When the tool that produced your evidence shuts down: the Google Checks case
Google is shutting down Checks, its compliance platform for app developers, at the end of September 2026. Active accounts received a deprecation email in mid-August; registrations and app uploads are already closed, and both accounts and data will be deleted automatically at shutdown. That leaves a few days to get out whatever needs to come out.
Two things are worth stopping on. The move to make right now, because deleted evidence cannot be reconstituted. And the stated reason, which reaches well beyond this product: if everyone now builds their own compliance tooling on an agent platform, what becomes of the evidence, and who audits the agent?
What Checks is, and who it is for
Checks came out of Area 120, Google’s in-house incubator, where it first appeared in February 2022. Its move into Google proper was announced on 3 May 2023. On 14 May 2024 the developers blog announced general availability to “all Android and iOS developers”, with automated privacy compliance reports on data collection and sharing practices. Two other lines were in private preview at that point: Code Compliance, an assistant that analyses source code as it is written, and AI Safety, automated adversarial testing for generative AI features.
Today the Checks site names those three areas: App Compliance, Code Compliance, AI Safety. The App Compliance page describes monitoring of third-party software component integrations, permissions and data flows, with recommendations tied to app store data safety disclosure requirements.
One point is worth settling straight away, because it decides what this shutdown changes for a DPO. Checks is a publisher’s tool: it addresses whoever wrote the app, to help them declare correctly what it does. The DPO’s question starts where the publisher’s ends: verifying, on the device, what the app actually sends.
What the email says, and what Google has not published
The email, titled “Deprecation of the Checks product”, went out to active accounts on 19 August 2026. It sets the timeline: deprecation started 17 August, shutdown at the end of September, registrations and app uploads already disabled, feature access liable to be limited in the meantime. At shutdown, accounts and associated data are deleted automatically; earlier deletion can be requested from support, quoting the account number. The reason is stated in as many words: entering “the agentic era”, where developers would now build their own compliance tools on an agent platform.
One practical point, so you do not go looking for it: this shutdown has no public page. As of 22 September 2026 the Checks site is live and still invites you to sign up, the general availability post on the developers blog is still published with no mention of a sunset, and the community inventory Killed by Google has not opened an entry. None of that is unusual for a product sold to teams: the notice goes out by email to active accounts, and the page follows if and when it follows. It simply means you should not wait for an online confirmation to act, because the date itself is days away.
The arithmetic is asymmetric, and it should decide the matter. Exporting costs an hour. Not having exported costs an artefact nothing can reconstitute, on the day an inspection covers the period it documented.
This article will be updated if Google publishes a page about the shutdown, or if the timeline changes.
This is not the first, and the timeline holds
The same kind of timeline has already been run elsewhere, almost to the week. On 15 December 2025 Google announced the end of its dark web report, the service that told a user when their data showed up in a breach. The timeline was precise: no more scanning for new breaches from 16 January 2026, feature discontinued and associated data deleted on 16 February 2026. Two months between the announcement and the deletion.
This is not an argument about instability. Every software company retires products, and Google said at the time it wanted to focus on tools that give clearer, more actionable next steps. It is a reminder about proportions. A feature lives two or three years. An obligation to account for what you did covers years already gone: the €403 million fine imposed on Google by the Irish authority on 21 September 2026 concerns a period that closed on 4 February 2020, six years and seven months between the last day examined and the decision.
Evidence is judged on its date, and on what you hold of it
Article 5(2) of the GDPR sets out the accountability principle: the controller has to be able to demonstrate compliance with the principles, and that demonstration is on them. This is not a formality. In the Irish decision mentioned above, one of the four findings is not that a processing operation was unlawful, but that the company could not demonstrate that it was lawful, fair and transparent. Not being able to prove is a failing in itself.
The practical consequence is easy to state and expensive to discover too late. A dashboard is not evidence: it is a view onto a database that belongs to someone else, and it closes when they close. Evidence is the artefact you hold, in a format you can reopen without the provider that produced it, carrying its date and the exact version of the app it documents.
Hence three inventory questions, worth asking once for every analysis already done: where does each artefact live today, in what form do you hold it yourself, and what date does it carry. A finding that exists only inside a provider’s interface is a finding you do not own.
The agent argument, and the act it does not perform
That leaves the stated reason, and it deserves better than a shrug, because you will hear it elsewhere: agents will replace compliance tools, everyone building their own.
