Monetization: The Privacy Risks and Rewards of In-App Purchases and IBA

Nov 5, 2020, 09:57 AM by BBB National Programs

Every day, teens download apps for free on the Google Play and Apple App Stores and, in doing so, participate in a hidden advertising ecosystem that collects data from them. Alongside this ecosystem, users have the choice to buy upgrades to these apps in the form of in-app purchases, which can be correlated with the same behavioral data that powers advertising. Though these monetization models have caused the mobile app economy to flourish, they sometimes come at the cost of user privacy. 

Recently, BBB National Programs’ TeenAge Privacy Program (TAPP) published a white paper on this topic called Risky Business: The Current State of Teen Privacy in the Android App Marketplace. The study identifies privacy risks across 1,100+ teen-directed apps and breaks down the complex relationship between data privacy, advertising, and in-app purchases. 

How to Make Money Off Apps

In the mobile app ecosystem, app publishers frequently rely on advertising in the form of contextual advertising or interest-based advertising (IBA, also known as targeted advertising) to monetize their products. 

In the Risky Business teen app dataset, almost 83% of apps used advertising to monetize, compared to 51% of apps directed to general audiences.

How does IBA work? 

Generally speaking, IBA is the process by which users are served with ads based on their interests as inferred from their behaviors. Think about this process as one long chain. On one end of the chain sit advertisers. On the other end of the chain sit end users. And in the middle sit third-party adtech companies and mobile app publishers. 

In the mobile app environment, this process is facilitated by software development kits (SDKs), pieces of software that allow third-party software libraries, including advertisement libraries, to be integrated into apps. 

As users engage with their favorite apps, some third-party libraries collect unique advertising identifiers from smartphones by adtech companies. App developers who integrate the libraries into their apps help adtech companies collect behavioral data from users as they engage with apps, and adtech companies work in concert with one another and with advertisers to ensure that users receive ads targeted to their interests. 

The result of this process is a user being served with an interest-based ad in real time as they engage with their favorite app. This is an automated, high-velocity process that happens in a fraction of a second. 

Seem harmless? It can be. But imagine that a teen is using a dating app and has her preferences set to prefer males and females. In some cases, third-party adtech companies, invisible to the user, will collect this gender preference data alongside the user’s unique device identifier to help target her with inappropriate or suggestive ads. Adtech companies can also correlate unique device identifiers with location data, app engagement, and other data points to build a full profile of that individual user. 

What’s contextual advertising?

To be clear, many apps don’t rely on IBA but instead use contextual advertising to monetize. Contextual advertising relies on the content of the app to infer a user’s interest, rather than behavioral data collected over time. 

If a teen is playing a flight simulator app and gets an ad for another flight simulator app, chances are that’s contextual advertising. Compared to IBA, contextual advertising requires very little data collection to facilitate. 

Monetization Tricks of the Trade 

Besides advertising, publishers may integrate the ability to purchase items, features, and upgrades into their apps. For example, an in-app purchase is something like a sword or armor that gives a user more power in a game, a key that unlocks more features in an app, or virtual currency that can be used for other in-app purchases. 

In the Risky Business teen dataset, 78% of apps contained in-app purchases, compared with less than 50% of apps directed to general audiences.

With these monetization models and digital tactics at their disposal, mobile app companies can use data collected from their users to maximize their revenue from both ads and in-app purchases. 

For example, many mobile app publishers cater to “whales” – users who are known to make a lot of in-app purchases – by continually releasing new and niche content behind small paywalls to keep those users engaged with the app for a long period of time. Companies also optimize their ad models to reel in “fish” – users who experience IBA as they use their favorite apps and make incremental purchases from time to time based on this advertising. 

“Fish” may become “whales” overtime due to the addicting nature of freemium app models. Some companies count on requiring in-app purchases to reach higher levels or providing in-game rewards for watching ads causing users to spend a lot more time in their apps. Teens are especially susceptible to these monetization tactics because of their age, and since app developers are paid for ad engagement, they often achieve great profitability at the users’ expense.

