98.2% of the 826,000 ad-enabled apps Pixalate analyzed across the Apple App Store and Google Play had a detectable privacy policy, according to its Q4 2024 GDPR Evasion in the Mobile App Ecosystem Report, published in March 2025. That leaves 14,906 apps with none at all, reaching an estimated 32.3 million lifetime users. The story here is not that most apps skip a privacy policy, most clearly do not, it is who the remaining 1.8% are and what happens to the users who install them.
What share of apps actually publish a privacy policy?
Pixalate's legal and data science teams scanned 826,000 apps carrying app-ads.txt files, the industry mechanism that authorizes which companies can sell an app's ad inventory, split between 242,000 Apple App Store listings and 584,000 Google Play listings. Of those, 14,906 had no privacy policy Pixalate could detect anywhere in their store listing or in-app disclosures, meaning 811,094 apps, 98.2% of the sample, did.
| Platform | Ad-enabled apps analyzed | Apps with no privacy policy | Share missing |
|---|---|---|---|
| Apple App Store | 242,000 | 11,313 | 4.7% |
| Google Play | 584,000 | 3,525 | 0.6% |
| Combined | 826,000 | 14,906 | 1.8% |
Source: Pixalate, Q4 2024 GDPR Evasion in the Mobile App Ecosystem Report, published March 2025.
Figure 1: The Apple App Store's no-policy rate runs nearly eight times higher than Google Play's, even though Google Play's sample was more than double the size. Source: Pixalate, Q4 2024 GDPR Evasion Report.
The gap between stores lines up with how each enforces its own rule. Google Play has required a privacy policy link from every published app, not just ones handling sensitive data, since July 20, 2022, and rejects new submissions that omit one. Apple requires a privacy policy URL under App Store Review Guideline 5.1.1 with no exceptions, but its review process checks the link exists at submission time rather than continuously re-verifying it stays live, which leaves more room for an app's policy to go dark after launch without triggering removal. If your app still links to a placeholder or an outdated policy, a privacy policy generator built around app store disclosure requirements closes that gap in the time it takes to answer a short questionnaire.
App stores have effectively closed a gap that still exists on the open web. How Many Websites Have a Privacy Policy? found detectable policy links on just 37.2% of the most-visited sites' homepages and 9.6% among sites ranked below 1 million, a far wider spread than anything Pixalate found across app stores, mainly because no equivalent gatekeeper reviews a website before it goes live the way Apple and Google review an app before it reaches a store listing.
How many app users are exposed by missing privacy policies?
The 14,906 apps without a privacy policy are not a fringe curiosity. Pixalate estimated they reached 32.3 million lifetime installs, concentrated in exactly the jurisdictions where a missing policy is also a legal violation.
Figure 2: Nearly all of the estimated exposure sits inside GDPR and UK GDPR jurisdiction. Source: Pixalate, Q4 2024 GDPR Evasion Report.
The missing policy did not stop these apps from monetizing. Among the no-policy apps in Pixalate's dataset, 92% (roughly 13,700 apps) still had an active relationship with Google's Ad Exchange, and 32% (about 4,700 apps) worked with Meta's ad network, both of which require a privacy policy from any publisher in their terms of service. Pixalate also found that among the top 100 highest-traffic apps in its no-policy dataset, 97% shared user data in the programmatic ad bidstream despite disclosing none of it. That combination, no policy plus active ad monetization plus real user volume, is what turns a compliance gap into regulatory exposure.
Why do some apps still have no privacy policy?
Abandonment explains most of the remaining gap. Pixalate's separate Q4 2022 tracking of apps with no detectable privacy policy link found that 68% of them had not been updated in over two years, up steadily from 60% at the start of that year.
Figure 3: Most apps missing a privacy policy are not actively maintained, and the abandonment share climbed through 2022. Source: Pixalate, Q4 2022 Abandoned Mobile Apps Report, published March 2023.
An app nobody maintains cannot fix a broken policy link, add a new disclosure when a law changes, or respond to an app store's compliance sweep. The practical read for a developer still shipping updates: the platforms already require a privacy policy at submission, so an active app missing one is closer to an oversight than a deliberate choice, and it is a fast one to correct compared to every other item on a store's rejection checklist.
Figure 4: Both stores gate submission on a privacy policy link, but only an active app can keep that link accurate afterward. Source: Google Play Developer Policy Center; Apple App Store Review Guideline 5.1.1.
How has app privacy policy compliance changed since 2014?
The 98.2% figure looks very different against the last time regulators measured this at scale. In May 2014, GPEN, a network of privacy enforcement authorities, coordinated a sweep of 1,211 popular apps across 26 authorities in 19 jurisdictions and published the results that September.
