Sensor Tower, an analytics platform which aggregates data on app downloads and usage for developers, has secretly collected data from millions of Android and iOS users through VPN and ad-blocking apps, reports Buzzfeed News.

The report adds that the company owns at least 20 Android and iOS applications with more than 35 million downloads. Out of those, Free and Unlimited VPN, Luna VPN, Mobile Data, and Adblock Focus were recently available in the Google Play Store while Adblock Focus and Luna VPN were available in Apple’s App Store.

Sensor Tower Apps Data Collection

However, Apple has now removed Adblock Focus while Google has removed Mobile Data after being contacted by BuzzFeed News. The companies are further conducting an investigation regarding this.

Here is how it all worked. When Sensor Tower’s app gets installed on the device, it asks users to install a root certificate, which enables Sensor Tower to monitor all traffic and data passing through the phone.

Sensor Tower bypasses Apple and Google’s restrictions on root certificate privileges by requiring users to install the certificate through an external website. The company says that it only collects anonymised usage and analytics data.

Interestingly, none of the applications have been tied to Sensor Tower on the App Store as they were listed under other company names. They were tied to Sensor Tower after BuzzFeed realised that the apps “contain code authored by developers who work for the company.” Apple spokesperson has confirmed that a dozen of Sensor Tower apps have been removed from the App Store due to violations.

Randy Nelson, Sensor Tower’s head of mobile insights, explains that the “vast majority” of the apps are “defunct and a few are in the process of sunsetting.” He doesn’t admit that the apps are now defunct because they were removed for policy violations.

(Source)