BeReal was built on a premise most social apps had abandoned: honesty. Once a day, at a random moment, the app gives you two minutes to shoot a simultaneous front-and-back camera photo. No filters. No staging. No second chances. Just you, right now.
It worked. The app grew to tens of millions of users by 2022. Friend groups, schools, and entire social circles adopted it as an antidote to the performative polish of Instagram and TikTok.
Then in 2024, French mobile gaming company Voodoo acquired BeReal for around €500 million. With that acquisition came a significant shift in business model — and a formal GDPR complaint that landed the app in front of European privacy regulators.
Why the Acquisition Changed Things
Voodoo’s business is built around advertising. Their games are free to download and monetized through high-frequency ad placements and behavioral targeting. When they acquired BeReal, that model came with them.
Within months, BeReal launched a self-serve advertising portal, began showing sponsored posts in the daily feed, and introduced behavioral tracking infrastructure to power ad targeting. For a product that had marketed itself on authenticity and the absence of influencer culture, the shift was striking.
The business logic was straightforward: BeReal had daily active users and daily camera access. For an ad-supported business, that’s an extraordinarily valuable data pipe. The daily prompt feature means users open the app at a random time each day, capturing a genuine, unscripted moment of their life — far more useful for behavioral profiling than a carefully curated Instagram post.
The GDPR Dark Pattern That Triggered a Formal Complaint
Here is where it became a legal matter.
GDPR’s Article 7 requires that consent to non-essential data processing be freely given. The regulation is explicit: consent is not freely given if refusing it carries a meaningful penalty or disadvantage. EU data protection authorities have consistently ruled that making a service meaningfully worse for users who decline tracking — while leaving it seamless for those who accept — violates the freely-given standard.
noyb (None of Your Business), the European privacy advocacy group that has successfully brought major cases against Meta, Google, TikTok, and others, filed a formal complaint with France’s CNIL — BeReal’s home regulator — alleging exactly this design. According to noyb’s published complaint, users who declined ad tracking received consent pop-up prompts every single time they opened the app to post. Users who accepted tracking were left alone.
The practical effect was a daily nudge: accept tracking or be interrupted every time you use the feature that is the entire point of the app. That, noyb argued, is not consent — it is coercion dressed up in a UI component.
The complaint called for financial penalties and deletion of data collected under the allegedly invalid consent framework.
What BeReal Actually Collects
Understanding the complaint requires understanding what BeReal has access to in the first place.
Camera access is unavoidable — the dual front-and-back capture is the product. But camera access on most platforms also enables video capture, BTS (Behind The Scene) recordings, and in-app selfies. BeReal holds the infrastructure to see your face, your surroundings, and the people around you every day.
Contacts are requested to help you find friends on the platform. This is standard social app practice, but contact list uploads have a documented history of being used for purposes beyond friend-finding — inferring social graphs, identifying people who aren’t users, and feeding recommendation and advertising systems.
Location data is optional in BeReal’s settings but has been enabled by default for some feature sets. Location attached to daily photos creates a precise record of where you go each day at what times.
Device identifiers and usage data are collected to enable personalization and, post-acquisition, ad targeting. These include advertising IDs (IDFA on iOS, GAID on Android), session data, and inferred interest categories built from how you use the app.
Behavioral profiles are the aggregate product of all of the above. An advertising platform uses this data to determine which ads to show you and what price to charge advertisers for your attention.
The Simultaneous Camera Problem
The dual-camera format is worth thinking about carefully.
A typical social photo captures one moment, curated by the user. A BeReal captures your face and what’s behind you at the same random time every day. Multiply that by years of daily use and you have a longitudinal record of someone’s physical life — where they live, where they work, who they spend time with, what their home looks like, what their emotional states look like across seasons and life events.
That record is created precisely because BeReal’s design prevents curation. The authenticity that makes the app appealing is also what makes the data more revealing than typical social content.
BeReal’s privacy policy states it does not sell photos to third parties. What “sell” means in a post-acquisition, advertising-supported context is narrower than users typically assume. Sharing data with advertising partners under contractual restrictions is not legally a sale under most definitions — including GDPR’s — even if the economic effect is similar.
Facial Data Under GDPR
Under GDPR, biometric data processed for the purpose of uniquely identifying a natural person is a special category requiring explicit, specific consent separate from general service terms. Facial images become biometric data when processed through facial recognition or facial analysis systems.
