Most people worry about obvious phone threats: malware, phishing links, stolen passwords, and suspicious downloads.
But privacy risks do not always come from obviously malicious apps.
Some of the most controversial apps on smartphones are perfectly legitimate services used by hundreds of millions of people. The concern is often how much information those apps collect, what permissions they receive, how that information is used, and what happens when a company suffers a security or privacy failure.
A recent Morning Overview report highlighted eight familiar apps that repeatedly appear in privacy discussions: TikTok, Temu, Facebook, Instagram, CapCut, SHEIN, Snapchat, and WhatsApp.
That does not mean all eight are malware or that everyone needs to immediately delete them. The reasons for concern differ considerably from one app to another.
1. TikTok
TikTok has probably faced more government scrutiny than any other mainstream social-media application in recent years.
A major concern involves data collection and its ownership by Chinese technology company ByteDance.
TikTok can collect information including device identifiers, approximate location, usage activity, and other data associated with how people interact with the platform. Its privacy practices and ByteDance’s Chinese ownership have contributed to restrictions on government devices in several countries.
But there is an important distinction.
Government restrictions on official devices do not automatically establish that TikTok is dangerous for every ordinary consumer.
For individuals, the decision is primarily about how comfortable they are with the amount of behavioral information being collected.
If you do not want to remove TikTok completely, review its permissions.
Does it actually need precise location?
Does it need access to your entire photo library?
Are microphone and camera permissions enabled permanently when they could instead be granted only when necessary?
Reducing unnecessary permissions can provide a middle ground between ignoring privacy concerns and deleting the app.
2. Temu
Temu has become enormously popular by offering products at extremely low prices.
The privacy conversation is more complicated.
The Temu application collects device, network, shopping, and behavioral information. Critics have questioned whether installing a permanent shopping application is worth the amount of information such an app can potentially accumulate over time.
Another reason Temu attracts attention is its corporate connection to PDD Holdings.
Google suspended Pinduoduo—a separate PDD Holdings shopping application—from Google Play in 2023 after malware was identified in versions distributed outside Google’s official store.
But that distinction is essential:
Pinduoduo and Temu are different apps.
Evidence concerning Pinduoduo should not be presented as proof that the Temu application itself contains malware.
If you only occasionally buy something from Temu, using its website instead of keeping the application permanently installed is one way to reduce continuous app-level access.
3. Facebook
Facebook’s privacy controversies stretch back years.
One of the biggest came after the Cambridge Analytica scandal.
In 2019, the U.S. Federal Trade Commission imposed a record $5 billion penalty on Facebook over privacy violations and required substantial changes to the company’s privacy oversight.
Facebook also participates in a much broader advertising ecosystem.
Meta can receive information about activity outside Facebook through technologies integrated into websites and applications.
That is one reason privacy-conscious users sometimes remove the Facebook app while keeping their account.
Facebook remains accessible through a mobile browser.
You lose some convenience, but the website may be sufficient if you only occasionally check messages, groups, Marketplace listings, or updates.
Deleting the application and deleting your Facebook account are two completely different actions.
4. Instagram
Instagram presents many of the same privacy questions because it is also owned by Meta.
The platform additionally has a significant regulatory history involving younger users.
Ireland’s Data Protection Commission fined Meta €405 million in 2022 over Instagram’s handling of children’s data, including issues involving teenagers’ contact information and account visibility.
Instagram can also request access to sensitive phone capabilities such as your camera, microphone, photos, contacts, and location depending on how you use it and which permissions you approve.
Some of those permissions make perfect sense.
An application centered around photographs obviously needs camera or photo access if you want to upload pictures.
The better question is whether it needs that access all the time.
Modern Android and iOS versions offer more granular controls.
You can often allow access only while using an app, provide approximate rather than precise location, or grant access only to selected photos.
Those options are worth using.
5. CapCut
CapCut is one of the most popular mobile video-editing applications.
It is also owned by ByteDance, TikTok’s parent company.
That corporate relationship means many of the jurisdiction and data-governance questions surrounding TikTok naturally extend into discussions about CapCut.
CapCut also needs access to something particularly personal:
Your videos and photographs.
That may include footage you never intend to publish.
Family videos.
Work material.
Unedited recordings.
Personal photographs.
Documents accidentally captured in the background.
This does not mean CapCut secretly steals every video on a phone.
The practical lesson is simpler.
Be selective about which media you allow cloud-connected editing applications to access.
On supported phones, granting access only to specific photos and videos can be preferable to giving an application unrestricted access to the entire library.
6. SHEIN
SHEIN’s inclusion has more to do with its privacy and security history.
In 2022, the New York Attorney General announced a $1.9 million penalty against Zoetop, SHEIN’s former owner, concerning its handling of a 2018 data breach.
That breach affected roughly 39 million SHEIN accounts, according to the enforcement action discussed by Morning Overview.
The historical breach does not prove that today’s SHEIN app is currently compromised.
Companies change systems.
Security practices evolve.
Corporate structures change.
Still, previous breaches are reasonable factors for consumers to consider when deciding which companies should retain their personal information.
And once again, shopping does not necessarily require an app.
If you buy from SHEIN twice a year, keeping its application installed 365 days a year may provide relatively little benefit.
Using the website is an alternative.
7. Snapchat
Snapchat built much of its early reputation around disappearing messages.
Its privacy history is more complicated.
The FTC reached a settlement with Snapchat in 2014 over allegations that the company misrepresented how completely messages disappeared and failed to properly explain certain data-collection practices.
Today, one of the features worth checking is Snap Map.
Location sharing can be useful when you deliberately want friends to know where you are.
