{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T13:26:15Z","timestamp":1784467575619,"version":"3.55.0"},"reference-count":70,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2022,11,8]],"date-time":"2022-11-08T00:00:00Z","timestamp":1667865600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,11,8]],"date-time":"2022-11-08T00:00:00Z","timestamp":1667865600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Cyber Security Cooperative Research Centre"},{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["830929"],"award-info":[{"award-number":["830929"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003170","name":"Stiftelsen f\u00f6r Kunskaps- och Kompetensutveckling","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003170","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100014195","name":"Region V\u00e4rmland","doi-asserted-by":"publisher","award":["RV2018-678"],"award-info":[{"award-number":["RV2018-678"]}],"id":[{"id":"10.13039\/501100014195","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/V011189\/1"],"award-info":[{"award-number":["EP\/V011189\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100016777","name":"Karlstad University","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100016777","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2023,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>An increasing number of mental health services are now offered through mobile health (mHealth) systems, such as in mobile applications (apps). Although there is an unprecedented growth in the adoption of mental health services, partly due to the COVID-19 pandemic, concerns about data privacy risks due to security breaches are also increasing. Whilst some studies have analyzed mHealth apps from different angles, including security, there is relatively little evidence for data privacy issues that may exist in mHealth apps used for mental health services, whose recipients can be particularly vulnerable. This paper reports an empirical study aimed at systematically identifying and understanding data privacy incorporated in mental health apps. We analyzed 27 top-ranked mental health apps from Google Play Store. Our methodology enabled us to perform an in-depth privacy analysis of the apps, covering static and dynamic analysis, data sharing behaviour, server-side tests, privacy impact assessment requests, and privacy policy evaluation. Furthermore, we mapped the findings to the LINDDUN threat taxonomy, describing how threats manifest on the studied apps. The findings reveal important data privacy issues such as unnecessary permissions, insecure cryptography implementations, and leaks of personal data and credentials in logs and web requests. There is also a high risk of user profiling as the apps\u2019 development do not provide foolproof mechanisms against linkability, detectability and identifiability. Data sharing among 3rd-parties and advertisers in the current apps\u2019 ecosystem aggravates this situation. Based on the empirical findings of this study, we provide recommendations to be considered by different stakeholders of mHealth apps in general and apps developers in particular. We conclude that while developers ought to be more knowledgeable in considering and addressing privacy issues, users and health professionals can also play a role by demanding privacy-friendly apps.<\/jats:p>","DOI":"10.1007\/s10664-022-10236-0","type":"journal-article","created":{"date-parts":[[2022,11,8]],"date-time":"2022-11-08T15:57:11Z","timestamp":1667923031000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":92,"title":["On the privacy of mental health apps"],"prefix":"10.1007","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9005-0543","authenticated-orcid":false,"given":"Leonardo Horn","family":"Iwaya","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"M. Ali","family":"Babar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Awais","family":"Rashid","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chamila","family":"Wijayarathna","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,11,8]]},"reference":[{"key":"10236_CR1","unstructured":"Adhikari