• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechTikTok

TikTok’s effort to wall off U.S. user data only focused on the ‘front door’ while leaving the back door wide open, former employees say

Alexandra Sternlicht
By
Alexandra Sternlicht
Alexandra Sternlicht
Down Arrow Button Icon
Alexandra Sternlicht
By
Alexandra Sternlicht
Alexandra Sternlicht
Down Arrow Button Icon
April 29, 2024, 6:30 AM ET
TikTok CEO Shou Zi Chew.
TikTok CEO Shou Zi Chew.

TikTok’s high-profile push to wall off U.S. user data from its China-based parent, as critics had demanded, failed to cut ties between the two because of its complex computer network structure, says the company’s former lead technical program manager for security engineering.

Recommended Video

ByteDance, TikTok’s owner, retained control over some computer systems used by TikTok employees including messaging as well as product and tech management software, according to Patrick Spaulding Ryan, who led TikTok’s security compliance from March 2020 to June 2022. 

Employees routinely shared user data, including U.S. user data, on these internal systems for testing, product development, and troubleshooting, said Ryan, whose account was corroborated by another former employee who left TikTok in early 2023. The practice left U.S. user data vulnerable to snooping by China-based ByteDance workers, Ryan and the other source said, at least while both were still on TikTok’s payroll. 

“There’s a front door that everyone is looking at, but the way to access the network is through employees,” said Ryan.

The allegation further undermines TikTok’s insistence that it kept U.S. user data out of the hands of its parent company. Critics have worried that the data could be used by Chinese government officials to spy on Americans, whose locations and online behaviors are tracked in minute detail by online services like TikTok, though there is no evidence of this actually happening. 

In response to the latest allegations, a TikTok spokesperson said in a statement: “This reporting is inaccurate and is clearly driven by anonymous sources with a preconceived agenda.” TikTok’s user data, the company said, was stored in Virginia and Singapore in 2022, and away from China. It declined to respond to allegations that some of its enterprise systems were hosted in China though at least 2022. 

On Wednesday, President Biden, worried by potential snooping, signed a bill that forces ByteDance to sell TikTok to a non-China-based company. The law gives ByteDance nine months to sell TikTok, with a potential three month extension, if needed, or face a ban on TikTok in the U.S. 

In a statement on X, the former Twitter, TikTok described the new law as unconstitutional and said it would challenge it in court. “We believe the facts and the law are clearly on our side, and we will ultimately prevail. The fact is, we have invested billions of dollars to keep U.S. data safe and our platform free from outside influence and manipulation,” TikTok said. 

In 2021, while facing a U.S. ban by then-President Trump, TikTok started an initiative to keep U.S user data away from ByteDance. The company ultimately beat back the ban, but continued what’s known as Project Texas, a $1.5 billion effort to store U.S. user data in the U.S. within a secure cloud environment hosted by tech giant Oracle. 

“That server is in China; it’s run by the Chinese.”  

The separation of TikTok’s U.S. user data into its own system, and away from other systems used by the rest of the company, put the team that manages U.S. data in an unusual place while he worked there, says Ryan. In order to communicate and cooperate with colleagues, the so-called U.S. Data Security team, or USDS, which was focused on keeping U.S. user data sequestered, had to frequently move data from its isolated environment, says Ryan and the other former TikTok employee. 

This ex-TikTok employee, who would speak only on the condition of anonymity for fear of TikTok retaliating by seizing the restricted stock units that person holds in the company, says USDS had its own version of Lark, TikTok’s proprietary Slack-like internal communications system. The Lark platform was, along with U.S. user data, hosted in an Oracle data center in the U.S. Yet, the team rarely used that version of Lark because TikTok workers elsewhere in the company didn’t have access, making it impossible for USDS workers to communicate outside of their team. Instead, they used a different version that all employees could access, called Feishu by Chinese workers, that was controlled by ByteDance in China, says Ryan and the other ex-TikTok worker. 

“When [USDS] makes any decisions, they have to be in the Chinese corporate version of Lark or Feishu, as people want to call it,” the former TikTok worker says. “That server is in China; it’s run by the Chinese.”  

In response to Fortune’s question about where Lark’s servers are located, a TikTok spokesperson said they’re hosted in multiple regions, including in the United States. The spokesperson declined to say whether he was referring to the servers used by TikTok specifically or more widely, including by TikTok corporate customers that license Lark for their internal employee messaging systems. The version of Lark that is licensed to enterprise customers has its main servers outside of China—in Singapore and other countries, says Ryan.

TikTok has given conflicting timelines for when it completed shifting the version of Lark used by U.S. data security workers to be entirely in the U.S. Asked by The New York Times in May 2023 about the topic, a TikTok spokesperson said U.S. user data was still being moved. When that transfer was complete, messages involving U.S. user data would be hosted on a separate “internal collaboration tool” (alluding to the U.S.-based Lark), the spokesperson said.

