You open Google Play and check an app’s Data Safety section. It says no data is shared with third parties. You install the app. A static analyzer then finds twelve tracking libraries bundled into the APK, and eight of them phone home within the first thirty seconds.
That’s not an outlier. It’s roughly what the studies below describe as the median. (If you want to understand what a tracker actually is and how it ends up in your apps, we covered that separately.)
Four research groups have measured this gap over the past eight years. None of the findings come from us. All four papers are publicly available, and we’ll link them at the end of each section.
1. Mozilla Foundation, February 2023: “See No Evil”
Mozilla looked at the twenty most-popular paid apps and the twenty most-popular free apps on Google Play, so forty in total. For each one they compared the app’s Data Safety declaration in the store against the wording of its own privacy policy.
In nearly 80% of the apps the two documents did not line up. Either the store form left out data collection that the privacy policy admitted to, or the two openly contradicted each other. Sixteen of the forty apps ended up with a “Poor” grade. Among them: Minecraft, Twitter, Facebook. These aren’t obscure flashlight clones. They’re on the front page of the store.
The loophole is structural. Google doesn’t verify the Data Safety form. Developers fill it out themselves, nobody checks it, and there’s no consequence for inaccuracy. The form exists to give users the feeling of scrutiny without the cost of actually doing any.
2. Binns et al., Oxford, 2018: tracker density across Android
The 2018 Oxford paper is still the widest tracker scan anyone has run on Android. The team analyzed 959,000 apps, effectively the whole free catalog of the US and UK Play stores at the time of the crawl.
90.4% of apps contained at least one third-party tracker. The median app had ten. Ten separate companies receiving device characteristics and often persistent identifiers, usually before the user has opened the app a second time.
Most of that traffic concentrates with a few players: Google, Facebook, Twitter, Oath/Verizon. Our own research data from 3,745 analyzed apps confirms the same concentration pattern years later. News apps and children’s apps tended to be the heaviest. The paper is open access and the dataset is public, and the findings have held up. If anything, tracker density has grown since.
3. Reyes et al., PETS 2018: “Won’t Somebody Think of the Children?”
This paper zooms in on the part of the Play Store that’s supposed to be the most regulated. Apps in the “Designed for Family” program are marketed to children and therefore fall under the US Children’s Online Privacy Protection Act.
The authors ran 5,855 children’s apps through a dynamic-analysis pipeline that actually watched network behavior, not just code. A majority were potentially violating COPPA. 19% of the apps used SDKs whose own terms of service prohibit use in child-directed applications, and shipped with them anyway. Of the 3,454 apps that handled the resettable advertising ID, two-thirds also sent persistent identifiers alongside it, which undoes the entire point of calling the ID “resettable”.
Apps that had voluntarily opted into the strictest children-facing category of the store were, often enough, doing the exact thing that category is supposed to prevent.
4. Kollnig et al., Oxford, 2022: Android vs iOS
The fair rebuttal to everything above is “sure, but iOS is better.” Kollnig’s 2022 Oxford team tested that claim directly. They took 12,000 random free apps from each store, 24,000 total, and ran code, permission, and network analysis on each.
89% of the Android apps and 79% of the iOS apps contained at least one tracking library. Both platforms sent personal data to servers outside the user’s country. 62% of iOS apps embedded Google AdMob. Apple’s App Tracking Transparency prompt cut some of the signal, but the underlying tracker ecosystems on both stores are almost identical. For a concrete example of what that looks like in practice, see our scan results for Instagram.
The authors’ conclusion is direct: “neither platform is clearly better than the other for privacy.” iOS Privacy Labels and Play Store Data Safety suffer from the same structural problem. Developers declare. Nobody independently audits.
What the four papers actually share
Four different methodologies, four different samples, four different years of data, one consistent finding: app-store metadata is not a reliable description of what the software underneath actually does.
And this isn’t a conspiracy. Most developers fill out the form honestly according to their own understanding of their app. The problem is the SDKs they pull in. Firebase, OneSignal, AppLovin, the Facebook SDK and dozens of others all ship with tracking code the developer didn’t write and often doesn’t fully understand. The disclosure is based on what the developer thinks their app does. The APK is based on what the compiler actually packaged.
Neither Google nor Apple has much incentive to close that gap on its own.
Why AppXpose exists
We don’t trust the labels. We scan the APK.
When you analyze an app in AppXpose we look at the bytecode, the embedded tracker signatures, the signing certificate, the requested permissions, and, if you enable the cloud scanner, a crowd-sourced database of signing certificates that flags repackaged and cloned apps. You can read more about how our tracker detection and scoring model works. None of that depends on a developer filling out a form correctly.
The studies above are why the product exists. The idea that app-store labels are unreliable didn’t come from us. We just decided to do something about it.
If you got this far, the most useful thing you can do now is read one of the original papers. They’re shorter than this post and the links are above. You won’t look at Google Play the same way afterwards.