Free tools, paid in data
Say you open Gmail to check a work email, Slack to catch up on a channel, and Notion to pull up a project doc. All free. All convenient. None of them come with a warning sticker about what they’re quietly collecting. But a 2026 analysis of the ten most common workplace apps found that the average one gathers 19 distinct data points and shares about two types of data with outside parties — often without the user realizing how far that information travels. That’s not just a privacy footnote; it’s the real cost of “free” when you’re working from home and your personal and professional lives run on the same device.
Most of the specific numbers in this article come from that Incogni study, which pulled data from Google Play listings for apps like Gmail, Microsoft Teams, Zoom Workplace, Slack, and Notion. The picture it paints is worth sitting with, because it shifts the question from “is my employer watching me?” to “what am I handing over every time I log in?”
What free productivity apps actually collect
The list reads like a privacy inventory you didn’t know you were filling out. Microsoft Teams collects 25 data types; Zoom Workplace collects 23; Microsoft Outlook, 22; Google Meet, 21. Even apps that feel lightweight — Slack, Trello, and Todoist — each collect 17 data types. And here’s the part that often surprises people: six of the ten apps gather data for advertising or marketing purposes, including Gmail, Slack, Notion, Outlook, Todoist, and Zoom Workplace. That means your email subject lines, your project notes, your chat history — they’re not just sitting in a server for your convenience. They’re feeding into systems designed to profile and target.
Notion shares eight distinct data types with third parties — the most in the study. Shared categories include email addresses, names, user IDs, device or other IDs, and app interactions. Several of those go to advertising partners. Notion’s privacy policy permits select ad-tech partners to place tracking tools on user browsers to collect behavioral data. When your workspace contains product roadmaps, HR notes, or client records, the stakes are higher than most users realize.
It’s not just about what the app itself sees. Teams and Zoom Workplace are the only two apps in the analysis that pull precise location data. That means your employer — or the app vendor — could know not just that you’re working from home, but exactly where your home is. And because many employees install these apps on personal devices to meet employer requirements (the BYOD reality), the data being collected includes contact details, financial information, and location that has nothing to do with work.
Third-party sharing and the chain you can’t see
Once data leaves your device, it doesn’t just sit in one place. The Incogni research found that Notion, for example, permits select advertising technology partners to place tracking tools on user browsers. That means the same platform where you draft performance reviews or store client contracts may be feeding behavioral data to ad networks. The EU Data Protection Board issued an opinion in December 2024 raising the bar for how platforms must justify use of personal data in AI model training under GDPR, but enforcement is still catching up to the speed at which these tools evolve.
- Open the privacy settings in each app you use for work — look for “data sharing,” “third-party partners,” and “advertising” sections.
- Disable any permission that allows your data to be used for marketing or analytics, if the option exists.
- Use separate profiles for personal and work accounts on the same app, especially in tools like Notion and Slack where workspace visibility can be broad.
- Review what data the app collects under “privacy policy” or “data collection” — if it’s vague, assume it’s more than you’d like.
The data doesn’t always stay safe, either. Workday, the only app in the analysis that does not allow users to request deletion of their data, confirmed two security incidents in August 2025 tied to its use of Salesforce as a CRM platform. Attackers obtained business contact information including names, email addresses, and phone numbers. Most apps examined have documented breach histories: a January 2026 database leak of 149 million login credentials included 48 million tied to Gmail accounts; a November 2025 breach at Japanese media company Nikkei used malware-stolen Slack credentials to access accounts belonging to more than 17,000 employees and business partners. Zoom, Notion, and Slack have all experienced data breaches. Todoist is the only app in the set with no known connection to a breach — a notable outlier.
The surveillance layer you didn’t install
Beyond the apps you choose, there’s a whole category of software you might not even know is running. Employee monitoring applications (EMAs) can install on work-issued devices and track keystrokes, webcam footage, email communications, and websites visited — often in “invisible mode,” running in the background without a visible alert. A survey of managers in Ontario, British Columbia, and Québec found that the most frequently used EMA apps included Kickidler, Spyera, Flexispy, and Teramind — all of which collect data using at least two highly invasive features such as video surveillance or keystroke logging.
