AGP Picks
View all

Pixalate Unveils Q2 2026 Ad SDK Trust Index 1.0: Independent Source-Code Ratings Let App Developers Audit 698 Ad & Data Broker SDKs (Across iOS & Android) for FTC Section 5 (Unfair & Deceptive Practices) & App Store Compliance Violation Risks

Pixalate Source-Code Analysis Flags 60+ SDKs Built to Broadcast Consumers' Precise Geolocation, Including Directly Into the Advertising Bidstream, Without Detected Disclosure — Exposing Up to 89,224 Apps with an Estimated 600+ Billion Downloads to App Store Removal and/or FTC Section 5 Risk

LONDON, Sept. 09, 2026 (GLOBE NEWSWIRE) --  Pixalate, an ad fraud and digital safety watchdog, today launched the Ad SDK Trust Index 1.0, an independent reference database designed to close the systemic vendor governance gap in the mobile ad ecosystem.

By auditing software development kits (SDKs) at the source-code level, the Index flags critical discrepancies where the code Pixalate found in an SDK conflicts with its public disclosures. The Index gives mobile developers an independent tool to identify potential undisclosed commercial surveillance pipelines and material omissions before they trigger regulatory enforcement or swift app store banishment.

Both Google and Apple hold developers accountable for the SDKs they integrate — yet neither gives developers an independent way to verify that an SDK's public privacy policy or bundled privacy manifest file (PrivacyInfo.xcprivacy / AndroidManifest.xml) matches its observed code behavior.

Pixalate’s Ad SDK Trust Index 1.0 evaluates 698 ad SDKs and data brokers, shifting the industry paradigm from self-attestation to objective, code-level verification. Google’s own public SDK Index relies on self-declared compliance checkmarks that developers can mistake for legal assurance, yet Pixalate's code analysis found that many widely integrated SDKs contain code that transmits precise geolocation data without declaring it in their public privacy policies or bundled manifest files.

By flagging potential undisclosed data-harvesting pipelines, Pixalate arms developers with the automated due diligence required to audit their existing software stacks and document compliance in an increasingly hostile regulatory environment.

Key Observations: Where SDK Code Diverges From Its Privacy Disclosures

  • Data Privacy & Safety Labels: Across 698 ad SDKs and data brokers, Pixalate found a recurring gap between what an SDK does in its code and what it discloses — the same gap that can turn an app's privacy label into a false statement and create risk for the developer who ships it.
  • FTC Section 5 Violation Risk: According to Pixalate’s analysis, 22 SDKs contain code that transmits precise* location without disclosure in their privacy policy — and 11 more collect it while publishing no privacy policy at all — 33 SDKs in total, impacting up to 10,613 apps from 4,873 developers. Flagged risks are identified through SDK source-code analysis, with the analyzed code snippets published alongside the rating for inspection. See Pixalate’s analysis here.
  • App Store ToS Violation Risk: According to Pixalate’s analysis, 57 SDKs contain code that transmits precise location without disclosure in their privacy manifest, impacting up to 88,787 apps from 25,564 developers. See Pixalate’s analysis here.

Risk ratings reflect Pixalate's opinion based on its assessment of each SDK and do not constitute a legal compliance determination; Privacy policy snapshots are as of May 11; SDK analysis as of May 21, 2026.

* For the purpose of Pixalate’s analysis, SDKs that collect ‘flexible’ location (i.e. collect precise location if able, coarse if not) are considered to collect precise location.

How the Pixalate Ad SDK Trust Index Works: Three-Layer Audit

Pixalate evaluates SDKs across three areas:

  • Code Analysis: Does the SDK obtain precise location — by reading device location APIs, or by accepting it through its own API surface — and is that data packaged into network-bound payloads (ad requests, event uploads) that can leave the SDK for potential downstream use and sale?
  • Manifest Files: Does the SDK correctly declare precise location collection in its bundled manifest file? (Apple PrivacyInfo.xcprivacy / Google AndroidManifest.xml)
  • Privacy Policy: Does a privacy policy exist? If so, does it declare location collection?

The output of these checks determines the SDK's rating across two dimensions:

  • App Store Terms of Service (ToS) Risk measures alignment between the location collection Pixalate observes in an SDK's code and location collection declarations in the SDK's bundled manifest file. Misalignment puts the integrating app at risk of rejection or removal under Apple's App Store Review Guidelines and Google Play policies.
  • FTC Section 5 Violation Risk measures alignment between code analysis and the SDK's public privacy policy. Misalignment — or the absence of a policy entirely — is the disclosure gap the FTC has cited in Section 5 enforcement actions against SDK operators and downstream data brokers.

