Meta's Terms: Rules for You, Suggestions for Them
Read Meta's terms across all its products and one thing becomes clear: the fine print is not the ceiling of what Meta takes from you, it is the floor. The terms describe the bare minimum you must surrender to press "accept." What Meta actually does, in scandal after scandal, goes far past anything those documents disclose. And when Meta breaks the kind of rule it enforces on everyone else, the punishment is a line item.
Part 1: What you sign away, product by product
Facebook and Instagram
Post anything and you grant Meta a "non-exclusive, transferable, sub-licensable, royalty-free, and worldwide license" to host, use, distribute, modify, copy, publicly perform or display, translate, and create derivative works from your content. Instagram's terms carry near-identical language. Meta says it does not claim ownership, and technically that is true, but ownership is not the point when you have handed over a free worldwide right to reuse your photos however the business needs.
"Delete" is not an off switch. The license ends when you delete the content "unless your content has been shared with others, and they have not deleted it," and even then copies can persist in backups for up to about 180 days. Meanwhile the Privacy Policy lets Meta collect the content of your messages, everything you view and how you interact with it, identifiers that fingerprint your device, and location estimated from your IP address even when you have location services switched off. And through the Meta Pixel, invisible code embedded across much of the web, it collects the sites you visit and the things you buy while you are nowhere near Facebook. In 2026 Meta began winding down the one tool that let you disconnect that off-site tracking.
WhatsApp encrypts the content of your messages, so Meta cannot read the words. What it is not encrypted against is everything around the words. Under WhatsApp's privacy policy, Meta sees your phone number, your entire address book uploaded on a regular basis (including people who never joined), who you talk to, how often, for how long, from what device, and your rough location, all shareable with the other Meta companies. The metadata is the map of your life even when the messages stay private.
In January 2021 WhatsApp told a billion people to accept a new policy or lose their account. Meta cannot read the encrypted messages themselves, and it does not need to, it already holds everything around them. The change was largely about data tied to messaging businesses, but the flat ultimatum, agree or be locked out of your own conversations, is the tell of who owns the app now, and it drove a mass exodus to Signal and Telegram (CNBC). Ireland's regulator later fined WhatsApp €225 million for not being straight with users about what it collects. Then, in June 2025, Meta put ads inside WhatsApp, breaking the founders' famous "No Ads! No Games! No Gimmicks!" promise. Both founders had already quit over Meta's direction, one walking away from roughly $850 million in unvested stock, telling Forbes, "I sold my users' privacy."
The Ray-Ban Meta glasses
The newest product is the most invasive. As of an April 2025 change, Meta AI with camera access is on by default, and the only way to stop the camera and AI from processing what you see is to disable the wake word entirely, which also kills hands-free control. There is no middle setting. Voice recordings are stored for up to a year to train Meta's products, with no opt-out short of deleting each one by hand. And because no AI runs locally, every time you use an AI feature the footage is shipped to Meta, where the EFF reports contractors have reviewed intimate recordings including people in bathrooms. Asked directly whether it trains AI on glasses photos, Meta would not say.
The people with the least say are the ones not wearing them. Researchers at Harvard wired a pair to facial-recognition tools and identified strangers on the street, pulling names, phone numbers, and home addresses in about a minute. A bystander never agreed to any terms, never saw a policy, and their only warning is a small indicator light that can be defeated with cheap hacks. The terms you accept can quietly conscript everyone around you.
Quest, Threads, and the single profile
Quest headsets read your body: the eye-tracking notice covers gaze data, hand and body tracking capture your movements, and apps can map the furniture in your room. Meta processes the rawest biometric data on-device and deletes it, an implicit admission of how sensitive it is, but a Meta account is still mandatory to use hardware you already paid for. Threads requires an Instagram account, and Messenger only turned on default encryption at the end of 2023. The through-line is one identity: under a single Meta account, your activity across Facebook, Instagram, Messenger, Threads, and Quest is combined into one advertising profile, so a VR session can shape your Instagram ads.
Part 2: What this means for a regular person
Put plainly: you do not have to use Facebook to be profiled by it. The Pixel watches you across the web whether or not you have an account. Deleting rarely deletes. Your contacts are uploaded even for friends who never signed up. The pattern of who you talk to and when is logged even when the messages are encrypted. Your face, your gaze, and the layout of your home can all become training data. And a single login stitches every product into one dossier that follows you around the internet and, increasingly, the physical world. You are not the customer. The profile is the product, and you are the raw material.
