Detect every compliance risk in mobile apps, automatically

Skanopy runs an app on a real phone and records what it sends, to whom, and when it happens.

Discover Skanopy in 2 minutes.

Declarations show intent. Skanopy shows facts.

Skanopy runs an Android app on a real phone and records what leaves it: which data, to which third-party actors, before or after the user’s choice.

For each verification method: what you get without Skanopy, and with it.
Without SkanopyWith Skanopy
The questionnaireWhat the teams believe they integrated.The SDKs actually present, including the ones nobody declared.
The SDK listWhat ships in the app, not what runs.Which ones actually run, when, and what they send.
The consent bannerThe vendor list it declares, with no way to check it.The ones it leaves out, firing anyway.
The code scanWhat the publisher wrote, not what the third-party kits do.What a kit does once running, and what its server asks it for next.

Everything a single analysis surfaces, powered by cutting-edge technology.

Privacy policy, declarations, SDK list: none of it tells you what the app does at runtime. An automated analysis on a real phone shows it.

Where the data goes

Every server contacted, the country it answers from, and the organisation hosting it.

Netherlands2
EU / EEA member
Equativ via LeaseWeb B.V.prg.smartadserver.com
Magnite via Magnite, Inc.prebid-server.rubiconproject.com
4 countries · 2 outside EU

What each actor is for

Each actor classified and described against a precise reference: advertising, analytics, social networks and many more.

adssocialstats

What carries on after a refusal

The user refuses tracking at launch. Here is what stops, and what carries on.

Advertising15Analytics00 s2 min

What leaves, and who receives it

Email address, phone number, device fingerprint: spotted in the exchanges, with the third party receiving them.

TypeValueThird party
Email address
m•••••@gmail.com
Batch
Phone number
+33 6 •• •• 21 47
Adjust
Device fingerprint
Xiaomi/beryllium/beryllium:10…
Google

A journey you describe

The measurement covers that journey, not just the app opening.

You describe

Refuse cookies, sign in, open an article, submit the contact form.

The analysis runs
  • Tracking refused
  • Signed in
  • Article opened
  • Form submitted

The banner, criterion by criterion

Every criterion recorded as the user actually meets it.

Accept and Reject given equal weightReject button present
Settings button presentWithdrawing consent just as simple

Active, but not declared

The actors the app really fires, against the list the banner announces.

admoxtraxr
bidly

Nothing to install, nothing to configure

You give a link, you get a report. Within 48 hours.

  1. Point us to the app

    Two ways in:

    • A Google Play Store link
    • A .apk file, for a pre-release before it ships
  2. Skanopy analyzes it

    On real phones, a real journey replayed automatically:

    • Tracking refused
    • Signed in
    • Article opened
    • Form submitted

    Every third-party actor that fires is mapped.

  3. You receive your report

    Every fact, named:

    • Active third-party actors
    • Identifiers shared
    • Permissions requested
    • Storage access
    • Consent-banner compliance

What the app does puts the publisher on the hook, even unknowingly.

Every third-party actor that fires puts the publisher on the hook, even unknowingly. Skanopy makes that activity visible and verifiable.

Grounds
€530MTransfers of European users’ data to China.Irish DPC2025

The Irish DPC found that European users’ data was accessible from China without protection equivalent to EU law. During the proceedings, TikTok acknowledged that data had in fact been stored on Chinese servers, contrary to its earlier statements.

€150MRefusing cookies made harder than accepting them.CNIL2022

On google.fr and youtube.com, a single button accepted cookies while refusing them took several clicks. The CNIL held that this asymmetry discouraged refusal, and paired the fine with an injunction carrying a daily penalty.

€60MAdvertising trackers set without collecting consent.CNIL2022

Issued the same day as the Google decision, on the same ground: refusing cookies took more effort than accepting them. The CNIL acts here under rules derived from the ePrivacy directive, which lets it proceed without the GDPR one-stop-shop.

€40MTargeted advertising with no proof of consent, upheld by France’s highest court.CNIL2023

Criteo tracks users for advertising retargeting but could not demonstrate that consent had actually been collected by its publisher partners. The CNIL also found failures in transparency and in handling data-subject rights.

€35MAdvertising cookies dropped before any consent.CNIL2020

Advertising cookies were dropped on arrival at amazon.fr, before any action by the visitor, and the notice shown did not mention their advertising purpose.

€8MAd identifier read on the device without consent, on the App Store.CNIL2023

On iOS 14.6, the identifiers used to personalise App Store advertising were read without prior consent, at the same time as Apple required that consent from third-party apps.

€6.5MData shared with advertising partners without valid consent.Norway2021

The Norwegian authority sanctioned data sharing with advertising partners: merely being a Grindr user reveals a sexual orientation, sensitive data requiring explicit consent. The amount initially considered was reduced after the company’s submissions were examined.

€3MDevice identifier read for advertising despite tracking refusal.CNIL2022

The mobile games publisher read a technical identifier for advertising purposes although the user had refused tracking in the iOS settings. A refusal expressed at the system level was therefore not enough to stop it.

The GDPR provides for fines of up to €20M, or 4% of worldwide annual turnover.

I built these tools for the web. I bring them to mobile.

Mohamed, Founder, Skanopy
Mohamed
Founder, Skanopy

At Didomi, the European leader in consent management, I designed the compliance monitoring that watches the web: trackers, cookies, evidence. I guided dozens of large European publishers, across media, news and e‑commerce, to compliance.

On mobile, it is the same problem, more opaque, and nobody is really addressing it.

I built Skanopy to bring to apps what proved itself on the web.

So what does the app you answer for really do?

A free flash audit. Skanopy analyzes the app and emails you a first compliance report within 48h: the third-party actors it really contacts. Nothing to install on your side.

Get your flash audit