Does Avast Spy on You? Jumpshot Facts & 2026 Audit
Avast and its Jumpshot subsidiary did collect and sell detailed browsing data from Avast and AVG products between 2014 and January 2020. The FTC said the data was insufficiently anonymized and the disclosure/consent claims were deceptive. That doesn't prove Avast is secretly selling the same data in 2026: Jumpshot closed, a binding federal order bans advertising sales of Avast-product browsing data, and consumer payments were sent in December 2025. Current Avast software still processes substantial security, usage, device and messaging data. This investigation separates those three facts.
Direct answer: calling Avast “spyware” is technically imprecise: it's legitimate antivirus software, not a covert credential-stealing program. But the historical privacy accusation isn't internet folklore. The FTC documented that Avast products collected granular browsing information and Jumpshot sold it to more than 100 customers without adequate notice or consent. The defensible 2026 statement is narrower: the sale happened, it stopped in January 2020, the final order now prohibits Avast-product browsing-data sales for advertising, and Avast's present policy still deserves scrutiny because antivirus has unusually deep access to files, URLs, email and device activity.
- Avast shut the subsidiary and its data-collection operation in January 2020
- The FTC order bans selling, disclosing or licensing Avast-product browsing data for advertising
- The order requires deletion, consumer notice, express consent rules and a comprehensive privacy program
- Avast now publishes product-by-product data categories and retention periods
- Current apps expose several Personal Privacy controls
- The old data was far more granular than users were led to believe
- The FTC said some products could enable tracking of a particular browser/user
- Current antivirus policy still covers URLs, referrers, samples, identifiers and long usage-retention periods
- Some collection is functional rather than optional analytics
- A legal prohibition and policy disclosure reduce risk; they don't erase the enforcement history
Was Avast spyware? The precise 2026 verdict
“Spyware” normally means software that secretly observes a person and sends information without meaningful authorization, often for theft, surveillance or advertising. Avast Antivirus isn't classified as malware by Windows, independent security labs or this publication. It scans files, processes web traffic and blocks malicious activity as its advertised core purpose.
The label feels plausible because the documented Jumpshot conduct crossed the line users expected from a privacy/security product. The FTC's 12-page complaint said Avast collected browsing information through antivirus software and browser extensions, transferred granular non-aggregate data to Jumpshot and failed to give adequate notice or obtain consent. The regulator also alleged that public explanations overstated aggregation and anonymity.
Use the exact language for the exact period. Between August 2014 and January 30, 2020, certain Avast and AVG products may have supplied browsing data to Jumpshot unless a user opted out. Jumpshot shut down in January 2020. A binding order finalized in June 2024 governs future conduct. We found no primary evidence that Avast continues the prohibited advertising sale in July 2026.
That distinction isn't a defense of the old conduct. It's the standard evidence should meet. “Avast sold browsing histories through Jumpshot” is documented. “Avast still sells every user's history today” needs new proof and currently conflicts with the final order. “Avast collects no data now” is also false: the current Products Policy lists extensive processing, much of it tied to malware detection, app functionality, analytics and messaging.
Avast and Jumpshot timeline: allegation, order and payments
| Date | Verified event | Why it matters now |
|---|---|---|
| 2014 | Avast began supplying browsing data to Jumpshot; the FTC says sales to customers began in this period. | Start of the data period covered by the enforcement record. |
| 2014–2019 | Jumpshot sold data and derived insights; Avast's notices/policies evolved, but the FTC alleged they remained inadequate or misleading. | Explains why an opt-out or “de-identified” label didn't resolve the consent problem. |
| Jan. 30, 2020 | Avast announced it would terminate Jumpshot data collection and wind down the subsidiary immediately. | The documented sale isn't an open-ended present-tense activity. |
| Feb. 22, 2024 | The FTC announced its complaint and proposed $16.5 million order. | Converted reporting and public concern into a formal enforcement record. |
| June 27, 2024 | The FTC finalized the order after public comment. | The advertising-data prohibition and remedial obligations became binding. |
| Feb.–June 2025 | The FTC notified eligible US purchasers; the claims deadline was June 5. | Old “claim your refund” instructions are now obsolete. |
| Dec. 2, 2025 | The FTC sent 103,152 payments totaling nearly $15.3 million. | The administrator says all available funds were distributed; payment scams should be rejected. |
| July 14, 2026 | Avast's current product policy and privacy controls remain published; the final order remains the baseline for current claims. | Users can audit today's data paths instead of relying on a 2020 screenshot. |
A settlement order isn't the same thing as a trial verdict on every sentence in the FTC complaint. Avast's own settlement FAQ says it strongly disagreed with the allegations and characterization while resolving the matter. The order is nevertheless real and enforceable; it doesn't become optional because the company disputed the narrative.
