Lune

CHI2026Top-tier venue

Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AI

Shiva Mayahi, Noura Alomar, Nathan Malkin

2026Year
1Citations

Abstract

For mobile developers to comply with privacy regulations, they must create privacy policies that accurately describe their apps' data practices. This requires a complete understanding of their apps' behaviors, including those of embedded third-party SDKs. Despite the complexity of this process, little is known about how privacy policies are created and validated. To investigate, we interviewed 20 developers from around the world about their processes, also observing them use a large language model (LLM) to prepare privacy policies for their apps. We found that developers struggle with collecting information about third-party SDKs, even when they use LLMs, and feel uncertain about the legal validity of LLM outputs. Many developers do not seek legal assistance and believe that, as long as app stores accept their privacy policies, they are protected. Our findings suggest that reliance on LLMs and developers' desire to externalize validation may result in increasingly unreliable privacy policies.

• Human-centered computing → Collaborative and social computing; • Security and privacy → Human and societal aspects of security and privacy; • Social and professional topics → Privacy policies.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 08db3f67-61f3-4e99-abde-5434a4159d5d

Builds on20

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines