🤖 AI Summary
This study addresses significant discrepancies between mobile app privacy policies and Google Play’s Data Safety labels, which impede users and regulators from accurately assessing actual data practices. Through a large-scale empirical analysis of 6,051 Android applications, the authors construct a unified data taxonomy and introduce a sensitivity-weighted risk scoring mechanism—enabled by large language model–based information extraction and text alignment—to systematically quantify disclosure misalignments. The findings reveal that disclosures of highly sensitive data types, such as personally identifiable information and device identifiers, exhibit the lowest consistency; data sharing practices are markedly less aligned than data collection practices; and apps in the continuous monitoring and communication categories disproportionately manifest high privacy risks, exposing structural gaps in current disclosure frameworks.
📝 Abstract
With the rapid growth of mobile applications, user data privacy has become an increasing concern. While privacy policies describe how apps collect and share data, platforms such as Google Play provide Data Safety labels intended to summarize these practices. Because these disclosure channels are declared separately, they may present inconsistent representations of app data practices, creating uncertainty for users and regulators. In this work, we conducted a large-scale empirical study of disclosure consistency across 6,051 Android apps. Using an LLM-based extraction framework and a unified schema over 14 Google Play data categories and two operations (collection and sharing), we measure per-app and per-category consistency and introduce a sensitivity-weighted risk score that emphasizes high-risk data types. We find that misalignment disproportionately affects sensitive categories such as personal information and device identifiers, with sharing disclosures exhibiting lower consistency than collection disclosures. Elevated privac risk is concentrated in app categories associated with persistent monitoring and communication. Overall, our findings highlight structural gaps in current disclosure mechanisms and underscore the need for stronger verification and greater transparency in platform-level privacy reporting.