TikTok gave itself the right to scan your face and voice with a loophole covering most Americans. Already paid $92 million for collecting children's face data. A professor warned: you can't change your face like a password. TikTok's own documents say kids can't control screen time. Their fix reduced usage by 90 seconds. They measured success by press coverage, not child safety. Reviewers spent 5-7 seconds per account. 1.4 million British children under 13 were on the platform. The FTC called it 'flagrant.'.
What they claim: 'We will seek required permissions' for biometric data.
What we found: Privacy policy: 'faceprints and voiceprints' with 'where required by law' loophole. Most US states have no biometric law. $92M BIPA settlement for children's facial data. Carnegie Mellon: 'you cannot change your face.' Only in US policy, not EU.
What they claim: 'The journalist incident was isolated misconduct.'
What we found: ByteDance tracked IP addresses of FT and BuzzFeed journalists to find sources. Coordinated across US and China. 4 fired including chief auditor. DOJ opened spying investigation.
What they claim: 'We do not collect keystroke or text inputs through this code.'
What we found: Felix Krause (2022): in-app browser injects JavaScript subscribing to ALL keyboard inputs -- 'equivalent of installing a keylogger.' Forced all links through this browser. TikTok's own privacy policy: collects 'keystroke patterns or rhythms.' Snopes confirmed key event tracking.
What they claim: 'Clipboard access was an anti-spam feature.'
What we found: Mysk researchers found silent clipboard reading (March 2020). iOS 14 revealed reading every 1-3 keystrokes, even in other apps. Nearby Apple devices via Universal Clipboard affected. ByteDance promised to stop March 2020, caught still doing it June 2020. Declined to say where data went.
What they claim: 'Our algorithm shows you content you're interested in.'
What we found: Amnesty (2023): 13-year-old accounts got suicide content within 3-20 minutes. Over half of videos were mental health struggles. Multiple videos in one hour romanticised suicide. Internal research: 'compulsive usage correlates with loss of analytical skills, memory, empathy.' 260 videos (~35 min) to form habit. 14 AGs sued.
What they claim: TikTok claims its screen time management tools protect users
What we found: In February 2026, the European Commission found TikTok's addictive design breaches the DSA — the first-ever enforcement targeting platform architecture. Infinite scroll, autoplay, push notifications, and hyper-personalised recommendations were all cited. Screen time tools were found to be "easy to dismiss and introduce limited friction." TikTok failed to assess how its design harms mental health. Fines up to 6% of global turnover.
What they claim: 'Project Texas ensures US data security.'
What we found: DOJ rejected as inadequate. Oracle: 3 years to review code. DOJ: 'resources far beyond what government and Oracle possess.' Supreme Court unanimously upheld ban. TikTok dark 12 hours. ByteDance retains algorithm IP via licensing in new JV.
What they claim: TikTok has repeatedly claimed EU user data is stored in European data centres under "Project Clover."
What we found: Ireland's Data Protection Commission fined TikTok €530 million in May 2025 for transferring EU user data to China — the largest GDPR fine against a social media company. During the investigation, TikTok admitted it had stored EU user data on Chinese servers despite claiming otherwise under Project Clover. TikTok appealed. In April 2026, the Irish Supreme Court ruled TikTok could continue transferring data to China during the appeal. The company that built an entire PR campaign around EU data sovereignty admitted it was storing EU data in China the whole time.
What they claim: TikTok claims EU user data is protected under GDPR with Project Clover data localisation
What we found: The Irish DPC fined TikTok €530 million in May 2025 for unlawful EU-to-China data transfers. Despite TikTok's €12 billion "Project Clover" to localise European data, the DPC found data was still being transferred to China. TikTok obtained a stay from the Irish High Court allowing transfers to continue during appeal. The largest GDPR fine of 2025.
What they claim: TikTok's previous privacy policy explicitly stated the app "does not collect precise GPS information."
What we found: After the January 2026 divestiture to TikTok USDS ($14B deal), the new privacy policy introduced precise GPS location tracking, AI interaction data collection, and an expanded off-platform advertising network. Harvard Law lecturer Timothy Edgar said the new structure "in some ways made the problem even worse."
What they claim: TikTok's pre-2026 privacy policy explicitly stated that GPS location data was not collected from U.S. users.
What we found: After the January 2026 divestiture to TikTok USDS, the new privacy policy reverses this: location is now classified as "sensitive data" and is actively collected. The new policy also introduces collection of citizenship and immigration status — a category not present in any prior version of the policy.
What they claim: TikTok USDS divested to US ownership to address national security concerns about Chinese data access
What we found: Under new US ownership (Jan 2026), TikTok's updated privacy policy explicitly classifies location tracking as sensitive data and now collects precise location (with permission) and citizenship/immigration status. The DOJ lifted the federal device ban in July 2026. Users must agree to new terms or lose access — no opt-out, no negotiation. User backlash led to mass deletion threats.
What they claim: 'US user data is stored in the US and Singapore.'
What we found: BuzzFeed leaked audio from 80+ meetings: 14 statements confirming China access. 'Everything is seen in China.' Beijing 'Master Admin' with 'access to everything.' DPC fined EUR 530M for storing EU data in China while denying it. TikTok admitted it happened again in 2025.
What they claim: 'We are proud of our efforts to protect children.'
What we found: DOJ/FTC (Aug 2024): 'flagrant' COPPA violation. Millions of under-13 accounts. 5-7 second reviews. UK ICO: 1.4M under-13s, GBP 12.7M fine. DPC: EUR 345M children's data. Internal: 'minors lack executive function.' Safety tools reduced usage by 1.5 minutes, measured by PR not protection.
What they claim: TikTok claims structural separation from ByteDance under the January 2026 divestiture deal, with Oracle hosting US data
What we found: Under the January 2026 joint venture deal, ByteDance retains under 20% ownership and Oracle hosts US data. However, ByteDance still owns and licenses the recommendation algorithm to TikTok US. Critics argue this violates the divestiture law's "no operational relationship" requirement. Cybersecurity expert Timothy Edgar warned the deal may result in less oversight of TikTok data than under ByteDance, not more.
Events detected by our automated monitoring of CVE databases, regulatory agencies, and breach trackers.