The White House app shot to the top of the Apple App Store’s news category last week after its new 24/7 broadcast channel, Trump TV, was swiftly positioned as a legitimate source for news while networks halted their pool coverage.
“The American people are not waiting on those cameras; they are going straight to the Presidency,” the White House said in a news release heralding the app, which hosts the Trump TV stream.
In order to see that messaging, users have to give something in exchange: their data. And they have no idea what the government could do with it.
“The people who do want to hear that message are going to the White House for it, and in doing so, they’re giving up a lot of information about themselves, and that provides the White House with an advantage going into the midterms,” said Philip Fields, a cybersecurity researcher and former FBI intelligence analyst who has researched the app.
Trending
Experts have speculated the data, including the results of political polling hosted by the app, could be used to push campaign messaging onto users, or to report a user to Immigration and Customs Enforcement or the Secret Service. Some think it could be used to make money.
No one can say definitively where the user data ends up. But it’s clear the White House app covertly collects excessive user data and shares it with third-party trackers while sidestepping federal security rules, according to cybersecurity experts and an independent risk assessment conducted by The Washington Sun.
“The bottom line is this app is just not very stable or secure,” said Joseph Gera, a former Apple App Store developer and senior platform engineer. “It’s asking for your location data in real time. It also asks for personal information to access your financial data, to access your messages, to access all kinds of information.”
Federal apps and websites are required to meet federal security requirements designed by the National Institute of Standards and Technology and authorized by security experts within each agency.
The White House declined to comment on multiple questions, including whether its app meets the high standard of federal risk management frameworks, instead referring The Washington Sun to its news release promoting the app’s success.
The White House app drew scrutiny earlier this year over a host of cybersecurity issues that analysts said make data vulnerable for both users and government staffers by regularly sharing their IP addresses, time zones and other data to third-party services like Parsely, OneSignal and a Russian widget service called Elfsight.
Despite those issues, the app remains preloaded on government-furnished mobile devices across the executive branch. After the Trump administration mandated that federal agencies force-install the app onto all government-issued mobile devices, cybersecurity researchers noted that no public security authorization or privacy assessments required under federal law had been completed.
Pushback over the app’s security apparatus forced White House developers to delegate tracking software to third-party services. But the app still includes scripts to monitor a user’s location several times per minute, according to Gera, and it’s unclear how that data is used by the White House or third-party services.
“The way that they’re doing their collection now is harder to discern, because they’ve just used commercial trackers instead,” Fields said.
The app also contains a latent keylogger script sourced online from an amateur developer based in India, according to Gera and confirmed by The Sun’s analysis. Keyloggers most commonly appear in surveillance malware to store written text from a device, but they also can be used as a benign tool to analyze inputs like typing frequency. While it’s unlikely to work on mobile devices, Fields said, it’s still concerning that the White House is using a keylogger web-sourced from an foreign coder.
According to internal app files, the software was developed by 45Press, a self-purported WordPress developer based in Ohio. Public contracts show the company was awarded more than $1.4 million in February to support the White House’s online services. 45Press does not directly answer questions from the media regarding customer contracts.
App marketplaces require developers to disclose what data app developers collect from their users, which platforms like the Apple App Store enforce through a “privacy manifest.”
In the app’s latest version, the White House left that manifest completely blank, implying it collects no data from users despite contradicting findings from cybersecurity experts.
Data collected through the app is sent primarily to a host of third-party service providers, who may sell it to advertisers, state adversaries or back to the federal government, Fields said, adding that federal agencies have admitted to purchasing Americans’ information from data brokers.
“It could be bought and sold by government agencies at this point because they’ve decided that they’re not going to take the Carpenter ruling seriously,” he said. “And they can just go and get ad data for free from the private sector or buy it from them without legal process.”
The Supreme Court ruled in Carpenter v. United States that federal agencies cannot obtain cellphone location data without a warrant.
Federal agencies have gone around the ruling by claiming data sourced from brokers is anonymous and is tied to mobile advertising IDs instead of a name. Experts have pushed back on that claim, arguing that device location data — like home and workplace addresses and commute patterns — make it possible to connect an advertising ID with a person’s real identity, especially when coupled with advanced artificial intelligence tools.
The White House app’s privacy policy explicitly states that data collected “is governed by the third-party website’s security and privacy policies.” It adds that user data can be used to create tailored content and statistical profiles for users, inform policy decisions, or share “information with other government agencies in response to lawful law enforcement requests.”
An unpublished feature within the White House browser extension allowed app administrators to create a political profile on a user, and included an “investigate” button to refer individuals to the Secret Service.
The Trump administration has made a concerted effort to repurpose Americans’ sensitive personal information in consolidated federal databases, according to the Center for American Progress. In an August report, a CAP tech policy analyst detailed how the administration has shared taxpayer and Medicaid records with ICE officials amid DOGE’s push to combine agency records.
“Centralized databases are also more vulnerable to security breaches and internal misuse,” the report states.
In 2015, the Office of Personnel Management suffered a catastrophic data breach that compromised security clearance data of 21 million federal employees and contractors.
One of those employees was Peter Loge, a former Obama-appointed advisor at the Food and Drug Administration who now leads the Project on Ethics in Political Communication at George Washington University.
Loge contends that rather than using user data for political strategy, the White House is more likely to leverage the information to steer supporters driven to the app toward one of Trump’s merchandise or cryptocurrency ventures.
“What we’ve seen is that Donald Trump is a businessman who’s monetizing politics. Therefore, this app is a way to make money,” Loge said. “The other people who could find this information either directly or through several layers of resale are, of course, hostile governments — foreign actors whose interests are the demise of American democracy.”