Before you install a cloud storage app, a note-taking app, or a photo organiser, both Apple and Google now show you a privacy summary directly on the app’s store listing. Apple calls it “App Privacy.” Google calls it “Data Safety.”
Most people scroll past these without reading them. That’s understandable — the labels don’t make headlines, the defaults are to ignore them, and the format isn’t always immediately legible. But they contain genuinely useful information about what an app is going to do with your data before you’ve given it the chance to do anything.
This guide explains how to read them, what the categories mean, where they’re reliable, and where they fall short.
Apple’s App Privacy Labels
Apple introduced App Privacy labels in December 2020 as a required part of the App Store listing for all apps. When you view an app on the App Store, scroll down to the “App Privacy” section. You’ll see a summary of what data the app collects.
The three main categories
Data Used to Track You. This covers data that is linked to your identity and used to target advertising across apps and websites — typically through advertising identifiers. If an app collects your location to show location-based ads, shares a device identifier with advertising networks, or links your purchases to a profile used for targeting, this category is where it shows up.
Data Linked to You. This covers data that the app collects and associates with your account or device, but keeps within the app or the developer’s own services rather than sharing with advertising networks. Your name, email, photos, messages, and usage data within the app often fall here. This is the category where cloud storage apps tend to show the most.
Data Not Linked to You. This is data collected for analytics or product improvement that the developer claims isn’t associated with your identity — crash reports, general usage patterns, and similar aggregate data.
What the subcategories tell you
Within each of those three buckets, Apple requires developers to categorise the specific types of data: location, contact info, health and fitness, financial info, browsing history, user content, identifiers, and others. “User content” is the relevant category for a storage or notes app — it covers the actual files, photos, audio, and documents you create or upload.
If an app shows “User Content” under “Data Linked to You,” that means the developer associates the contents of what you store with your identity. For cloud storage, that’s expected — your files need to be linked to your account. What matters is whether that linked user content is also shown under “Data Used to Track You” — which would mean the contents of your files are feeding an advertising or cross-app tracking system.
Google’s Data Safety Labels
Google introduced Data Safety labels for Android apps in mid-2022. You’ll find the “Data safety” section on any app’s Play Store listing.
Google’s structure is slightly different from Apple’s. Instead of three broad categories, Google asks developers to disclose:
What data is collected and why. This section lists specific data types and the purpose for which each is collected: app functionality, analytics, advertising and marketing, fraud prevention, personalisation, and so on. An app that collects your email address for account management will list that differently than one that collects it for marketing.
Whether data is shared with third parties. Google requires apps to disclose if data is sent to external parties — analytics providers, advertising networks, fraud detection services — and what type of data is shared with whom.
Whether data can be deleted. Users have the right to request deletion of their data. The Data Safety section must indicate whether the app provides a way to do this.
Security practices. This includes whether data is encrypted in transit, whether the app follows Google’s Families Policy, and whether it’s been independently audited.
Reading a Storage App’s Label in Practice
If you’re evaluating a cloud storage, photo management, or notes app, here’s what to look for specifically:
Flag: “User Content” under “Data Used to Track You” (Apple)
For a storage app, your actual files should not be used for cross-app tracking. If the label shows user content in the tracking category, that app is doing something unusual. It may be scanning your files’ contents for advertising signals or sharing file metadata with ad networks.
Flag: “User Content” shared with third parties for advertising (Google)
Similarly on Google’s Data Safety section: if the files or messages you store in the app are listed as shared with third parties for advertising purposes, the app is treating what you store as advertising inventory. This is a significant red flag for any app holding sensitive personal files.
Expected: “User Content” linked to your account for app functionality
This is normal for any cloud storage app. Your files need to be associated with your account so you can access them. The data type “User Content” showing up under “Data Linked to You” for purposes of “App Functionality” is unremarkable and doesn’t indicate a privacy problem.
Expected: Identifiers and usage data for analytics
Most apps collect some amount of crash and usage data to help developers understand how the app is performing. This should show up under “Data Not Linked to You” (Apple) or as data collected for analytics without being shared with ad networks (Google). This is a normal and generally low-risk data practice.
