Scan a mobile app for trackers
An app’s trackers are invisible on screen: they live in its traffic. Paste a Google Play link, Skanopy runs the app on a real phone and sends you the list of third parties it actually contacts. Free, within 48 hours.
What the analysis surfaces
An activity report, not a list of libraries. The free flash audit covers the first two readings; the full audit, all six.
The trackers actually active
Every third party contacted while the app runs, including the ones firing in the background with nothing on screen to show for it.
The company behind each domain
Every contacted host is attributed to its company and classified: advertising, audience measurement, attribution, social networks.
The timing against consent
What leaves before the banner, while it waits for an answer, and after a refusal. Every reading is dated and placed in the journey.
The data that leaves
The identifiers and device data transmitted, with the third party receiving them.
The destination
The country of each contacted server, the host behind it, and that country’s data-protection level per the CNIL referential.
The gap with the banner
The active parties the consent screen does not declare, IAB list and custom vendors included.
Why a list of SDKs is not enough
Most app scanners inspect the installer file and list the libraries they recognize inside, the SDKs, the ready-made software bricks apps embed. That is a useful inventory, but it is a photograph of the code, not of the activity: a kit can sit there and stay silent, and data can leave for a tracker without any known library giving it away.
Behavior only reads in the traffic. Which domains are contacted, at what moment, with what data: those facts only exist at runtime, on a real phone, following the journey a user would follow, consent banner included. That is what the Skanopy analysis does, fully automated, and it is what separates an activity report from an attendance list.
The difference is not theoretical: across twenty news apps analyzed after refusing tracking, 95 third parties still fired. A list of libraries would not have shown it; the traffic showed it, exchange by exchange, with the time of each trigger.
Twenty apps scanned, tracking refused: 95 third parties
We installed 20 of the top-ranked news apps and refused tracking. Within about two minutes of use, 95 third-party actors fired despite that refusal.
Read the full study- Advertising40
- Identity and data11
- Infrastructure / CDN11
- Analytics6
- Video6
- Social5
- Outside the list16
0third-party actors fired
Number of third-party actors per category, tracking refused.
Frequently asked questions
A component, most often a third-party SDK, that collects information about usage or the device and transmits it to its company: audience measurement, advertising, campaign attribution, personalization. Reading or writing information on the phone is the very act that, in France, Article 82 of the Data Protection Act governs.
Two approaches exist. Inspecting the installer file gives the list of embedded libraries. Running the app and observing its traffic gives the trackers actually active, when they fire and what they transmit. Skanopy practices the second, fully automated, on a real phone.
Yes. The flash audit analyzes your app and emails you, within 48 hours, the list of third parties it actually contacts. No commitment, no credit card.
Android apps: a Google Play link is enough, or an .apk file for an unpublished app. There is nothing to integrate into the app, and nothing for the publisher to prepare.
Compare the list with what your privacy policy, your record of processing and your consent banner declare. The gaps define the work: partners to document, consent to fix, SDKs to reconfigure. The full audit then provides the decrypted content of the exchanges to build each case.
No. What the law regulates is the timing and the conditions: most trackers require prior consent, and must stay silent after a refusal. The issue is not their presence, it is their behavior.
What is a tracker in a mobile app?
A component, most often a third-party SDK, that collects information about usage or the device and transmits it to its company: audience measurement, advertising, campaign attribution, personalization. Reading or writing information on the phone is the very act that, in France, Article 82 of the Data Protection Act governs.