A UNSW-led audit of nearly 200 school-endorsed apps has found most begin harvesting children’s data within seconds, often contradicting their own privacy policies and exposing significant gaps in oversight across education systems, developers and regulators.
The research, conducted by the UNSW Institute for Cyber Security and funded by the UNSW Australian Human Rights Institute, analysed approximately 200 Android apps sourced from state Department of Education recommendation lists, school resources and the Google Play Store.
For educators working in increasingly digital classrooms, the findings highlight risks embedded in tools that are routinely endorsed and used for teaching and learning.
The study found that 89.3 per cent of apps transmitted data to third parties before any user interaction. Simply opening an app triggered the transfer of device identifiers, location metadata and other sensitive information.
Lead researcher Dr Rahat Masood, a cyber security expert at UNSW, said this “idle telemetry” occurs regardless of whether a student actively uses the app.
“Even if you are not interacting with the app – you just open it – that is still transferring lots of data,” she said.
In total, 83.6 per cent of apps transmitted persistent identifiers capable of tracking a device across sessions and different apps, while 67.9 per cent included embedded trackers such as analytics and advertising tools.
“None of these are needed to actually run the educational apps,” Dr Masood said.
Policy trap
The audit also identified major issues with transparency and accuracy in app privacy policies – documents often relied upon in school procurement and approval processes.
Only 3 per cent of policies were written at a level considered “fairly easy” to read, with the remaining 97 per cent requiring university-level literacy or higher.
“Nobody will understand these terminologies and jargon,” Dr Masood said. “Comprehension, readability, understandability – all these metrics that we analysed were very bad.”
More concerningly, the study found only about one in four apps were consistent between their stated privacy policies and their actual behaviour during testing.
Apps that claimed not to collect personal data were, in practice, transmitting identifiers within seconds of launch. In some cases, apps described as having “no ads, no tracking” were found sending data to third-party analytics services immediately upon opening.
“We matched the privacy policy with the dynamic analysis,” Dr Masood said. “Only one in four were matching.”
Apps marketed specifically to children – using terms such as “Kids,” “Preschool,” or “ABC” – were found to be no safer than general-audience apps, and in some cases showed worse alignment between privacy claims and actual behaviour.
The study found 76 per cent of child-targeted apps exhibited at least one form of policy distortion, compared with 67 per cent of general educational apps.
Researchers described this as an “illusion of safety,” where child-centric branding cultivates trust without delivering stronger protections. Many of these apps embedded the same analytics and advertising tools commonly used in commercial platforms.
Beyond privacy concerns, the audit also identified security risks. Nearly 80 per cent of apps contained “hard-coded secrets” – API keys and credentials embedded in code that could be accessed if the app were decompiled.
“Anyone can access it and do whatever they want with the API,” Dr Masood said. “It is not good practice from a development point of view.”
Implications for schools
The findings raise questions about the adequacy of current app approval processes used by education departments. While recommended app lists are widely relied upon by schools, the research suggests these assessments often focus on high-level criteria and do not include detailed technical analysis.
“They don’t download the app – they don’t do the dynamic analysis, they don’t go through accessibility and readability of the privacy policies,” Dr Masood said.
She noted that teachers are typically not equipped with the time, resources or specialist knowledge to identify such risks independently.
“Teachers don’t know anything,” she said. “They are out of resources, and they don’t know about any security issues. They were just given an app to use.”
The research team is calling for stronger oversight of educational apps, including stricter standards for “child-directed” platforms, limits on data collection before user interaction, and requirements for plain-language privacy policies.
They are also developing a “traffic light” tool to provide a clear, accessible summary of an app’s privacy and security profile.