Flag: Location under “Data Used to Track You”
If a storage app is collecting your precise location for tracking purposes — not for a feature you’ve actively enabled, like tagging photos with location — that’s worth investigating. Location data used for tracking is one of the most sensitive categories.
What These Labels Don’t Tell You
The privacy labels are a meaningful improvement over the previous situation, which was no standardised disclosure at all. But they have real limitations worth understanding.
They’re self-reported
Neither Apple’s nor Google’s labels are independently verified at the point of publication. Developers fill them out and submit them. Apple and Google both have policies against inaccurate disclosures, and they conduct audits and remove apps that are found to be misrepresenting their practices — but the initial disclosure is the developer’s own claim about their own practices.
This means labels from well-resourced, legally cautious developers at major companies are likely to be accurate (they have more to lose from misrepresentation). Labels from smaller developers, or apps from jurisdictions where enforcement is difficult, are harder to trust.
They cover the app, not the server
A label tells you what the app on your device does. It tells you less about what the company does with data once it reaches their servers. A service might collect “User Content” (as disclosed in the label) and then use it for model training on the server side — a practice that the label’s category might not explicitly capture.
They use broad categories
“User Content” covers everything from the text of a note to the full content of a sensitive financial document. A label showing “User Content — App Functionality” doesn’t tell you whether that content is being scanned, indexed, or used for secondary purposes on the backend.
Shared with “third parties” is vague
Both Apple and Google require disclosure of data shared with third parties, but “third parties” can mean many things: a crash-reporting service, an analytics platform, an advertising exchange, a business partner, or an affiliated subsidiary. The label may not distinguish between these meaningfully.
How to Use Labels Alongside the Privacy Policy
The labels are a starting point, not a complete answer. The most productive way to use them:
Use the label as a filter. If an app’s label shows user content or precise location data under “Data Used to Track You,” that’s a reason to either avoid the app or read the privacy policy before continuing. You don’t need to investigate every app in detail — the label helps you identify which ones warrant scrutiny.
Use the label to navigate the privacy policy. If you see that an app shares “User Content” with third parties, look up “third parties” in the privacy policy and find out specifically who they are and why. The label tells you what; the policy (sometimes) tells you why and to whom.
Look for the absence of flags as a positive signal. An app that shows no data in the “Data Used to Track You” category, that limits third-party sharing to essential services like payment processors, and that clearly indicates data can be deleted is making a set of coherent commitments that are worth noting.
Check the label’s last updated date. Apps update their data practices, and labels may lag behind. If the privacy policy was updated more recently than the label on the App Store, read the policy — it’s more current.
What daftei’s Labels Show
daftei is available on both the App Store and Google Play. The app collects what’s necessary to provide encrypted personal storage: your account information to authenticate and manage your account, and the content you upload — photos, documents, voice notes, and other files — stored and associated with your account.
daftei doesn’t collect data for advertising, doesn’t share user content with advertising networks, and doesn’t sell personal data. There’s no advertising system to feed. The data types you’ll see in daftei’s App Privacy and Data Safety sections reflect an app designed around storage and privacy, not around monetising what users store.
If you want to check the current label before installing: search for daftei on the App Store or Google Play and scroll to the privacy section. The label should reflect a narrow set of data practices, because the product doesn’t need broad collection to function.
A Practical Checklist
Before installing any app where you’ll store personal files, photos, or sensitive information:
- Open the app’s store page — App Store on iOS, Play Store on Android.
- Scroll to the privacy section — “App Privacy” on iOS, “Data safety” on Android.
- Check “Data Used to Track You” (Apple) or ads-related sharing (Google). If user content appears here, investigate further before installing.
- Check what’s shared with third parties. Analytics services are expected. Advertising networks are a flag for a storage app.
- Confirm data can be deleted. A storage app should let you delete your account and your data. If the label indicates deletion isn’t possible, look for a policy explanation.
- Compare to the privacy policy. For apps you plan to use for sensitive storage, cross-check the label with the full policy — particularly the sections on AI, model training, and third-party data sharing.
The labels won’t tell you everything. But they’ll tell you enough to know when to look further — and sometimes enough to know when not to install at all.