Some monitoring tools run silently in the background, capturing screenshots at intervals, recording keystrokes, or even activating webcams. The data they collect can include personal messages, family conversations, or private documents that appear on your screen. Even when the tool is marketed for productivity, the line between oversight and surveillance gets blurred quickly. A single screenshot can capture something you never meant to share — and once it exists, it can be accessed, leaked, or misused.
The same survey found that 87.1% of owners and managers were at least somewhat concerned about negative impacts on employee trust, and 70.7% said they would be more likely to adopt an app if it did not use invasive features like keystroke logging and video surveillance. Yet 51.7% were still using EMAs despite those concerns. That gap — knowing the harm, deploying the tool anyway — is where the real privacy trap sits.
Protecting yourself without ditching every tool
You don’t need to abandon Slack or Gmail to reclaim some control. But you do need to treat every free app as a trade-off, not a gift. Start by segregating personal and work activity as much as possible. If your employer requires you to use a particular app on your personal device, ask whether a separate work profile or container is available. For video calls, use virtual backgrounds or blur — the research shows that smart measures like those are underused compared to manual ones like covering the camera or muting the microphone. But manual measures work, too: covering your laptop camera with a slide, muting your microphone by default before joining a call, and closing personal tabs before screen-sharing are low-effort habits that dramatically reduce exposure.
If your employer uses monitoring software on a company-issued device, your options are limited — but not zero. You can ask for a clear written policy explaining what data is collected, how long it’s kept, who has access, and whether it includes personal activity. Ontario’s Bill 88, passed in April 2022, was the first notification law for electronic monitoring in Canada, but notification alone isn’t enough. Push for restrictions on data types and collection methods. If the tool captures screenshots, ask if it can be configured to blur or exclude non-work windows. Most importantly, keep personal tasks off that device entirely — use your own phone or a separate personal computer for anything private.
For the apps you do control, review permissions regularly. Many tools default to sharing data with third parties; you can often opt out in privacy settings. Use unique accounts for work and personal use within the same platform — especially in shared workspaces like Notion, where a misconfigured permission can expose your drafts to the entire team. And if you’re in a position to influence your company’s tool choices, push for privacy-preserving defaults and training. The Center for Democracy and Technology’s public opinion polling found that American workers want to know why and how they’re monitored, be able to review all collected data, and have monitoring prohibited off-clock. Those are reasonable demands, not radical ones.
The bigger picture: privacy as a public good
This isn’t just about individual inconvenience. The normalization of pervasive data collection in workplace tools — and the quiet acceptance of monitoring software — reshapes the environment everyone works in. A 2025 survey found that 62% of remote workers reported feeling apprehensive about being monitored. When trust erodes, engagement drops, turnover rises, and the very productivity these tools claim to measure suffers. The Forbes article I read on the subject put it plainly: off-the-shelf tracking tools don’t account for the variety of circumstances different employees face, and rather than boosting performance, they drain motivation and create an adversarial atmosphere.
There’s also a legal dimension that’s still unfolding. The global market for privacy-enhancing technologies is projected to grow from $2.4 billion in 2023 to $25.8 billion by 2033, partly because companies want to analyze worker behavior while technically complying with privacy laws. But as a policy brief from Data & Society and co-authors points out, privacy-preserving AI techniques can become workarounds — they protect data without protecting people. The real issue isn’t the technology; it’s the imbalance of power between workers and employers, and the lack of meaningful avenues for workers to have a say in how data about them is used.
For more on securing your remote work setup, you might find these posts useful: know your rights around remote work data, easy ways to protect your data, and best practices for secure communication.
None of this means you have to become paranoid about every app you open. But it does mean treating free tools with the same skepticism you’d apply to any other product that costs nothing. The data you generate while doing your job has value — to app makers, advertisers, and sometimes to your employer in ways you didn’t agree to. Understanding what’s being collected, where it goes, and what you can do about it is the only real protection available. And that knowledge, once you have it, is hard to unsee.