R, Richards D, Scott K (2014) Security and privacy issues related to the use of mobile health apps. In: 25th Australasian conference on information systems, ACIS 2014, ACIS, pp 1\u201311"},{"key":"10236_CR2","doi-asserted-by":"crossref","unstructured":"Alepis E, Patsakis C (2017) Hey doc, is this normal?: Exploring Android permissions in the post marshmallow era. In: International conference on security, Privacy, and Applied Cryptography Engineering. Springer, pp 53\u201373","DOI":"10.1007\/978-3-319-71501-8_4"},{"key":"10236_CR3","doi-asserted-by":"crossref","unstructured":"Aljedaani B, Ahmad A, Zahedi M, Babar MA (2020) An Empirical study on developing secure mobile health apps: The developers\u2019 perspective. In: 2020 27Th asia-pacific software engineering conference (APSEC). IEEE, pp 208\u2013217","DOI":"10.1109\/APSEC51365.2020.00029"},{"issue":"6","key":"10236_CR4","doi-asserted-by":"publisher","first-page":"e15654","DOI":"10.2196\/15654","volume":"9","author":"B Aljedaani","year":"2021","unstructured":"Aljedaani B, Babar MA, et al. (2021) Challenges with developing secure mobile health applications: Systematic review. JMIR Mhealth and Uhealth 9(6):e15654","journal-title":"JMIR Mhealth and Uhealth"},{"key":"10236_CR5","unstructured":"Ament C (2017) The ubiquitous security expert: Overconfidence in information security. In: Proceedings of the 38th international conference on information systems (ICIS)"},{"issue":"6","key":"10236_CR6","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1145\/2666356.2594299","volume":"49","author":"S Arzt","year":"2014","unstructured":"Arzt S, Rasthofer S, Fritz C, Bodden E, Bartel A, Klein J, Le Traon Y, Octeau D, McDaniel P (2014) Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps. Acm Sigplan Notices 49(6):259\u2013269","journal-title":"Acm Sigplan Notices"},{"key":"10236_CR7","unstructured":"Aviram N, Schinzel S, Somorovsky J, Heninger N, Dankel M, Steube J, Valenta L, Adrian D, Halderman JA, Dukhovni V et al (2016) DROWN: Breaking TLS using SSLv2. In: 25Th USENIX security symposium (USENIX) security, vol 16, pp 689\u2013706"},{"issue":"1","key":"10236_CR8","doi-asserted-by":"publisher","first-page":"e7","DOI":"10.2196\/mental.4984","volume":"3","author":"D Bakker","year":"2016","unstructured":"Bakker D, Kazantzis N, Rickwood D, Rickard N (2016) Mental health smartphone apps: review and evidence-based recommendations for future developments. JMIR Mental Health 3(1):e7","journal-title":"JMIR Mental Health"},{"key":"10236_CR9","unstructured":"Bal G, Rannenberg K (2014) User control mechanisms for privacy protection should go hand in hand with privacy-consequence information: The case of smartphone apps. In: Proceedings of W3C workshop on privacy and user-centric controls, pp 1\u20135"},{"issue":"10","key":"10236_CR10","doi-asserted-by":"publisher","first-page":"1051","DOI":"10.1001\/jama.2015.19426","volume":"315","author":"SR Blenner","year":"2016","unstructured":"Blenner SR, K\u00f6llmer M, Rouse AJ, Daneshvar N, Williams C, Andrews LB (2016) Privacy policies of Android Diabetes Apps and Sharing of Health Information. JAMA 315(10):1051\u20131052","journal-title":"JAMA"},{"issue":"2","key":"10236_CR11","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1191\/1478088706qp063oa","volume":"3","author":"V Braun","year":"2006","unstructured":"Braun V, Clarke V (2006) Using thematic analysis in psychology. Qualitative Research in Psychology 3(2):77\u2013101","journal-title":"Qualitative Research in Psychology"},{"key":"10236_CR12","doi-asserted-by":"crossref","unstructured":"Brooks S, Garcia M, Lefkovitz N, Lightman S, Nadeau E (2017) NISTIR 8062 an introduction to privacy engineering and risk management in federal systems","DOI":"10.6028\/NIST.IR.8062"},{"key":"10236_CR13","first-page":"12","volume":"5","author":"A Cavoukian","year":"2009","unstructured":"Cavoukian A, et al. (2009) Privacy by design: The 7 foundational principles. Information and privacy commissioner of Ontario, Canada 5:12","journal-title":"Information and privacy commissioner of