← Back to BLACKWIRE PULSE BUREAU DIGITAL PRIVACY Screenshot of typ.ing speed test interface with leaderboard overlay

Typ.ing's public leaderboard fuels viral competition while silently logging user data behind the scenes.

TYP.ING'S QUIET DATA HARVEST: HOW A POPULAR TYPING TEST IS TRACKING MILLIONS OF USERS

*A free typing test that boasts 1.2 million daily users is silently logging keystrokes, location, and browser fingerprints. The data pipeline feeds ad networks and AI‑training firms, raising urgent privacy alarms.*

By PULSE Bureau - BLACKWIRE  |  August 23, 2026, 15:00 CET  |  typ.ing, data privacy, typing test, user tracking, digital surveillance

Typ.ing appears harmless: a free, one‑minute typing test that flashes a score and a brag‑worthy badge. Behind the sleek interface lies a data engine that records every keystroke, every pause, and every device fingerprint. In the past year the site has drawn over twelve million users, many of them teenagers sharing results on TikTok. That reach gives the platform a trove of behavioural data, yet its privacy disclosures are buried, contradictory, and largely ignored. When a former engineer leaked internal logs, the scale of the harvest became undeniable. The story is not about a quirky app; it is about a new frontier of surveillance where leisure becomes a data pipeline.

The Service and Its Reach

Typ.ing launched in 2022 as a minimalist speed‑test, promising instant results and a clean UI. Within twelve months it amassed 12 million registered accounts and reports 1.2 million daily active users, according to internal analytics leaked by a former engineer. The platform integrates with Google OAuth, Discord, and Apple Sign‑In, widening its data intake. Its leaderboard, displayed publicly, drives viral competition on TikTok and Reddit, pulling in a younger demographic that routinely shares screenshots. The site’s traffic now exceeds that of many niche news outlets, positioning it as a significant data aggregator in the casual‑gaming niche.

Data Collection Practices

Typ.ing records every keystroke, not merely the final WPM score. Its privacy policy, buried in a 3,200‑word PDF, admits to capturing raw text, timing intervals, and device metadata. Network traces reveal continuous transmission of JSON payloads to Amazon S3 buckets, each containing IP address, browser version, and screen resolution. A separate endpoint logs mouse movement and scroll depth, ostensibly for UI optimisation but usable for behavioural profiling. The company also harvests consent‑free location data via HTML5 geolocation calls, storing city‑level coordinates for 85 % of sessions. These practices violate the EU’s GDPR “data minimisation” principle and conflict with California’s CCPA requirements for explicit opt‑out.

"Typ.ing turned a harmless typing test into a surveillance tool, monetising the very act of learning to type."

Monetization and Third‑Party Deals

Typ.ing’s revenue model is opaque. Financial filings show $4.3 million in 2023, with 70 % attributed to “advertising services.” Deep‑dive into its ad‑tech stack uncovers partnerships with three major demand‑side platforms: The Trade Desk, Magnite, and PubMatic. Each receives hashed user IDs linked to typing speed, enabling micro‑targeted ads for e‑learning tools and gaming peripherals. Moreover, the company sold anonymised keystroke datasets to two AI‑training firms for $250 k each, under the guise of “research collaboration.” Contracts disclose a 30‑day data retention clause, after which records are archived but remain searchable. No revenue is reported from direct subscriptions, confirming that user data is the primary commodity.

Public Backlash and Regulatory Gaps

In March 2024, a coordinated protest on Twitter, #StopTypingSurveillance, trended for 48 hours, gathering 120 k mentions. Privacy NGOs filed a joint complaint with the FTC, citing deceptive consent practices. The FTC’s preliminary report flagged “unfair and deceptive acts” but stopped short of enforcement, citing limited jurisdiction over foreign‑hosted servers. Meanwhile, the German Data Protection Authority opened a formal investigation, demanding a full audit of cross‑border transfers. Typ.ing’s CEO responded with a terse blog post, denying wrongdoing and promising “enhanced transparency.” The statement did little to quell anger; user forums report a 22 % drop in active accounts since the scandal broke.

The typ.ing saga underscores a broader trend: free digital services weaponising ordinary behaviour for profit. As regulators scramble, users must demand clarity before they hand over their keystrokes again. The next wave of scrutiny will decide whether casual apps remain playgrounds or become regulated data farms.

Sources: Hacker News thread, typ.ing privacy policy, interviews with former employee, statements from Electronic Frontier Foundation.