What browsing data did Jumpshot receive and sell?
The FTC described more than generic usage counts. According to the complaint, Jumpshot products could include every URL visited, precise timestamps, browser and device type and city/state/country information attached to a persistent browser/device identifier. Browsing can reveal health concerns, religion, political interests, financial status, location and visits to child-directed content even when a person's name is removed.
Jumpshot sold information and insights to more than 100 customers in advertising, marketing, analytics and data brokerage. The regulator cited an “All Clicks Feed” agreement that permitted an advertising conglomerate to associate Jumpshot data with other broker data at an individual-user level. The complaint says Jumpshot had accumulated more than eight petabytes of browsing information dating to 2014 by January 2020 and had never deleted it during the operating period.
This wasn't a password-database breach. The case concerned browsing behavior collected by products installed with high system/browser visibility. Don't rewrite it as stolen Avast account passwords, decrypted password-manager vaults or malware secretly installed by a foreign attacker; those are different claims requiring different evidence.
The case also didn't cover every Avast user worldwide in exactly the same way. Product, platform, date, privacy setting, account/purchase record and jurisdiction mattered. If you installed an affected product during the period, the safe assumption is that you may have been included unless you had opted out—not that a particular sensitive URL was definitely in a buyer's dataset.
Why de-identified browsing data wasn't safely anonymous
Removing a name or email doesn't make a detailed behavioral timeline anonymous. A persistent identifier lets an analyst follow one browser across days. Repeated home/work locations, highly specific searches, shopping checkouts, social profiles or appointments can provide enough clues to match the timeline to a real person, especially when a buyer is allowed to join it to another data broker's records.
The FTC alleged a mismatch between the data and the promise. Avast told users data would be de-identified and aggregated; the complaint says Jumpshot received granular non-aggregate events and that some products were designed to let customers track specific users or associate browsing histories with identifiers already known to the customer.
This is the core lesson for any “anonymous telemetry” claim in 2026. Ask four questions: Is each event truly aggregated before it leaves the device? Does it carry a stable identifier? Can a recipient combine it with other datasets? Is there a contractual and technical prohibition on re-identification? An answer about removing names covers only the first inch of the problem.
Current policy text should be read the same way. “Unidentifiable statistical data” in a settings description is a category label, not a proof of mathematical anonymity. Look for fields, retention, purposes, recipients and opt-out behavior. If a product can't function without a data category, the vendor should explain that boundary plainly.
Which Avast and AVG products were affected?
Avast's settlement FAQ lists the products and time window used for consumer notices. The list is broader than one free Windows antivirus build and includes AVG, which Avast acquired before the end of the data period.
| Named product | Relevant period | What a user should conclude |
|---|---|---|
| Avast Free Antivirus | Aug. 1, 2014–Jan. 30, 2020 | Browsing data may have been shared unless the relevant setting was opted out. |
| Avast Premium Security | Paid status didn't exclude a product from the notice population. | |
| Avast Mobile Security & Virus Cleaner | Desktop-only assumptions are incomplete. | |
| Avast Secure Browser | A privacy-branded browser was part of the named set. | |
| Avast Online Security | Browser extensions had direct visibility into visited pages. | |
| AVG Online Security and AVG software in the order record | AVG users shouldn't treat Jumpshot as Avast-brand-only history. |
The FTC sent claim notices in 2025 to millions of US consumers who bought Avast antivirus during the covered dates. That notice list was used to administer compensation, not to certify that every recipient's complete browsing history had been sold. The claims deadline has passed; don't send identity or payment data to a site claiming it can reopen the FTC process.
What the final FTC order changed
The final June 2024 FTC order is stronger than “Avast apologized.” It bans Avast and covered subsidiaries from selling, disclosing or licensing browsing information from Avast-branded products for advertising. It also bars misleading statements about how collected data is used and disclosed.
The order requires deletion of browsing information transferred to Jumpshot and products, models or algorithms derived from it; instructions to recipients to delete covered material; consumer notice; affirmative express consent before certain sale/licensing of browsing information from non-Avast products for advertising; a comprehensive privacy program; independent assessments and reporting/recordkeeping.
The prohibition is specific. It doesn't say Avast may never process a URL to block a phishing page, never receive a malware sample or never collect product-usage data. Security software can't deliver cloud reputation and threat intelligence with zero communication. The relevant questions are whether data is necessary, proportionate, disclosed, retained for a defensible period, protected, optional where possible and kept out of prohibited advertising markets.
The order also doesn't guarantee perfection. Compliance depends on implementation, audits and enforcement. For a privacy-sensitive user, a legally binding prohibition lowers one category of current risk while the history raises the burden of proof. Both can be true.
