
ACaliforniacollege student hasaccusedpopular video-sharing appTikTokin a class-actionlawsuitof transferring privateuserdatato servers inChina, despite the company's assurances that it does not store personaldatathere.
The allegations may deepen legal troubles in the United States forTikTok, which is owned by Beijing ByteDance Technology Co but operates entirely outside ofChinaand has developed an especially devoted fan base among US teenagers.
The company is already facing a USgovernment national security probe over concerns aboutdatastorage and possible censorship of politically sensitive content.
Thelawsuit, filed in the USDistrict Court for the Northern District ofCalifornialast Wednesday and originally reported by The Daily Beast, allegesTikTokhas surreptitiously "vacuumed up and transferred to servers inChinavast quantities of private and personally-identifiableuserdata."
TikTokdid not immediately respond to a request for comment on the allegations but maintains that it stores all USuserdatain the United States with backups in Singapore.
The documents identify the plaintiff as Misty Hong, a college student and resident of Palo Alto,California, who downloaded theTikTokapp in March or April 2019 but never created an account.
Months later, she alleges, she discovered thatTikTokhad created an account for her without her knowledge and produced a dossier of private information about her, including biometric information gleaned from videos she created but never posted.
According to the filing,TikToktransferreduserdatato two servers inChinabugly.qq.com, and umeng.com as recently as April 2019, including information about theuser's device and any websites theuserhad visited.
Bugly is owned by Tencent,China's largest mobile software company, which also owns social network WeChat, while Umeng is part of Chinese e-commerce giant Alibaba Group.
Thelawsuitalso claims that source code from Chinese tech giant Baidu is embedded within theTikTokapp, as is code from Igexin, a Chinese advertising service, which security researchers discovered in 2017 was enabling developers to install spyware on auser's phone.
The legal documents did not provide evidence of thedatatransfers or the existence of Baidu or Igexin source code in the app. Hong and her legal representatives could not immediately be reached for comment.