The Hidden Price of Free: How a Global Industry Extracts Value from the People Who Can Least Afford It

A quick loan left Chinedu facing early repayment demands and abuse from a digital lender. Credit: TechCity Media

In 2021, Chinedu needed cash fast. He downloaded a loan app. It asked for his personal details and permission to see his contacts. He said yes. The money hit his account within minutes.

He had a month to pay it back. A week later, the messages started.

Then the lender called his mother.

“Madam, Chinedu is owing us ₦36,000. Tell him to come and pay unless we will delist him. He is a fraudster,”

A message sent to Chinedu’s mother

She was furious. She had heard stories about loan apps calling people’s relatives, but she never expected one to call her about her own son.

Chinedu’s story shows how fast a private money problem becomes public shame. The app did not just chase him for repayment. It used his own contact list to pressure the people who love him, turning a ₦36,000 debt into a fraud accusation aimed at his mother.

This is not one bad app. Borrowers across Nigeria describe the same pattern: lenders calling parents, partners, bosses, and pastors, accusing borrowers of theft, threatening to expose them. This happens because many apps collect far more personal data than they need before they ever release a loan.

By January 2026, regulators had logged thousands of complaints like Chinedu’s. Between March and August 2025, Nigeria’s Federal Competition and Consumer Protection Commission (FCCPC) recorded 1,442 fintech and banking complaints. Those cases helped recover more than ₦10 billion for affected consumers. The Nigeria Data Protection Commission (NDPC) reported more than 400 active investigations into digital lenders in 2023 alone.

The complaints keep coming faster than regulators can clear them. Source: FCCPC and NDPC. Graphic: TechCity Media

Behind every number is a real cost: lost jobs, broken families, ruined reputations. It is built on a simple, ugly economy. Cheap phones. Free apps. Global data markets that turn ordinary people’s information into profit. The people who pay the highest price are usually the ones who can least afford to.

How We Reported This Story

TechCity ran technical audits over several months. We archived the consent screens shown to users in Lagos and in New York. We reviewed independent research on low-cost smartphones and preinstalled software. We installed and tested loan apps ourselves. We reviewed regulatory filings and court rulings. We interviewed 31 people: 22 Nigerian users between the ages of 22 and 65 (including six elders), eight members of diaspora households, and one former content moderator. Every sensitive document and recording is catalogued and protected.

Two Phones, Two Sets of Rules

Open Facebook on a phone bought in Lagos. Open it on a phone in New York. The app looks the same. The privacy choices you get do not.

We tested this ourselves, using the same app, the same account type, from IP addresses in both cities. On the New York account, ad tracking controls showed up early, in plain language, with a clear on/off switch. On the Lagos account, those same controls were buried behind extra taps, shown in smaller type, and switched on by default. Turning tracking off took more work in Lagos than in New York.

Illustrative recreation based on TechCity’s side-by-side test of the same app and account type from New York and Lagos IP addresses. Graphic: TechCity Media

This is not a technical limitation. It is a choice. When regulators demand better consent flows, platforms build them. Ireland’s Data Protection Commission fined TikTok €530 million in 2025, and TikTok changed its practices in response.

Nigeria has shown the same thing can happen here. In July 2024, the FCCPC and NDPC ruled that Meta’s WhatsApp update did not get free, informed consent from users. A tribunal upheld a $220 million fine against Meta in April 2025, the largest share of $290 million in total fines levied by three Nigerian regulators.

When Meta threatened to pull out of Nigeria rather than comply, the FCCPC pointed out that Meta had faced similar penalties in India, South Korea, France, and Australia without ever threatening to leave those markets. The Commission’s response was blunt: “They obeyed.”

National regulators are starting to win against global platforms. Source: Ireland Data Protection Commission and Nigeria FCCPC. Graphic: TechCity Media

A Google spokesperson told us Google offers tools like Privacy Checkup and My Ad Center, and pointed to Play Store rules that ban loan apps from requesting sensitive permissions. Those tools and policies are real. But our own tests found many loan apps kept collecting contact data anyway, using technical workarounds, even after the policy update. Google’s full on-record response to this investigation appears later in this story.

