How Skanopy analyzes a mobile app, from first contact to report

Skanopy is a deep behavioral analysis platform for mobile apps. Here is how an analysis unfolds, with nothing to install and no code to touch.

Read articleJuly 14, 2026 · 4 min read

A push notification SDK sent 36 categories of data for four years. The publisher had no idea.

On 9 September 2026, the Spanish data protection authority found that a public app had been sending names, email addresses and GPS coordinates to a third party through a misconfigured notification module. What the decision establishes, and what it changes for publishers.

September 10, 2026 · 12 min read
The 36 categories of data sent to the third party, grouped by nature (list produced by the publisher, decision AEPD PS/00287/2025; grouping by Skanopy)
Device, network and app23 categories
Identity and contact5 categories
City, region, country, GPS4 categories

The Android advertising ID: personal data, not a technical setting

GAID, AAID, AD_ID: Android’s advertising identifier is personal data. Who can read it, when it turns to zeros, what to use instead, and what regulators expect around it.

August 26, 2026 · 8 min read
What the app receives when it asks for the advertising identifier (Google Play policy and Android documentation)
real value        the user changed nothing
                  AND the app declares the AD_ID permission

string of zeros   the user deleted the identifier in the Android

Google Play’s Data safety section: the declaration nobody verifies

The Data safety section of a Play Store listing is filled in by the publisher, and Google does not check it against what the app actually does.

July 27, 2026 · 12 min read
Consistency between an app’s privacy policy and its own Data safety listing (Mozilla, 40 of the most popular Play Store apps, February 2023)
Poor16 apps
Needs improvement15 apps
OK6 apps

Transfers outside the EU: where your mobile app’s data actually lands

Transfers outside the EU from a mobile app: adequacy decisions, Standard Contractual Clauses, transfer impact assessments, and how to establish where data goes.

July 26, 2026 · 11 min read
Split of the 530 million euro fine imposed on TikTok (final decision, 2 May 2025)
Transfers, Article 46(1)485 M€
Information, Article 13(1)(f)45 M€

Location data: how it leaves a mobile app, and how far it travels

Location data from mobile apps travels all the way to data brokers. The technical paths it takes, what regulators established, and what a publisher can verify.

July 25, 2026 · 13 min read
Advertising identifiers held in a single database (CNIL decision MED-2018-042, 30 October 2018)
Auctions it did not answer43 million
Auctions it answered25 million

Tracking before consent: what the research measured in mobile apps

Independent research measured it across tens of thousands of Android apps: most send data to third parties before any consent. The evidence, study by study.

July 24, 2026 · 9 min read
At first launch, across 1,201 apps tested (Kollnig et al., Oxford, 2021)
Track before interaction71 %
Ask for consent10 %
Offer a real refusal3 %

What France’s top news apps do after you refuse tracking

We took 20 top French news apps, tapped refuse on the tracking prompt, and watched. 95 third-party vendors contacted, thirteen the consent screen never names.

June 27, 2026 · 8 min read

Mobile compliance: does the publisher still have control?

On a major French news app, what leaves the device before and after a consent refusal: vendors fired before any choice, traffic that does not drop after it.

June 18, 2026 · 7 min read
Requests by vendor family, before any choice then after the refusal
vendor                     before   after
First-party                   10      46
Taboola                        0      45
Digiteka / Ultimedia           0      41

We mapped a major app. Here is everything it emits.

Real-world network observation of a mainstream app: the embedded ad networks, the permissions, the identifiers and the behavioural data that leave the device.

June 11, 2026 · 9 min read
Requests to third parties, by recipient
Google AdMob43 req.
AT Internet11 req.
Batch9 req.

The CNIL recommendation on mobile applications, explained for publishers

Which version is in force, who carries which obligations, what triggers consent and the four cases that exempt it: the CNIL recommendation read for a publisher.

June 10, 2026 · 9 min read
The 166 checklist points, by role (CNIL recommendation, chapters 5 to 9)
Developer39 points
OS provider38 points
Publisher37 points

The duty to inform: the 2026 European action, and what a mobile app struggles to declare

On 19 March 2026, 25 European authorities launched a coordinated action on Articles 12 to 14 of the GDPR. What they are checking, and why a mobile app’s privacy information has to be demonstrated rather than drafted.

September 5, 2026 · 5 min read

Android permissions: what minimization means for your app

Normal, dangerous, special: what Android permissions really open, why a permission is not consent, and how minimization is judged.

September 3, 2026 · 5 min read

CNIL inspections in 2026: the priority themes, and what they change for your mobile app

The CNIL’s 2026 priority inspection themes, the share of inspections they really cover, and what that changes for a mobile app.

September 1, 2026 · 4 min read

Age verification in mobile apps: what the 2025 formal notices announce

The CNIL’s 2025 enforcement report lists apps put on formal notice over age control of minors. What it means for publishers, and where to start.

August 26, 2026 · 4 min read

The TCF inside a mobile app: where consent lives, and how to read it

In an Android app, TCF consent lives in local storage: IABTCF_ keys any SDK can read. Where to find them, what the TC string encodes, and what they do not say.

August 26, 2026 · 4 min read

Preparing for a CNIL audit of your mobile app

CNIL audit of a mobile app: how to prepare, what an inspection really checks, and how to audit trackers, SDKs and consent before you are asked.

July 23, 2026 · 8 min read

The CJEU IAB Europe ruling: liability no longer stops at the publisher

The Court of Justice of the EU ruled that the TC string is personal data and that liability across the ad chain is joint. What it changes for adtech vendors.

July 18, 2026 · 5 min read

CNIL mobile app guidance for SDK providers: what changes

The CNIL mobile app guidance names SDK providers in the chain of responsibility, and inspections began in spring 2025. What adtech vendors should take from it.

July 15, 2026 · 4 min read

An SDK that fires before consent: the vendor’s blind spot

An SDK can fire before the banner or keep sending after a refusal, invisible from the vendor’s servers. Why this behavior can only be measured on the device.

July 11, 2026 · 4 min read

Auditing a mobile app: as essential as a website, far harder

A website audits like an open book. A mobile app is a closed box: encrypted traffic, hardened against analysis. Why auditing it matters, and why it is harder.

July 10, 2026 · 7 min read

TCF and Consent Mode: is the consent signal honored inside the app?

The TCF and Consent Mode encode the user’s choice, but nothing guarantees an SDK honors it inside the app. An overview and a caution for adtech vendors.

July 8, 2026 · 4 min read

Third-party SDKs and trackers: your app, your responsibility

Ad networks, analytics, crash reporting: every embedded SDK processes data under your responsibility as the publisher. How to take back control, with evidence.

June 10, 2026 · 4 min read

Mobile app compliance monitoring: why one-off audits fall short

An app changes with every release, and so do its SDKs. Compliance monitoring continuously verifies what your app collects and transmits, version after version.

June 10, 2026 · 3 min read