security

Free Antivirus Software Isn't Free — You Pay With Your Data

Free antivirus apps require deep system access to work. Some use that access to collect browsing history, file metadata, and behavioral data sold to third parties.

The Best Seat in the House for Surveillance

To do its job, antivirus software needs access that almost no other application on your computer receives. It reads every file you open. It intercepts every download before it reaches your disk. It monitors your network connections in real time. It logs what programs launch, when, and what they do.

This is legitimate and necessary. A security tool cannot detect malware without watching system behavior. The access is not a design flaw — it is a design requirement.

The question is what happens with that access when the software is free and the company still needs to generate revenue.

The Avast Investigation: A Documented Case

In 2020, a joint investigation by PCMag and Motherboard revealed that Avast — one of the world’s most widely installed free antivirus programs — was selling detailed user browsing data to corporate clients through a subsidiary called Jumpshot.

The data being sold was not generic traffic statistics. It was granular, timestamped behavioral logs: which websites individual users visited, in what sequence, at what times, and for how long. The data was sold to clients including consumer brands, advertising agencies, and market research firms.

Avast’s privacy policy disclosed that “non-personal” data might be shared with third parties. The investigation found that the data being sold, while nominally anonymized, was detailed enough that it could in practice be de-anonymized — matched back to individuals using publicly available information.

Avast shut down Jumpshot in 2020 following the investigation and public pressure. In 2022, the US Federal Trade Commission filed a complaint against Avast, ultimately resulting in a settlement that included a $16.5 million fine and restrictions on the company’s data practices.

The case established several things clearly. First, free antivirus software has historically used its system access to collect behavioral data beyond what is needed for security. Second, this data has commercial value and has been sold. Third, privacy policy language about “non-personal” data sharing did not adequately inform users about what was actually happening.

What Other Free Antivirus Tools Collect

Avast is the most documented case, but it is not isolated. The business model pressure applies across the free antivirus market.

AVG, which Avast acquired in 2016, operated similar data collection practices through the Jumpshot subsidiary. AVG products install browser extensions that can collect browsing history independently of the core antivirus functions.

360 Total Security and related products from Qihoo 360, a Chinese company, have been the subject of longstanding concerns from security researchers about data sent back to company servers, including browsing behavior and file metadata.

Kaspersky drew significant regulatory attention in 2022, when the FCC added it to the Covered List of companies posing national security risks, and in 2024 and 2025 as US and EU regulators imposed formal restrictions on its products. Kaspersky’s data handling practices — specifically, what information its cloud-based threat analysis sends back to servers — was central to those concerns.

Free tiers of commercial security suites — including many Windows-native third-party tools — typically offer reduced functionality in exchange for data collection that helps the company’s analytics and research divisions, which have commercial value.

The Browser Extension Problem

Many free antivirus products install browser extensions alongside the core security software. These extensions are often presented as security enhancements: they check links before you click, warn about phishing sites, and verify secure connections.

They also have the technical capability to read the URL of every page you visit, the search terms you enter, the content of pages you load, and your interaction behavior on those pages. Browser extensions operate with permissions that are broad enough to constitute significant surveillance if the extension chooses to use them.

Privacy policies for these browser extensions are often separate from the main antivirus privacy policy — and often less carefully reviewed by users.

Reviewing which browser extensions are installed in your browser and what permissions they hold is a straightforward audit. Go to your browser’s extension or add-on manager and examine the permissions listed for any security-related extensions. If a security extension requests access to “read and change all your data on all websites,” that is exactly the permission it states.

What Antivirus Software Can See About Your Files

The file-level access that antivirus software requires means it can, in principle, observe the types and content of files on your system.

For security purposes, it needs to read files to check them for malware signatures. It observes file names, file types, creation and modification dates, and in some cases file content. This is how it works.

What security companies do with this file metadata beyond the security function is governed by their privacy policies. Most legitimate security software companies limit file-level data collection to what is needed for threat detection and use it to improve detection capabilities rather than selling it commercially.

However, “improving detection capabilities” can include sharing file hash information with cloud intelligence networks — a practice where a fingerprint of a file is sent to the company’s servers to check against known threat databases. This is a legitimate and useful practice. It also means your file metadata (though not the file content itself, in most implementations) is transmitted to the security company’s infrastructure.

Understanding what is transmitted, when, and to whom is a matter of reading technical documentation that most users do not have the time or technical background to evaluate.

Reading the Privacy Policy: What to Look For

The key sections of any antivirus privacy policy are not the introductory summaries. They are the specific sections on data collection, data sharing, and third-party relationships.

Data collected: Look for what categories of data the policy identifies. “Usage data” and “product improvement data” are broad categories that can encompass significant behavioral information. Ask whether browsing history, file names, or application usage are specifically mentioned.

Third-party sharing: Look for language about “service providers,” “partners,” “analytics vendors,” and “business purposes.” These categories can cover a wide range of sharing arrangements. “We do not sell personal data” in jurisdictions where CCPA applies is a meaningful statement — but sharing data with partners under contract for analytics purposes is not technically “selling” under CCPA’s definition, even if the data flows commercially.

Data retention: Look for how long data is retained and under what circumstances it is deleted. Behavioral data that informs an analytics product may be retained indefinitely; the policy should specify.

Jurisdiction: Where is the company headquartered, and where is its data processed? Data processed in certain jurisdictions may be subject to government access requirements that are different from those in your home country.

The straightforward answer is that paid antivirus software has a more sustainable revenue model that does not require monetizing user data. A company charging $30 to $60 per year for security software does not need to sell behavioral analytics on the side to cover its costs.

This does not make paid antivirus universally privacy-respecting. Some paid security products still collect and use behavioral data, both for legitimate security research purposes and for product improvement. But the commercial pressure to extract additional value from user data is lower when users are paying directly.

The free tier of a commercial security product is typically designed to encourage upgrade to a paid tier. This means the free tier may be genuinely limited in functionality and less likely to be used as a data collection engine than a standalone free product whose entire business model depends on monetizing user data.

What Operating Systems Already Provide

Windows Defender (now Microsoft Defender) and Apple’s built-in XProtect, Gatekeeper, and MRT systems provide meaningful baseline security against common threats at no additional cost and with privacy behaviors governed by the privacy policies of the operating system vendor rather than a third-party security company.

For many home users, the built-in security tools of their operating system, combined with sensible habits — not clicking unknown links, keeping software updated, using strong unique passwords — provide adequate protection without introducing a third-party application with broad system access.

Microsoft’s privacy practices around Defender are imperfect, particularly in the context of Windows telemetry more broadly. But they are more transparent and more thoroughly audited than the practices of many free third-party antivirus tools.

Protecting What Your Antivirus Can See

If you store sensitive personal files — financial documents, health records, legal correspondence, personal photos — on a device where free antivirus software is installed, that software has system-level access to everything on the device.

This is not a reason to go without security software. It is a reason to understand what your security software’s privacy policy actually says, and to choose security tools from vendors whose data practices are documented and whose revenue model does not depend on monetizing your behavioral data.

The security market, like the app market more broadly, has a cost structure that does not disappear just because you are not writing a check. Free tools find another way to cover costs. In the security context, where the tool has unusually broad system access, understanding what that other way is — before installing — is not optional.

Your antivirus software sees more of your digital life than any other application on your system. It is worth knowing what it does with that view.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts