Viral selfie app Meitu requests permissions like GPS, call, and carrier info that are unrelated to core use, raising questions from security and privacy experts
You've probably seen a Meitu selfie in your Instagram or Facebook feed in the past 24 hours.
Context & Ripple Effects
Meitu spent 2016 building the profile that makes this week's scrutiny matter: a Chinese selfie-app developer with hundreds of millions of monthly active users and a multibillion-dollar valuation, heading toward a Hong Kong IPO of up to $710M at a $5.2B valuation. Its filters then went viral across Instagram and Facebook feeds, pushing the app into Western markets almost overnight.
That virality is what triggered the current story: security and privacy experts are now asking why an app whose core job is editing selfies requests GPS, call, and carrier information it has no obvious use for.
First-order effects
- Users discovering Meitu through their social feeds now face an uninstall-or-keep decision based on permissions rather than filter quality, directly threatening the viral install momentum the app is riding.
- The permission questions land on Meitu's brand at the exact moment it is marketing itself to public-market investors, making data practices part of the IPO narrative whether the company wants them there or not.
Second-order effects
- App stores and reviewers apply the same permission audit to every other viral consumer app crossing borders, so Meitu's episode raises the disclosure bar for the whole category of camera and beauty apps.
- Meitu's hardware ambitions compound the exposure: the later Xiaomi partnership putting Meitu's brand on phones means the same data-collection questions attach to devices, not just one app.
Third-order effects
- If the pattern holds, viral apps from foreign developers will face permission-boundary scrutiny as a standard part of entering Western markets, with data practices functioning as a de facto regulatory and reputational gate ahead of any formal rules.
- For companies like Meitu, valuation becomes tied to trust as much as user counts — hundreds of millions of MAUs cut both ways once each user is also a potential privacy complainant.
The trend: Consumer apps going viral across borders are finding that their data-permission choices, not just their features, now determine how far and how durably they can expand.