Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion
Preethi Santhanam, Hoang Dang, Zhiyong Shan, Iulian Neamtiu
Abstract
Sixty-five percent of mobile apps require user accounts for offering full-fledged functionality. Account information includes private data, e.g., address, phone number, credit card. Our concern is “leftover” account data kept on the server after account deletion, which can be a significant privacy violation. Specifically, we analyzed 1,435 popular apps from Google Play (and 771 associated websites), of which 678 have their own sign-up process, to answer questions such as: Can accounts be deleted at all? Following account deletion, will user data remain on the app’s servers? If so, for how long? Do apps keep their promise to remove data? Answering these questions, and more generally, understanding and tackling the leftover account problem, is challenging. A fundamental obstacle is that leftover data is manipulated and retained in a private space, on the app’s backend servers; we devised a novel, reverse-engineering approach to infer leftover data from app–server communication. Another obstacle is the distributed nature of this data: program analysis as well as information retrieval are required on both the app and its website. We have developed an end-to-end solution (static analysis, dynamic analysis, natural language processing) to the leftover account problem. First, our toolchain checks whether an app, or its website, support account deletion; next, it checks whether the app/website have a data retention policy, and whether the account is left on servers after deletion, or after the specified retention period; finally, it automatically cleans up leftover accounts. We found that 64.45% of apps do not offer any means for users to delete accounts; 2.5% of apps still keep account data on app servers even after accounts are deleted by users. Only 5% of apps specify a retention period; some of these apps violate their own policy by still retaining data months after the period has ended. Experiments show that our approach is effective, with an F-measure %, and efficient, with a typical analysis time of 279 seconds per app/website.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b6de1e1c-323b-47b5-ace7-2a1596b231beCited by top-tier papers2
- Withdrawing is believing? Detecting Inconsistencies between Withdrawal Choices and Third-party Data Collections in Mobile AppsXiaolin Du, Zhemin Yang, Jiapeng Lin, Yinzhi Cao et al.S&P 2024 · 8 citations
- No Way to Sign Out? Unpacking Non-Compliance with Google Play's App Account Deletion RequirementsJingwen Yan, Song Liao, Jin Ma, Mohammed Aldeen et al.USENIX Security 2025
Builds on2
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 123 citations
- Life after App Uninstallation: Are the Data Still Alive? Data Residue Attacks on AndroidXiao Zhang, Kailiang Ying, Yousra Aafer, Zhenshen Qiu et al.NDSS 2016 · 34 citations
Related papers
- How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account DeletionYijing Liu, Yan Jia, Qingyin Tan, Zheli Liu et al.USENIX Security 2022
- Understanding Account Deletion and Relevant Dark Patterns on Social MediaBrennan Schaffner, Neha A. Lingareddy, Marshini ChettyCSCW 2022 · 66 citations
- Vulnerable Implicit Service: A RevisitLingguang Lei, Yi He, Kun Sun, Jiwu Jing et al.CCS 2017 · 5 citations
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
- How does misconfiguration of analytic services compromise mobile privacy?Xueling Zhang, Xiaoyin Wang, Rocky Slavin, Travis D. Breaux et al.ICSE 2020 · 21 citations