Ontario, Canada"},{"issue":"1","key":"10236_CR14","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","volume":"16","author":"M Deng","year":"2011","unstructured":"Deng M, Wuyts K, Scandariato R, Preneel B, Joosen W (2011) A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements. Requir Eng 16(1):3\u201332","journal-title":"Requir Eng"},{"issue":"11","key":"10236_CR15","doi-asserted-by":"publisher","first-page":"e247","DOI":"10.2196\/jmir.2791","volume":"15","author":"T Donker","year":"2013","unstructured":"Donker T, Petrie K, Proudfoot J, Clarke J, Birch MR, Christensen H (2013) Smartphones for smarter delivery of mental health programs: a systematic review. Journal of Medical Internet Research 15(11):e247","journal-title":"Journal of Medical Internet Research"},{"key":"10236_CR16","doi-asserted-by":"crossref","unstructured":"Durumeric Z, Li F, Kasten J, Amann J, Beekman J, Payer M, Weaver N, Adrian D, Paxson V, Bailey M et al (2014) The matter of heartbleed. In: Proceedings of the 2014 conference on internet measurement conference, pp 475\u2013488 ,","DOI":"10.1145\/2663716.2663755"},{"key":"10236_CR17","doi-asserted-by":"crossref","unstructured":"Egele M, Brumley D, Fratantonio Y, Kruegel C (2013) An empirical study of cryptographic misuse in Android applications. In: Proceedings of the 2013 ACM SIGSAC conference on computer & communications security, pp 73\u201384","DOI":"10.1145\/2508859.2516693"},{"issue":"2","key":"10236_CR18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2619091","volume":"32","author":"W Enck","year":"2014","unstructured":"Enck W, Gilbert P, Han S, Tendulkar V, Chun BG, Cox LP, Jung J, McDaniel P, Sheth AN (2014) Taintdroid: an information-flow tracking system for realtime privacy monitoring on smartphones. ACM Transactions on Computer Systems (TOCS) 32(2):1\u201329","journal-title":"ACM Transactions on Computer Systems (TOCS)"},{"key":"10236_CR19","unstructured":"EU Commission (2017) Guidelines on data protection impact assessment (DPIA) (wp248rev.01). https:\/\/ec.europa.eu\/newsroom\/article29\/item-detail.cfm?item_id=611236, accessed: 2020-12-11"},{"issue":"April","key":"10236_CR20","first-page":"1","volume":"119","author":"European Commission","year":"2016","unstructured":"European Commission (2016) Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation). Official Journal of the European Union 119(April):1\u201388","journal-title":"Official Journal of the European Union"},{"key":"10236_CR21","unstructured":"FIRSTOrg (2019) Common vulnerability scoring system v3.1, Tech. rep., Forum of Incident Response and Security Teams (FIRST)"},{"key":"10236_CR22","doi-asserted-by":"crossref","unstructured":"Gardiner J, Chowdhury PD, Halsey J, Tahaei M, Elahi T, Rashid A (2021) Building A privacy testbed: Use cases and design considerations. In: Proceedings of 4th international workshop on security and privacy requirements engineering (SECPRE)","DOI":"10.1007\/978-3-030-95484-0_12"},{"key":"10236_CR23","unstructured":"GDPREU (2020) Data protection impact assessment (DPIA). https:\/\/gdpr.eu\/data-protection-impact-assessment-template\/https:\/\/gdpr.eu\/data-protection-impact-assessment-template\/, accessed: 2020-11-18"},{"key":"10236_CR24","doi-asserted-by":"crossref","unstructured":"Giota KG, Kleftaras G (2014) Mental health apps: innovations, risks and ethical considerations. E-Health Telecommunication Systems and Networks 2014","DOI":"10.4236\/etsn.2014.33003"},{"issue":"3","key":"10236_CR25","first-page":"25","volume":"14","author":"S G\u00fcrses","year":"2011","unstructured":"G\u00fcrses S, Troncoso C, Diaz C (2011) Engineering privacy by design. Computers, Privacy & Data Protection 14(3):25","journal-title":"Computers, Privacy & Data Protection"},{"key":"10236_CR26","first-page":"645\u2014654","volume":"2014","author":"D He","year":"2014","unstructured":"He D, Naveed M, Gunter CA, Nahrstedt K (2014) Security concerns in Android mhealth apps. AMIA Annual Symposium proceedings AMIA Symposium 2014:645\u2014654","journal-title":"AMIA Annual Symposium proceedings AMIA Symposium"},{"key":"10236_CR27","unstructured":"Heilweil R (2020) Feeling anxious about coronavirus? there\u2019s an