Google Removes Android Apps for Kids Over Data Collection

Android boasts the largest app ecosystem, featuring close to 3 million applications available through the official Google Play Store. However, this extensive collection also means that problematic apps can occasionally evade detection.
Recent investigations by the International Digital Accountability Council (IDAC), a Boston-based nonprofit organization dedicated to oversight, revealed that three widely-used apps geared towards younger audiences were found to be non-compliant with Google’s data collection guidelines. These apps potentially accessed users’ Android ID and AAID (Android Advertising ID) numbers, and this data leakage may be linked to the utilization of SDKs from Unity, Umeng, and Appodeal.
In total, these applications had accumulated over 20 million downloads.
The apps – Princess Salon, Number Coloring and Cats & Cosplay – have since been removed from the Google Play Store, as demonstrated in the links provided. Google has confirmed to us that the removal occurred following IDAC’s notification of the policy breaches.
“We can verify that the apps mentioned in the report have been taken down,” stated a Google representative. “We respond to any app found to be in violation of our policies by taking appropriate action.”
These violations highlight a broader concern regarding the publishers’ commitment to upholding data protection standards. “Our research uncovered practices that generated significant concerns about data handling within these applications,” explained Quentin Palfrey, president of IDAC.
This situation has come to light amidst increased scrutiny of Google and the scope of its operations. Just this week, the U.S. Department of Justice, along with 11 states, filed a lawsuit against the company, alleging monopolistic and anticompetitive conduct in the realm of search and search advertising.
It’s important to note that these app violations are unrelated to search; however, they emphasize the vastness of Google’s infrastructure and how even minor lapses can impact a substantial number of users – potentially reaching tens of millions. They also underscore the difficulties inherent in proactively identifying and addressing individual violations at such a large scale, particularly when the users involved are children.
Currently, apps from at least two of the publishers, Creative APPS and Libii Tech (whose applications feature the characters depicted at the top of this article), remain available. Furthermore, versions of the removed apps can still be downloaded through alternative APK websites (such as this one). While versions are also available on iOS (for example here), IDAC’s technical team indicated that their initial assessment did not reveal comparable issues, but they will continue to monitor the situation.
This instance of non-compliance is intricate, but serves as an illustration of how users can be tracked through apps without their knowledge.
Highlighting the unseen processes and data handling within seemingly harmless apps, IDAC identified three specific SDKs utilized by the app developers as contributing factors: the Unity 3D game engine, Umeng (an Alibaba-owned analytics provider often referred to as the “Flurry of China,” and sometimes characterized as an adware provider), and Appodeal (another app monetization and analytics provider).
Palfrey clarified that the core issue lies in the potential to connect data accessed through these SDKs with other information, such as location data. “The transmission of AAID information alongside a persistent identifier [like Android ID] could circumvent Google’s privacy safeguards,” he explained.
IDAC did not detail the violations within each SDK, but noted that certain versions of Unity’s SDK were simultaneously collecting both the user’s AAID and Android ID, potentially enabling developers “to bypass privacy controls and track users over time and across different devices.”
IDAC describes the AAID as “a key to consolidating all data pertaining to a user in a single location.” It allows advertisers to deliver targeted advertisements based on a user’s preferences. Users have the ability to reset their AAID. However, if an SDK also provides access to a user’s Android ID, a permanent identifier, it establishes a “bridge” for identifying and tracking that user.
Palfrey refrained from specifying the extent of data potentially compromised due to the identified violations, but Google affirmed its ongoing efforts to collaborate and implement procedures to detect similar malicious actors, whether intentional or unintentional.
“As an example of our ongoing work, we introduced the Families ad certification program in 2019,” the spokesperson said. “Apps seeking to display ads within children’s and family apps are required to utilize ad SDKs that have self-certified compliance with policies designed for kids and families. We also mandate that apps exclusively targeting children do not incorporate any APIs or SDKs that are not approved for use in child-directed services.”
IDAC, established in April 2020 as a spin-off of the Future of Privacy Forum, has also conducted investigations into data privacy breaches in fertility apps and COVID-19 trackers. Earlier this week, the organization also released findings regarding data leakage from an older version of Twitter’s MoPub SDK, impacting millions of users.
Related Posts

Peripheral Labs: Self-Driving Car Sensors Enhance Sports Fan Experience

YouTube Disputes Billboard Music Charts Data Usage

Oscars to Stream Exclusively on YouTube Starting in 2029

Warner Bros. Discovery Rejects Paramount Bid, Calls Offer 'Illusory'

WikiFlix: Netflix as it Might Have Been in 1923
