Analysis of the 40 most popular Android apps on the Google Play Store finds nearly 80% had discrepancies between their privacy policies and Data Safety labels
The apps' privacy policies, however, both explicitly state that they share user information with advertisers, Internet service providers …
Context & Ripple Effects
This is the second time Mozilla has run this playbook against an app category: its earlier analysis of 32 mental health and prayer apps found nearly all collecting heavy user data with lax protections. The new audit shifts focus from app behavior to the store layer itself — Google Play's own Data Safety labels, which are supposed to summarize what apps collect.
The discrepancy rate also marks a sharp jump from the last large-scale measurement, when a study of 11,430 Play Store apps found 14.2% with internally contradictory privacy policies. The difference: that study measured policies against themselves, while Mozilla now measures policies against Google's structured disclosure format — suggesting the label system introduced to fix transparency may be adding a new inconsistency rather than resolving it.
First-order effects
- Developers of the flagged apps — which state they share user information with advertisers and ISPs — now face a choice between correcting their Data Safety declarations or their policies, since the two currently contradict each other on Google's own storefront.
- Users deciding whether to install these apps are getting conflicting signals at the point of decision: the label says one thing about data sharing, the policy another.
Second-order effects
- Google is put on the defensive over whether Data Safety is enforced at all; if the label is self-attested and unverified, the finding pressures the company to add auditing or watch the feature lose credibility the way prior voluntary disclosures did.
- The methodology hands other watchdogs a repeatable template — Mozilla's earlier app-audit work already triggered removals when Google pulled three children's apps after a nonprofit raised concerns, so comparable audits of other categories become more likely.
Third-order effects
- If researcher audits keep showing gap rates this high, platform-run disclosure regimes drift toward needing independent verification or regulator involvement, echoing the ad-fraud era when permission misuse went unchecked across billions of downloads before outside investigations forced action.
- The structural question is whether app stores can remain both marketplace operator and arbiter of truthfulness; sustained discrepancies push the verification role outward — to researchers, nonprofits, and eventually regulators.
The trend: App store privacy disclosures are shifting from self-attested paperwork toward externally audited claims, as repeated researcher studies show the gap between what platforms certify and what apps actually disclose.