/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Report: some iPhone apps use Glassbox's analytics SDK to record in-app user interactions without permission, and recordings sometimes don't mask sensitive data

And there's no way a user would know  —  Many major companies, like Air Canada, Hollister and Expedia, are recording every tap and swipe you make on their iPhone apps.

TechCrunch Zack Whittaker

Context & Ripple Effects

The Glassbox disclosure lands on top of a long paper trail of iOS data leakage: researchers had already caught [[a:933188|24 popular iOS apps shipping GPS, Bluetooth beacon and Wi-Fi identifiers to data monetization firms]] months earlier, and a 2015 survey found popular apps routinely passing email and location to third parties. What makes this report different is the mechanism — a mainstream analytics vendor whose session-replay SDK records every tap and swipe inside branded apps like Air Canada, Hollister and Expedia, sometimes failing to mask sensitive fields.

Apple's response came within a day: the company said it had notified developers to remove the recording code absent explicit user consent. That speed matters because it frames the episode as an App Store review failure, not just a developer misstep — the SDK passed vetting and ran at scale before anyone outside noticed.

First-order effects

  • Air Canada, Hollister, Expedia and other apps embedding Glassbox's SDK face immediate removal demands from Apple, forcing emergency app updates to strip the session-recording code.
  • Users recorded by those apps have no way to know what was captured, and where masking failed, sensitive interactions may sit in vendor-side recordings outside their control.

Second-order effects

  • Session-replay analytics vendors like Glassbox face client defections and pressure to prove masking works by default, since their value proposition — full-fidelity session capture — is exactly what triggered Apple's crackdown.
  • Apple's App Store review process takes reputational damage: static review missed a widely distributed SDK, inviting calls for runtime monitoring or mandatory SDK disclosure rather than pre-launch checks alone.

Third-order effects

  • The episode fits a recurring structure — the 2015 survey, the 2018 monetization-firm findings, later ATT opt-out violations, and 2024 push-notification workarounds all show collection techniques outrunning enforcement — pointing toward SDK-level governance as the durable fix: platforms auditing third-party code continuously instead of trusting developers' declarations.
  • If platforms keep patching channels only after press disclosures, brands will keep absorbing the privacy liability of vendors they barely vet, pushing large app operators toward contractual audit rights over every embedded SDK.

The trend: iOS privacy enforcement is running as reactive whack-a-mole, with each disclosed SDK or channel gap forcing Apple into another round of removal notices while vendors find new collection paths.