The average smartphone user has 60 to 90 apps, using only ~10 daily and ~30 monthly. As a result, 60% to 70% of apps sit unused in the background, collecting personal data. New analysis by Surfshark revealed that bloatware begins with a brand-new phone, as manufacturers load a substantial number of pre-installed apps onto their devices before they reach the user. Samsung leads with 88 preloaded user-facing apps, followed by Google with 71, Xiaomi with 61, and Apple’s iPhone with 50. Interestingly, some of them include third-party apps like Facebook or Instagram that are privacy-invasive, especially when they are never used and just sit in the background.
“Data collection practices by popular applications, particularly social media platforms and chatbots, raise privacy concerns. While certain data points are necessary for basic operational functionality, entities may harvest information for targeted advertising or may even share it with undisclosed third parties. As a result, users are highly recommended to audit installed applications, review permissions, and remove or disable unused apps. Even never-used applications can gather personal data and link to your device,” explains Tomas Stamulis, Chief Security Officer at Surfshark.
Analysis shows that Samsung smartphones come preloaded with apps from Samsung, Google, mobile carriers, and third-party partners. In Bayton’s database of voluntarily synced Samsung smartphones, 88 user-facing apps were logged as preloaded, and 57% of those were marked by the Universal Debloater Alliance Next Generation project as safe to remove and not affecting the phone’s functionality. For example, the iPhone comes with up to 50 built-in apps, all developed by Apple, and EU users can remove up to 98% of them, compared to 88% in other countries.
35 out of 88 pre-installed Samsung apps are available on Google Play, collecting an average of 13 data types per app. This includes location-category data — such as approximate location (14 apps), precise location (12 apps), and physical addresses (11 apps) — among many other types of information.
Facebook and Instagram collect the most data among Samsung pre-installed apps, with each gathering 37 of 38 data types — accounting for 97% of the 38 data types listed on Google Play. Other third-party apps make the list too, including Netflix, Microsoft OneDrive, and Link to Windows, which collect 12, 15, and 6 data types, respectively.
In contrast, an evaluation of 47 of 50 pre-installed iOS apps available on the App Store collects an average of 8 data types. This includes location-category data, such as approximate location (19 apps), precise location (8 apps), or physical addresses (5 apps). It also includes behavioral data, user-generated content, and sensitive information.
Stamulis adds that linking your data to a single ecosystem may be convenient, but those seeking a more privacy-focused approach can minimize data collection by using third-party apps.
“Relying entirely on pre-installed applications can affect your privacy, as apps don’t always protect user data as you might expect. Shifting to third-party alternatives that are privacy-focused can help minimize data collection, limit overall exposure, and reduce unwanted targeted ads. It can also mitigate the risks associated with potential data breaches as your personal data is not stored in a single database.”
Google phones offer the least flexibility for removing pre-installed apps
Bayton’s database shows 71 preloaded user-facing apps on Google smartphones, with 38% identified as safe to remove by the Universal Debloater Alliance Next Generation project. The 40 apps on Google Play disclose an average of 13 data types collected per app, including physical addresses (15 apps), approximate location (14 apps), and precise location (11 apps).
Meanwhile, Xiaomi smartphones have 61 preloaded user-facing apps, with 57% marked safe to remove. There are 33 apps that can be found on Google Play and collect an average of 16 data types, including physical addresses (17 apps), approximate location (15 apps), and precise location (11 apps).
On both Google and Xiaomi smartphones, Google Gemini and the Google app are the most data-hungry, each collecting 29 of 38 data types. However, both manufacturers include apps that claim to collect no data: on Google devices, these include Password Manager, Pixel Screenshots, and Pixel Studio, and on Xiaomi devices – Weather, File Manager, and Mi Browser.

Guest Post: People miss 60% of AI bots on social media: the polite ones hide best
Posted in Commentary with tags Surfshark on September 17, 2026 by itnerdSurfshark’s analysis of 1,722 participants worldwide shows that people detect only 40% of bot-generated social media comments. The ones people miss most often are positive, friendly, and logic-sounding bots. According to the researcher, positive social media bots can be utilized for social engineering attacks to bypass real users’ defenses.
“On social media, everyone notices the angry trolls. That’s why the angry trolls are the ones who often get caught. In the simulated social media environment, participants flagged half (50.2%) of negative AI-generated bots,” said Luís Costa, Research and Insights Lead at Surfshark.
However, when a bot hid behind a positive and friendly persona, participants’ detection rate dropped to 38%, a huge 12-point gap. Besides, the simulation is active online, and you can test your bot detection skills.
“Often, AI-powered accounts used in sophisticated manipulation campaigns are agreeable, logical, or simply unremarkable. They can support real users’ opinions and just inflate the number of comments in the discussion to make a minority view look like everyone feels the same way. Seldom do people report such accounts.”
Surfshark researcher points out that positive and friendly AI bots on social media are considered more dangerous than those that are confrontational and annoying. By being friendly and logical, bots bypass people’s skepticism. You don’t see them as an enemy or a threat, so you are more likely to turn to private chat, share personal information, click a link they share, or believe their “logical” disinformation, which can subtly shift your political and social opinions before you even realize you’re talking to an AI machine.
During the live simulation, one of the biggest red flags was the use of emojis. Bots that used many emojis were caught over 60% of the time, while those that kept communication simple were detected only 35% of the time. This huge 30.6-point gap shows why relying solely on emojis is a bad way to protect yourself on social media. Any scammer who simply stops using an excessive amount of emojis instantly becomes twice as hard to spot.
Users of text-driven platforms led the simulation: X users achieved a 49% bot-detection rate and were the strongest bot hunters, significantly ahead of users from visual- and video-first platforms like TikTok (38%) and Facebook (39%). This means AI bots on TikTok and Facebook are more likely to manipulate real users.
Is it still possible to detect AI-generated content on social media?
Even automated detection tools are struggling to detect AI-generated content. For humans, well-made AI content is now almost indistinguishable from content generated by a real person. Luís Costa, Research and Insights Lead at Surfshark, shares recommendations on what people should do to protect themselves on social media:
In this video, find more security expert’s tips on how to tell a bot from a human on social media: https://www.youtube.com/watch?v=nwuhIfnRKko
“Bot or Not” live simulation, created by Interaction Design students from Malmö University, inspired the launch of Surfshark’s Cybersecurity Advocacy Fund, which provides up to €100,000 in annual financial support distributed among students, researchers, and creative cybersecurity awareness initiatives worldwide. The application process is now open. You can find more information here.
For complete research material behind this study, click here.
Leave a comment »