If you have linked your TikTok or Facebook account, periodically review your connected apps in those platforms' security settings and revoke access if necessary. Conclusion
In April 2023, a security flaw was exposed when it was reported that a Citibank employee accidentally exposed sensitive customer data while using CapCut’s "screen recording" or "video capture" features. This highlighted a risk inherent in the app's permissions: The app requests broad permissions to access the camera, microphone, and screen recording capabilities. If installed on a device used for work, it poses a risk of capturing proprietary or sensitive information in the background or during recording sessions.
Any information you provide when contacting the help desk, including bug reports and feedback. 2. Automatically Collected Information capcut user data
In certain jurisdictions, CapCut’s privacy policy notes that the app may collect biometric identifiers. This includes facial geometry and voiceprints used for features like body effects, facial filters, and automated text-to-speech tools. While the app states this processing happens on-device whenever possible, the explicit mention of biometric data collection in policy agreements raises red flags for privacy-conscious users. Extensive Device Permissions
Governed by state-level privacy laws (like CCPA), though CapCut has faced class-action lawsuits in the US regarding unauthorized data collection. How CapCut Uses Your Data If you have linked your TikTok or Facebook
CapCut tracks your device model, operating system, IP address, unique device identifiers (like IDFA or GAID), system language, and mobile carrier.
Monitoring user data helps prevent fraud, enforce community guidelines, and comply with local laws. The Privacy Risks: Why Experts Are Concerned If installed on a device used for work,
The policy explicitly states that if ByteDance undergoes a merger, acquisition, or sale of assets, user data is considered an asset that can be transferred to the new entity.
To save drafts to the cloud, allow cloud rendering, or enable social sharing, the app requires access to your content and account data.