The Phone That Ships With the Problem Already Inside

For many Nigerians, the privacy gap starts before they ever open an app. It starts with the phone itself.

Transsion Holdings, maker of Tecno, Infinix, and itel, sells more phones in Africa than any other company. A Tecno Spark or Infinix Hot model costing under ₦160,000 is often someone’s first computer.

Independent security researchers have raised real concerns about these devices. Lookout has documented preinstalled software on budget phones that quietly sends device data off the phone. Secure-D and Upstream have reported malware, including Triada and xHelper, on some low-cost models. In some cases, the malware survived a factory reset and tried to sign users up for paid subscriptions without their consent.

This matters because a device’s persistent ID, its list of installed apps, and its rough location can all be linked together to track a person across apps and over time. Many of these preinstalled programs cannot be removed through normal settings.

Most buyers never find the privacy settings buried in these phones, especially older users or people buying their first device.

“I bought the phone for the boy to do school work. I did not know the phone itself was sending text messages to people. I feel like someone is watching my family.”

Dauda Ibrahim, 63, a market trader

How Loan Apps Turned Contact Lists Into Weapons

Digital lending met a real need: fast credit without bank paperwork. But many apps asked for far more than they needed to approve a loan. Access to contacts. SMS and call logs. Storage. Location. Borrowers were often asked to hand over their Bank Verification Number, National ID Number, bank details, and a photo of their face. Some apps used free coupons to get people to install them in the first place.

Illustrative recreation of a loan app permission flow, based on TechCity’s hands-on testing of five instrumented apps. Graphic: TechCity Media

Even the paperwork was not honest. Clara, a former loan app employee, told us the loan documents were scripted, and the interest rate on the first page often did not match the rate on the last page. Most customers tapped “allow” on every permission request without reading what they were agreeing to.

“This is real life. I was there. They would call customers and say nasty words to them. We also captured their contact details.”

Clara, a former loan app employee

When a borrower missed a payment, some apps used that stolen access to blast messages to everyone in the borrower’s phone and make automated shame calls. Clara described one case where staff wrote “Rest in Peace” across a borrower’s photo and sent it to his entire contact list. Staff earned commissions based on how much they could pressure people into paying.

A former loan-app employee, Clara, witnessed firsthand how borrowers were harassed and manipulated. Credit: TechCity Media

“Every time I reported to work, I felt like a liar. I had to resign for my peace of mind. That was not life.”

Clara

We tested five of these apps ourselves: Easy Buy, Flash Credit, Eagle Cash, Okada Naira, and True Loan, both from the Google Play Store and as sideloaded files. We recorded every permission request and every action the apps took once installed. Several apps found ways to rebuild a user’s contact list even after Google updated its Play Store rules to ban this practice for personal loan apps.

An academic study found that roughly 30 percent of loan apps approved on Google Play used some form of workaround to get around the ban. Google removed dozens of flagged apps after the study came out, but deletion did not end the problem. Many apps came back as sideloaded files, under new names, distributed outside the Play Store entirely.

The damage lands on real people. Ngozi Okafor, 22, told TechCity that a loan app messaged her entire contact list accusing her of theft.

“My sister called me crying. People were saying I had stolen. I lost a job offer because they called my employer. I had to pay to stop it.”

Ngozi Okafor, 22

Regulators have responded. In July 2025, Nigeria’s DEON Consumer Lending Regulations took effect, requiring clear opt-in consent for loans, banning pre-approved top-ups, and creating real penalties, including personal liability for company executives. But rules on paper cannot stop an app that sideloads under a new name. That takes active technical enforcement.

The Invisible Workforce That Trained Silicon Valley’s AI

This pipeline does not stop at your phone. It reaches into the people who build the AI systems you use every day.

AI needs huge amounts of labeled data. For years, major US tech companies outsourced this work, along with content moderation, to firms operating in Kenya, Uganda, and elsewhere. One of the largest was Sama, based in San Francisco.

Court filings and worker testimony describe pay as low as $1.46 to $3.74 an hour for some moderators, who were repeatedly shown violent and sexual content with little to no psychological support. Several moderators have filed medical affidavits in Kenyan courts documenting PTSD and other trauma.

