Analytics for "interaction with the service": Surreptitious Collection of User Interaction Data

03/13/2023
by   Feiyang Tang, et al.
0

The rise of mobile apps has brought greater convenience and customization for users. However, many apps use analytics services to collect a wide range of user interaction data purportedly to improve their service, while presenting app users with vague or incomplete information about this collection in their privacy policies. Typically, such policies neglect to describe all types of user interaction data or how the data is collected. User interaction data is not directly regulated by privacy legislation such as the GDPR. However, the extent and hidden nature of its collection means both that apps are walking a legal tightrope and that users' trust is at risk. To facilitate transparency and comparison, and based on common phrases used in published privacy policies and Android documentation, we make a standardized collection claim template. Based on static analysis of actual data collection implementations, we compare the privacy policy claims of the top 10 apps to fact-checked collection claims. Our findings reveal that all the claims made by these apps are incomplete. By providing a standardized way of describing user interaction data collection in mobile apps and comparing actual collection practices to privacy policies, this work aims to increase transparency and establish trust between app developers and users.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/20/2023

Transparency in App Analytics: Analyzing the Collection of User Interaction Data

The rise of mobile apps has brought greater convenience and many options...
research
10/26/2022

Annotating Privacy Policies in the Sharing Economy

Applications (apps) of the Digital Sharing Economy (DSE), such as Uber, ...
research
11/14/2022

Buying Privacy: User Perceptions of Privacy Threats from Mobile Apps

As technology and technology companies have grown in power, ubiquity, an...
research
03/30/2023

A CI-based Auditing Framework for Data Collection Practices

Apps and devices (mobile devices, web browsers, IoT, VR, voice assistant...
research
12/11/2022

Authoring Platform for Mobile Citizen Science Apps with Client-side ML

Data collection is an integral part of any citizen science project. Give...
research
02/17/2023

More Data Types More Problems: A Temporal Analysis of Complexity, Stability, and Sensitivity in Privacy Policies

Collecting personally identifiable information (PII) on data subjects ha...

Please sign up or login with your details

Forgot password? Click here to reset