computer security

Disclosure Divergence: Measuring Privacy Policy and Data Safety Misalignment at Scale

arXiv:2607.14442

summary

The paper studies how often Android apps' privacy policies match the Data Safety labels shown on Google Play, using a large dataset and an LLM to extract and compare disclosures, and introduces a risk score that highlights mismatches especially for sensitive data.

Abstract

With the rapid growth of mobile applications, user data privacy has become an increasing concern. While privacy policies describe how apps collect and share data, platforms such as Google Play provide Data Safety labels intended to summarize these practices. Because these disclosure channels are declared separately, they may present inconsistent representations of app data practices, creating uncertainty for users and regulators. In this work, we conducted a large-scale empirical study of disclosure consistency across 6,051 Android apps. Using an LLM-based extraction framework and a unified schema over 14 Google Play data categories and two operations (collection and sharing), we measure per-app and per-category consistency and introduce a sensitivity-weighted risk score that emphasizes high-risk data types. We find that misalignment disproportionately affects sensitive categories such as personal information and device identifiers, with sharing disclosures exhibiting lower consistency than collection disclosures. Elevated privac risk is concentrated in app categories associated with persistent monitoring and communication. Overall, our findings highlight structural gaps in current disclosure mechanisms and underscore the need for stronger verification and greater transparency in platform-level privacy reporting.

Topics & keywords

#privacy policies#data safety labels#android apps#disclosure consistency#risk assessment#llm extractionLLM-based extractionprivacy policydata safetyrisk scoremisalignmentsensitive data
Disclosure Divergence: Measuring Privacy Policy and Data Safety Misalignment at Scale · wovepaper