When Threads launched in 2023, the app’s App Store privacy label generated immediate attention from privacy researchers. The list of data categories it claimed to collect was long — longer than most social apps, and notably longer than the platform it positioned itself to compete with at the time.
The list is still there, and it’s worth reading carefully if you use Threads or are considering it.
The Full List of Categories
Threads collects data across 14 categories, according to its App Store privacy label:
- Contact info — email address, phone number, name
- Identifiers — user IDs and device IDs linked to your account
- Location — both coarse location (city-level) and precise geolocation
- Contacts — your device address book, if permission is granted
- Browsing history — sites and content visited across the broader web
- Search history — searches performed on the platform and on external sites
- Purchase history — transactions linked to your Meta account across Meta properties
- Financial info — payment method details if stored with Meta Pay
- Health and fitness data — health-related content you engage with or search for
- Sensitive info — racial or ethnic origin, political opinions, union membership, sexual orientation
- Usage data — how you use the app, which features you engage with, how long you spend
- Diagnostics — crash logs and performance data from the app
- Other user content — posts, messages, photos, and videos you share
- Inferences — conclusions Meta draws about your characteristics and interests from the above
Categories 9 and 10 draw the most sustained attention from privacy researchers. Most social apps do not list health information or sexual orientation as data they collect or infer. Threads does — because Meta’s systems derive these signals from the content users engage with and the accounts they follow, not from data users explicitly provide.
What “Collects” Actually Means for Sensitive Categories
The terminology in App Store privacy labels can be misleading because it conflates directly provided data with inferred data. Both categories appear under “collects,” but the mechanisms are different.
Health and fitness data
Threads is not reading your medical records. It means that if you follow accounts related to a specific health condition, engage with content about fitness, or interact with posts discussing a medical topic, that engagement pattern is categorized and stored as part of your profile. The behavior is observed and inferred — not directly declared.
This kind of inferred health data can be sensitive for real reasons. Someone who consistently engages with content about a particular chronic illness, mental health condition, or medical procedure has implicitly disclosed something they may not have intended to share with an advertising platform.
Sensitive info including sexual orientation
The same mechanism applies. If you follow LGBTQ+ accounts, engage with related content, or your network activity correlates with known patterns, that characteristic can be inferred and stored as an attribute of your advertising profile. You don’t need to state it. You don’t even need to be aware it’s happening. Engagement history, follow patterns, and content interaction are sufficient.
This is worth knowing explicitly because the privacy risks of having this data stored — and potentially shared — are real, not hypothetical. Inferred sexual orientation data in the hands of a platform that shares data with third parties is a specific and concrete risk for some users.
Browsing history from external sites
Threads itself doesn’t know what websites you visit. But Meta’s tracking infrastructure does. The Meta Pixel — a piece of tracking code embedded on many external websites — allows Meta to associate your web browsing activity with your Meta identity, including your Threads account. If you visit a news site, a healthcare portal, or a financial services site that uses the Meta Pixel, that visit can flow into the same profile that Threads contributes to.
This cross-site tracking is not specific to Threads, but it’s worth understanding that your Threads account exists within a much larger data ecosystem.
How Meta Uses This Data
Advertising
Meta’s primary use of aggregated data across its platforms is advertising. Threads doesn’t run ads in most markets at the time of writing, but Meta’s data model is unified across Facebook, Instagram, WhatsApp, and Threads. Data from all four properties contributes to the same underlying advertising profile.
What you do on Threads — the accounts you follow, the content you engage with, the topics you search — feeds the same targeting system that Facebook advertisers use. Advertisers can target based on inferred demographics, interests, behaviors, and characteristics that include the sensitive categories listed above.
Third-party sharing
Meta’s data practices involve sharing with advertising measurement partners: companies that help advertisers verify whether their campaigns produced results. These partners receive signals from Meta that can include demographic attributes and behavioral data inferred from your activity. You are not directly identified to these partners, but the signals they receive are derived from your specific behavior.
