Analysis of 200 education dept-endorsed school apps finds most are selling BS when it comes to the privacy of children’s data

Analysis of almost 200 school-endorsed apps found that most start harvesting children’s data within seconds in contravention of the developer’s own privacy policies, leaving underage users exposed to significant privacy and security risks.

The findings by UNSW researchers come from an audit of around 200 Android educational apps sourced from school recommendation lists, state Department of Education websites, and the Google Play Store.

The results were presented in the paper “Analysing Privacy Risks in Children’s Educational Apps in Australia,” authored by Dr Rahat Masood, a cyber security expert at UNSW, and his colleagues Sicheng Jin, Jung-Sook Lee and Hye-Young (Helen) Paik.

The research team found that many of the apps collected sensitive data, transmitting it to third parties, and hiding behind privacy policies so complex very few parents can understand them.

Dr Masood said they wanted to analyse whether Australia, the federal government and education departments are aware of the security and privacy risks involved for children as teaching goes digital and relies on tech suppliers.

Illusion of safety

What’s quickly became apparent is that tech platforms are driving a truck through the privacy of students while pretending to be safer for underage users. In some instances apps marketed to young children – using terms such as “Kids,” “Preschool,” or “ABC” – were no safer than general-audience apps, and in some instances worse alignment between their stated privacy commitments and actual behaviour.

The research paper described this as “the illusion of safety” – child-centric branding cultivates parental trust without providing genuine protection.

A staggering 76% of apps targeted at children showed at least one form of policy distortion, compared with 67% of general educational titles.

The researchers found apps carrying child-friendly names often embedded the same advertising and analytics tools found in commercial entertainment apps, including the same tools used to track adults using the internet.

API vulnerabilities

They also found significant security concerns.

Almost 80% of apps contained “hard-coded secrets” – API (Application Programming Interfaces) keys and credentials embedded directly in the app’s code in a way that could be accessed by anyone who decompiled the application.

“Hard-coded secrets mean that if you configure an API, you have a password or passphrase and the API key is hard-coded within the code,” Dr Masood said.

“Anyone can access it and do whatever they want with the API. It is not a good practice from a development point of view.”

Their analysis found that 89.3% of apps began transmitting data to third parties before a user had interacted with the app at all. Opening an app was enough to send device identifiers, location metadata, and other sensitive information to analytics platforms and advertising networks.

“Even if you are not interacting with the app – you just open it and that’s it – it is still transferring lots of data,” Dr Masood said.

“Telemetry data which mainly refers to tracker-related identifiers and used for the automatic collection and transmission of data to remote servers. Despite just opening the app and not using any educational feature, it is still transferring a lot of information that is sensitive and can actually identify your device.”

Report coauthor Dr Rahat Masood

The research findings also sit in contrast to the government’s ban on children under 16 using social media amid concerns that tech companies target young people.

Australia’s privacy commissioner flagged concerns about privacy and safety during the trail period for the ban but the issues she raised were largely ignored in the final report.

The Office of the Australian Information Commissioner (OAIC) told the organisers of the Age Assurance Technology Trial (AATT), which preceded the under-16s ban, that their reports used inflated privacy language that couldn’t be supported by the trial’s own methodology.  The OAIC noted that a comprehensive privacy assessment against the Privacy Act had not been conducted as part of the trial, despite being proposed in the evaluation proposal.

Feeding Facebook

That broad interpretation of privacy appears to also apply to assessments of government-endorsed apps for school kids.

The UNSW researchers found that 83.6% of apps checked transmit persistent identifiers – unique codes that can track a device across sessions and across different apps. More than two-thirds (67.9%) of the apps contained at least one embedded tracker or analytics tool, such as Firebase, Facebook SDK, or Unity Analytics.

Dr Masood noted that “none of these are needed to actually run the educational app.”

The research team also analysed the privacy policies of the apps and found that just 3% were “fairly easy” to read. The other 97% required university-level literacy or higher to grasp their meaning.

“Nobody will understand these terminologies and jargon,” she said.

“Comprehension, readability, understandability – all these metrics that we analysed were all very bad.”

On top of that the legal text often doesn’t reflect what the app actually does. Just a quarter of the apps examined – ie, about 50 – were fully consistent between their stated privacy policy and their observed behaviour during testing.

“We matched the privacy policy with the dynamic analysis – when the app is running, whether it is collecting the data and whether it is mentioned in the privacy policy or not,” Dr Masood said.

