Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AI
Shiva Mayahi, Noura Alomar, Nathan Malkin
Abstract
For mobile developers to comply with privacy regulations, they must create privacy policies that accurately describe their apps' data practices. This requires a complete understanding of their apps' behaviors, including those of embedded third-party SDKs. Despite the complexity of this process, little is known about how privacy policies are created and validated. To investigate, we interviewed 20 developers from around the world about their processes, also observing them use a large language model (LLM) to prepare privacy policies for their apps. We found that developers struggle with collecting information about third-party SDKs, even when they use LLMs, and feel uncertain about the legal validity of LLM outputs. Many developers do not seek legal assistance and believe that, as long as app stores accept their privacy policies, they are protected. Our findings suggest that reliance on LLMs and developers' desire to externalize validation may result in increasingly unreliable privacy policies.
• Human-centered computing → Collaborative and social computing; • Security and privacy → Human and societal aspects of security and privacy; • Social and professional topics → Privacy policies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 08db3f67-61f3-4e99-abde-5434a4159d5dBuilds on20
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
- Shaping Human-AI Collaboration: Varied Scaffolding Levels in Co-writing with Language ModelsParamveer S. Dhillon, Somayeh Molaei, Jiaqi Li, Maximilian Golub et al.CHI 2024 · 102 citations
- Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and ChallengesMohammad Tahaei, Alisa Frik, Kami VanieaCHI 2021 · 75 citations
- DiaryMate: Understanding User Perceptions and Experience in Human-AI Collaboration for Personal JournalingTaewan Kim, Donghoon Shin, Young-Ho Kim, Hwajung HongCHI 2024 · 74 citations
- Understanding Challenges for Developers to Create Accurate Privacy Nutrition LabelsTianshi Li, Kayla Reiman, Yuvraj Agarwal, Lorrie Faith Cranor et al.CHI 2022 · 56 citations
Related papers
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing et al.USENIX Security 2024 · 18 citations
- Assessing Privacy Compliance Awareness and Practices Among Mobile Third-party Library DevelopersFares F. Alharbi, Ece Gumusel, Luyi Xing, Xiaojing LiaoCCS 2026
- Navigating Developers' Quagmire: LLM-Enabled Privacy Compliance Analysis for SDK IntegrationsZhaojie Hu, Xueqiang WangS&P 2026
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
- Navigating the Data Avalanche: Towards Supporting Developers in Developing Privacy-Friendly Children's AppsAnirudh Ekambaranathan, Jun Zhao, George ChalhoubUbiComp 2023 · 9 citations
