Prove your SDK honors user consent
Your publishers integrate your SDK however they like, and you have no way to see it. Skanopy runs their apps on a real phone and checks whether your SDK fires at the right moment, and honors the user’s refusal.
What leaves, and who receives it
Email address, phone number, device fingerprint: spotted in the exchanges, with the third party receiving them.
See your SDK the way a regulator will.
Liability no longer stops at the publisher. Since the Court of Justice of the European Union’s ruling on the IAB consent framework (March 2024), the advertising chain falls under joint controllership across the EU. And regulators are extending this to SDK providers: in France, the CNIL’s mobile-app guidance names them explicitly, under inspection since spring 2025. In other words, how a publisher integrates your SDK now involves you too.
Yet that integration happens on the publisher’s side, out of your sight. An SDK that fires before the banner, a refusal ignored, an identifier that leaves despite the user’s refusal: you cannot see any of it from your servers, because it all happens inside the app, on the user’s device.
Skanopy runs real apps that embed your SDK on a real phone, and documents what it does: whether it fires, when relative to consent, whether it keeps sending after a refusal, and what data it transmits. You get a factual, dated and reproducible finding, app by app: proof that your integration is clean, or the precise list of what is not.
What you gain.
The concrete gain, exactly as it appears in the report you receive.
Liability reaches you
CJEU ruling on the IAB framework, CNIL guidance: the SDK provider is in scope, not just the publisher.
Your blind spot on the publisher side
Integration happens inside the app, not on your servers. Real behavior only shows on the device.
Before or after consent
Does your SDK fire before the banner, and keep sending after the user refuses.
Evidence, app by app
A factual, dated and reproducible finding for every app tested: what is clean, what is not.
How Skanopy works.
Point us to the app
Two ways in:
- A Google Play Store link
- A .apk file, for a pre-release before it ships
Skanopy analyzes it
On real phones, a real journey replayed automatically:
- Tracking refused
- Signed in
- Article opened
- Form submitted
Every third-party actor that fires is mapped.
You receive your report
Every fact, named:
- Active third-party actors
- Identifiers shared
- Permissions requested
- Storage access
- Consent-banner compliance
Your questions, our answers.
Without your code. Skanopy runs real apps that already embed your SDK on a real phone, and observes its actual behavior.
The regulatory trend points that way: the CJEU ruling on the IAB framework finds joint controllership, and the CNIL explicitly names SDK providers. Knowing what your SDK does in the field becomes a sensible precaution.
The ones you point us to, or a representative sample of apps that embed your SDK. Each analysis runs on a real app, under real usage conditions.
We observe your SDK’s real behavior on a real phone, and place it in time relative to the moment the user accepts or refuses in the banner. Skanopy documents these facts; it does not issue a TCF or Consent Mode compliance verdict.
No. Skanopy produces a technical, factual and reproducible finding. The legal assessment stays yours, or your counsel’s.
Skanopy analyzes Android apps, and your analyses stay in Europe.
How do you check our SDK without our source code?
Without your code. Skanopy runs real apps that already embed your SDK on a real phone, and observes its actual behavior.