logo

A study of 1,000 Android apps finds a privacy policy logging gap

ID: 65369e30-487f-5d6a-9f97-c10b28314fc8

STIX ID: report--65369e30-487f-5d6a-9f97-c10b28314fc8

Feed Name: Help Net Security

Threat Score
35/100

Date Published: 2026-04-24

Date Updated: 2026-04-28

Author: Anamarija Pogorelec

...
...

Researchers analyzed privacy policies and runtime logs from 1,000 Android apps and found that most apps do not disclose logging practices; only four apps had policies matching the sensitive data observed in logs. The study highlights GDPR/CCPA exposure from undisclosed logging (IP addresses, device identifiers, emails, location), the role of third-party SDKs in exfiltrating log data, and recommends CI-stage log audits, inclusion of logging in PIAs, third-party SDK inventories, and log retention/redaction controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.