Figure 5: Enforcement tightened steadily after 2014, with both major stores now gating submission on a privacy policy link. Sources: GPEN sweep results (2014); Google Play Developer Policy Center; Mozilla Foundation (2023); Pixalate (2025).
GPEN's 2014 sweep found 85% of the sampled apps failed to clearly explain how they collected, used, or disclosed personal data, 59% left users struggling to find any basic privacy information before installing, and 11% had no privacy information whatsoever. That 11% figure from a decade ago is a rougher, harder-to-detect version of the same question Pixalate answered precisely in 2024, and both point the same direction: outright absence of a privacy policy has become the exception rather than the norm, even as the quality and accuracy of the policies apps do publish remains a separate, unresolved problem. Mozilla's 2023 review of 40 top Google Play apps found nearly 80% had discrepancies between what their privacy policy said and what their Google Play Data Safety label disclosed, which is the compliance gap that picks up where "does a policy exist" leaves off.
The Bottom Line
Publishing a privacy policy is no longer the exception among apps that carry ads and collect user data, 98.2% of the apps in Pixalate's Q4 2024 sample had one. The remaining 14,906 apps are concentrated on the Apple App Store, skew heavily toward abandoned software nobody is updating, and still reached an estimated 32.3 million users, most of them in the EU and UK where a missing policy is also a GDPR violation. For an active app, having no privacy policy at all is now the easiest compliance gap to close, since both Apple and Google already require the link at submission. Keeping that policy accurate as data practices change, not just present, is the harder and more common failure mode, and it is where a privacy policy generator built for app store disclosure requirements does the most good.
Frequently Asked Questions
What percentage of apps have a privacy policy? 98.2% of the 826,000 ad-enabled apps Pixalate analyzed across the Apple App Store and Google Play had a detectable privacy policy, according to its Q4 2024 GDPR Evasion in the Mobile App Ecosystem Report, published March 2025. That still left 14,906 apps with none.
How many app users are affected by apps with no privacy policy? An estimated 32.3 million lifetime users installed one of the 14,906 no-privacy-policy apps Pixalate identified, including 27.5 million users in the EU and 4.8 million in the UK, per the same Q4 2024 report.
Which app store has more apps without a privacy policy? The Apple App Store accounted for 11,313 of the no-policy apps Pixalate found versus 3,525 on Google Play, even though Google Play's analyzed sample was larger, at 584,000 apps against the App Store's 242,000.
Why do some apps still have no privacy policy? 68% of apps with no detectable privacy policy link were abandoned, meaning no update in over two years, as of Q4 2022, up from 60% at the start of that year, per Pixalate's abandoned mobile apps tracking. Google Play has required every app to post a privacy policy link since July 20, 2022, and Apple requires one under App Store Review Guideline 5.1.1, so most surviving gaps sit in apps nobody is actively maintaining.
Where the Numbers Come From
- Pixalate. (2025). "Q4 2024 GDPR Evasion in the Mobile App Ecosystem Report." 826,000 ad-enabled apps analyzed (242,000 Apple App Store, 584,000 Google Play), 14,906 with no detectable privacy policy, 32.3 million estimated lifetime users affected. Published March 12, 2025.
- Pixalate. (2023). "Q4 2022 Abandoned Mobile Apps Report." 68% of apps with no privacy policy link found abandoned (no update in 2+ years) in Q4 2022, up from 60% in Q1 2022. Published March 8, 2023.
- National Law Review, summarizing the Global Privacy Enforcement Network. (2014). "Global Privacy Enforcement Network (GPEN) Publishes Privacy Sweep Results." 1,211 apps examined by 26 privacy authorities across 19 jurisdictions, May 12 to 18, 2014; 85% failed to clearly explain data practices, 59% made basic privacy information hard to find, 11% had no privacy information at all, 43% did not tailor communications to mobile, 31% requested excessive permissions. Results published September 10, 2014.
- Mozilla Foundation. (2023). "Mozilla Study: Data Privacy Labels for Most Top Apps in Google Play Store Are False or Misleading." 40 top Google Play apps reviewed, nearly 80% with discrepancies between privacy policy and Data Safety label. Published February 23, 2023.
- Google Play. "Privacy Policy Requirements, Developer Policy Center." Confirms every app has required a privacy policy link since July 20, 2022.
Note: All figures verified as of July 2026. Pixalate's Q4 2024 figures cover ad-enabled apps carrying app-ads.txt files rather than every app in either store, since that is the population its ad-tech scanning methodology can directly observe; treat 98.2% as the best available estimate for monetized, ad-supported apps rather than a universal figure for every app published. Figures are refreshed at least twice a year to track new Pixalate report editions.