Platform features and safety
Meta also uses behavioral data to rank content, recommend accounts, detect spam and abuse, and enforce its community standards. These are legitimate uses of behavioral data and are part of how any large social platform operates.
Threads DMs and the Encryption Gap
Threads added direct messaging features in late 2025. This is worth addressing separately.
Unlike WhatsApp — which offers end-to-end encryption for messages by default — Threads DMs are not end-to-end encrypted. Meta’s servers can access the content of messages sent through Threads. If you’re using Threads DMs to share personal content, sensitive information, or files you consider private, those items are accessible to Meta and stored under Meta’s data retention policies.
This is a meaningful distinction for anyone who conflates messaging on Threads with secure communication. Signal, iMessage (when sending between Apple devices), and WhatsApp offer end-to-end encryption for messages. Threads does not.
For personal file sharing specifically: content shared through Threads DMs is on Meta’s infrastructure, subject to Meta’s legal obligations, and accessible to Meta under its own terms. It’s not a private channel.
The EU Experience
Meta’s cross-platform data collection and sharing practices have been the subject of sustained GDPR enforcement in the European Union. The outcome has included significant fines and required changes to how Meta handles EU user data.
Threads launched with EU availability deliberately delayed while Meta assessed whether its cross-platform data sharing would comply with GDPR requirements. When it launched in the EU, Meta introduced localized consent flows and restricted some data-sharing practices for EU users.
Under GDPR, EU Threads users have the right to access the data Meta holds about them, request corrections, and request deletion. Meta’s data portability tools, accessible through Account Center, let EU users download their data across Meta properties.
For users in the US, Australia, and most other regions, fewer regulatory protections apply. CCPA gives California residents similar access and deletion rights, but enforcement is more limited.
How Threads Compares to Alternatives
| Platform | Data Categories Collected | E2E Encrypted DMs | Ad Profile |
|---|---|---|---|
| Threads | 14 (including health, sensitive info) | No | Unified Meta profile |
| Similar to Threads, shared infrastructure | No | Unified Meta profile | |
| X (Twitter) | Fewer declared categories | No | Separate X profile |
| Mastodon | Account info, usage; instance-dependent | No | Typically none |
| Bluesky | Account info, usage, public content | No | Minimal; no ads |
Mastodon and Bluesky represent federated or decentralized alternatives with substantially smaller data footprints. The trade-off is network size — both platforms have meaningfully smaller user bases, which affects the utility of the “social” part of social media.
The data gap between Threads and Mastodon or Bluesky is significant if you care about avoiding the Meta profile ecosystem. If you’re already active on Instagram or Facebook, Threads adds to a profile that already exists — the marginal data contribution is less dramatic than it appears if you’re comparing Threads in isolation.
The Trade-Off in Plain Terms
Threads works well for public conversation, has a large installed user base through Instagram integration, and is free to use. The data collection is extensive — the 14-category list is real and includes genuinely sensitive inferences.
The specific practical risks are:
- Sensitive characteristics being inferred from engagement patterns and stored in an advertising profile
- Cross-site tracking connecting web browsing activity to your Meta identity
- DMs not being end-to-end encrypted, making them accessible to Meta
- The full Meta advertising infrastructure being able to target you based on Threads activity even if Threads itself doesn’t display ads
For users who post publicly and treat Threads as a public discussion platform — equivalent to posting on a public forum — the practical privacy exposure is similar to Instagram. Public posts on a Meta platform contribute to a Meta profile. That’s the deal.
For users who expect any of the following from Threads, the platform wasn’t designed for it:
- Private communication that Meta cannot read
- File or memory storage that doesn’t train targeting models
- A place to share sensitive personal content without that content contributing to an advertising profile
Understanding what Threads is designed to be — a public social platform built on Meta’s data infrastructure — makes the privacy label make sense. It collects everything it does because that’s what the product’s business model requires.
The question isn’t whether the trade-off is fair. It’s whether you know what the trade-off is when you make it.