Social media

What Meta says about your data — and what the record shows.

The shape repeats: a reassuring message about your privacy, a practice that quietly runs the other way, and — often — a regulator or a court that later spells out the gap. This page walks the documented cases, holds to what has actually been established, and points you to what you can do about it. (Facebook, Instagram, WhatsApp, and Threads all belong to the same company, Meta.)

The pattern

The assurance, then the asterisk

Every case below has the same structure. Read it as a habit, not a headline.

A company this size makes countless privacy promises, and most are kept. What follows is the subset that wasn’t — where the public message pointed one way and the underlying practice pointed another, and where the difference was large enough that a court, a regulator, or the company’s own later reversal put it on the record. Those are the only cases we’ll cite. We describe the documented representation, the documented practice, and the documented consequence — the mechanism, not anyone’s motive.

The tell is the pattern, not any single case. A reassuring default; a policy that loosens once a deal has cleared; a “security” feature that doubles as an ad signal. The same shape recurs often enough to be worth learning to recognize.

The receipts

Five times the practice outran the promise

Each entry pairs what people were told with what was later established, and links a primary source so you can check it yourself.

2018 · Cambridge Analytica · friends’ data

Data left through a door the platform held open

A personality-quiz app installed by roughly 270,000 people collected not just their profiles but their friends’ — up to 87 million people who never touched the app — and the data reached a political-profiling firm. The company’s own rules forbade that sharing, yet its design permitted it, and it later acknowledged that a search feature could have exposed the public profile of nearly every user. NBC News · FTC

2019 · FTC complaint · two-factor authentication

A number given for security, spent on advertising

Between 2015 and 2018 the company urged users to add a phone number to switch on two-factor authentication — a security step — without disclosing that the same number would also feed ad targeting. The Federal Trade Commission called it deceptive, and its record $5 billion order in 2019 barred using security phone numbers for advertising. FTC press release · World Privacy Forum

2019 · FTC complaint · facial recognition

Face-matching presented as opt-in, switched on by default

The company suggested its photo face-matching was something users chose to enable. The FTC found the setting was turned on by default for many people and that the company had misrepresented how much control users actually had over it. The 2019 order required plain notice and affirmative consent before any use beyond what had been disclosed. FTC · analysis

2014–2017 · WhatsApp · €110M EU fine

“We can’t link your accounts” — until the accounts were linked

When Meta bought WhatsApp in 2014, users were told the two services’ data would stay separate, and EU regulators were told that automatically matching the accounts was not technically possible. In 2016 WhatsApp began sharing phone numbers with Facebook for ads and friend suggestions. In 2017 the European Commission fined the company €110 million, finding the matching had in fact been possible in 2014 and that staff had known. European Commission · case summary

2018–2019 · Onavo · Apple ban

A “VPN” that watched everything — then a paid version aimed at teens

Onavo Protect was offered as a data-saving VPN; it was used to monitor what people did inside other apps, and Apple removed it in 2018 for collecting far more than the app needed. The code was repackaged into a “Facebook Research” app that paid users aged 13 to 35 up to $20 a month for near-total device access — web traffic, other apps, even decrypted data, run through intermediaries that hid the company’s name. Apple banned it in 2019. TechCrunch investigation · follow-up

One you can set aside

No, it isn’t the microphone

The most common suspicion is the one with the least behind it.

When an ad feels like it read your mind, the instinct is to blame the phone’s microphone. But the mechanisms above already explain the uncanny targeting without any audio at all: linked identities, tracking that follows you between apps and sites, and a detailed profile stitched from both do the work on their own. The eavesdropping theory has never been demonstrated in public; the data flows have — repeatedly, in court filings and regulators’ orders. Chasing a microphone you can’t verify only distracts from the tracking you can. The real machinery is duller, better documented, and far more fixable.

What you can do

You can close most of the doors. Leaving is the hard part.

The same company that buries the settings makes the exit harder still.

Two moves help. First, tighten what you can: off-platform activity, ad-targeting categories, face-matching, and linked-account settings are all adjustable, even when they’re buried several menus deep — our Tools and Guides pages walk through the ones that actually matter. Second, go in knowing that deleting an account is obstructed on purpose: the “download your data, then delete” path is wrapped in delays, deactivation detours, and design nudges meant to make you give up. Community directories like JustDeleteMe exist precisely because the difficulty is the point — they rate how hard each service is to leave and link straight to the real deletion page.

Get involved

It’s free, open to everyone at Pitt, and joining takes about a minute.

No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.