Search papers, labs, and topics across Lattice.
This study conducts a large-scale analysis of data privacy disclosures across 6,051 Android apps, revealing significant inconsistencies between privacy policies and Data Safety labels provided by platforms like Google Play. By employing an LLM-based extraction framework, the researchers assess disclosure consistency across 14 data categories and introduce a sensitivity-weighted risk score that highlights high-risk data types. The findings indicate that sensitive categories, particularly personal information and device identifiers, face greater misalignment, with sharing disclosures being notably less consistent than collection disclosures, emphasizing critical gaps in current privacy reporting mechanisms.
Misalignment in app privacy disclosures reveals that sensitive user data is often inadequately protected, with sharing practices being less transparent than collection methods.
With the rapid growth of mobile applications, user data privacy has become an increasing concern. While privacy policies describe how apps collect and share data, platforms such as Google Play provide Data Safety labels intended to summarize these practices. Because these disclosure channels are declared separately, they may present inconsistent representations of app data practices, creating uncertainty for users and regulators. In this work, we conducted a large-scale empirical study of disclosure consistency across 6,051 Android apps. Using an LLM-based extraction framework and a unified schema over 14 Google Play data categories and two operations (collection and sharing), we measure per-app and per-category consistency and introduce a sensitivity-weighted risk score that emphasizes high-risk data types. We find that misalignment disproportionately affects sensitive categories such as personal information and device identifiers, with sharing disclosures exhibiting lower consistency than collection disclosures. Elevated privacy risk is concentrated in app categories associated with persistent monitoring and communication. Overall, our findings highlight structural gaps in current disclosure mechanisms and underscore the need for stronger verification and greater transparency in platform-level privacy reporting.