It becomes much less attractive if you have accumulated hundreds of Snapchat contacts over the years and no longer remember who can see what.
If you use Snapchat, review your Snap Map settings.
Consider Ghost Mode if you do not want your location shared.
Also review the friend list itself.
Someone you casually added years ago does not necessarily need ongoing access to personal information today.
8. WhatsApp
WhatsApp is the most complicated entry on this list.
Its personal messages and calls are protected by end-to-end encryption by default.
That is an important security feature.
The concern raised by privacy advocates generally relates more to metadata and Meta’s broader data practices than to WhatsApp simply reading everyone’s encrypted messages.
Ireland’s Data Protection Commission fined WhatsApp €225 million in 2021 over transparency issues concerning how information was handled and shared with other Meta companies.
Metadata can still reveal useful information.
Who communicates with whom?
When?
How frequently?
From what device?
From which network?
Encryption can protect message content while other information surrounding the communication remains available.
That distinction frequently gets lost in discussions about WhatsApp.
Saying “WhatsApp is encrypted” is true.
Saying “therefore WhatsApp collects no useful information about users” is not.
Should You Really Delete All Eight?
Probably not simply because they appeared on somebody’s list.
There is a major difference between an application that has controversial privacy practices and an application confirmed to contain malware.
The eight applications highlighted by Morning Overview are mainstream services. The article’s argument largely concerns privacy, data collection, corporate history, permissions, and regulatory actions—not a discovery that all eight applications are malicious.
That nuance matters.
Actual malicious applications can behave much more aggressively.
For example, security researchers continue discovering Android banking Trojans capable of abusing Accessibility permissions, displaying fake banking screens, capturing credentials, intercepting PINs, and remotely controlling infected devices. Recent ToxicPanda 2.0 research illustrates how serious genuine mobile malware can become.
Likewise, McAfee reported a 2026 Android campaign involving more than 50 applications that had collectively accumulated over 2.3 million downloads before the threat was identified.
That is a different threat category.
The Apps You Should Be Most Worried About May Have Boring Names
A fake flashlight, PDF reader, cleaner, investment tool, security utility, or package-tracking application may deserve more immediate attention than Instagram.
Why?
Malware developers deliberately use ordinary-looking apps to get onto phones.
Malwarebytes reports that banking malware is frequently distributed through applications with generic names such as utilities, security tools, retailers, or investment applications, particularly through links and downloads outside official stores.
Another large 2026 campaign called Trapdoor involved 455 malicious Android apps and reportedly generated millions of downloads, often using seemingly useful applications such as PDF viewers and device-cleaning tools.
So don’t focus exclusively on famous names.
The obscure app you installed six months ago and forgot about could deserve considerably more scrutiny.
Check Permissions Before Deleting Anything
Instead of randomly removing applications, open your phone’s privacy controls.
Look particularly closely at apps with access to:
Camera.
Microphone.
Precise location.
Contacts.
SMS messages.
Photos.
Accessibility services.
VPN configuration.
Device administrator privileges.
An application requesting a permission is not automatically malicious.
Context matters.
Google Maps legitimately needs location.
A video-calling application legitimately needs camera and microphone access.
A basic calculator asking for Accessibility control, SMS access, microphone access, and precise location deserves much more skepticism.
That is the question users should ask:
Does this application genuinely need this permission to perform the job I installed it for?
If the answer is no, remove the permission.
If you cannot explain why the application is installed at all, consider removing the application.
Accessibility Permission Deserves Extra Attention
Android’s Accessibility Service is designed to help people interact with their devices.
Unfortunately, it can also provide powerful capabilities to malicious software.
Recent banking Trojans have abused Accessibility features to inspect interfaces, automate actions, display deceptive overlays, capture information, and assist with account takeover.
Check which applications currently have Accessibility privileges.
If you see something you do not recognize, investigate it immediately.
Likewise, review applications with Device Administrator or VPN privileges.
Those permissions can provide substantially more control than an ordinary app receives.
Be Especially Careful With Sideloaded Apps
Downloading applications outside official stores is not automatically dangerous.
But it removes an important security layer.
Malwarebytes notes that serious Android malware campaigns frequently rely on links delivered through text messages or websites that persuade users to install APK files outside Google Play.
A message saying:
“Your package could not be delivered. Install this tracking app.”
or:
“Download this banking security update.”
should immediately raise suspicion.
Recent campaigns have even impersonated recognizable companies and airlines to persuade victims to install malicious applications.
Installing software because a random SMS tells you to is one of the easiest ways to turn a phishing attempt into a full device compromise.
Deleting an App Doesn’t Delete Your Account
This is another important distinction.
Removing Facebook, Instagram, TikTok, Temu, or another application from your phone generally removes the local app.
It does not necessarily erase the account or information the company already holds.
If your objective is simply reducing background permissions and app access, uninstalling may be enough.
If your objective is removing your information from the service entirely, you need to investigate the company’s account-deletion and privacy controls separately.
Those are different actions.
A Better Rule Than “Delete These Eight Apps”
There isn’t a universal list of eight applications everyone should immediately remove.
A better smartphone-security routine is to periodically ask three questions about every installed app:
Do I still use it?
Do its permissions make sense?
Do I trust the company with the information it can access?
If an app fails all three questions, there is little reason to keep it.
This approach catches something that dramatic “delete these apps now” headlines often miss.
The biggest threat may not be TikTok, Facebook, or WhatsApp.
It could be the forgotten QR scanner, cleaner, free VPN, PDF converter, unofficial streaming app, or APK you installed from a message six months ago.
And unlike debates over mainstream apps’ privacy practices, removing software you neither recognize nor use is usually a very easy decision.