BeReal’s privacy policy does not state that it applies facial recognition to uploaded photos. Whether that remains true as Voodoo integrates BeReal’s data with its wider advertising infrastructure is not publicly confirmed. The CNIL complaint will examine exactly what processing occurs.
For EU users, the standard is straightforward: if their faces are being processed to uniquely identify them or build behavioral profiles, that requires explicit consent under Article 9. Consent bundled into general terms of service does not meet the standard.
What UK and US Users Should Know
GDPR protections apply to users in the European Economic Area. But UK users retained GDPR-equivalent protections under UK GDPR post-Brexit, and California users have rights under CCPA. Neither framework gives you the same specific consent requirements for biometric processing that EU GDPR does, but both give you rights worth exercising.
Under CCPA, California residents can:
- Request a copy of all personal data BeReal holds
- Request deletion of that data
- Opt out of the sale or sharing of personal data
Under UK GDPR, UK residents can exercise the same rights as EU users — access, deletion, restriction of processing, and objection to processing for direct marketing.
The practical difference is enforcement. noyb’s complaint is aimed at CNIL specifically because BeReal is based in France. UK and US users can submit requests directly to BeReal but have fewer regulatory tools to compel compliance quickly.
How to Protect Yourself Right Now
Regardless of where you are, these steps reduce your exposure.
Revoke unnecessary permissions. On iOS: Settings → Privacy & Security → Camera, Contacts, Location — review what BeReal has access to and revoke anything beyond camera. On Android: Settings → Apps → BeReal → Permissions.
Disable ad tracking. On iOS: Settings → BeReal → Tracking. If the toggle exists, disable it. If you’ve never been prompted, iOS may have blocked it automatically — but confirm. On Android: Settings → Privacy → Ads → Opt out of Ads Personalization.
Disable location. Unless you actively use BeReal’s location features, there’s no reason the app needs to know where you are. Set location access to “Never” or “While Using the App” at most.
Submit a data access request. You can request a copy of your BeReal data regardless of your location. This tells you exactly what the company holds and sometimes surfaces surprises. Look for the data request option in Settings → Privacy, or contact BeReal’s privacy team directly.
Consider what you’re posting. BeReal’s design encourages thoughtlessness — that’s the point. But for an app undergoing a regulatory challenge over its data practices, this is a reasonable moment to think about whether daily front-and-back camera captures, stored on Voodoo-operated servers, align with your privacy preferences.
The Recurring Acquisition Pattern
BeReal is a specific case study in a general pattern that has repeated across the social app landscape for fifteen years.
Instagram was acquired by Facebook in 2012. At acquisition, Instagram had no ads and a simple privacy policy. Within two years, Meta began integrating Instagram’s data with its advertising infrastructure. The integration is now complete — Instagram is one of Meta’s primary ad-revenue products.
WhatsApp was acquired in 2014 with an explicit promise from Mark Zuckerberg that nothing would change. By 2016, WhatsApp updated its terms to share user data with Facebook for advertising purposes. The backlash prompted a German regulatory order. The integration continued.
Waze was acquired by Google in 2013. The mapping app’s community-contributed traffic data became part of Google Maps and Google’s broader location intelligence infrastructure.
The pattern is not corruption. It’s business logic. Companies acquire products with large engaged user bases and then monetize those user bases using the acquiring company’s existing infrastructure. The product often stays good. The data relationship always changes.
Before trusting any app with daily camera access, daily location data, and a full contact list — even one you genuinely like — the most useful question is not what the current privacy policy says. It’s who owns the company and how they make money.
The Alternative Architecture
Apps that generate revenue from subscriptions rather than advertising have a structurally different relationship with your data. There’s no advertiser to serve, which means there’s no business case for collecting more than what’s needed to provide the service.
daftei stores photos and files under a subscription model with no advertising and no third-party AI training on user content. Your photos are not used to build behavioral profiles or target ads, because there are no ads to target. That distinction — subscription versus advertising revenue — is increasingly the clearest indicator of how a service will handle your data, especially if it’s ever acquired.
The CNIL complaint against BeReal may take months or years to resolve. In the meantime, users who are uncomfortable with the post-Voodoo data relationship have the practical options above — or the option of putting daily photos somewhere that doesn’t depend on their attention to make money.