Think of this like a product recall list, but for data. Every entry below is based on a regulator's official findings (like the FTC), a court record, or established investigative reporting — never speculation. Each one links to a primary source so you can read the details yourself.
This page exists because we build things the other way: no ad trackers, no data brokers, no selling what you type into your planner. If you'd like to know how our own apps handle your data, see our post on app tracking or the privacy policy.
The FTC alleged that online therapy platform BetterHelp shared users' email addresses, IP addresses, and answers to health intake questionnaires with Facebook, Snapchat, Pinterest, and Criteo for advertising — despite repeatedly telling users their health information would stay private.
People sharing details about depression, anxiety, or relationship struggles believed that stayed between them and a therapist. Instead, some of it reportedly helped power ad targeting on platforms with no role in their care.
BetterHelp paid $7.8 million, returned to affected users as refunds, and is now barred from sharing health data for advertising.
The FTC alleged fertility-tracking app Premom shared users' sensitive reproductive health data — including pregnancy status and fertility predictions — with third-party analytics and marketing firms, including two based in China, without adequate disclosure or consent.
People logging deeply personal reproductive health information trusted it would stay inside a fertility app, not get routed to outside marketing firms — especially sensitive given the legal stakes around reproductive data.
Premom's developer, Easy Healthcare, paid a $200,000 settlement and is now banned from sharing health data for advertising without consent.
In its first-ever enforcement action under the Health Breach Notification Rule, the FTC found that prescription discount platform GoodRx shared users' medication names, health conditions, and personal identifiers with Facebook, Google, and other advertisers for years — despite promising in its own privacy policy that it never would.
People searching for the cheapest price on medication for conditions like depression or high blood pressure didn't expect that search to become part of an advertising profile.
GoodRx paid a $1.5 million penalty and is permanently barred from sharing health data with third parties for advertising.
The FTC and DOJ alleged that WW International and its Kurbo weight-loss app for kids illegally collected personal information — including name, age, weight, and dieting habits — from children as young as 8, without verifiable parental consent, in violation of federal children's privacy law (COPPA).
This wasn't adults choosing to share sensitive health data. It was an app marketed directly to children collecting weight and body information from users as young as elementary school.
The companies paid a $1.5 million penalty and, in a first for the FTC, were ordered to delete not just the illegally collected data but any algorithms built using it.
Norway's data protection authority found that dating app Grindr shared user data — including GPS location, advertising ID, and the fact that someone was a Grindr user, which by itself can reveal sexual orientation — with multiple ad-tech companies without a valid legal basis for consent.
Being identifiable as a Grindr user can out someone's sexual orientation, which carries real safety risk in many parts of the world. A widely reported 2018 case involved a Catholic priest whose location data, harvested through Grindr, was used to out him publicly and led to his resignation.
Norway fined Grindr roughly $6.5 million; a Norwegian court upheld a reduced fine of about $5.7 million on appeal in 2023.
An investigation by The Markup found that Life360 — a family location-sharing and safety app used by tens of millions of parents to track their kids — was selling users' precise, identifiable location data to roughly a dozen data brokers, some of which reportedly resold it onward.
Parents downloaded a "safety" app specifically to know where their kids were, not realizing that same location trail was being sold into a data marketplace they had no visibility into.
Following the reporting and subsequent scrutiny from U.S. senators, Life360 said it would wind down sales to certain data brokers, though it continued other forms of data monetization; the company faced further litigation over its data practices in 2023.
The FTC alleged that Flo Health, maker of one of the most popular period and ovulation-tracking apps, promised users their health data would stay private, then shared data — including pregnancy status and period dates — with Facebook, Google, and other outside analytics firms.
Millions of users tracked intimate reproductive health details trusting a specific privacy promise; instead, some of that data reportedly reached major ad platforms.
Flo Health settled with the FTC, agreeing to get user consent before sharing health data and to an independent review of its privacy practices; it separately settled private class-action lawsuits over the same conduct.
A Motherboard/Vice investigation found that Muslim Pro, a prayer-times and Quran app used by tens of millions of people, was part of a location-data supply chain: it sent location data to a data broker, which in turn sold access to that data to U.S. military and government contractors.
People using a religious-practice app had no reason to think their location trail could end up in a government data marketplace — a particular concern for a community already subject to disproportionate surveillance.
Following the reporting, Muslim Pro said it would end its relationship with the data broker; the story contributed to broader scrutiny of the location-data-broker industry.
The Los Angeles City Attorney sued the operator of The Weather Channel app (then owned by IBM), alleging it told users their location data would be used to personalize weather alerts while also collecting and selling that data to third parties, including hedge funds, for unrelated purposes.
Users granted "always on" location access believing it served a specific, weather-related purpose — not realizing that same continuous location trail was reportedly being monetized elsewhere.
The company settled with the city in 2020, agreeing to more clearly disclose how location data is used and shared, without admitting wrongdoing.
The FTC and New Jersey's Attorney General found that Vizio installed software on 11 million smart TVs that captured second-by-second details of what was on screen, matched that viewing data to specific consumers, and sold it to advertisers and other third parties — without ever clearly telling owners it was happening.
People who bought a television, not a data-collection device, had no reasonable way to know their nightly viewing habits were being tracked and sold — a pattern that later became common across the smart-TV industry.
Vizio paid $2.2 million and was required to prominently disclose its data collection and get consent going forward.