined AliExpress around $1.5 million for misleading consumers with false discount rates, and around the same time fined Temu roughly $970,000 for violating the Personal Information Protection Act by secretly transferring user data to China and Singapore.

AliExpress’s response was cooperative rather than combative — the company stated it would continue incorporating the PIPC’s feedback to improve its service for customers, and had already taken some corrective measures, including establishing legal grounds to obtain user consent for overseas data transfers, by the time the fine was announced.

Final verdict on AliExpress

This is the one app on the list where “documented privacy violation with a dollar figure attached” is unambiguously true. It’s also the one where the company’s follow-up response — corrective orders, partial compliance before the fine, public acknowledgment — looks more like normal regulatory back-and-forth than a cover-up.

What’s confirmed

  • $1.4M PIPC fine for unauthorized data transfers to 180,000+ overseas sellers (2024)
  • $1.5M FTC (Korea) fine for misleading discount claims (2025)
  • First-ever PIPA enforcement action involving international data transfers

Want tools that help you compare prices across shopping platforms before you buy?

10 Useful Websites Worth Bookmarking

Side-by-side: documented issues at a glance

AppParent companyStrongest documented issueCurrent status
TikTokByteDance / TikTok USDS JVFTC/DOJ lawsuit over children’s data (COPPA)Active litigation; US ownership restructured Jan 2026
CapCutByteDanceClass-action over biometric data collection (BIPA)Partially dismissed, key claims proceeding (2025)
TemuPDD Holdings24 device permissions; two technical anomalies (NTC)Audit found no critical risk; Korean fine $970K
SheinShein GroupNamed in USCESRC data-risk briefNo individual fine confirmed yet
Bigo LiveJoyy Inc.“Warning” privacy rating, unencrypted transmissionCaught in new under-16 access restrictions (2026)
LikeeJoyy Inc.No app-specific audit found; same parent as BigoFalls under youth-platform restriction discussions
AliExpressAlibaba$1.4M Korean fine for unauthorized data transfersCorrective measures partially implemented

Visualizing the documented penalties

AliExpress — PIPC fine$1.4M
AliExpress — FTC (Korea) fine$1.5M
Temu — PIPC fine$970K
TikTok — Vietnam fine$33.5K

Chart shows confirmed monetary penalties only. CapCut and Shein have active legal/regulatory scrutiny but no confirmed monetary fines specific to these apps as of this writing.

10 things worth doing this week (regardless of which apps you use)

None of this requires deleting anything if you don’t want to. These are the changes that actually move the needle, based on what the documented cases above were about — permissions, consent, and data transfers.

  1. Open your phone’s permission manager (Settings > Privacy > Permission Manager on Android) and check which apps have location, microphone, and camera access you didn’t expect.
  2. Turn off “precise location” for any app that doesn’t need it for its core function — shopping and editing apps rarely do.
  3. Review your Google account’s third-party app access at myaccount.google.com and revoke anything you no longer use.
  4. Reset your advertising ID periodically (Settings > Google > Ads) to limit cross-app tracking profiles.
  5. Enable auto-delete on Google activity data, setting retention to 3 or 18 months instead of indefinite.
  6. Check account-deletion options before you sign up for anything — the AliExpress case specifically involved a hard-to-find unsubscribe page.
  7. Read the actual permission prompt the first time an app asks for camera, mic, or contacts access — don’t tap “allow” reflexively.
  8. Use unique passwords for shopping and social apps so a breach on one doesn’t cascade to your email or banking.
  9. If you have kids using short-video or live-streaming apps, check the app’s age rating against what regulators in your country currently require — this changed significantly in 2026.
  10. Bookmark a couple of vetted alternative tools for editing, shopping comparisons, and content creation so switching isn’t a scramble if you do decide to make a change.

Need a no-fuss way to check whether a tool or app is actually legit before installing it?

Read Our Legitimacy Check Guide

Frequently asked questions

Is TikTok still owned by a Chinese company in 2026?

As of January 2026, TikTok’s US operations moved to TikTok USDS Joint Venture LLC, a majority American-owned entity with Oracle and Silver Lake as new investors, while ByteDance retained a minority stake. The app’s terms of service and privacy policy were overhauled as part of this transition.

Has CapCut actually been found guilty of collecting biometric data illegally?

Not yet — the case is still active. A federal judge in 2025 dismissed some claims but allowed key privacy and biometric data allegations under California privacy law to proceed, finding it unclear how much users actually understood about CapCut’s data practices.

Does Temu really request 24 permissions on Android?

According to an independent review cited by cybersecurity researchers, yes — including Bluetooth and Wi-Fi network information, which was flagged as a cause for concern even though a separate audit found no critical security risks.

Has AliExpress been fined for privacy violations?

Yes. South Korea’s Personal Information Protection Commission fined AliExpress roughly $1.4 million in 2024 for transferring customer data to over 180,000 overseas sellers without proper notice, marking the first PIPA enforcement action involving international data transfers.

Are Bigo Live and Likee safe for teenagers?

Bigo Live has received a “Warning” privacy rating from Common Sense Media, and both apps are part of a wave of new under-16 social media restrictions being introduced in multiple countries in 2026. Likee doesn’t have an independently documented audit of its own, but shares a parent company with Bigo Live.

Should I delete all seven of these apps?

That’s a personal call, not a universal rule. What’s documented varies a lot by app — AliExpress has a confirmed fine, CapCut has an active lawsuit, while Shein and Likee have less app-specific documentation. Adjusting permissions and reviewing what each app can access is a reasonable middle ground for most people.

Discover Tools Before Everyone Else!

We don’t spam! Read our privacy policy for more info.

Advertisement