Part 3: How many hands touch it, and how cheap it is
Once data reaches Meta it does not sit in one place. The first hands are the millions of other websites and apps that send it in. The Meta Pixel sits on roughly a third of popular websites, and investigations by The Markup found it quietly transmitting the most sensitive data imaginable: 33 of the top 100 US hospitals were sending patient information to Meta, and major tax-filing services (TaxAct, H&R Block, TaxSlayer) were sending income and refund data, which a Congressional report said they shared "recklessly." In 2025 a California jury found Meta liable for collecting menstrual and pregnancy data from the Flo period-tracking app.
This is what made Cambridge Analytica possible. A single personality quiz installed by a few hundred thousand people harvested data from up to 87 million of their friends, because the platform was built to let one app reach across an entire social graph. Around that sits an advertising machine that Meta insists does not "sell" your data, and in the strict sense that is right: advertisers never receive the raw profiles. Instead, businesses upload their own customer lists to match against you, Meta historically bought offline dossiers from brokers like Acxiom and Experian, and ProPublica once catalogued more than 52,000 attributes Meta used to classify users. When Meta announced it would cut brokers loose, the EFF warned it was not telling the whole story.
And the moment data leaks, it stops mattering whether Meta sells it, because the criminals do. In 2021 the personal details of 533 million users, including phone numbers many had never made public, were dumped free on a hacking forum and wired into a bot that sold lookups for pennies. Governments line up too, filing hundreds of thousands of data requests a year. And Meta has turned its reach on rivals and children alike, using the Onavo VPN in a secret project to snoop on Snapchat traffic, and internally studying how to reach teenagers who felt "worthless" and "insecure." Ask how many hands touch your data and the honest answer is: more than anyone can count.
Part 4: When Meta does worse than its own rules
The terms are strict. Meta's own conduct is not. The pattern started early with Beacon in 2007, which broadcast users' off-site purchases to their friends, and ran through the 2014 revelation that Facebook had secretly manipulated the news feeds of 689,003 people to test whether it could alter their moods. None of that was disclosed in any policy a user accepted.
Cambridge Analytica was not just a leak, it was Meta violating a consent order it had already signed with the US government, which is why the FTC's $5 billion penalty remains one of the largest in history. The EU added a record €1.2 billion for unlawful data transfers, and Texas won a $1.4 billion settlement for capturing people's facial geometry without consent. Whistleblower Frances Haugen showed Congress that Meta's own research found its products harm teenage girls, and kept it quiet. Amnesty International concluded Meta's algorithms amplified hate that helped drive the Rohingya genocide in Myanmar. And in 2025, researchers caught Meta covertly linking your web browsing to your app identity through hidden localhost connections on Android, defeating incognito mode on thousands of the most-visited sites, until public disclosure forced it to stop. Time and again, Meta does exactly what its terms forbid everyone else from doing to Meta.
Part 5: The double standard, and Aaron Swartz
Nowhere is the hypocrisy clearer than in how Meta treats copying. Meta aggressively sues anyone who scrapes its platforms for breaching its terms. Yet in Kadrey v. Meta, court filings show Meta itself torrented roughly 82 terabytes of pirated books from shadow libraries to train Llama, and even seeded them back out to other pirates while doing so. One engineer wrote that "torrenting from a corporate laptop doesn't feel right"; another warned it was "beyond our ethical threshold." According to the filings, the effort was escalated to and approved by Mark Zuckerberg, over a dataset executives themselves flagged as pirated.
The hypocrisy is exact. Meta sued the scraper Bright Data for violating its terms, then lost, when it emerged Meta had itself paid Bright Data to scrape other websites. Its own AI crawler may bypass the rules sites use to block it, and the privacy group noyb argues Meta's European AI opt-out breaks the law, which requires opt-in consent, not a buried opt-out form. For all this, Meta's worst case is civil copyright liability. In June 2025 a judge even granted Meta a fair-use win over those specific authors, while carefully noting the ruling did not mean Meta's conduct was lawful in general, only that these plaintiffs argued it poorly.