“Only one in four were matching. Some of the policies appear to have been generated using AI tools.”

One app listed in its store description as “Data Not Collected” was observed initialising Firebase analytics and transmitting persistent identifiers from the moment it first launched. Another that claimed “no ads, no tracking” was found to be sending data to Unity Analytics and Google before a user had done anything.

Crackdown needed

Dr Masood said the problem starts with the each state’s Department of Education drawing up its recommended list of apps for educators.

“They look at very high-level details and they don’t download the app – they don’t do the dynamic analysis, they don’t go through the accessibility and readability of the privacy policies,” she said.

Schools are told the apps were assessed through a quality assurance framework, but she said it’s inadequate and teachers are largely unaware of the risks embedded in these tools, while parents assume that if an app has been approved, it is safe..

“They [teachers] are out of resources – first of all – and they don’t know about any security issues. They were just given an app to use and that’s it,” she said.

Dr Masood and her colleagues believe a “traffic light” system would be a better solution as a visual summary of an app’s privacy and security profile, bypassing the legal jargon.

Their research calls for stricter oversight of the “child-directed” app category, arguing that labels such as “Kids” or “Educational” should have a verified technical baseline, rather than being used as a content descriptor.

The also want regulators to prohibit “idle telemetry” – transmitting data before a user has done anything.

The project was funded by the UNSW Australian Human Rights Institute.

Source link

Visited 1 times, 1 visit(s) today

Related Article

15 Of The Best Free Apps For Your Amazon Fire Tablet

Bosca78/Getty Images We may receive a commission on purchases made from links. Amazon Fire has a lineup of tablets to suit people with varying needs. Even if you have an Amazon Fire Tablet that’s too old, you can still find some clever uses for it. The Amazon

Leapmotor Lafa5 Ultra Hits Market at Auto China 2026

Gasgoo Munich- Leapmotor launched the Lafa5 Ultra at the Auto China 2026 on April 24, offering two variants—the 500Ultra and 600Ultra—priced between 118,800 and 124,800 yuan for a limited time. The offer runs through May 31. By bringing in Tim from Mediastorm as a guest host, the company sent a clear message: this car is

Samsung Galaxy’s Ocean Mode and Coral Reef Initiative Receive International Recognition and Awards – Samsung Global Newsroom

Samsung Electronics today announced that its “Coral in Focus” initiative, powered by Ocean Mode,1 an advanced camera feature on the newer Galaxy mobile phones, has received multiple awards for its contributions to coral reef conservation, including Gold in the “Best Sustainability or Conservation Initiative” category at Engage for Good’s 2026 Halo Awards. Additionally, “Coral in

破解 AI 模型迷思:GPT-5.5 不是首選 性價比最高是 GPT-5.3 Codex xhigh

Andy 2026年4月26日週日 上午7:06 在 AI 工具推陳出新的時代,我們很容易陷入一種「買新不買舊」的迷思,下意識地認為冠上最新版號的 GPT-5.5 絕對是工作上的最佳選擇。但如果你是一位精打細算、不想看著額度與錢包像流水般消失的聰明用家,我們必須來談談客觀數據揭露的殘酷現實:最新的模型確實更聰明,但它也出乎意料地「貴」。 GPT-5.5 驚人的「高額入場費」 讓我們直接攤開這張「智慧 vs. 價格(Intelligence vs. Price)」的客觀分析圖。如果你是在意 API 計費成本的開發者,這張圖表絕對會讓你對「性價比」有全新的體悟。 圖表中最引人注目的,是整個 GPT-5.5 系列的定價分佈: 你會發現,無論是表現墊底的 GPT-5.5 (low),還是站在智慧頂端的 GPT-5.5 (xhigh),它們的價格線全部垂直緊貼在每百萬 Tokens 約 $11.30 USD 的高位。 這意味著,只要你呼叫了 GPT-5.5 系列,你就是支付著最高昂的溢價。 我已經付了訂閱費 為什麼還要管價格? 這時很多 ChatGPT Plus 或 Pro 的訂戶可能會問:「我每個月已經付了固定月費,難道不是吃到飽任用嗎?這張圖表的『價格』跟我有什麼關係?」 這是一個非常常見的誤解。月費買到的其實是「入場券」,而不是「無限資源」。 圖表上的「價格(Price)」,反映的是模型背後龐大的算力與伺服器成本。對於系統來說: 越貴的模型,消耗配額的速度就越快: 因為 GPT-5.5 運行成本極高($11.30 USD),為了控制伺服器負載,官方會對這類新模型設定極為嚴格的「動態使用上限」。 價格,其實就是你的「使用時間」: 當你用 GPT-5.5 處理大量任務時,你很快就會撞到那面令人沮喪的牆——「您已達到使用上限,請等待數小時後再試」。 換句話說,圖表上的「高價」,在訂閱制用戶的現實體驗中,會直接轉化為「高消耗率」與「更少的連續工作時間」。 性價比黑馬:GPT-5.3 Codex

