Skip to content

Security & Privacy

Missing Declaration of Email Collection in Privacy Policy

Description

The vulnerability exists in the application's failure to properly check if the privacy policy mentions the collection of users' emails when this data type is declared in the Play Data Safety Section, potentially exposing users' personal information without their consent.

Recommendation

To mitigate the vulnerability of collecting users' emails, ensure that your privacy policy clearly states the purpose for collecting this data, obtains explicit consent from users, and implements strong security measures to protect the information from unauthorized access or misuse. Additionally, regularly review and update your privacy policy to stay compliant with data protection regulations.

Detect this with Ostorlab

Ostorlab checks Android and iOS apps for this issue.

Scan your app free

Standards

  • OWASP_MASVS_L1:
  • OWASP_MASVS_L2:
  • OWASP_MASVS_RESILIENCE:
  • CWE_TOP_25:
  • GDPR:
    • ART_5
    • ART_6
    • ART_7
    • ART_9
    • ART_11
    • ART_13
    • ART_15
    • ART_16
    • ART_17
    • ART_32
  • CCPA:
    • CCPA_1798_100
    • CCPA_1798_105
    • CCPA_1798_110
    • CCPA_1798_115
    • CCPA_1798_120
    • CCPA_1798_125
    • CCPA_1798_130
    • CCPA_1798_135
    • CCPA_1798_140
    • CCPA_1798_150
  • PCI_STANDARDS:
  • OWASP_MASVS_v2_1:
    • MASVS_PRIVACY_1
    • MASVS_PRIVACY_2
    • MASVS_PRIVACY_3
    • MASVS_PRIVACY_4
  • OWASP_ASVS_L1:
  • OWASP_ASVS_L2:
  • OWASP_ASVS_L3:
  • SOC2_CONTROLS:
    • CC_2_3
    • CC_5_3
  • CNIL_FOR_EDITORS:
    • EDITORS_3_1_1
  • OWASP_MOBILE_TOP_10:
    • M6_2024