Length is the point
A typical privacy policy runs 2,500 to 6,000 words of dense legal prose. Reading every policy an average person agrees to in a year would take several hundred hours, a figure researchers have arrived at repeatedly since the first study on it in 2008.
Nobody expects you to read them. That is not a failure of the format, it is a property of it. Length and density are what make "I agree" the only realistic action.
But policies are not uniformly dense. The consequential decisions live in about six sections, and those sections are usually short, because the substance is genuinely small. Everything else is jurisdictional boilerplate.
Here is how to find them, what the phrasing means, and how to check whether the policy matches the product.
1. What is collected
Usually the longest section and the least informative, because it lists everything the company might ever collect rather than what this app actually does.
Skip the obvious items. Look specifically for four things:
- Precise location. The single most revealing item on any phone. Distinct from approximate or coarse location, and the distinction is deliberate.
- Contacts or address book. The only category that exposes people who never agreed to anything.
- Device identifiers. Advertising ID, IDFA, device fingerprint. These are what let separate companies recognise you as the same person across unrelated apps.
- Usage or behavioural analytics. Broad, and worth reading closely: there is a real difference between crash reports and a record of everything you tapped.
The check that matters: does this list match the permissions the app actually requests? A policy describing minimal collection alongside an app asking for location, contacts and identifiers is describing something other than what you installed. Our breakdown of what each permission exposes is in app permissions explained.
2. Why it is collected
Short section, high signal. You are looking for the join between each purpose and the data it justifies.
Good policies say specific things: location is used to show weather for your area and is not stored after the request. Weak ones say to improve our services, which justifies anything.
Under GDPR, companies must state a lawful basis. Three appear constantly:
| Basis | What it means | How to read it |
|---|---|---|
| Consent | You actively agreed | Strongest for you. Withdrawable. |
| Contract | Needed to deliver what you asked for | Usually fair. A delivery app needs your address. |
| Legitimate interest | The company judged its interest outweighs your rights | Legal, and the one used for processing people would refuse if asked |
Legitimate interest is not a loophole and it is not a scandal. But when it appears next to advertising or profiling, it means that processing is happening without your consent because the company decided it could.
3. Who it is shared with
The most important section, and often the shortest.
The question is not whether data is shared. Almost every app shares with somebody, if only a hosting provider. The question is whether the partners are named.
- Named partners are a real commitment. You can look them up.
- Categories such as analytics providers, advertising partners, business affiliates are not a commitment at all. The company can add or swap partners inside a category without ever amending the policy.
The sell versus share distinction
Watch for a policy that states plainly we do not sell your personal information and then, elsewhere, describes sharing with advertising partners.
Both statements are usually true. In most jurisdictions a sale requires money changing hands for the data specifically. Providing data to an advertising network in exchange for advertising services is not a sale under that definition, while producing much the same outcome: your behaviour ends up in a profile held by a company you never chose.
If the sentence we do not sell your data is doing heavy lifting on a marketing page, go and read the sharing section. That is where the real answer is.
4. How long it is kept
Short, easy to skip, and the biggest single red flag lives here.
Look for a defined period: 90 days, 24 months, deleted within 30 days of account closure. A number means someone made a decision and can be held to it.
The phrase to catch is:
We retain your data for as long as necessary to provide our services.
That defines nothing. Necessary is decided by the company, and under it data can be kept indefinitely while the sentence still reads like a limit. It is the most common formulation in the industry and it is worth noticing every time.
Also check whether deletion is described at all. A policy with no deletion process is telling you that closing your account removes your access, not your data.
5. What rights you have
Depends on where you live, and good policies say so plainly.
Under GDPR you can request a copy of your data, correction, deletion, and portability. Under CCPA and similar US state laws you can request disclosure and deletion, and opt out of sale or sharing.
What to look for is not the list of rights, which is largely dictated by law, but the mechanism:
- Is there a real address or form, or only a generic support inbox?
- Is there a stated response time?
- Can you delete the account inside the app, or only by writing to someone?
Rights that require a letter to a legal department are rights most people will never exercise, which is frequently the point.
6. How the policy changes
The last section, and it decides how much everything above is worth.
The good version: material changes are notified by email or in-app, with a stated notice period before they take effect.
The weak version: we may update this policy from time to time; please check this page periodically. That places the burden on you to re-read a document you were never expected to read once. Under it, everything above can change tomorrow without you being told.
