Map the activity of third-party actors

An app contacts dozens of servers no one ever sees. Skanopy surfaces them all and names the actor behind each one, so your record of processing and your list of processors rest on what actually happens, not on what was declared.

Where the data goes

Every server contacted, the country it answers from, and the organisation hosting it.

Netherlands2
EU / EEA member
Equativ via LeaseWeb B.V.prg.smartadserver.com
Magnite via Magnite, Inc.prebid-server.rubiconproject.com
4 countries · 2 outside EU

Every server contacted, every actor behind it.

An app constantly contacts outside servers. Behind each one sits a third-party actor: an ad network, an audience-measurement tool, an attribution service. These pieces of software embedded in the app (the SDKs) have the same access as the rest of the app, and often fire without the publisher ever seeing them.

Skanopy runs the app on a real phone and records every server contacted, tied to the actor behind it. You see who is actually active, where the data goes, and when: before the user makes any choice, or despite a refusal to be tracked.

These are exactly the points an inspection sets out to establish. In France, the CNIL has run a dedicated control campaign on data collection by mobile apps since spring 2025. You see them first.

What Skanopy reveals.

Every point is a finding from the report: captured on a real phone, dated and verifiable.

Who is really active

The third-party actors that actually fire inside the app, not just the ones it declares.

Where the data goes

The country of each contacted server and its data-protection level per the CNIL referential, a useful marker for transfers outside the European Union.

Fired without consent

The actors that fire before any choice, or despite a refusal to be tracked.

Declared or not

The actors actually active that the consent banner leaves undeclared.

How Skanopy works.

  1. Point us to the app

    Two ways in:

    • A Google Play Store link
    • A .apk file, for a pre-release before it ships
  2. Skanopy analyzes it

    On real phones, a real journey replayed automatically:

    • Tracking refused
    • Signed in
    • Article opened
    • Form submitted

    Every third-party actor that fires is mapped.

  3. You receive your report

    Every fact, named:

    • Active third-party actors
    • Identifiers shared
    • Permissions requested
    • Storage access
    • Consent-banner compliance

Your questions, our answers.

  • Skanopy does not analyze the code. It runs the app on a real phone and observes what it actually does. A Google Play link or an .apk file is enough.

  • A list tells you a tracker is present in the app. Skanopy shows that it actually fired, what it sent and to whom. Presence is not activity.

  • Skanopy places each contacted server by country and shows its data-protection level per the CNIL referential, a valuable marker for transfers outside the European Union.

  • An actor actually active in the app that the consent banner never mentions to the user.

  • Yes. In France, the CNIL has run a control campaign on data collection by mobile apps since spring 2025, examining embedded trackers in particular.

How do you see these actors without access to the app’s code?

Skanopy does not analyze the code. It runs the app on a real phone and observes what it actually does. A Google Play link or an .apk file is enough.