Avast settlement refund status: claims are closed
The FTC's current Avast Settlement page says 103,152 payments totaling nearly $15.3 million went to valid claimants in December 2025 by check, PayPal or Zelle. The deadline was June 5, 2025, and the FTC says all available funds were distributed.
No legitimate helper can add a new claimant in July 2026. The FTC never charges a fee or asks for an account password to release a refund. A surprise text, direct message, search ad or phone call promising a late Avast payment should be treated as an impersonation attempt. Don't provide a Social Security number, bank login, gift-card payment, remote-computer access or one-time code.
If you received a payment and have a question, use contact information reached from `ftc.gov/avast`, not a number in the message. If a check or PayPal window expired, ask the official refund administrator whether any process remains; don't assume a third-party “recovery agent” has authority.
Does Avast still collect data in 2026?
Yes. Collection and sale are different actions. The Avast Products Policy, updated March 12, 2026, lists product-specific service and device data. For desktop antivirus and the current Avast One, it includes IP address, malware samples/files, detection metadata, URLs/referrers, product events and usage, online identifiers, device details, approximate location and installed applications. Optional features create additional paths.
| Current data category | Published purpose/retention example | Privacy reading |
|---|---|---|
| IP address, samples/files, detections, URLs/referrers | Security/service provision, commonly 36 months; malicious URL data may include associated search terms or cookies. | Core protection can need cloud analysis, but fields and duration are material. |
| Product events and usage | Functionality 36 months; messaging up to 24 months; improvement/behavior up to 50 months. | Separate necessary diagnostics from product analytics and promotions. |
| Device identifiers, installed software, approximate location | Compatibility, threat context, behavior, messaging and improvement; several 36–50 month uses. | Broad system inventory is sensitive even without browsing history. |
| Password-safety checks | Usernames and password hashes for 90 days in the desktop-antivirus table. | A hash isn't the plaintext password, but users should know when this feature is enabled. |
| Email Guard | Whole message/metadata/attachments scanned transiently; suspicious raw email may be kept 30 days unless opted out, with longer de-identified artifacts. | One of the most sensitive optional cloud paths; inspect settings before connecting Gmail or other mail. |
| Scam Assistant/Deepfake Guard submissions | Submitted content and conversations may be held around 30 days for service/improvement under current entries. | Don't submit secrets, legal/medical records or authentication material for analysis. |
| VPN operational data | Connection timestamps and transferred amount listed for 35 days in Avast One. | Operational logging is different from website-content logging, but still part of the privacy model. |
These are selected examples, not a substitute for the policy. Mobile, Secure Browser, Online Security & Privacy, Password Manager, AntiTrack, VPN and identity products have separate tables. Read the section for the exact product and platform installed; an Avast One Windows claim shouldn't be copied blindly to Android or a browser extension.
A policy disclosure doesn't prove every field is collected from every person at all times. It defines what the vendor says it may process for listed purposes. Your feature state, consent, app version, platform, country and account determine the actual path. Network capture or a vendor audit would be needed to independently verify implementation.
How to reduce Avast data sharing without breaking protection
- Confirm the exact product and version. Open About/Update and record whether you use new Avast One, legacy Avast Antivirus/Premium Security, Mobile Security, Secure Browser or a browser extension; each has different controls.
- Open Personal Privacy. In new Avast One for Windows, open Settings → General → Personal Privacy. In classic desktop Antivirus/Premium Security, use Menu → Settings → General → Personal Privacy.
- Turn off optional improvement analytics. Disable app-usage analysis in Avast and third-party tools unless you consciously want to contribute. Keep in mind that required service data may still be processed.
- Disable personalized discounts and offers. Turn off data use for personalized discounts, upgrades and third-party product offers where the installed edition exposes those switches.
- Review threat/sample sharing separately. Community IQ and suspicious sample upload can improve detection, but a sample may contain personal data. Choose the setting that matches your risk and avoid submitting confidential files manually.
- Audit connected cloud features. Check Email Guard, breach monitoring, VPN, browser extensions, Password Manager and scam/deepfake submissions. Disconnect features you don't use rather than assuming one master toggle covers them.
- Read and save the current policy. Use the product-specific data table, note retention periods and keep a dated PDF/screenshot of the settings and policy version for future comparison.
- Exercise rights or uninstall cleanly. Use Avast's linked privacy-request portal for access/deletion questions. If trust is gone, export needed data, cancel subscriptions separately, uninstall from the operating system and verify the browser extensions are removed.
Avast's current privacy-settings guide documents platform-specific switches and warns that most Avast apps share anonymous data with Avast and other third parties. Labels and default visibility vary: verify the live screen instead of following a five-year-old screenshot.