Putting the Pieces Together

The traditional prohibitions on data collection and advertising imposed by the Children’s Online Privacy Protection Act (COPPA) that apply to children under 13 don’t apply to teenagers. Consequently, companies are free to mine teens for their data as they engage with mobile apps. Using this data, adtech companies can make powerful inferences about teen behavior, and app publishers can engineer user experiences to encourage teens to engage in profitable behavior. 

For example, dark patterns – manipulative design tactics, push notifications, and addictive gaming experiences that characterize freemium models – can be paired with data collected from their app usage to create customized digital traps. And sensitive data about a teen’s behavior – such as precise location – can be shared downstream with other adtech companies and combined with other types of data to serve them IBA. 

To make all of this concrete, here’s a possible scenario. 

Say a teen user downloads a new, popular social media app. After downloading, the app asks for permission to use his location, and the teen user grants the permission request. Unbeknownst to the teen, as he’s using the app, he’s now sharing his device identifier, event data (a log of certain actions he takes on his device), and location data to both the app publisher and third-party adtech companies. The teen puts the app away at lunch, and he receives a targeted push notification an hour later that prompts him to engage with the app. When he opens the app, he is presented with a screen that he cannot easily close encouraging him to make an in-app purchase. When he makes an in-app purchase, not only is the app publisher aware of this event, the platform where he downloaded the app gains this knowledge since it facilitates the credit card purchase. Later, the teen goes for a walk, and while he’s using the app, he receives a targeted ad based on his location encouraging him to buy a coffee at a nearby shop. He clicks the ad to learn more about a potential discount.

In sum, as the result of the teen downloading and using the app for a few brief moments throughout the day, a number of different entities swiftly obtained data about him. Data that the teen or his parents might consider sensitive has now been seen, used, and stored in the records of app publishers, adtech companies, and advertisers.  

A Question of Data Ethics

The mobile app ecosystem has brought a lot of value to our shared digital economy. But important questions about privacy, user design, and data ethics are raised as a result of how this ecosystem functions. Users of all ages should keep this environment in mind as they engage with free-to-play games, dating apps, or useful utility apps, and be aware of the privacy tradeoffs involved when they decide to download a new app. Teen users and their parents should be especially sensitive of these issues given teens’ unique habits, preferences, and developmental state and their deep engagement with the digital world.

Other Blog Articles

Blog

Champions for Truth in Advertising

Today, the National Advertising Division (NAD) continues to carry the torch for truth-in-advertising. As the advertising landscape has evolved over the last 50 years, NAD has continued to adapt to new products, new industries, and new advertising media. Laura Brett, Vice President of NAD, and New York Office Lead for BBB National Programs discusses truth-in-advertising trends, hot topics, and issues that lie ahead.
Read more
Blog

Status Update on Transatlantic Data Transfers: Building Bridges Takes Time

As 2020 draws to a close it is a good time to reflect on learnings about the future of authorized transatlantic data transfer mechanisms. In light of Brexit and continuing developments surrounding Schrems II, we discuss what the structure of the current Privacy Shield Framework can teach us much about what future commercial transfer mechanisms are likely to look like, as well as what businesses can do to shore up their compliance efforts.
Read more
Blog

Operation Income Illusion: A Positive Step by the FTC to Curb Deceptive Income Claims

The Federal Trade Commission (FTC)’s December 14 Operation Income Illusion initiative is a crackdown by the FTC and 19 federal, state, and local law enforcement partners against those that purport to offer significant income opportunities but that end up costing consumers thousands of dollars. This effort is consistent with an ongoing effort in the direct selling industry to ensure income claims are communicated truthfully and accurately.
Read more
Blog

CFBAI and CCAI 2019 Report on Compliance and Progress Published

BBB National Programs has published the Children's Food and Beverage Advertising Initiative (CFBAI) and Children’s Confection Advertising Initiative (CCAI) Report on Compliance and Progress During 2019. The report finds excellent compliance by all companies participating in the programs from January 2019 – December 2019. The report also notes the CFBAI participants’ implementation of stricter Uniform Nutrition Criteria in 2020.
Read more