Singles looking for connections turning to matchmakers

People in big cities are finding that dating apps are no longer serving them, which is giving matchmakers their moment. Yana Iskayeva/Getty Images Alicia Williams has had some rough dating experiences. The 29-year-old mom of two dated a guy who claimed he was divorced, even presenting her with papers to prove it. It turns out

How Effective Is M-A’s Phone Policy?

M-A instituted a new phone pocket policy this year following the Phone-Free School Act, requiring students to store their mobile devices in phone pockets during class. While the policy is intended to limit disruptive cell phone use, students and teachers have seen mixed results. Teachers are using a variety of methods to enforce the policy.

13 Popular Fast Food Loyalty Apps, Ranked Worst To Best

PeopleImages/Shutterstock Craving a cheap cheeseburger? There’s an app for that. Fast food giants use cheap mobile discounts as lures to keep customers engaged. That $18 combo everyone complains about might drop to half price with the right coupon — or even turn it into a free meal

Samsung Galaxy’s Ocean Mode and Coral Reef Initiative Receive International Recognition and Awards

SEOUL, Korea – April 24, 2026 – Samsung Electronics Co., Ltd. today announced that its “Coral in Focus” initiative, powered by Ocean Mode,1 an advanced camera feature on the newer Galaxy mobile phones, has received multiple awards for its contribution to coral reef conservation, including Gold in the “Best Sustainability or Conservation Initiative” category at  Engage for

I tried every free AI note-taking app and found the one that actually works

I’ve lost count of how many AI note-taking apps I’ve installed this year. Every week, there’s a new one that promises to record, transcribe, and summarize my meetings, and every week, the free tier either collapses after 30 minutes or locks the AI features behind a credit pool that’s used up in days. After a

Jeep Wagoneer S Pause Shows How Tough The EV Market Has Become

Jeep’s electric transition is starting to look less like a straight line and more like a series of corrections. The Wagoneer S arrived as a major statement vehicle for the brand, but its first full stretch on the market has exposed how hard it still is to turn EV ambition into steady demand in the

This free open-source app gave my Android phone the task manager it should’ve had

On desktop operating systems, you can usually look up exactly which apps and services are currently running on your device. Utilities like htop or Task Manager let you monitor what processes are actually running on the machine, either in the foreground or the background. However, Android (by default) doesn’t have anything like this. This is

Ultra-Fast EV Charging Infrastructure Market to Reach US$44.06

Ultra-Fast EV Charging Infrastructure Market Ultra-Fast EV Charging Infrastructure Market Growth Outlook 2026 to 2032: US$13.42 Billion Market Expands as Charging Speed Becomes a Core EV Adoption Driver The global Ultra-Fast EV Charging Infrastructure Market is moving into a high-growth phase as electric mobility shifts from early adoption to practical mass-market scale. According to Global

Sacramento Regional Transit ZipPass app to expire in June

Sacramento Regional Transit workers and members of the public sit inside the air-conditioned S700 low-floor light rail train at the Township 9 station in Sacramento on June 12, 2024. RT’s ZipPass app, which is where riders have purchased and accessed transit passes, will be retired in June, RT spokesperson Jessica Gonzalez said. Bailey Stover Sacramento

‘Genuinely feels like a flagship phone’: Samsung has done well with its Galaxy A57, but is it the best budget Android handset of 2026?

With a slim and light build, plus a stylish glass-and-metal chassis, Samsung’s affordable new Galaxy A57 is undeniably a great-looking phone — and not just compared to other budget handsets, but even when it’s up against other flagships, including its Galaxy S26 siblings. Combined with some notable hardware and software upgrades over its excellent A56

0
Would love your thoughts, please comment.x
()
x