Locket Widget is one of the more charming app concepts of recent years. You share a widget with a friend or partner — they put it on their home screen, you put theirs on yours, and throughout the day you send each other candid photos that appear directly on the lock screen. No likes, no feeds, no followers. Just an intimate photo channel between two people.
It went viral for good reason. The concept is genuinely warm, especially for long-distance couples and parents with children away at college. As of 2025, Locket had been downloaded tens of millions of times.
But child safety organizations, privacy researchers, and parents have raised concerns about what the app collects relative to its stated purpose. Locket’s data practices are more extensive than its cozy branding suggests, and the app’s audience — which skews toward teenagers and young adults — means those practices warrant serious scrutiny.
What Locket Collects at Signup
Creating a Locket account requires:
- Phone number — mandatory, used for identity verification and friend discovery
- Full name — displayed to your widget partner(s)
- Contacts — Locket requests access to your full contact list to find others already using the app
The contacts request is worth pausing on. Uploading your contact list to an app means giving the company access to names, phone numbers, and email addresses of people who have not consented to share their information with Locket. This is standard social app practice, but it’s a meaningful disclosure on behalf of everyone in your phone’s contacts — most of whom will never use Locket.
Contact data is used for friend-finding features and, depending on the app’s terms, may be used to identify users through social graph inference. Advertising platforms use contact graph data to find “lookalike audiences” and to target ads at people who appear in the contact lists of existing users, even without those non-users ever signing up.
The Photo License
Locket’s terms of service include a licensing clause for user-uploaded content. Language of this type is standard across social apps — it allows the company to display, distribute, and modify content as needed to provide the service — but the scope varies significantly between apps.
Privacy review organizations including Common Sense Media and DeleteMe have flagged Locket’s photo license as broad. The terms grant the company a non-exclusive, royalty-free, worldwide license to use, reproduce, modify, adapt, publish, and distribute photos submitted through the service.
The “modify and adapt” language is what typically concerns privacy advocates. A license to display a photo between two widget users requires only display rights. “Modify, adapt, publish, and distribute” goes further and creates legitimate questions about whether photos could be used for purposes beyond the core service — including training AI image models or using photos in marketing materials.
Locket has not publicly confirmed that it uses user photos for AI training. But the license as written would permit it. For an app used by teenagers sending spontaneous daily photos of themselves, the gap between what the license permits and what users understand themselves to have agreed to is significant.
Third-Party Advertising and Tracking
Common Sense Media’s privacy evaluation of Locket found evidence of third-party tracking and data sharing with advertising networks. The app uses third-party analytics and advertising SDKs — standard tools that collect device identifiers, usage patterns, and behavioral signals.
On iOS, third-party tracking requires explicit opt-in consent under Apple’s App Tracking Transparency framework. If you’ve been prompted and declined, iOS should block cross-app tracking identifiers. But first-party analytics — data about how you use Locket itself, collected by Locket — continue regardless of ATT status.
The combination of contact list access, phone number identity, usage data, and behavioral analytics creates a relatively comprehensive profile for a photo-sharing app. The stated purpose is intimate photo exchange. The data collected is considerably broader.
Location Data
Locket includes a “Memories” feature and other location-adjacent features depending on the app version. Whether location permission is requested varies by feature usage and device.
If location access has been granted, photos sent through Locket may include geolocation metadata. Even if the app strips metadata before displaying photos, it may retain the raw location data server-side.
For teenage users whose parents have given them permission to use the app, location data in photos has specific risks — particularly if the app is used to send photos home from school, a friend’s house, or other locations. The data tells anyone with server access exactly where the teenager was when each photo was taken.
Check location permission status in device settings regardless of whether you’ve been explicitly prompted by the app.
The Audience Problem
Locket’s marketing and design are aimed at teenagers, young adults, and couples. The app’s App Store screenshots show friends and partners sharing casual daily photos. Common Sense Media’s evaluation notes it as appropriate for ages 16 and up but not younger, primarily due to privacy practices rather than content.
Apps marketed to teenagers are subject to COPPA in the United States if they knowingly collect data from users under 13. For users 13-17, no equivalent federal protection exists in the US — though several states have enacted teen privacy protections. Locket’s data collection practices, which include contact lists and behavioral data, are legal for users over 13 even if they would be subject to parental consent requirements for younger users.
Parents whose teenagers use Locket — particularly for the widget-with-friends use case common in high school social groups — should know that the app collects a contact list (including the teenager’s friends’ phone numbers) and that photos are governed by a broad commercial license.
Privacy Settings Worth Checking
If you or someone in your family uses Locket, these settings are worth reviewing:
Contact access. On iOS: Settings → Privacy & Security → Contacts → Locket. If the app has contacts access and you haven’t actively used the friend-finding features, revoke it. The core widget functionality — exchanging photos with specific people — does not require ongoing contacts access after the initial friend connection is made.
Location access. iOS: Settings → Privacy & Security → Location Services → Locket. Set to “Never” unless you actively use location-tagged features.
Camera access. Required for sending photos. “While Using the App” is the appropriate setting — “Always” is never appropriate for a camera app.
Notifications. Locket sends notifications when a partner sends a photo. This is the expected behavior. But apps with notification access can send prompts at any time. Review notification settings if the volume is excessive.
App Tracking Transparency. iOS: Settings → Locket → Tracking. Ensure tracking is disabled if you haven’t opted in.
Requesting or Deleting Your Data
Under CCPA (California users), you have the right to request a copy of the data Locket holds about you and to request deletion. EU users have equivalent rights under GDPR. UK users under UK GDPR.
For contact data specifically: data about your contacts that you uploaded when granting contacts access is your own data that you submitted on behalf of others. Deleting your account should remove the contacts data Locket holds about you. It will not remove the data they may have already derived from it — inferred social graphs, lookalike audiences built from your contact list — which may persist in advertising systems.
This limitation is common across apps that use contact lists for friend-finding. The derived data often has a longer life than the source data.
Alternatives for Intimate Photo Sharing
Locket’s core concept — a private, low-friction photo channel between two people — is genuinely useful. If the data practices are a concern, there are alternatives with different trade-off profiles:
WhatsApp. End-to-end encrypted photo sharing in a direct message. No broadcast feed, no public followers. The limitation: WhatsApp is owned by Meta and, while message content is E2EE, metadata (who you message, when, how often) is retained and shared with Meta for purposes including advertising.
Signal. End-to-end encrypted, open-source, non-commercial. No ads, no metadata retention for advertising. The trade-off is that Signal doesn’t have a home-screen widget feature equivalent to Locket’s.
iMessage. E2EE between Apple devices. Limited to Apple users. No ads.
daftei shared albums. If the goal is creating a shared private space for photos between two people rather than home-screen widget notifications, a shared album in a privacy-focused storage service provides similar functionality without the real-time notification push.
None of these replicate Locket’s distinctive home-screen widget experience exactly. That feature is genuinely original. But if the privacy practices are a dealbreaker, especially for a teenager’s account, the alternatives above represent meaningfully different data relationships.
The Warm-Branding Attention Gap
Locket’s brand is intentionally warm. Soft colors, hearts, the premise of intimacy and connection. That warmth, which is genuine to the product’s design, tends to suppress the skeptical reading of a privacy policy that the same user might apply to, say, a data analytics app.
It shouldn’t. The data collection is the same regardless of how the interface feels. An app that collects your contact list, phone number, and full name under a broad photo license is doing that whether or not the UI looks like a greeting card.
The useful habit is to treat the privacy review of any app that requests camera, contacts, or location access as an independent step from evaluating the product itself. Both can be good. Both can be worth doing. But whether the app is warm and charming has no bearing on what the terms actually say.
Read the permissions. Check the license clause. Look up the privacy evaluation on Common Sense Media or similar. Then decide.