Longitudinal stability of Mini App privacy violations

Determine whether the privacy-policy violations observed in Telegram Mini Apps persist across application updates, accounting for the ability of developer-controlled infrastructure to change Mini App behavior without redistribution through the Telegram platform.

Background

TeleGapper observes Telegram Mini Apps at runtime and reports that 59.4% of the 278 working applications analyzed contacted at least one third party not disclosed in the applicable privacy policy. Because Telegram Mini Apps are Web applications served from developer-controlled infrastructure, developers can modify their behavior without submitting a newly packaged application through Telegram. The reported measurements therefore represent a temporal snapshot rather than evidence that the same applications will remain compliant or noncompliant over time.

A longitudinal campaign is explicitly identified as necessary to determine whether the documented violations persist across application updates. Resolving this question would clarify the stability of the observed privacy-compliance gap and assess the practical significance of the platform's hot-update capability.

References

Several directions remain open. On the tooling side, we plan to extend the framework to iOS, which requires a different automation and interception stack, and to investigate root-free TLS interception in order to lower the barrier to independent replication. On the measurement side, a longitudinal campaign would establish whether the violations we document persist across app updates, a question made particularly relevant by the hot-update capability discussed in Section~\ref{sec:discussion}: apps served from developer-controlled infrastructure can change behavior without redistribution through the platform.

TeleGapper: On the (un)reliability of Privacy Policies in Telegram Mini apps  (2608.13390 - Ferrari et al., 13 Aug 2026) in Section Conclusion and Future works, Section sec:conclusion