Beware, Facebook and Instagram are the worst social media for your privacy

Popular social media apps on an Apple iPhone: Facebook, Instagram, YouTube, Pinterest, X (formerly Twitter), LinkedIn, Reddit, TikTok, and Threads.
(Image credit: Kenneth Cheung/via Getty Images)

Update: On October 4, 2024, we made some edits as LinkedIn reached out following some corrections made to the report by Incogni. As per the new ranking, LinkedIn isn't one of the worst social media for privacy, but ranks as the 9th less privacy-invasive platform out of the 15 tested social media services.

Despite using social media platforms every day, we all know that they may be bad for our digital privacy – even if you're using security software like the best VPN apps. But how bad are they, exactly? This is what the team at Incogni, a data removal service provider, set out to discover.

After looking into the top 15 most popular social networks, researchers uncovered stark differences in how these platforms handle our personal data. Unsurprisingly, perhaps, Facebook and Instagram came out as the worst when it comes to protecting our privacy. Reddit, Snapchat, and Pinterest (in order) are the platforms representing the lowest risk.

Keep reading as I go through some of the biggest takeaways and some tips to boost your social media privacy.

Social media services have different views on privacy

Researchers assessed the privacy risks for each platform according to five categories. As expected, the data collection and retention category significantly shaped the final privacy ranking (see the graph below), with Meta's Facebook, Messenger, and Instagram getting the worst results.

Another variable researchers looked at was the level of user control and consent. These include privacy settings, default privacy settings, and opt-out or visibility options. Again, some Meta platforms (Messenger and WhatsApp) performed the worst alongside TikTok.

Experts at Incogni were especially surprised not only by how many data points each of these platforms collects and shares with third parties, but also by the number of data points you can't opt out for. 

The transgressions category refers to fines and data breach incidents. Here, Telegram, Reddit, Quora, and Discord obtained a very positive score: 0. Not so good for X (formerly known as Twitter) which saw over a quarter of its total score come from this category, alongside Facebook and LinkedIn. The latter was the platform that suffered the greatest number of data breaches and mass data scrapes – according to Incogni's data.

In terms of transparency – meaning how much user data reaches governments and the accessibility of certain features – Quora and Telegram had the worst ratings, while LinkedIn, Discord, Snapchat, and YouTube performed the best.

Lastly, user-friendliness looked at how easy is to understand the platform's privacy policy and how many steps you need to take to delete your account. Needless to say, Facebook products performed badly here, too, alongside Google-owned YouTube.

You need a degree to understand social media policies

"Everything seems designed to make it hard for people to fully understand what’s happening with their personal information," Emilia Jasinska-Dias, Incogni spokesperson, told me. 

Researchers found, in fact, that to understand the privacy policy of the platforms analyzed, a user would need to be at a college literacy level. Jasinska-Dias believes this may be intentional. She said: "It seems that they’re constructed so that people won’t read them."

According to experts, a consistent, standards-based format that is easy to navigate is needed to ensure that anyone can make informed decisions about which social media platform they want to use – and which data they're comfortable giving away.

It takes up to 6 clicks to delete your account

If you've ever embarked on a mission to close an old Facebook account, then you probably know this already – deleting a social media profile is anything but easy.

Researchers found that the steps required to delete a social media account can vary from a minimum of two clicks (TikTok, Telegram, and Discord) to a maximum of six. The latter category includes all of Meta's products besides WhatsApp, which requires three, as well as YouTube.

Yet, as the report points out, "account deletion ought to be a relatively easy process."

Your data stay up to 180 days after leaving a platform

"The most shocking discovery was how long data is sometimes held after a user decides to delete their account," said again Jasinska-Dias. "In some cases, it might be as long as 6 months."

Among the platforms holding onto your personal information for about 180 days, after clearly expressing the intention to depart from a specific service, are Facebook, Instagram, Messenger, YouTube, and Discord. On the contrary, Telegram retains your data for just a few days after deletion.

This is especially worrisome considering that some of the most invasive platforms (Facebook and X) suffered at least two data breach incidents in the past.

Data protection laws aren't enough

While most social media platforms have constructed their business model around harvesting your personal data since the beginning, in recent years many countries have implemented new privacy laws aimed at minimizing data collection and retention. So, are these measures helping at all? Well, according to Incogni, not much.