What some workers were reportedly paid to review the internet’s worst content. Source: court filings and worker testimony. Graphic: TechCity Media

In February 2026, two Swedish newspapers and a Kenyan freelance journalist reported that footage from Ray-Ban smart glasses, sometimes filmed without the knowledge of the person being recorded, was routed to Sama’s annotation teams. In March 2026, a class action lawsuit was filed against Meta and EssilorLuxottica in a US federal court.

Former Sama workers say they labeled intimate footage from people’s homes and personal financial records. Meta later cancelled its contract with Sama, which led to more than 1,100 layoffs at Sama’s Nairobi office, leaving many workers without income or support.

One moderator told us they woke up every morning already thinking about the footage they had to label that day. This was not the first time Sama sat at the center of this kind of harm. The company’s contract with OpenAI ended in 2022 after workers were assigned to label child sexual abuse material.

These outsourcing decisions are made by corporate buyers looking for lower costs. The human cost lands on workers who have the least power to push back.

“Laws without leadership are like medicines without a dose. If the regulator does not enforce deliberately, companies will push the limit.”

Saidu Lawal Mohammed, digital rights lawyer and managing partner, Spectrum Legal Services

Following the Money: How Big Tech Data Reaches Brokers

Put these pieces together and you get a pipeline. A cheap phone collects device data. A loan app collects contact and message data. Platforms track behavior across sessions. Outsourced workers label sensitive footage. Somewhere at the end of that chain, data brokers buy and combine financial, social, and device signals to build profiles they can sell.

Through whistleblower documents and intermediary records, we found technical evidence that data tied to remittances, money sent home by Nigerians living abroad, was packaged in formats that data brokers accept. We could not confirm every contract behind these transfers. Some records remain redacted or were never made available to us. But the pattern is consistent and well documented.

The money involved is enormous. Nigeria received more than $20 billion in remittances in 2024, with 2026 projections closer to $26 billion. Every one of those transfers creates a record: who sent it, who received it, how much, how often, and from what device. Most remittance apps require identity verification, which ties every transaction to a real name.

Every diaspora transfer creates a data trail. Source: reporting cited in this investigation. Graphic: TechCity Media

In the US, financial privacy laws offer some protection, but they do not uniformly stop remittance platforms from sharing aggregated or derived behavioral data with partners. Once that data reaches a broker, it can be combined with social and location data to build a profile of a diaspora household in Atlanta, Houston, or New York, and sold to advertisers, lenders, or political campaigns.

“I send $200 every month for my mother’s healthcare. Then I started getting ads about funeral plans and high-interest loans aimed at migrants. It felt like someone sold my pattern.”

Michael Ayodeji, a remitter based in Atlanta

“I never signed up for my life to be used as a marketing list.”

Elizabeth Nnaji, a remitter in New York

Why Enforcement Keeps Falling Short

Regulation works, but only where it is enforced. Nigeria’s Data Protection Act of 2023 created the NDPC and set clear data rights. The FCCPC used its consumer protection powers to force the removal of abusive apps and rolled out DEON in 2025 to regulate digital lenders. The tribunal ruling upholding the FCCPC’s fine against Meta in April 2025 proved a national regulator can win against a global platform.

A tribunal upheld the FCCPC’s 220 million dollar fine against Meta in April 2025. Source: FCCPC

But enforcement stays fragmented across borders. The UK’s Information Commissioner’s Office told us its authority only covers UK data subjects. Nigeria’s National Information Technology Development Agency told us the Data Protection Act governs how companies process information, but it does not give journalists automatic access to internal company records.

We contacted Meta, TikTok, Sama, Transsion, and the loan apps named in this story by email and certified letter between July 9 and July 22, 2026. Google was the only company that answered on the record.

A Google spokesperson sent us this statement: “We believe that protecting your privacy starts with the world’s most advanced security. That’s why our products protect your data and respect your privacy with industry-leading technology. And because privacy is personal, we put you in control of your personal information with easy-to-use settings. This is how we keep more people safe online than anyone else in the world.”

