“If the app is free, you are the product” doesn’t mean so much till you stop to think of how free apps monetize user data.
Many free applications do use information about their users to generate advertising revenue. Others make money from subscriptions, commissions, transaction charges, premium features, business tools or financial services. Data supports these business models by helping companies understand users, improve products, prevent fraud and decide which content or offers to display.
Personal information has become valuable because it helps companies answer commercially important questions: Who is likely to watch this video, purchase this product, repay this loan or respond to this advertisement?
The concern is not that every company secretly sells a database containing users’ names and phone numbers. The larger issue is that everyday actions can be converted into detailed profiles, predictions and audience categories that influence what people see online.
Why are most apps free?
Free access allows an application to attract users quickly. A larger audience creates more opportunities to sell advertising, collect transaction fees or persuade some users to pay for premium features.
Google offers services such as Search, Maps and YouTube without a direct subscription for most users. Advertising helps fund those services. Google says it uses account information, activity and inferred interests to make advertisements more relevant, while allowing users to adjust or disable ad personalisation. It also states that it does not sell users’ personal information.
Meta uses a similar advertising model across Facebook and Instagram. Businesses pay Meta to reach selected audiences, while the platform uses information about accounts, activity and interests to determine which users may be relevant. Meta also says it does not sell personal information directly to advertisers.
Other applications use a freemium model. Spotify provides free listening supported by advertising while charging subscribers for an ad-free premium service. Duolingo’s filings explain that it earns advertising revenue from free users while also selling subscriptions and in-app purchases. Canva provides a free design service but charges for premium tools, content and higher AI limits.
What data do applications collect?
The information collected depends on the service and the permissions granted. Common categories include:
- Names, email addresses and telephone numbers.
- Device type, operating system, IP address and advertising identifiers.
- Search history, clicks, viewing time and purchases.
- Approximate or precise location.
- Contacts, photographs, microphone or camera access.
- Payment and transaction records.
- Content uploaded or messages sent through the service.
- Information inferred from behaviour, such as likely interests or purchasing intent.
A music application may study what a person plays, skips and saves. A transport platform needs location data to match riders with drivers and calculate routes. A fintech may collect identity and transaction information to satisfy financial regulations and detect suspicious activity.
Uber’s privacy documentation covers location, trip and service-use information. LinkedIn says it can use profile details, searches, content activity, professional connections and inferred information to personalise advertising.
The important question is whether the data requested is reasonably connected to the service. A navigation app has a clear reason to request location access. A basic calculator requesting contacts, microphone access and continuous location deserves closer examination.
Read also: Are Fitness Apps Compromising Your Privacy?
How data becomes revenue
Data normally passes through several stages. Firstly, the application records events: a user opened a page, searched for shoes, watched a video or completed a payment. Analytics systems organise these events and identify patterns.
Machine-learning systems can then predict which product, song, advertisement or post is most likely to interest the user. An advertising platform may place the user in an audience category such as “interested in affordable smartphones” without giving the advertiser the person’s full identity.
Advertisers compete to show messages to suitable audiences. The platform earns money when an advertisement is displayed, clicked or leads to a purchase.
Google explains that cookies and device identifiers can support advertisement delivery, frequency control, personalisation and performance measurement. LinkedIn similarly uses profile, activity and partner information to target and measure advertisements.
This information also improves recommendations. Research examining TikTok found that watch duration, likes, follows, language and location influence the content users receive. Spotify says its algorithms select and arrange content to provide recommendations specific to each listener.
The same technology can create a better experience and a narrower one. Relevant recommendations save time, but repeated predictions can limit what users encounter and make platforms extremely effective at holding attention.
Do applications sell data or sell access to audiences?
Both practices exist in the wider data economy, but they are not identical.
A company sells personal data when information is transferred to another organisation in exchange for money or another benefit, subject to the applicable legal definition.
An advertising platform may instead keep the underlying information and allow advertisers to select an audience. A retailer could ask to reach users in Lagos who recently showed interest in laptops. The platform displays the advertisement without necessarily revealing each user’s name or contact information.
Google and Meta publicly state that they do not sell personal information. Their commercial advantage comes from controlling the systems that understand and reach audiences.
Companies may still share data with cloud providers, analytics companies, payment processors, fraud-prevention services and other partners. Whether this is lawful depends on the purpose, contract, consent requirements and relevant privacy law.
African platforms use data differently
Africa’s fintech and digital-service companies often make money from transactions rather than advertising.
PalmPay, Moniepoint and Flutterwave use personal and transactional information for onboarding, payments, regulatory checks, fraud prevention and service delivery. PalmPay’s policy describes facial verification for secure onboarding and fraud prevention. Flutterwave says it processes personal information to verify identities, complete transactions and detect unauthorised activity. Moniepoint’s policy identifies fraud, sanctions and credit-reference service providers among its data sources and partners.
Their principal revenue may come from payments, banking services, merchant fees or credit rather than selling advertising profiles. Data is still commercially valuable because it can reduce fraud, improve credit decisions and make services more reliable.
Jumia uses browsing behaviour and optional cookies to personalise products, offers and advertising. Uber uses location and trip data to operate its marketplace. Boomplay combines free, advertising-supported access with a paid subscription offering downloads and listening without advertisements.
These differences show why users should not assume that every free platform follows the same data business model.
What rights do African users have?
Data-protection laws increasingly require businesses to collect information for clear purposes, secure it and respect users’ rights.
Under Nigeria’s Data Protection Act, users have rights including being informed, accessing their data, requesting corrections and objecting to certain processing. Kenya’s Data Protection Act similarly provides rights to information, access, correction, objection and deletion in applicable circumstances. South Africa’s POPIA establishes conditions for lawful processing by public and private organisations.
These rights are not absolute. A financial institution, for example, may be legally required to retain some records after an account is closed. However, an organisation should be able to explain what it collects, why it needs it and how users can exercise their rights.
Read also: Nigeria Leads Anglophone Countries Committee in African Data Protection Efforts
How users can protect their information
Before installing an application, examine its store privacy label, developer identity, reviews and requested permissions.
Pay particular attention to location, contacts, SMS, call logs, camera, microphone, health information, photographs and files. Android and iPhone allow users to review and withdraw these permissions later. Location, camera and microphone access can often be limited to periods when the application is actively in use.
Users should also:
- Reject optional tracking when it is unnecessary.
- Review advertising and privacy settings.
- Remove applications they no longer use.
- Use unique passwords or passkeys and activate MFA.
- Avoid signing into every service through the same social account.
- Download or inspect account data where that option is available.
- Be cautious when an app requests information unrelated to its main function.
Free applications create genuine value. They connect people, support businesses, enable payments and provide access to education, entertainment and productivity tools.
The reasonable goal is not to avoid every service that processes data. It is to understand the exchange: what information the service receives, what benefit the user receives and whether the company provides meaningful transparency and control.
Don’t miss important articles during the week. Subscribe to Techbuild Africa weekly digest for updates