app for that. https:\/\/www.vox.com\/recode\/2020\/3\/20\/21185351\/mental-health-apps-coronavirus-pandemic-anxiety, accessed: 2020-12-02"},{"key":"10236_CR28","unstructured":"Howard M, Lipner S (2006) The security development lifecycle, vol 8. Microsoft Press Redmond"},{"key":"10236_CR29","doi-asserted-by":"crossref","unstructured":"Huang HY, Bashir M (2017) Android app permission and users\u2019 adoption: a case study of mental health application. In: Tryfonas T (ed) Human aspects of information security, privacy and trust. Springer International Publishing, Cham, pp 110\u2013122","DOI":"10.1007\/978-3-319-58460-7_8"},{"issue":"4","key":"10236_CR30","doi-asserted-by":"publisher","first-page":"e192542","DOI":"10.1001\/jamanetworkopen.2019.2542","volume":"2","author":"K Huckvale","year":"2019","unstructured":"Huckvale K, Torous J, Larsen ME (2019) Assessment of the data sharing and privacy practices of smartphone apps for depression and smoking cessation. JAMA Network Open 2(4):e192542\u2013e192542","journal-title":"JAMA Network Open"},{"key":"10236_CR31","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1016\/j.cose.2018.02.003","volume":"75","author":"M Hussain","year":"2018","unstructured":"Hussain M, Al-Haiqi A, Zaidan AA, Zaidan BB, Kiah M, Iqbal S, Iqbal S, Abdulnabi M (2018) A security framework for mhealth apps on Android platform. Computers & Security 75:191\u2013217","journal-title":"Computers & Security"},{"issue":"10","key":"10236_CR32","doi-asserted-by":"publisher","first-page":"e9217","DOI":"10.2196\/mhealth.9217","volume":"6","author":"L Hutton","year":"2018","unstructured":"Hutton L, Price BA, Kelly R, McCormick C, Bandara AK, Hatzakis T, Meadows M, Nuseibeh B et al (2018) Assessing the privacy of mhealth apps for self-tracking: heuristic evaluation approach. JMIR Mhealth and Uhealth 6(10):e9217","journal-title":"JMIR Mhealth and Uhealth"},{"key":"10236_CR33","unstructured":"IBM (2020) Cost of a data breach report. Tech. rep., International Business Machines Corporation. https:\/\/www.ibm.com\/security\/digital-assets\/cost-data-breach-report\/1Cost%20of%20a%20Data%20Breac%20Report%202020.pdf"},{"key":"10236_CR34","unstructured":"ICO UK (2019) Guide to the general data protection regulation (GDPR). Tech. rep., Information Commissioner\u2019s Office (ICO)"},{"issue":"3","key":"10236_CR35","doi-asserted-by":"publisher","first-page":"e11642","DOI":"10.2196\/11642","volume":"7","author":"LH Iwaya","year":"2019","unstructured":"Iwaya LH, Fischer-H\u00fcbner S, RM \u00c5hlfeldt, Martucci LA (2019) Mobile health systems for community-based primary care: Identifying controls and mitigating privacy threats. JMIR Mhealth and Uhealth 7(3):e11642","journal-title":"JMIR Mhealth and Uhealth"},{"key":"10236_CR36","unstructured":"Kotipalli SR, Imran MA (2016) Hacking Android. Packt Publishing Ltd"},{"key":"10236_CR37","doi-asserted-by":"crossref","unstructured":"Kr\u00fcger S, Nadi S, Reif M, Ali K, Mezini M, Bodden E, G\u00f6pfert F, G\u00fcnther F, Weinert C, Demmler D et al (2017) Cognicrypt: Supporting developers in using cryptography. In: 2017 32nd IEEE\/ACM international conference on automated software engineering (ASE), IEEE, pp 931\u2013936","DOI":"10.1109\/ASE.2017.8115707"},{"key":"10236_CR38","doi-asserted-by":"crossref","unstructured":"LaMalva G, Schmeelk S (2020) MobSF: Mobile health care Android applications through the lens of open source static analysis. In: 2020 IEEE MIT Undergraduate Research Technology Conference (URTC), IEEE, pp 1\u20134","DOI":"10.1109\/URTC51696.2020.9668870"},{"key":"10236_CR39","unstructured":"Lee J (2019) Identifying and mitigating misuse of secrets in Android with dynamic analysis techniques. PhD thesis, Rice University"},{"issue":"2","key":"10236_CR40","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1007\/s10506-019-09243-2","volume":"27","author":"M Lippi","year":"2019","unstructured":"Lippi M, Pa\u0142ka P, Contissa G, Lagioia F, Micklitz HW, Sartor G, Torroni P (2019) CLAUDETTE: an automated detector of potentially unfair clauses in online terms of service. Artificial Intelligence and Law 27(2):117\u2013139","journal-title":"Artificial