Did you know?

In this photo illustration, the big tech companies Google, Apple, Meta, Amazon, Microsoft logos seen displayed on a mobile phone screen.

(Image credit: Photo Illustration by Idrees Abbas/SOPA Images/LightRocket via Getty Images)

Experts at Proton, the provider behind ProtonVPN and ProtonMail, found that only after a week into 2024 the likes of Meta, Google, Apple, and Microsoft earned enough to pay off all the fines they got in 2023.

Facebook, for instance, was hit the most by legal fines for breaching the privacy of its users – three from EU bodies and five from other jurisdictions. WhatsApp, another Meta-owned product, was fined five times, while TikTok and X received four fines each. Despite this, the research clearly shows how these platforms remain among the worst for privacy protection.

"Examining the number and amounts of fines imposed on each platform, it’s apparent that they aren’t enough to make platforms change their approach toward how user personal information is handled," Jasinska-Dias told me, adding that, at the moment, there are no regulations that would sufficiently secure users' interest.

She believes the only way for policymakers to limit the extent of personal data collection is to ensure that violating the law isn’t more profitable than complying with it.

How to boost your privacy on social media

As Incogni's research shows, the most popular social media platforms are also the most invasive services around. While privacy-respecting alternatives do exist – think Mastodon, Nostr, and Matrix, for instance – you might not be willing to give up your social media presence on other platforms just yet. It's then crucial to learn how to minimize the data you share.

As a rule of thumb, Jasinska-Dias suggests opting for services that allow registration without using your real details whenever possible. If you cannot do that, you might want to think about creating a dedicated email account instead of giving away your main address. I would refrain from signing up with your phone number if you can, too.

"It’s worth noting that platforms belonging to Google and Meta make managing your privacy more complicated," said Jasinska-Dias. It's vital to keep in mind that these services are integrated into a bigger group and they share your data between them.

I strongly suggest reviewing your privacy settings to make sure you're sharing only strictly necessary information with the social media company. 

You should also become more confident with the provider's usage and privacy policies while staying up-to-date with any changes that occur. For example, last week LinkedIn silently began training its AI data with user data. If you haven't done so already, here are some instructions on how you can opt out.

Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Which apps were most hungry for your data in 2024?
Young woman holds a smartphone with a beam of light obscuring her eyes
Privacy powerhouses: 5 apps to take your online security to the next level
Cartoon illustration of multiple smartphones
Are you oversharing? These are the 10 pieces of information you don't want to give away – ranked
Biometric identification of a woman face on a pink background
I spent 7 days on a data detox – here's what I learned
Illustration of a thief escaping with a white fingerprint
5 massive privacy scandals that rocked the world – and made millions of victims
Abstract winter forest design with glowing pine trees on dark starry background
Season's cyber-cleanings: how to tidy up your digital footprint
Latest in Cyber Security
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
An AI face in profile against a digital background.
Worried about DeepSeek? Well, Google Gemini collects even more of your personal data
Apple
"We will never build a backdoor" – Apple kills its iCloud's end-to-end encryption feature in the UK
DeepSeek
DeepSeek accused of sharing users' data with TikTok's ByteDance in another blow around privacy concerns
Latest in News
NordicTrack Ultra 1
The new NordicTrack Ultra 1 treadmill looks like it was designed by an architect and costs $15,000
An Nvidia GeForce RTX 5070
Nvidia RTX 5080 stock is so barren that retailers are holding competitions where you can "win" the right to buy one for MSRP
Assassin's Creed Shadows
Ubisoft shareholder accuses publisher of 'misleading investors', plans protest outside Paris HQ
Google Gemini AI logo on a smartphone with Google background
I made an AI version of Bilbo Baggins using Goggle Gemini for free, and shared a pipe with him outside Bag End – here’s what you can now do with Gems
Nicole Kidman wears a blue blouse with her arms crossed.
Netflix might be renewing The Perfect Couple and Beauty in Black for season 2, but I don’t get why when it’s canceled shows with poorer ratings
The Russo brothers posing for a photograph and Herman carrying a Volkswagen camper van in The Electric State
'We're optimists': AI enthusiasts Joe and Anthony Russo defend its use in movies and TV shows, but admit there are 'very real dangers' around its application