As mobile app usage continues to rise, so does the generation of extensive user interaction data, which includes actions such as swiping, zooming, or the time spent on a screen. Apps often collect a large amount of this data and claim to anonymize it, yet concerns arise regarding the adequacy of these measures. In many cases, the so-called anonymized data still has the potential to profile and, in some instances, re-identify individual users. This situation is compounded by a lack of transparency, leading to potential breaches of user trust. Our work investigates the gap between privacy policies and actual app behavior, focusing on the collection and handling of user interaction data. We analyzed the top 100 apps across diverse categories using static analysis methods to evaluate the alignment between policy claims and implemented data collection techniques. Our findings highlight the lack of transparency in data collection and the associated risk of re-identification, raising concerns about user privacy and trust. This study emphasizes the importance of clear communication and enhanced transparency in privacy practices for mobile app development.
翻译:随着移动应用使用量的持续增长,大量用户交互数据也随之产生,包括滑动、缩放等操作行为或屏幕停留时长。应用常常收集大量此类数据并声称已进行匿名化处理,然而这些措施是否充分仍引发关切。在许多情况下,所谓的匿名化数据仍具备用户画像构建能力,在某些案例中甚至能重新识别个体用户。这种状况因缺乏透明度而进一步恶化,可能导致用户信任的潜在破坏。我们的研究聚焦隐私政策与实际应用行为之间的差异,重点关注用户交互数据的收集与处理环节。我们采用静态分析方法,对跨类别的100款头部应用进行政策声明与实施数据收集技术之间一致性的评估。研究结果揭示了数据收集缺乏透明度及其伴随的重新识别风险,引发对用户隐私与信任的深切忧虑。本研究强调了移动应用开发中明确沟通与增强隐私实践透明度的关键重要性。