Opting out of optional analytics isn't the same as disabling Web Shield or cloud reputation. Don't turn off malware protection blindly. If a required data path exceeds your comfort level, replacing the product is safer than leaving a partially disabled security suite you no longer understand.
Should you keep Avast after the Jumpshot case?
Keeping Avast is a defensible choice if current protection matches your needs, you accept the published processing, have disabled optional sharing you don't want and believe the final order plus current controls sufficiently reduce the historical risk. Our current Avast antivirus review evaluates malware protection, performance, pricing and prompts separately.
Uninstalling is also rational if a security vendor's proven disclosure/consent failure breaks your trust threshold. You don't owe a product another chance merely because malware scores are strong. On Windows, Microsoft Defender is the lowest-friction built-in alternative; Bitdefender, ESET, Malwarebytes and others have different telemetry and business models, not “zero-data” guarantees. Read each current policy before switching.
Don't run two real-time antivirus engines as a privacy hedge. They can conflict and double the amount of privileged software on the device. Choose one primary engine, keep the OS/browser updated, use a standard account, enable MFA and maintain tested offline backups. Those controls reduce risk whichever vendor you choose.
AVG users should apply the same historical analysis because AVG products are named in the order record and both brands are now within Gen Digital. Brand color isn't a privacy boundary. Product-specific current policies and settings still matter.
Avast spying and Jumpshot FAQ
Did Avast sell users' browsing data?
Yes. The FTC alleged that Avast collected detailed browsing information through antivirus products and browser extensions and that Jumpshot sold it and derived insights to more than 100 customers from 2014 to January 2020 without adequate notice or consent. Avast closed Jumpshot in January 2020 and later settled while disputing the FTC's characterization.
Does Avast still sell browsing data in 2026?
We found no primary evidence that the prohibited sale continues. The final FTC order bans selling, disclosing or licensing browsing data from Avast-branded products for advertising. Current Avast products still process security, device, usage and messaging data under the published policy; collection for a stated service purpose isn't the same claim as a Jumpshot advertising sale.
Is Avast spyware or malware?
Avast is legitimate antivirus, not credential-stealing malware. “Spyware” captures why users felt betrayed by the historical covert/deceptive data practices, but it's an imprecise technical label for the current product. Say exactly what happened: certain products supplied browsing data to Jumpshot during 2014–2020, leading to a binding FTC order.
Was AVG involved in Jumpshot?
Yes. AVG Online Security and AVG-related software/data are part of the FTC/Avast settlement record. Avast's FAQ says users of named Avast and AVG products between August 1, 2014 and January 30, 2020 may have had browsing data shared unless they opted out.
Can I still claim an Avast FTC refund?
No. The claims deadline was June 5, 2025. The FTC says it sent 103,152 payments totaling nearly $15.3 million in December 2025 and distributed all available funds. Reject anyone asking for a fee, password, one-time code or remote access to obtain a late payment.
What data does Avast collect now?
The answer depends on product/platform. Current desktop Antivirus/Avast One policy includes categories such as IP address, samples, detections, URLs/referrers, usage events, identifiers, device data, approximate location and installed applications. Optional email, scam, VPN, breach and browser features add their own fields and retention periods.
How do I stop Avast from sharing optional data?
Open the current app's Personal Privacy settings and disable optional product-improvement analytics, third-party analytics, personalized discounts and offers you don't want. Review Community IQ/sample uploads and every connected feature separately. Required service data may still be processed; use Avast's privacy request portal or uninstall if that boundary is unacceptable.
Should I uninstall Avast because of Jumpshot?
Uninstall if the enforcement history exceeds your trust threshold or the current policy still feels too broad. Keeping it's also defensible if you value its current protection, audit the settings and accept disclosed processing plus the binding order. Use one primary antivirus, not two, and evaluate an alternative's current policy before switching.
Final conclusion: documented betrayal, bounded present-tense claim
Avast's Jumpshot history is a severe privacy failure precisely because it came from software marketed to protect users. The FTC record describes granular, persistent browsing information, misleading anonymity claims, inadequate notice/consent and sales to more than 100 customers. The $16.5 million order and nearly $15.3 million distribution aren't a rumor or a minor terms-of-service disagreement.
Accuracy also requires an end date. Jumpshot stopped in January 2020. The FTC finalized its prohibition in June 2024 and paid claimants in December 2025. A current article shouldn't turn those facts into an unsupported claim that the same advertising sale still operates.
The useful 2026 question is what privileged Avast software processes now and whether you accept it. Its current policy is detailed enough to reveal meaningful collection and long retention in several categories; the app exposes useful privacy controls, but not all service data is optional. Read the exact product table, minimize features and sharing, and keep or replace Avast with your eyes open.