Google also pointed us to its public policies. The company says its privacy tools, including Privacy Checkup and My Ad Center, work the same way for users everywhere, including Nigeria, and that its Play Store Financial Services policy already requires Nigerian digital lenders to hold a verifiable approval letter from the FCCPC before their app can list on Google Play. That same policy bans loan apps from touching contacts, photos, precise location, and phone numbers outright. The FCCPC has publicly credited Google for this policy on its own website.

Google’s Play Store Financial Services policy sets the rules loan apps must follow to list. Source: Google Play Console Help
Nigeria’s FCCPC publicly welcomed Google’s loan app policy on its own website. Source: FCCPC

Google told us it has taken specific steps to comply with Nigeria’s Data Protection Act, 2023, including new cookie consent choices for signed-out users on Search and YouTube, an updated account creation flow with added consent controls, and formal registration with the NDPC along with an appointed Data Protection Officer. Nigerian users can request access to, correction of, or deletion of their data directly through Google’s data subject request forms.

We take Google’s policies seriously, and where our reporting lines up with them, we say so. Google’s Play Store rules are real, and they go further than most competitors on paper. But our own testing tells a more complicated story once an app is actually live. Even after the policy took effect in May 2023, we found loan apps using technical workarounds to rebuild contact lists the policy was written to block. The FCCPC’s own numbers back this up: an academic study found roughly 30 percent of approved loan apps still circumventing the rules as of January 2026, and Google removed 93 apps after that disclosure went public. A strong policy on paper is not the same as a policy that holds up in practice.

Meta, TikTok, Sama, Transsion, and the loan apps named in this story did not respond by our deadline.

The US Federal Trade Commission had not responded to our public records request by publication and said it was continuing to process it.

Silence is its own kind of answer. Most companies point to their public policies, or say nothing at all. Regulators point to limited staff and legal authority. The internal records, consent logs, and audit trails that would connect a tap on “allow” to a corporate decision remain largely out of reach without a court order or a regulator’s subpoena power.

One court has broken that pattern. In September 2025, Kenya’s Court of Appeal ruled that Meta can be sued in Kenyan courts, rejecting Meta’s argument that the case belonged in the US. It is proof that an African court can assert authority over a US tech platform and win.

What Needs to Change

This is not an argument against global technology or cross-border business. It is an argument for one standard, applied everywhere, and enforced.

Platforms should offer the same default privacy protections to every user, regardless of where they live. App stores should hold every developer to the same rules and actively block apps built to harass people. Phone makers should disclose exactly what comes preinstalled on a device and make it easy to remove software users do not want. Companies that outsource AI labeling work should pay fair wages and provide the same mental health support that in-house staff receive. Remittance platforms should treat every transaction as sensitive personal data and require real, informed consent before sharing it with anyone else. And countries with real market power should set a privacy floor that closes the gap other companies currently exploit.

A Note on the Limits of This Investigation

Our technical evidence is strong and consistent across every test we ran. But it does not prove that every data transfer we traced was authorized by a specific contract. Some internal records remain redacted or unavailable. Confirming exactly which contracts covered which transfers would require access to documents we could not obtain during this investigation.

We filed a public records request with the FTC. The Commission told us it could not respond within the statutory 20-business-day deadline under 5 U.S.C. § 552(a)(6)(A)(i). It said it was continuing to process the request and would contact us if it could not complete the request within the extended time period to discuss modifying the request, alternative processing time frames, or both. The FTC had not provided the requested records by publication. We will update this story if it responds.

We also reached out to Mercy Mutemi, the attorney representing former Sama moderators in Nairobi, for comment. She did not respond before publication

The People Behind the Numbers

Consent records, network captures, and tribunal rulings all matter. But so does a mother getting a call accusing her son of fraud. So does a market trader who never knew his phone was watching him. So does a moderator who still sees the footage when he closes his eyes. So does a son abroad, wondering if the money he sends home is being sold behind his back.

None of this is unavoidable. It is the result of choices made by corporations, regulators, and lawmakers. Choices can change.

If you were harassed by a loan app, worked as an AI labeler or content moderator, or have documents showing how remittance or device data reaches data brokers, contact TechCity at info@techcityng.com. We will protect your identity.

Reporting for this story was supported by the Fund for Investigative Journalism.

Exit mobile version