App Level App Store Data Safety & Privacy Labels Are Only as Accurate as the SDKs Inside Them

The privacy label a consumer sees before installing an app is assembled from what each embedded SDK says about itself. Google's own Data safety guidance points developers to fill out their Data Safety label by checking the Google SDK Index for each SDK's self-published data safety guidance; Apple likewise points developers to fill out the App Store "nutrition label" from a privacy report Xcode assembles out of each SDK's self-declared privacy manifest.

Neither store verifies this data safety and privacy label: Google states its review is "not designed to verify the accuracy and completeness" of a developer's data-safety declarations, while Apple's App Store privacy labels carry the disclaimer, “This information has not been verified by Apple.”

Other independent research shows those self-declarations often don't hold up. Research into 158 widely used Android SDKs found more than 30% publish no privacy policy, and among those that do, 37% collect more data than disclosed (Meng et al., 2024).

When an SDK collects data it doesn't disclose, the app's privacy label may be inaccurate. That creates potential risk for the app developer on two fronts. Apple and Google may reject or remove an app where its privacy declaration appears inconsistent with the behavior of its embedded SDK under their respective terms of service, and under FTC Section 5, developers have faced enforcement action where embedded SDKs created disclosure gaps between an app's stated privacy practices and its actual data collection behavior.

FTC Enforcement and Publisher Liability

Under FTC Section 5, which prohibits "unfair or deceptive acts or practices," a misleading privacy disclosure can be a deceptive act. The FTC has brought a wave of enforcement actions across the SDK-to-bidstream location data pipeline — against SDK operators X-Mode/Outlogic and InMarket, and downstream data brokers Gravy Analytics/Venntel and Mobilewalla. The FTC has alleged that disclosure gaps, missing consent, and harvesting data from real-time ad auctions all constitute unfair practices.

In 2023, the FTC charged telehealth provider GoodRx over the prescription and health data that third-party tracking tools (SDKs and pixels from companies including Facebook, Google, and Criteo) transmitted to advertisers — despite a privacy policy promising it would never share health information with advertisers — resulting in a $1.5 million penalty under the FTC's Health Breach Notification Rule, in an action that also charged Section 5 violations, signaling that app developers can be held responsible for the data practices of the SDKs they integrate. The FTC reached similar settlements with mental-health platform BetterHelp ($7.8 million) and fertility-app developer Easy Healthcare/Premom, in each case placing responsibility on the developer — not the SDK vendor — for the sensitive data its embedded SDKs disclosed in conflict with the app's own privacy policy.

Ad SDKs are frequently built and owned by SSPs. When an SSP's own SDK carries a ‘Critical’ risk rating, that potential compliance risk may also extend to the SSP, where the SDK's undisclosed behavior reflects on the SSP's own data practices.

How App Developers Use Pixalate's SDK Trust Index

Pixalate’s Ad SDK Trust Index is built for the SDK decisions developers make every day.

  • Vet before you integrate. Check an SDK's risk rating before it ships in your app.
  • Audit what's already live. Surface inherited FTC and app store risk in your existing SDK stack.
  • Document due diligence. Cite the source code and privacy manifest evidence behind ratings.

The Liability Google's SDK Index Leaves With App Developers

Google's SDK Index — Google’s public catalog of Android SDKs that developers currently use to vet the SDKs they integrate into Android apps — surfaces certain popularity, usage, and permission signals, but it does not close the loop in privacy alignment via privacy policy analysis. As independent researchers have observed, the Google SDK Index shows the Android permissions an SDK requests but “fails to provide information on the specific category of data being collected” (Khandelwal et al., USENIX Security 2024).

Pixalate’s Ad SDK Trust Index highlights where Google's SDK Index leaves gaps for developers relying on it for compliance due diligence.

Access the Ad SDK Trust Index

The Pixalate Ad SDK Trust Index is available at pixalate.com/sdk-trust-index.

The Index is updated quarterly. Analyzed code snippets and privacy manifests cited in ratings are published alongside the Index for inspection.

About Pixalate

Pixalate is a global platform specializing in privacy compliance, ad fraud prevention, and digital ad supply chain data intelligence. Founded in 2012 and recognized by UNICEF as a “key innovator” for children's online privacy, Pixalate is trusted by regulators, data researchers, advertisers, publishers, ad tech platforms, and financial analysts across the Connected TV (CTV), mobile app, and website ecosystems. Pixalate is accredited by the MRC for the detection and filtration of Sophisticated Invalid Traffic (SIVT). pixalate.com

Disclaimer

The Pixalate Ad SDK Trust Index reflects Pixalate's opinions on observed privacy and compliance signals across mobile SDKs and does not constitute a legal compliance determination, a finding of liability, or an assertion that any SDK, its provider, or integrating developer has violated COPPA, FTC Section 5, app store terms of service, or any other law or regulation. All data is grounded in Pixalate's proprietary technology and automated processes, and no assurances are made as to the accuracy or completeness of any classification. Read the full disclaimer here.

Contact

press@pixalate.com


Primary Logo

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Puerto Rico Industry Journal

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.