QUICK SUMMARY: The official White House app promises it collects no personal data. An independent audit found otherwise: three embedded trackers, including a Russian-founded vendor and a sanctioned Chinese company’s tracking code, more than the news apps it’s supposed to replace. Here’s the kicker: no app-specific privacy policy exists. So there’s no stopping White House app data harvesting activity.
President Donald J. Trump’s White House built an app to deliver “unparalleled access” straight from the source. Nearly 700,000 Americans installed it in its first week. Its privacy policy makes two specific promises: “We will collect no personal information about you,” and “We do not track or record information about individuals and their visits.”
An independent audit of the app’s code found both promises false.
Independent Audit Finds Three Trackers Inside the White House App
Some of what spread online after the app’s launch didn’t hold up. A widely shared claim that the app tracked users’ exact GPS location every 4.5 minutes was later walked back by the same outlets that first reported it: the tracking code exists in the app, researchers confirmed, but there’s no independent confirmation it’s actively switched on. That distinction matters, and this article holds to it.
What doesn’t need walking back is simpler and better documented. An audit conducted through Exodus Privacy, a third-party tool that scans Android apps for embedded trackers and permissions, found the White House app carries three embedded trackers: more than AP News (two) and Feedly (zero), apps built for the identical job of delivering breaking news.
The White House App’s Privacy Policy Never Mentions the App Itself
The app’s published privacy policy is unambiguous: no personal information collected, no tracking, no record of individual visits. Those are direct quotes from the same document every user agrees to before installing it. The document never addresses the app’s actual permissions or its embedded trackers at all: it’s the general whitehouse.gov site policy, applied wholesale to a mobile app with entirely different data behavior.
The App Carries More Trackers Than AP News or Feedly

A White House spokesperson has described the app’s job as delivering breaking news, livestreams, and policy updates. That’s the same function AP News and Feedly perform with two trackers and zero trackers, respectively. The White House app carries more for the identical task.
The permission list goes further than the tracker count. Precise GPS location. Biometric fingerprint access. The ability to modify shared storage. Auto-start at boot. Permission to draw over other apps. Wi-Fi network scanning. None of those map to a stated function in the app’s own tab list: Priorities, Achievements, Affordability, Investment Boom, TrumpRx, Trump Accounts, Border, News, and Social.
Two federal apps offer a useful contrast. IRS2Go requests location, but the IRS discloses exactly why: to help taxpayers find nearby free tax-prep assistance. MyTSA requests location too, and TSA’s own Privacy Impact Assessment states the data stays on the device and is never transmitted. Both agencies wrote down what the permission does and why. The White House app has no app-specific privacy policy explaining any of its permissions.
OneSignal, Elfsight, and Huawei Mobile Services Core Receive App Data
Beyond the fact of the trackers, there’s the question of where the data goes. Researchers who decompiled the app identified OneSignal, a push-notification and analytics vendor, receiving IP addresses, device identifiers, carrier information, and session data on every launch. A second embedded service, Elfsight, is a Russian-founded software vendor. A third tracker identified in the Exodus Privacy audit is Huawei Mobile Services Core, built by a Chinese company the U.S. government has formally sanctioned.
None of this is disclosed in the app’s privacy policy. It isn’t the first time a foreign vendor has shown up inside U.S. government infrastructure this year; hackers breach government networks through supply-chain gaps just like this one, using software weaknesses nobody flagged until it was already deployed.
The app was built under a contract with 45Press, an Ohio-based web development firm with no disclosed prior mobile app experience, awarded by the Executive Office of the President in February 2026. Federal contracting records show an initial obligation of $1.4 million against a total contract value of up to $8.37 million. That’s public money spent on a product that, per independent audit, collects more than free alternatives built to do the identical job, backed by a privacy promise its own code doesn’t keep. The DOGE accountability gap already left a lot of federal contracting oversight unresolved before this app ever shipped.
Deleting the App Won’t Undo Data Already Sent
The app remains available on the Apple App Store and Google Play. Uninstalling removes the app’s ongoing access, though data already transmitted during use cannot be recalled. Reviewing app permissions in phone settings, revoking location and storage access manually, and monitoring for updates to the app’s privacy disclosure are the concrete steps available right now. Federal employees on government-issued phones report the app reinstalling itself after deletion, tied to the mandate issued by the federal CIO’s office earlier this year.
Frequently Asked Questions
Is the White House app actually harvesting user data?
Independent code audits confirm it collects and transmits more data, including IP address, device ID, and carrier information, than its own privacy policy discloses. The word “harvesting” describes that documented gap between promise and practice.
Does the White House app track my exact location?
The app contains code capable of location tracking, but no independent source has confirmed that capability is actively switched on. Treat this claim as unconfirmed, not settled.
What companies receive data from the White House app?
Audits identify OneSignal, Elfsight (a Russian-founded vendor), and Huawei Mobile Services Core (built by a sanctioned Chinese company) as embedded trackers receiving app data.
How does the White House app compare to other news apps?
Exodus Privacy audit data shows it carries three embedded trackers, compared to two for AP News and zero for Feedly, apps built for the same core function.
Is this different from how other government apps use location?
Yes. IRS2Go and MyTSA both disclose a specific, documented reason for requesting location. The White House app has no app-specific privacy policy explaining its permissions at all.
How much did the White House app cost to build?
Reporting places the contract at $1.4 million with an outside developer.
Can I remove the app if it’s already installed?
Yes, through standard app-deletion steps, though data already transmitted cannot be recalled. Government employees on federal devices have reported the app reinstalling automatically under a CIO mandate.