Intelligence and Law"},{"key":"10236_CR41","first-page":"81","volume-title":"Towards a Code of Conduct on Privacy for mHealth to Foster Trust Amongst Users of Mobile Health Applications","author":"E Mantovani","year":"2017","unstructured":"Mantovani E, Antokol J, Hoekstra M, Nouwt S, Schutte N, Zilgalvis P, Castro G\u00f3mez-Valad\u00e9s JP, Prettner C (2017) Towards a Code of Conduct on Privacy for mHealth to Foster Trust Amongst Users of Mobile Health Applications. Springer International Publishing, Cham, pp 81\u2013106"},{"issue":"1","key":"10236_CR42","first-page":"19","volume":"27","author":"CL Marvel","year":"2004","unstructured":"Marvel CL, Paradiso S (2004) Cognitive and neurological impairment in mood disorders. Psychiatric Clinics 27(1):19\u201336","journal-title":"Psychiatric Clinics"},{"key":"10236_CR43","unstructured":"Momen N (2020) Measuring apps\u2019 privacy-friendliness: Introducing transparency to apps\u2019 data access behavior. PhD thesis, Karlstads universitet"},{"key":"10236_CR44","doi-asserted-by":"crossref","unstructured":"Muchagata J, Ferreira A (2019) Mobile apps for people with dementia: Are they compliant with the general data protection regulation (GDPR)?. In: Proceedings of the 12th International Joint Conference on Biomedical Engineering Systems and Technologies -Volume 5: HEALTHINF, INSTICC, SciTePress, pp 68\u201377","DOI":"10.5220\/0007352200680077"},{"key":"10236_CR45","unstructured":"MWR InfoSecurity (2015) Drozer user guide. https:\/\/labs.f-secure.com\/assets\/BlogFiles\/mwri-drozer-user-guide-2015-03-23.pdfhttps:\/\/labs.f-secure.com\/assets\/BlogFiles\/mwri-drozer-user-guide-2015-03-23.pdf"},{"key":"10236_CR46","unstructured":"NIST (2022) LINDDUN privacy threat modeling framework. https:\/\/www.nist.gov\/privacy-framework\/linddun-privacy-threat-modeling-framework, accessed: 2022-01-12"},{"key":"10236_CR47","unstructured":"OAIC (2020) Guide to undertaking privacy impact assessments. Tech. rep., Office of the Australian Information Commissioner (OAIC), https:\/\/www.oaic.gov.au\/_data\/assets\/pdf_file\/0013\/2074\/guide-to-undertaking-privacy-impact-assessments.pdf"},{"key":"10236_CR48","doi-asserted-by":"publisher","first-page":"110","DOI":"10.1016\/j.invent.2018.12.001","volume":"15","author":"K O\u2019Loughlin","year":"2019","unstructured":"O\u2019Loughlin K, Neary M, Adkins EC, Schueller SM (2019) Reviewing the data security and privacy policies of mobile apps for depression. Internet Interventions 15:110\u2013115","journal-title":"Internet Interventions"},{"key":"10236_CR49","doi-asserted-by":"publisher","first-page":"9390","DOI":"10.1109\/ACCESS.2018.2799522","volume":"6","author":"A Papageorgiou","year":"2018","unstructured":"Papageorgiou A, Strigkos M, Politou E, Alepis E, Solanas A, Patsakis C (2018) Security and privacy analysis of mobile health applications: the alarming state of practice. IEEE Access 6:9390\u20139403","journal-title":"IEEE Access"},{"key":"10236_CR50","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1016\/j.ijlp.2019.04.002","volume":"64","author":"L Parker","year":"2019","unstructured":"Parker L, Halter V, Karliychuk T, Grundy Q (2019) How private is your mental health app data? an empirical study of mental health app privacy policies and practices. Int J Law Psychiatry 64:198\u2013204","journal-title":"Int J Law Psychiatry"},{"key":"10236_CR51","unstructured":"Pfitzmann A, Hansen M (2010) A terminology for talking about privacy by data minimization: Anonymity, unlinkability, undetectability, unobservability, pseudonymity, and identity management. Dresden, Germany https:\/\/dud.inf.tu-dresden.de\/literatur\/Anon_Terminology_v0.34.pdf"},{"issue":"7","key":"10236_CR52","doi-asserted-by":"publisher","first-page":"e158","DOI":"10.2196\/mhealth.9871","volume":"6","author":"AC Powell","year":"2018","unstructured":"Powell AC, Singh P, Torous J (2018) The complexity of mental health app privacy policies: a potential barrier to privacy. JMIR Mhealth and Uhealth 6(7):e158","journal-title":"JMIR Mhealth and Uhealth"},{"issue":"4","key":"10236_CR53","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1037\/a0038113","volume":"55","author":"JL