We Asked Claude a BNPL Privacy Question | Appnalysis

We ran a real conversation with Claude on a BNPL privacy permissions question. Here's what it returned, what it couldn't access, and the compliance risk hiding in plain sight.

A second real conversation, and a compliance risk most teams would never think to check for

Following our first case study, where Claude struggled to answer a UK vs US neobank ranking question, we ran a second real conversation. Same AI assistant. Same honesty about what happened, including the parts that didn’t go as planned.

This time, the question wasn’t about rankings. It was about something with real regulatory weight.

The Question

“What are the common privacy permissions requested by the top 10 most downloaded buy-now-pay-later apps in the UK iOS App Store?”

A reasonable question for a compliance lead, an investor doing due diligence, or a product team benchmarking against competitors before a launch.

It’s also a question with a sharper edge than it first appears, because BNPL apps sit in a genuinely sensitive category. Financial data, identity verification, spending behaviour. Getting privacy practices wrong here isn’t just a PR risk. It’s a regulatory one.

Attempt 1: Claude Answers a Different Question

This is the attempt worth paying closest attention to, not because it failed loudly, but because it didn’t fail loudly at all.

Claude searched the web and returned a confident, well-written summary of the BNPL market: Klarna leading in brand awareness, followed by PayPal Pay Later and Clearpay, with Zilch and Monzo Flex also featured prominently.

It read like an answer. It had the tone of an answer. It cited sources.

It wasn’t the answer that was asked for.

The question asked for a ranked top 10 by downloads, and specific privacy permissions for each app. What Claude actually provided was qualitative market commentary about brand popularity a different dataset entirely, dressed in the structure of a direct response.

This is arguably the more important failure mode to understand. An incomplete answer is easy to spot. A confidently stated answer to a slightly different question is not. When asked directly whether the response was based on actual download rankings or on general market reputation, Claude acknowledged the gap:

“No. What I gave you was not based on actual download data or App Store ranking. It was inferred from consumer comparison articles that talk about brand popularity and market leadership.”

Result: A fluent answer to the wrong question.

Attempt 2: Apple’s Official Charts

Claude went directly to Apple’s UK Finance category chart, attempting to identify BNPL apps by their actual chart position.

Rate limited. A 429 error from Apple’s own servers blocked the request entirely.

Result: Blocked at the source.

Attempt 3: Third-Party Chart Trackers

Claude tried a well-known third-party app intelligence tracker that publishes live App Store rankings.

Blocked again, this time by bot detection on the tracking site itself, designed to prevent exactly the kind of automated access an AI assistant would attempt.

Result: Blocked by design.

Attempt 4: Honest Admission

After three attempts, one that quietly answered the wrong question and two that were blocked outright, Claude acknowledged the pattern plainly:

“This is now the fourth distinct technical barrier today on essentially the same category of question. I don’t think persisting with workarounds is going to get you a trustworthy answer.”

A question with real compliance implications had returned market commentary, two access blocks, and an honest but unsatisfying conclusion.

Two-panel diagram: left shows a numbered list from 1 to 10 with padlock icons per row; right shows a single speech bubble with a tag shape attached
Two-panel diagram: left shows a numbered list from 1 to 10 with padlock icons per row; right shows a single speech bubble with a tag shape attached

The Same Question. Asked to Appnalysis.

Asked directly via Ask Appnalysis.

The answer, per app, per platform, with sources:

For iOS, Appnalysis identified the actual top BNPL apps and broke down exactly what each one declares:

  • Zilch, rated 17+, collects contact info, identifiers, app activity and diagnostics, all linked to the user, and declares tracking via identifiers and app activity
  • Klarna, rated 4+, collects an extensive range including financial info, location, browsing history, search history and purchases, all linked to the user
  • Tabby, rated 4+, collects contact info and app activity linked to the user
  • Frasers Plus (Tymit), rated 4+, collects financial info, location, identifiers and app activity, all linked to the user
  • Clearpay, rated 4+, collects comprehensive data including financial info, location, search history and purchases, all linked to the user

Each entry came with its governing regulatory framework cited directly: UK GDPR / Data Protection Act 2018, Apple’s App Tracking Transparency, PECR, and Apple’s App Privacy Details.

No rate limits. No bot detection. No confidently worded answer to a different question.

Try this question yourself

The Finding That Actually Matters

Here’s where this case study goes further than the first one.

Look again at those age ratings: 4+, 4+, 4+, 4+. Four out of five of these apps are rated suitable for all ages, despite collecting financial information, location data, identifiers, and in some cases browsing and search history.

That combination, a child-accessible age rating plus extensive financial and behavioural data collection, automatically brings these apps under the scope of the ICO Children’s Code, a regulatory framework most product and compliance teams wouldn’t think to check for a financial services app.

This isn’t a hypothetical risk. It’s a structural one, sitting quietly in App Store metadata, visible only if you know to look for the intersection of age rating and data collection scope.

A ranking question would never have surfaced this. Only a structured, cross-referenced analysis of permissions, declarations and regulatory mapping could.

This is the difference between data and intelligence.

It is also what it means to say Appnalysis is an Agent rather than a data source. The Children's Code finding was produced by Appnalysis reasoning across age ratings, data declarations and regulatory frameworks together, not by looking anything up.

Compliance dashboard showing five vertical app cards in a row: the leftmost card displays a 17+ age rating with a distinct darker border, while the four remaining cards each show a 4+ age rating with an amber shield badge in the top-right corner and three muted data-category pills below, indicating ICO Children's Code applicability
Compliance dashboard showing five vertical app cards in a row: the leftmost card displays a 17+ age rating with a distinct darker border, while the four remaining cards each show a 4+ age rating with an amber shield badge in the top-right corner and three muted data-category pills below, indicating ICO Children's Code applicability

Why This Connects to a Bigger Shift

We’ve written before about why software is becoming a more accountable industry, and why evidence is replacing declarations as the currency businesses, regulators and investors actually trust. (See: The Software Industry Is Growing Up)

This case study is that argument made concrete.

A compliance question that Claude could not reliably answer, not because it lacked intelligence, but because it lacked structured access to the right data, turned out to contain a genuine regulatory finding once asked through the right channel.

That’s not a coincidence. It’s the entire point. The questions that matter most to businesses today increasingly live exactly where general AI assistants can’t reach: behind JavaScript-rendered pages, behind rate limits, behind bot detection, and inside structured regulatory frameworks that require domain expertise to map correctly.

Decisions you can defend require evidence you can access.

Go Deeper

  • We Asked Claude to Answer a Simple App Store Question — the first case study, on cross-market chart comparison
  • The Software Industry Is Growing Up — why evidence is becoming more valuable than declarations across the industry
  • Why Claude, ChatGPT and Gemini Still Struggle With Some Questions — the structural explanation behind both case studies
  • App intelligence as an agent: what it means for AI workflows — the architecture behind the reasoning demonstrated in this case study

Try It Yourself

Ask Appnalysis a compliance question your AI assistant couldn’t answer properly, and see what it might be missing.

Ask Appnalysis

Published by Appnalysis. Mobile intelligence for the agentic age.