But more than a year later, TikTok’s policy team gave a different story in a post on X. It said the “secure environment for protected U.S. data,” overseen by the U.S. data security team, had been completed in January 2023—months before the Times published its story. 

In response to a question by Fortune about the discrepancy, a TikTok spokesperson provided yet another timeline. In this telling, the secure data environment, or servers and data centers, for the U.S.-only version of Lark was completed in January 2023. But Project Texas, the actual isolation of U.S. user data within that infrastructure, is ongoing, the spokesperson said without giving an expected date of completion. 

Some of TikTok’s other software that is used by employees to do their jobs also leaves the door open to monitoring by ByteDance’s China-based workers, Ryan said. That’s because these services are mostly hosted in, or accessible from ByteDance and TikTok’s internal network, which is largely based in China, says Ryan. In theory, ByteDance workers with certain clearances may be able to see what U.S.-based TikTok employees using these systems are doing. However, Ryan couldn’t point to specific instances of U.S. user data being shared across these systems, which included Atlassian’s Jira product management software and Asana, used for tracking the status of tasks assigned to workers and for project management.

TikTok’s spokesperson responded to the allegations that ByteDance could access internal TikTok systems by invoking its effort to isolate U.S. user data through Project Texas. But the company also acknowledged that Project Texas is incomplete, leaving open the possibility that workers in China can still gain access. 

Ryan pointed to Atlassian’s Jira product management software, used within TikTok and ByteDance, as a potential weak point. An Atlassian spokesperson couldn’t say whether ByteDance employees in China have access to TikTok’s version because customers using the on-premise version, as Ryan described at TikTok, decide themselves about the security settings and other configurations. This includes “where they choose to store or process data,” the Atlassian spokesperson noted in an emailed statement. 

Ryan said TikTok also relied on a second service called Feishu Project that ByteDance-built and is used for tracking projects. This service, which is used far more frequently than Jira by TikTok employees, is also hosted in China, according to Ryan.

TikTok did not directly address these allegations about privacy vulnerabilities created by third-party systems. 

TikTok has faced a deluge of news reports from various media outlets about vulnerabilities in its data practices. For example, last week, Forbes reported that ByteDance workers in China could access U.S. advertiser data, including tax information. And last year Forbes reported that TikTok stored creator data in China. Also this month, Fortune published an article in which former TikTok workers described the service’s close ties with ByteDance despite TikTok’s claims of independence. 

In response, several federal officials went on the offensive against TikTok, before ultimately passing the TikTok bill into law. Federal Communications Commission Commissioner Brendan Carr summarized Fortune’s story, noting that an employee sharing U.S. data in spreadsheets with counterparts at ByteDance in Beijing occurred after TikTok’s Project Texas started. Meanwhile, Sen. Josh Hawley (R-MO), called the Fortune article, “Piece of evidence #10,571 that TikTok is transferring Americans’ data to China. And lying about it. Constantly.”

Join us at the Fortune Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
Alexandra Sternlicht
By Alexandra Sternlicht
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Photo of vegan cheese products
AITech
A Mark Cuban–backed vegan cheese company trained AI to scrutinize cardboard boxes. It’s saved $400,000
By Jake AngeloMay 1, 2026
9 hours ago
Young trade worker learning on job
SuccessHiring
Forget Big Tech: Small businesses will hire nearly 1 million grads in 2026—and some of the hottest roles are gloriously AI-proof
By Emma BurleighMay 1, 2026
10 hours ago
Andrew McAfee
SuccessCareers
MIT AI expert warns automating Gen Z entry-level jobs could backfire—and cost companies their future workforce
By Preston ForeMay 1, 2026
10 hours ago
duke
Big TechAmazon
Amazon Prime Video reaches deal with Duke Blue Devils to air 3 games per season
By The Associated PressMay 1, 2026
12 hours ago
valerie
CommentaryLayoffs
Tesla’s former HR chief: the AI layoff panic Is built on a false premise—here’s what most workers need to know
By Valerie Capers WorkmanMay 1, 2026
13 hours ago
AI
AIdisruption
Meet the Americans dismissing AI hype and using it with ingenuity: ‘The efficiencies gained out of it have been tremendous’
By Cathy Bussewitz and The Associated PressMay 1, 2026
13 hours ago

Most Popular

Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
Personal Finance
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
By Fatima Hussein and The Associated PressMay 1, 2026
13 hours ago
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
1 day ago
The U.S. economy is booming — just not where 50 million Americans live
Commentary
The U.S. economy is booming — just not where 50 million Americans live
By Derek KilmerMay 1, 2026
17 hours ago
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
Conferences
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
By Nick LichtenbergApril 29, 2026
3 days ago
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
4 days ago
Exclusive: America's largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
Banking
Exclusive: America's largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
By Nick LichtenbergApril 29, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.