Prentice","year":"2014","unstructured":"Prentice JL, Dobson KS (2014) A review of the risks and benefits associated with mobile phone applications for psychological interventions. Canadian Psychology\/Psychologie Canadienne 55(4):282","journal-title":"Canadian Psychology\/Psychologie Canadienne"},{"issue":"5","key":"10236_CR54","doi-asserted-by":"publisher","first-page":"427","DOI":"10.1002\/cpp.1855","volume":"21","author":"M Price","year":"2014","unstructured":"Price M, Yuen EK, Goetter EM, Herbert JD, Forman EM, Acierno R, Ruggiero KJ (2014) mhealth: a mechanism to deliver more accessible, more effective mental health care. Clinical Psychology & Psychotherapy 21(5):427\u2013436","journal-title":"Clinical Psychology & Psychotherapy"},{"issue":"1","key":"10236_CR55","doi-asserted-by":"publisher","first-page":"178","DOI":"10.1007\/s10664-019-09749-y","volume":"25","author":"VP Ranganath","year":"2020","unstructured":"Ranganath VP, Mitra J (2020) Are free Android app security analysis tools effective in detecting known vulnerabilities? Empir Softw Eng 25(1):178\u2013219","journal-title":"Empir Softw Eng"},{"key":"10236_CR56","doi-asserted-by":"publisher","first-page":"100243","DOI":"10.1016\/j.invent.2019.100243","volume":"17","author":"JM Robillard","year":"2019","unstructured":"Robillard JM, Feng TL, Sporn AB, Lai JA, Lo C, Ta M, Nadler R (2019) Availability, readability, and content of privacy policies and terms of agreements of mental health apps. Internet Interventions 17:100243","journal-title":"Internet Interventions"},{"issue":"8","key":"10236_CR57","doi-asserted-by":"publisher","first-page":"873","DOI":"10.1016\/j.jagp.2017.04.009","volume":"25","author":"L Rosenfeld","year":"2017","unstructured":"Rosenfeld L, Torous J, Vahia IV (2017) Data security and privacy in apps for dementia: An analysis of existing privacy policies. The American Journal of Geriatric Psychiatry 25(8):873\u2013877. use of Technology in Geriatric Mental Health","journal-title":"The American Journal of Geriatric Psychiatry"},{"key":"10236_CR58","doi-asserted-by":"crossref","unstructured":"Samhi J, Bartel A, Bissyand\u00e9 TF, Klein J (2021) Raicc: Revealing Atypical inter-component communication in Android apps. In: 2021 IEEE\/ACM 43rd international conference on software engineering (ICSE), IEEE, pp 1398\u20131409","DOI":"10.1109\/ICSE43902.2021.00126"},{"issue":"4","key":"10236_CR59","doi-asserted-by":"crossref","first-page":"126","DOI":"10.58729\/1941-6679.1353","volume":"26","author":"BH Sampat","year":"2017","unstructured":"Sampat BH, Prabhakar B (2017) Privacy risks and security threats in mhealth apps. Journal of International Technology and Information Management 26(4):126\u2013153","journal-title":"Journal of International Technology and Information Management"},{"issue":"4","key":"10236_CR60","doi-asserted-by":"publisher","first-page":"491","DOI":"10.2478\/popets-2020-0083","volume":"2020","author":"L Shipp","year":"2020","unstructured":"Shipp L, Blasco J (2020) How private is your period?: a systematic analysis of menstrual app privacy policies. Proc Priv Enhancing Technol 2020 (4):491\u2013510","journal-title":"Proc Priv Enhancing Technol"},{"key":"10236_CR61","unstructured":"Solomos K, Ilia P, Ioannidis S, Kourtellis N (2019) TALON: An automated framework for cross-device tracking detection. In: 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019), USENIX Association, Chaoyang District, Beijing, pp 227\u2013241"},{"issue":"e1","key":"10236_CR62","doi-asserted-by":"publisher","first-page":"e28","DOI":"10.1136\/amiajnl-2013-002605","volume":"22","author":"A Sunyaev","year":"2014","unstructured":"Sunyaev A, Dehling T, Taylor PL, Mandl KD (2014) Availability and quality of mobile health app privacy policies. J Am Med Inform Assoc 22 (e1):e28\u2013e33","journal-title":"J Am Med Inform Assoc"},{"issue":"1","key":"10236_CR63","first-page":"57","volume":"4","author":"S Timpson","year":"2009","unstructured":"Timpson S (2009) The importance of a layered privacy policy on all mobile internet sites and mobile marketing