How Skanopy analyzes a mobile app, from first contact to report
Skanopy is a deep behavioral analysis platform for mobile apps. Here is how an analysis unfolds, with nothing to install and no code to touch.
A push notification SDK sent 36 categories of data for four years. The publisher had no idea.
On 9 September 2026, the Spanish data protection authority found that a public app had been sending names, email addresses and GPS coordinates to a third party through a misconfigured notification module. What the decision establishes, and what it changes for publishers.
The Android advertising ID: personal data, not a technical setting
GAID, AAID, AD_ID: Android’s advertising identifier is personal data. Who can read it, when it turns to zeros, what to use instead, and what regulators expect around it.
real value the user changed nothing
AND the app declares the AD_ID permission
string of zeros the user deleted the identifier in the AndroidGoogle Play’s Data safety section: the declaration nobody verifies
The Data safety section of a Play Store listing is filled in by the publisher, and Google does not check it against what the app actually does.
Transfers outside the EU: where your mobile app’s data actually lands
Transfers outside the EU from a mobile app: adequacy decisions, Standard Contractual Clauses, transfer impact assessments, and how to establish where data goes.
Location data: how it leaves a mobile app, and how far it travels
Location data from mobile apps travels all the way to data brokers. The technical paths it takes, what regulators established, and what a publisher can verify.
Tracking before consent: what the research measured in mobile apps
Independent research measured it across tens of thousands of Android apps: most send data to third parties before any consent. The evidence, study by study.
What France’s top news apps do after you refuse tracking
We took 20 top French news apps, tapped refuse on the tracking prompt, and watched. 95 third-party vendors contacted, thirteen the consent screen never names.

Mobile compliance: does the publisher still have control?
On a major French news app, what leaves the device before and after a consent refusal: vendors fired before any choice, traffic that does not drop after it.
vendor before after First-party 10 46 Taboola 0 45 Digiteka / Ultimedia 0 41
We mapped a major app. Here is everything it emits.
Real-world network observation of a mainstream app: the embedded ad networks, the permissions, the identifiers and the behavioural data that leave the device.
The CNIL recommendation on mobile applications, explained for publishers
Which version is in force, who carries which obligations, what triggers consent and the four cases that exempt it: the CNIL recommendation read for a publisher.
The duty to inform: the 2026 European action, and what a mobile app struggles to declare
On 19 March 2026, 25 European authorities launched a coordinated action on Articles 12 to 14 of the GDPR. What they are checking, and why a mobile app’s privacy information has to be demonstrated rather than drafted.
Android permissions: what minimization means for your app
Normal, dangerous, special: what Android permissions really open, why a permission is not consent, and how minimization is judged.
CNIL inspections in 2026: the priority themes, and what they change for your mobile app
The CNIL’s 2026 priority inspection themes, the share of inspections they really cover, and what that changes for a mobile app.
Age verification in mobile apps: what the 2025 formal notices announce
The CNIL’s 2025 enforcement report lists apps put on formal notice over age control of minors. What it means for publishers, and where to start.
The TCF inside a mobile app: where consent lives, and how to read it
In an Android app, TCF consent lives in local storage: IABTCF_ keys any SDK can read. Where to find them, what the TC string encodes, and what they do not say.
Preparing for a CNIL audit of your mobile app
CNIL audit of a mobile app: how to prepare, what an inspection really checks, and how to audit trackers, SDKs and consent before you are asked.
The CJEU IAB Europe ruling: liability no longer stops at the publisher
The Court of Justice of the EU ruled that the TC string is personal data and that liability across the ad chain is joint. What it changes for adtech vendors.
CNIL mobile app guidance for SDK providers: what changes
The CNIL mobile app guidance names SDK providers in the chain of responsibility, and inspections began in spring 2025. What adtech vendors should take from it.
An SDK that fires before consent: the vendor’s blind spot
An SDK can fire before the banner or keep sending after a refusal, invisible from the vendor’s servers. Why this behavior can only be measured on the device.
Auditing a mobile app: as essential as a website, far harder
A website audits like an open book. A mobile app is a closed box: encrypted traffic, hardened against analysis. Why auditing it matters, and why it is harder.
TCF and Consent Mode: is the consent signal honored inside the app?
The TCF and Consent Mode encode the user’s choice, but nothing guarantees an SDK honors it inside the app. An overview and a caution for adtech vendors.
Third-party SDKs and trackers: your app, your responsibility
Ad networks, analytics, crash reporting: every embedded SDK processes data under your responsibility as the publisher. How to take back control, with evidence.
Mobile app compliance monitoring: why one-off audits fall short
An app changes with every release, and so do its SDKs. Compliance monitoring continuously verifies what your app collects and transmits, version after version.