How Skanopy analyzes a mobile app, from first contact to report
Skanopy is a deep behavioral analysis platform for mobile apps. Here is how an analysis unfolds, with nothing to install and no code to touch.
Google Play’s Data safety section: the declaration nobody verifies
The Data safety section of a Play Store listing is filled in by the publisher, and Google does not check it against what the app actually does.
Transfers outside the EU: where your mobile app’s data actually lands
Transfers outside the EU from a mobile app: adequacy decisions, Standard Contractual Clauses, transfer impact assessments, and how to establish where data goes.
Location data: how it leaves a mobile app, and how far it travels
Location data from mobile apps travels all the way to data brokers. The technical paths it takes, what regulators established, and what a publisher can verify.
Tracking before consent: what the research measured in mobile apps
Independent research measured it across tens of thousands of Android apps: most send data to third parties before any consent. The evidence, study by study.
What France’s top news apps do after you refuse tracking
We took 20 top French news apps, tapped refuse on the tracking prompt, and watched. 95 third-party vendors contacted, thirteen the consent screen never names.

Mobile compliance: does the publisher still have control?
On a major French news app, what leaves the device before and after a consent refusal: vendors fired before any choice, traffic that does not drop after it.
vendor before after First-party 10 46 Taboola 0 45 Digiteka / Ultimedia 0 41
We mapped a major app. Here is everything it emits.
Real-world network observation of a mainstream app: the embedded ad networks, the permissions, the identifiers and the behavioural data that leave the device.
Preparing for a CNIL audit of your mobile app
CNIL audit of a mobile app: how to prepare, what an inspection really checks, and how to audit trackers, SDKs and consent before you are asked.
The CJEU IAB Europe ruling: liability no longer stops at the publisher
The Court of Justice of the EU ruled that the TC string is personal data and that liability across the ad chain is joint. What it changes for adtech vendors.
The CNIL puts SDK providers in scope: what its guidance changes
The CNIL names SDK providers in the chain of responsibility for mobile apps, and inspections began in spring 2025. What adtech vendors should take from it.
An SDK that fires before consent: the vendor’s blind spot
An SDK can fire before the banner or keep sending after a refusal, invisible from the vendor’s servers. Why this behavior can only be measured on the device.
Auditing a mobile app: as essential as a website, far harder
A website audits like an open book. A mobile app is a closed box: encrypted traffic, hardened against analysis. Why auditing it matters, and why it is harder.
TCF and Consent Mode: is the consent signal honored inside the app?
The TCF and Consent Mode encode the user’s choice, but nothing guarantees an SDK honors it inside the app. An overview and a caution for adtech vendors.
Third-party SDKs and trackers: your app, your responsibility
Ad networks, analytics, crash reporting: every embedded SDK processes data under your responsibility as the publisher. How to take back control, with evidence.
Mobile app compliance monitoring: why one-off audits fall short
An app changes with every release, and so do its SDKs. Compliance monitoring continuously verifies what your app collects and transmits, version after version.
The CNIL mobile app recommendation, explained for publishers
Published in 2024 and enforced since 2025, the French DPA’s recommendation sets the bar for SDKs, permissions and consent. What publishers should verify.