POWERED BYMOBSTR

Data Privacy Intelligence

A privacy policy
is a claim.
Not a fact.

InterroPol reads the privacy policy of any mobile app or browser extension, then tests every claim against technical evidence gathered by Mobstr. You see what an application says it does with data, what it actually does, and exactly where the two fail to meet.

POWERED BYMOBSTR Application discovery, technical analysis and continuous monitoring across Android, iOS, Chrome and Edge.
EXHIBIT A  /  POLICY EXTRACT ILLUSTRATIVE
The statementSupplier workforce app

We collect only the information necessary to provide the service. We do not share your personal data with third parties, and your data is stored in the United Kingdom.

The evidenceMobstr analysis
Permissions14
SDKs11
Recipients8
Countries4
The finding
NOT SUPPORTED

Two advertising recipients and two transfer locations are absent from the published policy.

Package 4.2.1  /  analysed 14 days ago 3 of 9 contradicted
Continuously interrogated Android appsiOS appsChrome extensionsEdge extensions

The visibility gap

You cannot govern
what you cannot see.

Applications arrive through central IT, business teams, suppliers and individual users. Mobile apps and browser extensions process organisational, personal and special category data while sitting outside every register you maintain.

01 / KNOWN

The applications you have a record of

Approved catalogue entries, managed browser extensions and formally procured supplier services. Visible, registered, reviewed at least once.

  • Approved catalogue
  • Managed devices
  • Contracted suppliers
02 / UNRECORDED

The applications nobody wrote down

Unmanaged downloads, overlooked extensions, trial tools, supplier dependencies and anything introduced outside a review process.

  • Shadow installs
  • Trial tools
  • Supplier chains
03 / BEHAVIOUR

The data activity behind both

Permissions, SDKs, libraries, trackers, AI services, third party recipients and international transfers that no published policy explains clearly.

  • Components
  • Recipients
  • Transfers
Mobstr finds the estate and takes it apart. InterroPol turns that evidence into privacy understanding, policy validation and a governance decision you can defend in front of a regulator.

How it fits together

Mobstr gathers the evidence.
InterroPol puts it to the test.

Two capabilities, one record. Mobstr examines the application and its technical ecosystem. InterroPol interrogates the privacy policy, maps the data handling and tests whether the published commitments survive contact with the evidence.

APPLICATION DISCOVERY AND TECHNICAL ANALYSIS MOBSTR

The evidence

  • Find the mobile apps and browser extensions actually in use
  • Analyse Android, iOS, Chrome and Edge packages
  • Inspect permissions, SDKs, libraries and trackers
  • Assess security posture against OWASP mobile indicators
  • Track application and dependency changes over time
  • Feed managed estate and API workflows
DATA PRIVACY INTELLIGENCE INTERROPOL

The interrogation

  • Rewrite the privacy policy in plain English
  • Identify personal and special category data
  • Map storage locations, sovereignty and transfers
  • Name every third party, AI service and data recipient
  • Test each published statement against technical evidence
  • Score the risk and produce the evidence record
Security

Is the application technically sound?

Privacy

What data is collected, stored and shared?

Compliance

Can you evidence the control and the decision?

Governance

Does this application deserve your trust?

Exhibit B / The interrogation ledger

Statement on the left.
Evidence on the right.

This is the shape of every InterroPol assessment. Each commitment made in the policy is isolated, then tested against what Mobstr found inside the application. The example below is illustrative and is not drawn from a named customer or product.

Supplier workforce app  /  Android 4.2.1  /  assessed 14 days ago

“We collect only the information necessary to provide the service.”
14 permissions requested. 6 carry no described purpose.
NOT EVIDENCED
“We do not share your personal data with third parties.”
8 third party recipients observed. 2 are advertising networks.
CONTRADICTED
“Location is used only when you choose to share it.”
Background location declared in the manifest and requested at launch.
CONTRADICTED
“Your data is stored in the United Kingdom.”
Endpoints resolve to 4 countries. 2 sit outside the stated scope.
CONTRADICTED
“Your data is encrypted in transit.”
TLS 1.3 across all observed endpoints. No cleartext traffic permitted.
SUPPORTED
“AI features help improve your experience.”
2 external model providers embedded. Content submission path confirmed.
NOT EVIDENCED
“We do not collect health information.”
No health permissions, sensors or health SDKs present in the package.
SUPPORTED
“We retain data no longer than necessary.”
No retention period published. No deletion route observed.
NOT EVIDENCED
“You can delete your account at any time.”
In-app deletion route present, reachable and confirmed working.
SUPPORTED
9 commitments tested 3 supported 3 not evidenced 3 contradicted Privacy risk score 62.0 / 100

The platform

Six things InterroPol does
with a policy and an app.

InterroPol is short for interrogate policy. It converts published privacy commitments and Mobstr technical evidence into intelligence that privacy, security, risk and procurement teams can act on together.

APPLICATION DISCOVERYINTELLIGENCE VIEW
Conceptual interfaceEvidence via Mobstr

The method

Five steps, repeated
every time anything changes.

The order matters. Evidence is gathered before the policy is read, so the interrogation is never anchored by what the supplier chose to tell you.

STEP 01

Discover

Identify the mobile apps and browser extensions present across the estate and the supplier ecosystem.

STEP 02

Analyse

Mobstr examines permissions, components, dependencies, trackers and security indicators.

STEP 03

Interrogate

InterroPol extracts and explains the privacy commitments, purposes, data types and sharing.

STEP 04

Validate

Declared practice is set against technical evidence and every divergence is recorded.

STEP 05

Monitor

Policies, packages and risk indicators are tracked continuously as the ecosystem moves.

Built for regulated organisations

Application intelligence
for real governance pressure.

The same evidence answers different questions depending on who is asking. Clinical assurance, citizen data governance, regulated outsourcing and enterprise application control all draw on one record.

NHS AND HEALTHCARE

Patient, clinical and workforce assurance

Support DPIAs, DTAC submissions, special category oversight and continuous supplier monitoring.

LOCAL GOVERNMENT

Visibility across citizen and workforce apps

Surface data sharing, international transfer and estate risks across highly varied services.

FINANCIAL SERVICES

Third party and regulated application oversight

Strengthen due diligence, DORA registers, outsourcing assurance and portfolio governance.

ENTERPRISE AND CHARITY

Clear intelligence without specialist overload

Prioritise application risk, improve procurement and give leadership evidence they can read.

Research and insight

The thinking behind
Data Privacy Intelligence.

Security alone does not describe whether an application deserves trust. Organisations need continuous visibility across security, privacy, compliance and governance at once.

RESEARCH PAPER 001

The State of Mobile Application Privacy 2026

Why Data Privacy Intelligence is the next generation of application risk management, and how organisations can establish what applications really do with data.

Request the paper
EXECUTIVE CHECKLIST

Ten questions to ask before trusting an application

Data, permissions, recipients, locations, AI, policy alignment, monitoring and evidence.

SAMPLE OUTPUT

A worked privacy intelligence assessment

Scores, findings, evidence, detected changes and the recommended governance action.

Start with your estate

Find what is there.
Understand what it does.
Decide what to trust.

We will run an interrogation against applications you actually use and walk you through the evidence, the findings and what we would recommend you do next.

InterroPolPOWERED BYMOBSTR

We will reply within one working day. We do not add you to a marketing list.