Consumer Mobile App Privacy Label and SDK Audit Checklist
Audit retail mobile application SDKs and tracking flows for App Store Privacy Nutrition Labels and Data Safety sections.
Use this prompt to audit third-party analytics, ad tech, and CRM SDKs embedded within retail mobile applications. It produces an exhaustive data disclosure checklist to ensure compliance with Apple ATT and Google Play Data Safety requirements.
Role: Mobile Security and Privacy Compliance Engineer specializing in consumer data governance and app store privacy declarations.
Context
- Retail application: {{app_name}}
- Ecosystem targets: {{target_store_ecosystems}}
- Integrated analytics & adtech SDKs: {{third_party_sdks}}
- Consumer data collected: {{data_collection_types}}
- Account deletion & data management mechanisms: {{account_deletion_flow}}
- Loyalty and behavioral profiling tier: {{loyalty_program_tier}}
Task
Generate an exhaustive mobile privacy audit checklist to accurately map data flows from {{third_party_sdks}} and {{loyalty_program_tier}} into Apple Privacy Nutrition Labels and Google Play Data Safety declarations for {{app_name}} across {{target_store_ecosystems}}.
Method
- Inventory all data types collected in {{data_collection_types}} (e.g., precise location, purchase history, device identifiers).
- Trace data access, transmission, and retention across each SDK listed in {{third_party_sdks}}.
- Map data collection purposes (App Functionality, Analytics, Developer Advertising, Personalization) against platform-specific disclosure taxonomies.
- Audit App Tracking Transparency (ATT) implementation and prompt timing relative to user onboarding.
- Verify that {{account_deletion_flow}} satisfies store mandates for direct, in-app account and data deletion.
- Evaluate encryption in transit and ephemeral data handling for checkout and payment instrumentation.
- Assemble an actionable pre-submission audit checklist with data mapping verifications for each store platform.
Constraints
- Checkpoints MUST explicitly differentiate between Apple App Store Privacy Details and Google Play Data Safety section requirements.
- The checklist MUST require affirmative proof of in-app account deletion compliance.
- You MUST NOT approve third-party SDKs that collect device fingerprinting signals without user consent.
- The audit MUST address user data sharing with third-party advertising brokers.
Output format
- Section 1: SDK Data Interception & Purpose Mapping Matrix (Markdown table)
- Section 2: App Store Privacy Nutrition Label Checklist (Apple iOS specific, structured with checkboxes
[ ], Data Category, Purpose, and Linked to Identity status) - Section 3: Google Play Data Safety Declaration Checklist (Google Play specific, structured with checkboxes
[ ], Data Type, Shared vs. Collected, and Security Practices) - Section 4: Account Deletion and Consent Flow Verification Protocol (5-8 strict pass/fail criteria)
Self-review
- Are all 6 variables ({{app_name}}, {{target_store_ecosystems}}, {{third_party_sdks}}, {{data_collection_types}}, {{account_deletion_flow}}, {{loyalty_program_tier}}) fully utilized?
- Does the checklist distinctly cover both Apple Privacy Nutrition and Google Play Data Safety requirements?
- Is the account deletion requirement evaluated in strict compliance with current store guidelines?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.