How Skanopy analyzes a mobile app, from first contact to report

Skanopy is a deep behavioral analysis platform for mobile apps. Here is how an analysis unfolds, with nothing to install and no code to touch.

Read articleJuly 14, 2026 · 4 min read

Google Play’s Data safety section: the declaration nobody verifies

The Data safety section of a Play Store listing is filled in by the publisher, and Google does not check it against what the app actually does.

July 27, 2026 · 12 min read
Consistency between an app’s privacy policy and its own Data safety listing (Mozilla, 40 of the most popular Play Store apps, February 2023)
Poor16 apps
Needs improvement15 apps
OK6 apps

Transfers outside the EU: where your mobile app’s data actually lands

Transfers outside the EU from a mobile app: adequacy decisions, Standard Contractual Clauses, transfer impact assessments, and how to establish where data goes.

July 26, 2026 · 11 min read
Split of the 530 million euro fine imposed on TikTok (final decision, 2 May 2025)
Transfers, Article 46(1)485 M€
Information, Article 13(1)(f)45 M€

Location data: how it leaves a mobile app, and how far it travels

Location data from mobile apps travels all the way to data brokers. The technical paths it takes, what regulators established, and what a publisher can verify.

July 25, 2026 · 13 min read
Advertising identifiers held in a single database (CNIL decision MED-2018-042, 30 October 2018)
Auctions it did not answer43 million
Auctions it answered25 million

Tracking before consent: what the research measured in mobile apps

Independent research measured it across tens of thousands of Android apps: most send data to third parties before any consent. The evidence, study by study.

July 24, 2026 · 9 min read
At first launch, across 1,201 apps tested (Kollnig et al., Oxford, 2021)
Track before interaction71 %
Ask for consent10 %
Offer a real refusal3 %

What France’s top news apps do after you refuse tracking

We took 20 top French news apps, tapped refuse on the tracking prompt, and watched. 95 third-party vendors contacted, thirteen the consent screen never names.

June 27, 2026 · 8 min read

Mobile compliance: does the publisher still have control?

On a major French news app, what leaves the device before and after a consent refusal: vendors fired before any choice, traffic that does not drop after it.

June 18, 2026 · 7 min read
Requests by vendor family, before any choice then after the refusal
vendor                     before   after
First-party                   10      46
Taboola                        0      45
Digiteka / Ultimedia           0      41

We mapped a major app. Here is everything it emits.

Real-world network observation of a mainstream app: the embedded ad networks, the permissions, the identifiers and the behavioural data that leave the device.

June 11, 2026 · 9 min read
Requests to third parties, by recipient
Google AdMob43 req.
AT Internet11 req.
Batch9 req.

Preparing for a CNIL audit of your mobile app

CNIL audit of a mobile app: how to prepare, what an inspection really checks, and how to audit trackers, SDKs and consent before you are asked.

July 23, 2026 · 8 min read

The CJEU IAB Europe ruling: liability no longer stops at the publisher

The Court of Justice of the EU ruled that the TC string is personal data and that liability across the ad chain is joint. What it changes for adtech vendors.

July 18, 2026 · 5 min read

The CNIL puts SDK providers in scope: what its guidance changes

The CNIL names SDK providers in the chain of responsibility for mobile apps, and inspections began in spring 2025. What adtech vendors should take from it.

July 15, 2026 · 4 min read

An SDK that fires before consent: the vendor’s blind spot

An SDK can fire before the banner or keep sending after a refusal, invisible from the vendor’s servers. Why this behavior can only be measured on the device.

July 11, 2026 · 4 min read

Auditing a mobile app: as essential as a website, far harder

A website audits like an open book. A mobile app is a closed box: encrypted traffic, hardened against analysis. Why auditing it matters, and why it is harder.

July 10, 2026 · 7 min read

TCF and Consent Mode: is the consent signal honored inside the app?

The TCF and Consent Mode encode the user’s choice, but nothing guarantees an SDK honors it inside the app. An overview and a caution for adtech vendors.

July 8, 2026 · 4 min read

Third-party SDKs and trackers: your app, your responsibility

Ad networks, analytics, crash reporting: every embedded SDK processes data under your responsibility as the publisher. How to take back control, with evidence.

June 10, 2026 · 4 min read

Mobile app compliance monitoring: why one-off audits fall short

An app changes with every release, and so do its SDKs. Compliance monitoring continuously verifies what your app collects and transmits, version after version.

June 10, 2026 · 3 min read

The CNIL mobile app recommendation, explained for publishers

Published in 2024 and enforced since 2025, the French DPA’s recommendation sets the bar for SDKs, permissions and consent. What publishers should verify.

June 10, 2026 · 4 min read