Phrases worth recognising
Certain formulations appear across thousands of policies because they are legally safe and practically unlimited. None of them is a scandal on its own. All of them mean less than they appear to.
"We may share information with trusted partners." Trusted is doing no work; it is not a defined term and imposes no obligation. What matters is whether the partners are named.
"Aggregated or anonymised data." Genuine anonymisation is difficult and often reversible. Research has repeatedly shown that small numbers of location points, or a handful of behavioural attributes, are enough to re-identify individuals within a supposedly anonymous dataset. Treat this as reduced risk rather than no risk.
"We may collect information such as…" Such as means the list is illustrative rather than exhaustive. A closed list says we collect the following.
"To improve our services." The broadest purpose in common use. Almost any processing can be argued to improve a service.
"Industry-standard security measures." Describes no specific control. Meaningful commitments name something: encryption at rest, TLS in transit, an audit standard.
"By continuing to use the service, you accept the updated policy." Consent by inertia. It converts your failure to re-read a document into agreement with terms you have not seen.
"We do not sell your personal information." Frequently true and frequently beside the point. See the sharing section above.
None of these should make you close the tab. They should tell you which sentences carry a commitment and which are decoration, so you spend your five minutes on the former.
The five minute pass
In order, using your browser's find function:
- Search
third partand read the sharing section. Named partners or categories? - Search
selland see what the sentence around it is doing. - Search
retainorretentionand look for a number. - Search
location,contacts,identifierand check each against the app's actual permissions. - Search
legitimate interestand see what it is being used to justify. - Read the final section on how the policy changes.
Six searches. About five minutes. It will not make you a lawyer and it will catch nearly everything that would have changed your decision.
Checking a policy against reality
A policy is a claim. Three places let you test it in a couple of minutes:
The store listing's data safety section. Both Google Play and the App Store now require developers to declare what they collect and share. It is self-reported rather than audited, but a mismatch between the listing and the policy is a real finding.
The permission requests. The app cannot collect what it has not been granted. A short, well-matched permission list is a stronger signal than any paragraph of prose. See app permissions explained.
The business model. This is the most reliable of the three. An app funded by advertising has a structural reason to want data it does not need for features, whatever its policy says. An app funded by a purchase does not. We cover the mechanics in how free apps actually make money, and the wider evaluation in how to choose an app you will still use in a year.
Our own, held to the same test
We build apps, so treat this as a disclosure rather than a neutral example.
PackPilot and PawDex each publish their own policy on their own site. Neither app contains an advertising SDK, which is why both permission lists are short: advertising libraries are where most of the surprising collection in ordinary apps originates. PawDex requests location to record a walk route, active during a recording rather than continuously. Neither requests contacts, microphone, or SMS.
Run the six searches on those policies rather than taking this paragraph as the answer. That is the correct way to treat any company writing about its own privacy practices, including this one.
Related Reading
- App Permissions Explained covers what each request actually exposes.
- How Free Apps Actually Make Money explains the incentives behind data collection.
- Dark Patterns in Apps: A Field Guide covers consent flows built to make agreeing easier than refusing.
- What Happens to Your Data When an App Shuts Down covers the section policies rarely address.
Frequently Asked Questions
A full careful read of a typical policy takes 15 to 30 minutes, and studies estimate reading every policy an average person encounters in a year would take several hundred hours. Reading the six sections that carry the decisions takes about five minutes.
What is collected, why it is collected, who it is shared with, how long it is kept, what rights you have, and how the policy can change. Everything else is usually boilerplate or legal framing.
It means the data leaves the company you chose to trust and reaches companies you did not. The important detail is whether those partners are named or described only as categories, because unnamed categories can expand without the policy ever changing.
No, and the distinction is often used deliberately. Many companies truthfully say they do not sell data while sharing it with advertising partners for value, which achieves a similar result without meeting the legal definition of a sale in most jurisdictions.
It is a lawful basis under GDPR that allows processing without consent when the company judges its interest is not outweighed by your rights. It is legitimate, and it is also the basis most often used to justify processing people would decline if asked.
Compare it against the app's permission requests and the store's data safety section. A policy claiming minimal collection alongside an app requesting location, contacts, and device identifiers is describing a different product than the one you installed.
A retention section that says data is kept as long as necessary without defining necessary. It grants unlimited retention while sounding like a limit.