VPVet: Vetting Privacy Policies of Virtual Reality Apps
Yuxia Zhan, Yan Meng, Lu Zhou, Yichang Xiong, Xiaokuan Zhang, Lichuan Ma, Guoxing Chen, Qingqi Pei, Haojin Zhu
Abstract
Virtual reality (VR) apps can harvest a wider range of user data than web/mobile apps running on personal computers or smartphones. Existing law and privacy regulations emphasize that VR developers should inform users of what data are collected/used/shared (CUS) through privacy policies. However, privacy policies in the VR ecosystem are still in their early stages, and many developers fail to write appropriate privacy policies that comply with regulations and meet user expectations. In this paper, we propose VPVet to automatically vet privacy policy compliance issues for VR apps. VPVet first analyzes the availability and completeness of a VR privacy policy and then refines its analysis based on three key criteria: granularity, minimization, and consistency of CUS statements. Our study establishes the first and currently largest VR privacy policy dataset named VRPP, consisting of privacy policies of 11,923 different VR apps from 10 mainstream platforms. Our vetting results reveal severe privacy issues within the VR ecosystem, including the limited availability and poor quality of privacy policies, along with their coarse granularity, lack of adaptation to VR traits and the inconsistency between CUS statements in privacy policies and their actual behaviors. We open-source VPVet system along with our findings at repository https://github.com/kalamoo/PPAudit , aiming to raise awareness within the VR community and pave the way for further research in this field.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 472a6a36-d6fb-4d31-8848-1f44d93689e9Cited by top-tier papers6
- Motion in the Clear: Reconstructing VR User Behavior from Network TrafficJiHo Lee, JinYi Yoon, Taejoong Chung, Brendan David-John et al.USENIX Security 2026
- DIPBox: A Multi-scale Testing Framework for Tracking Dataset RegenerationTian Dong, Yan Meng, Shaofeng Li, Guoxing Chen et al.CCS 2026
- PrivaCI in VR: Exploring Perceptions and Acceptability of Data Sharing in Virtual Reality Through Contextual IntegrityEmiram Kablo, Melina Kleber, Patricia Arias CabarcosUSENIX Security 2025
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
- Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR FirmwareVamsi Shankar Simhadri, Yichang Xiong, Habiba Farrukh, Xiaokuan ZhangCCS 2025
Builds on14
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- Evaluating the Contextual Integrity of Privacy Regulation: Parents' IoT Toy Privacy Norms Versus COPPANoah J. Apthorpe, Sarah Varghese, Nick FeamsterUSENIX Security 2019 · 69 citations
- OVRseen: Auditing Network Traffic and Privacy Policies in Oculus VRRahmadi Trimananda, Hieu Le, Hao Cui, Janice Tran Ho et al.USENIX Security 2022
Related papers
- An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy PerspectivesHanyang Guo, Hong-Ning Dai, Xiapu Luo, Zibin Zheng et al.ICSE 2024 · 17 citations
- Immersive Invaders: Privacy Threats from Deceptive Design in Virtual Reality Games and ApplicationsHilda Hadan, Michaela Valiquette, Lennart E. Nacke, Leah Zhang-KennedyCSCW 2025 · 2 citations
- A Fine-grained Chinese Software Privacy Policy Dataset for Sequence Labeling and Regulation Compliant IdentificationKaifa Zhao, Le Yu, Shiyao Zhou, Jing Li et al.EMNLP 2022 · 7 citations
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
- Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile AppsShidong Pan, Dawen Zhang, Mark Staples, Zhenchang Xing et al.USENIX Security 2024 · 18 citations