campaigns. International Journal of Mobile Marketing 4(1):57\u201361","journal-title":"International Journal of Mobile Marketing"},{"key":"10236_CR64","unstructured":"Wagner A, Mesbah N (2019) Too confident to care: Investigating overconfidence in privacy decision making. In: Proceedings of the 27th European conference on information systems (ECIS)"},{"issue":"3","key":"10236_CR65","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3183575","volume":"21","author":"F Wei","year":"2018","unstructured":"Wei F, Roy S, Ou X (2018) Amandroid: A precise and general inter-component data flow analysis framework for security vetting of Android apps. ACM Transactions on Privacy and Security (TOPS) 21(3):1\u201332","journal-title":"ACM Transactions on Privacy and Security (TOPS)"},{"key":"10236_CR66","doi-asserted-by":"crossref","unstructured":"Wong MY, Lie D (2016) Intellidroid: a targeted input generator for the dynamic analysis of Android malware. In: NDSS, vol 16, pp 21\u201324","DOI":"10.14722\/ndss.2016.23118"},{"key":"10236_CR67","unstructured":"Wuyts K, Scandariato R, Joosen W (2014) LINDDUN threat tree catalog (v2.0). https:\/\/7e71aeba-b883-4889-aee9-a3064f8be401.filesusr.com\/ugd\/cc602e_d7cf949767b7486d8bff0ecc05b91db6.pdf, Accessed: 2021-03-11"},{"key":"10236_CR68","doi-asserted-by":"crossref","unstructured":"Zaeem RN, Barber KS (2020) The effect of the gdpr on privacy policies: Recent progress and future promise. ACM Transactions on Management of Information Systems","DOI":"10.1145\/3389685"},{"issue":"4","key":"10236_CR69","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3127519","volume":"18","author":"RN Zaeem","year":"2018","unstructured":"Zaeem RN, German RL, Barber KS (2018) Privacycheck: Automatic summarization of privacy policies using data mining. ACM Trans Internet Technol (TOIT) 18(4):1\u201318","journal-title":"ACM Trans Internet Technol (TOIT)"},{"key":"10236_CR70","unstructured":"Zaeem RN, Anya S, Issa A, Nimergood J, Rogers I, Shah V, Srivastava A, Barber KS (2020) PrivacyCheck v2: A tool that recaps privacy policies for you. In: Proceedings of the 29th ACM international conference on information & knowledge management, pp 3441\u20133444"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10236-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-022-10236-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10236-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T18:16:16Z","timestamp":1728324976000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-022-10236-0"}},"subtitle":["An empirical investigation and its implications for app development"],"short-title":[],"issued":{"date-parts":[[2022,11,8]]},"references-count":70,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,1]]}},"alternative-id":["10236"],"URL":"https:\/\/doi.org\/10.1007\/s10664-022-10236-0","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,8]]},"assertion":[{"value":"1 September 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 November 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The work has been supported by the Cyber Security Cooperative Research Centre (CSCRC) Limited, whose activities are partially funded by the Australian Government\u2019s Cooperative Research Centres Programme. The work of L.H. Iwaya has also been partially supported by the European Commission\u2019s H2020 Programme via the CyberSec4Europe project (Grant: 830929), the Swedish Knowledge Foundation via the TRUEdig project, and the Region V\u00e4rmland via the DigitalWell Arena project (Grant: RV2018-678). Awais Rashid is supported by REPHRAIN, National Research Centre on Privacy, Harm Reduction and Adversarial Influence Online (EPSRC Grant: EP\/V011189\/1).","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no conflicts of interest to declare. All co-authors have seen and agree with the contents of the manuscript and there is no financial interest to report. We certify that the submission is original work and is not under review at any other publication.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"<!--Emphasis Type='Bold' removed-->Conflict of Interests"}}],"article-number":"2"}}