Now remember Aaron Swartz. In 2010 and 2011 he bulk-downloaded academic articles from JSTOR through MIT's network, using access he was authorized to have, for no commercial purpose. JSTOR itself declined to pursue him. The US Justice Department did not. It charged him with thirteen felonies under the Computer Fraud and Abuse Act, carrying a combined maximum of 35 years in prison and a million dollars in fines. Prosecutors sought years behind bars and refused any deal that would have spared him a felony record. He never made it to trial. Swartz died by suicide in January 2013, at 26.
Hold the two side by side. A young man downloaded knowledge he was allowed to read, hurt no one, and was hounded toward the possibility of decades in prison until he took his own life. A trillion-dollar company pirated 82 terabytes of books, seeded them to strangers, did it on the chief executive's sign-off, for profit, and its punishment is a settlement its lawyers will negotiate down. The law that ended Aaron Swartz's life is the same legal system that, for Meta, rounds down to the cost of doing business.
The bare minimum
Here is the whole pattern in one sentence: the Terms and Conditions are the bare minimum Meta demands of you, a worldwide license to your life, enforced in court, while Meta itself does far worse than anything those terms forbid. They are not scraping the bottom of the barrel of what their own rules allow. They are scraping everything, everywhere, and the rules, it turns out, were only ever written for us.
Sources & further reading
- Meta Terms of Service (primary source, the content license)
- Instagram Terms of Use (the permissions you give)
- Meta Privacy Policy (what they collect)
- Meta's developer docs: what the Meta Pixel is
- Bloomberg/Yahoo: Meta scraps the Off-Facebook Activity disconnect control (2026)
- WhatsApp Privacy Policy (content vs metadata, sharing with Meta companies)
- CNBC: the 2021 WhatsApp policy backlash, delay, and actual scope
- Irish DPC: WhatsApp fined €225M for transparency failures
- WhatsApp in 2012: 'Why we don't sell ads'
- Forbes: WhatsApp rolls out ads, breaking 'No Ads! No Games! No Gimmicks!'
- Forbes: Brian Acton on leaving ~$850M behind and #DeleteFacebook
- TechCrunch: Ray-Ban Meta glasses, AI on by default, voice stored up to a year
- EFF: Think twice before buying or using Meta's Ray-Bans
- 404 Media: Ray-Ban Meta glasses used to instantly dox strangers (I-XRAY)
- TechCrunch: Meta won't say if it trains AI on Ray-Ban photos
- Meta: Quest eye-tracking privacy notice (biometric data)
- Meta: cross-product ad data combination in Accounts Center
- The Markup: 33 of the top 100 US hospitals sent patient data to Meta via the Pixel
- The Markup: tax-filing sites sent financial data to Meta
- The Markup: Congressional report finds tax-prep firms 'recklessly' shared taxpayer data
- National Law Review: jury finds Meta liable in the Flo period-tracker case
- CNBC: Cambridge Analytica affected up to 87 million users
- ProPublica: the 52,000+ attributes Facebook uses to classify you
- EFF: Facebook isn't telling the whole story about ending its data-broker deals
- 533 million users' phone numbers leaked free on a hacking forum
- Meta Transparency Center: government requests for user data
- TechCrunch: Facebook's 'Project Ghostbusters' snooped on Snapchat traffic via Onavo
- MIT Technology Review: Facebook research targeted 'insecure' teens
- CBC: Facebook shuts down Beacon after backlash
- Forbes: Facebook manipulated 689,003 users' emotions for a study
- FTC: the $5 billion penalty for violating the 2012 consent order
- Hunton: the record €1.2B EU data-transfer fine
- Texas AG: $1.4 billion settlement over unauthorized facial-recognition data
- NPR: Frances Haugen tells Congress Facebook harms children
- Amnesty International: Meta's algorithms promoted violence against the Rohingya
- localmess.github.io: the covert localhost tracking research
- Kadrey v. Meta, case docket (N.D. Cal., 3:23-cv-03417)
- Cybernews: Meta torrented 82 TB of pirated books for Llama
- Engadget: lawsuit says Zuckerberg approved Meta's use of pirated books
- PC Gamer: 'torrenting from a corporate laptop doesn't feel right'
- TechCrunch: court rules for Bright Data, the scraper Meta used, then sued
- Fortune: the Meta-ExternalAgent crawler that may bypass robots.txt
- noyb: cease-and-desist over Meta AI training and its opt-out
- Wikipedia: United States v. Swartz