Trace every piece of personal data

Identifiers that follow the user leave the device with nothing on screen to show it. Skanopy spots them one by one, names who receives them, and shows the request that proves it. You know which personal data actually leaves, and to whom, before anyone asks you.

What leaves, and who receives it

Email address, phone number, device fingerprint: spotted in the exchanges, with the third party receiving them.

TypeValueThird party
Email address
m•••••@gmail.com
Batch
Phone number
+33 6 •• •• 21 47
Adjust
Device fingerprint
Xiaomi/beryllium/beryllium:10…
Google

The identifiers leaving the device, one by one.

An advertising ID, a device fingerprint, a pseudonym that follows the user from one service to the next: these pieces of personal data leave the device continuously, with nothing on screen to show it. The traffic is protected, the trackers sit deep inside the app.

Skanopy sees what the app really sends and ties each piece of data to the actor that receives it. It also looks at what those trackers store on the device, beyond what travels over the network.

For a DPO, this is the missing material: the GDPR’s accountability principle requires being able to prove what data leaves, and to whom. A privacy-policy review does not show it; the app’s real behavior does. Research has measured that nearly three in ten apps transmit personal data without prior consent (CISPA study, 2021).

What Skanopy reveals.

Every point is a finding from the report: captured on a real phone, dated and verifiable.

The identifiers tracked

Advertising ID, device fingerprint and the other identifiers that make it possible to follow the user.

Tied to who receives them

Every piece of data detected is linked to the third-party actor that receives it.

What the app really sends

Detection reads what leaves the device, even when it is protected.

Down to the device

What the trackers store on the phone, beyond the network.

How Skanopy works.

  1. Point us to the app

    Two ways in:

    • A Google Play Store link
    • A .apk file, for a pre-release before it ships
  2. Skanopy analyzes it

    On real phones, a real journey replayed automatically:

    • Tracking refused
    • Signed in
    • Article opened
    • Form submitted

    Every third-party actor that fires is mapped.

  3. You receive your report

    Every fact, named:

    • Active third-party actors
    • Identifiers shared
    • Permissions requested
    • Storage access
    • Consent-banner compliance

Your questions, our answers.

  • Advertising IDs, device fingerprints and the other identifiers that follow the user, along with the personal data spotted in what the app sends.

  • Yes. It makes it possible to track a user over time: as such it is personal data, and collecting it for advertising requires consent.

  • Skanopy observes the app on a real phone and analyzes what leaves the device, even when it is protected.

  • Every piece of data detected is dated, tied to the actor that receives it, and reproducible. It is a factual finding, not an assumption.

  • No. A Google Play link or an .apk file is enough.

What data does Skanopy detect?

Advertising IDs, device fingerprints and the other identifiers that follow the user, along with the personal data spotted in what the app sends.