Sign in with Google, Apple or Facebook: pros and cons
Social login saves passwords but ties accounts to one provider. See what Google, Apple and Facebook share, when it makes sense and how to review connections.
Login securityPublished
Signing in with Google, Apple or Facebook means a website or app lets another company confirm who you are, instead of storing a password for you. It is convenient and often safer than a short, reused password. The price is that more of your digital life depends on one provider account, and that provider learns which services you use.
How “Sign in with …” works
When you tap the button, the service sends you to the provider, you approve, and the provider returns a signed confirmation plus the data you agreed to share. Technically this is usually OpenID Connect, a layer on top of OAuth 2.0. It is a direct descendant of the OpenID idea this domain was originally created for: one login, many sites.
What each provider typically shares
| Provider | Typically passed to the app | Privacy options worth knowing |
|---|---|---|
| Name, email address, profile photo | Review and remove connections under “Third-party apps and services” in your Google Account | |
| Apple | Name and email address | “Hide My Email” gives the app a unique relay address instead of your real one |
| Public profile and email address, sometimes more if the app asks and you agree | Check the permissions screen and the apps and websites list in your settings |
Exact data depends on the app and the permissions you grant, so read the consent screen once instead of tapping through. The app you sign in to also becomes responsible for the data it receives, under the GDPR for users in the EU.
Hide My Email in practice
With Sign in with Apple you can choose “Hide My Email”. The app then sees an address ending in privaterelay.appleid.com. Mail sent by that app is forwarded to your inbox, and you can stop the forwarding in your Apple Account settings if the app turns into a spam source. Apple describes the feature in its support article on Hide My Email. A side effect: if you later want to sign in another way, the service does not know your real address, so plan an alternative before you rely on this for something important.
Advantages and risks
Advantages
- No new password to create, remember or leak from the service.
- One account to protect well, ideally with a passkey and 2FA.
- Fewer sign-up forms and fewer addresses to manage.
Risks
- If the provider account is suspended, hacked or lost, all linked logins go with it.
- The provider can see which services you use and when you sign in.
- Some services create one account per email address. Mixing social login and email login can leave you with two accounts or locked out.
- Convenience makes it easy to forget old connections that still hold access to your data.
When it makes sense
Social login suits newsletters, shops you use rarely and apps without passkey support, where the alternative would otherwise be a weak password. It is a poor fit for your bank, your work tools and anything you must still reach in ten years. For those, use a unique login stored in a password manager or a passkey directly with the service.
Step by step: clean up and secure your connections
- Secure the provider account first. Turn on a passkey or 2FA for your Google, Apple or Facebook account. Everything else hangs off it.
- List your connections. In each provider’s security settings, open the list of third-party apps and sign-ins.
- Remove what you no longer use. Revoking access does not delete your account at the service, but it cuts the link.
- Add a second way in for important accounts. In the service’s settings, add an email address and a password or passkey, so you are not locked out if the provider account has a problem.
- Check your recovery options. Make sure your provider account can be restored, as covered in our guide to account recovery.
- Mind your email. Many resets run through your inbox, so secure your email account too.
Social login in a company
In a business setting the same pattern appears as single sign-on, where an identity provider you control confirms employees. That gives you central MFA and quick offboarding, which consumer social login cannot offer.
Questions people ask before they tap the button
What if I delete my Google, Apple or Facebook account later? Every service where you signed in only through that account can become unreachable. Before closing a provider account, open the services that matter and add another way in, such as an email address with a password or a passkey.
Should I use the same provider everywhere? Using one provider keeps things simple but concentrates risk. A reasonable compromise is to use social login only for low-stakes services, and a password manager or passkeys for everything else. That way a problem with one account never touches your bank or your work.
Does social login mean the service never sees my password? Correct. The service receives a signed confirmation instead of a password, so a breach at that service cannot expose a password for your provider account. It can still expose the profile data you shared, such as your name and email address.
Is there a risk with “Login with” buttons on shady sites? Yes. Check that the sign-in window is the provider’s real page before you enter anything, and read what the app asks for. If a small app wants access to your contacts or files just to log in, decline.
A quick checklist
- Do I need this account in five years? If yes, create a direct login.
- Is my provider account protected with a passkey or 2FA?
- Have I read the permissions on the consent screen?
- Do I know how to revoke access later?
What to take away
Use social login deliberately: for convenience on low-stakes services, never as the only key to something important, and always with a well-protected provider account behind it.
Frequently asked questions
Is it safer to sign in with Google or Apple than to create a password?
Often yes, compared with a short or reused password. The provider handles authentication, and you can protect that one account with a passkey and 2FA. The trade-off is concentration: if that account is locked or compromised, every linked service is affected.
What does Sign in with Apple share with an app?
Apps can receive your name and an email address. You can choose to share your real address or use Apple's Hide My Email option, which creates a unique relay address that forwards to your inbox. You can switch the relay address off later.
Can I still get into an account if I lose my Google or Apple account?
Only if you planned for it. Many services let you add an email and password, or a passkey, in addition to the social login. Do this for accounts that matter, before you need it.
How do I see which apps I have connected?
Open the security settings of your Google, Apple or Facebook account and look for the list of third-party apps or connected services. Remove anything you no longer use.
More in Login security
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.
How authenticator codes (TOTP) work and how to use them
TOTP codes are the six-digit numbers in authenticator apps. See how they are generated, why they work offline, their limits and how to back them up safely.