What is right about it: compliance involves a lot of reading and writing. Reconciling a record of processing with a privacy policy, classifying purposes, rewording a notice, drafting an answer to a questionnaire. A model is useful there, and that part of the work is genuinely going to change.
What is missing sits upstream, and it is acquisition. No model installs an app on a phone, drives it screen by screen, and records what leaves it. The French data protection authority describes the method without ambiguity in its mobile app recommendation: to check that a third-party software component honours its commitments, it says an audit method based on intercepting network communications can be considered (page 56); and to check how consent is collected, it recommends setting up a test bench, equipped with a test phone or an emulator for intercepting network communications, to make sure no request symptomatic of a tracker leaves before consent has actually been obtained (page 37). A bench, a phone, an interception: three objects, not a line of reasoning.
An agent can say what an app should do. It cannot say what an app did. Between the two there is a device, a real session, and a trace.
The second omission sits in a question that reason invites all by itself: if the tool becomes an agent everyone builds for themselves, who audits it? A third-party method, described and reproducible, is what you put in front of an inspector. An in-house agent moves the burden, since you then have to prove that the instrument of proof is itself sound. On that point the recommendation explicitly allows both routes: the publisher can set up that test bench, or engage a third-party provider for the purpose.
What we take from it
A product shuts down, and what it produced goes with it. What a DPO has to be able to produce if asked in five years is neither access to an interface nor a screenshot: it is a dated record of what a specific version of the app actually sent, and to whom.
That is what Skanopy does. An Android app is installed on a real phone, driven automatically through a real journey, and what leaves it is recorded: the third-party actors contacted, the data sent, and the moment of each transmission relative to the user’s choice. The result is a dated artefact, tied to a version, that you export and keep version after version. We provide the findings and the technical evidence; the report handed to your client stays yours.
That is the whole point of a mobile app analysis: it does not state the law, it produces the dated artefact the law is applied to. Whatever tooling comes and goes, that artefact is what remains, and it is yours.
Sources
Every statement in this article traces back to one of these documents, consulted on 22 September 2026.
- Checks ’26The public Checks site, still live as of 22 September 2026Google
- Google ’24The power of Checks is now available to all Android and iOS DevelopersGoogle Developers Blog, 14 May 2024
- TechCrunch ’23Checks, the project incubated in Area 120, officially exits to GoogleTechCrunch, 3 May 2023
- DEV ’26Google Checks Is Shutting Down: What the Privacy Compliance Platform Deprecation Means for Developersjamilxt, DEV Community, 19 August 2026
- TechCrunch ’25Dark web report discontinued: scanning ends 16 January, data deleted 16 February 2026TechCrunch, 15 December 2025
- CNIL ’25Recommendation on mobile applications, modified version (pages 37 and 56)CNIL, 8 April 2025
- DPC ’26Data Protection Commission fines Google €403 million following inquiry into its processing of location dataData Protection Commission (Ireland), 21 September 2026
- Killed by GoogleCommunity inventory of discontinued Google products and serviceskilledbygoogle.com, consulted 22 September 2026
Common questions
- When is Google Checks shutting down, and what happens to the data?
- At the end of September 2026, per the deprecation email sent to active accounts on 19 August. Deprecation started on 17 August; registrations and app uploads are already disabled. At shutdown, accounts and associated data are deleted automatically, and earlier deletion can be requested from support. The shutdown was notified by email, with no public page on the Checks site as of 22 September 2026, so do not wait for an online confirmation before exporting.
- What should you do if your team uses Checks?
- Export the reports and findings first, because the operation costs an hour and the missing artefact costs a lot: an inspection or a complaint often lands years after the facts it concerns. Then take stock of what those outputs fed into, store listing declarations, records of processing, internal documentation, and decide for each use where the evidence will live from now on.
- Can an AI agent run a mobile app compliance analysis?
- It can do the reading and writing part: reconciling a record of processing with a policy, classifying purposes, drafting an answer. It cannot do the acquisition, which is a physical act. The French authority describes the expected method itself: a test bench, a phone or an emulator, and interception of network communications to check what leaves before consent. A model says what an app should do; only observation says what it did. And any tool built in-house raises the next question: you then have to prove that the instrument of proof is itself sound.
- How long should a mobile app analysis be kept?
- No text sets a retention period for these artefacts. The sensible measure is the period during which the facts they document can still be examined: the Irish decision of 21 September 2026 concerns a period that closed on 4 February 2020, six years and seven months earlier. A useful analysis is therefore a dated one, tied to a specific version of the app, kept in a format you can reopen without the provider that produced it.