Just because a children’s app looks innocuous doesn’t mean it’s not doing some shady stuff in the background. Google has taken action against three children’s apps in the Play Store—Princess Salon, Number Coloring and Cats & Cosplay—for violating its data collection policies, according to a report in TechCrunch.
Per the report, which the company confirmed to Gizmodo, Google took action on the apps after researchers at the International Digital Accountability Council, a nonprofit privacy watchdog, informed it of the violations. In a statement on its website, the IDAC stated that one of the problems was related to the software development kits used within the three apps: Unity, Appodeal and Umeng.
The organization affirmed that its tests had discovered that certain versions of the three SDKs used in the apps “were not in compliance with broader Google Play policies around data collection.” Although the IDAC did not list all the alleged violations in detail, it did highlight one specific problem related to certain versions of the Unity SDK.
“IDAC’s tests highlighted that certain versions of Unity’s SDK were collecting both the user’s AAID and Android ID simultaneously, which may have allowed Unity to bypass privacy controls and track users over time and across devices,” the organization stated.
IDAC goes on to explain that this is significant because when the AAID—which is a unique, resettable ID for advertising that basically allows ad networks to create a personalized data profile of your likes and dislikes, among other things—is linked with the Android ID, it creates a “bridge” that allows companies to track users.
Android ID is another unique identifier that, unlike the AAID, cannot be reset. The privacy organization concludes that “ID bridging” ultimately makes users’ ability to reset their AAID useless. As explained by Wired, users can choose to reset their AAID to stop the profiles ad networks have collected on them from growing even more or force the networks to create a new profile on them altogether.
According to TechCrunch, the Princess Salon, Number Coloring and Cats & Cosplay apps had more than 20 million downloads between them.
Gizmodo reached out to Google to ask about the IDAC report and confirm whether it took action on these apps because of it. The company confirmed via email that it took down the apps.
If these apps were indeed collecting data that allowed them to track children across devices (it’s not clear that they did or how much data they collected, just that they could potentially do so), that’s pretty upsetting. While I don’t have children, if I did, I would be pretty cranky if their games were collecting and building profiles on them. Besides being appalling, it’s also a potential violation of the Children’s Online Privacy Protection Act, a federal law that bans operators of websites and online services, including apps and social media networks, from collecting the personal information of children under 13 years old without parental consent.
Update 10/25/2020, 10:45 p.m. ET: This post has been updated to reflect the additional information provided by Google.