We ran a real conversation with Claude on a BNPL privacy permissions question. Here's what it returned, what it couldn't access, and the compliance risk hiding in plain sight.
A second real conversation, and a compliance risk most teams would never think to check for
Following our first case study, where Claude struggled to answer a UK vs US neobank ranking question, we ran a second real conversation. Same AI assistant. Same honesty about what happened, including the parts that didn’t go as planned.
This time, the question wasn’t about rankings. It was about something with real regulatory weight.
“What are the common privacy permissions requested by the top 10 most downloaded buy-now-pay-later apps in the UK iOS App Store?”
A reasonable question for a compliance lead, an investor doing due diligence, or a product team benchmarking against competitors before a launch.
It’s also a question with a sharper edge than it first appears, because BNPL apps sit in a genuinely sensitive category. Financial data, identity verification, spending behaviour. Getting privacy practices wrong here isn’t just a PR risk. It’s a regulatory one.
This is the attempt worth paying closest attention to, not because it failed loudly, but because it didn’t fail loudly at all.
Claude searched the web and returned a confident, well-written summary of the BNPL market: Klarna leading in brand awareness, followed by PayPal Pay Later and Clearpay, with Zilch and Monzo Flex also featured prominently.
It read like an answer. It had the tone of an answer. It cited sources.
It wasn’t the answer that was asked for.
The question asked for a ranked top 10 by downloads, and specific privacy permissions for each app. What Claude actually provided was qualitative market commentary about brand popularity a different dataset entirely, dressed in the structure of a direct response.
This is arguably the more important failure mode to understand. An incomplete answer is easy to spot. A confidently stated answer to a slightly different question is not. When asked directly whether the response was based on actual download rankings or on general market reputation, Claude acknowledged the gap:
“No. What I gave you was not based on actual download data or App Store ranking. It was inferred from consumer comparison articles that talk about brand popularity and market leadership.”
Result: A fluent answer to the wrong question.
Claude went directly to Apple’s UK Finance category chart, attempting to identify BNPL apps by their actual chart position.
Rate limited. A 429 error from Apple’s own servers blocked the request entirely.
Result: Blocked at the source.
Claude tried a well-known third-party app intelligence tracker that publishes live App Store rankings.
Blocked again, this time by bot detection on the tracking site itself, designed to prevent exactly the kind of automated access an AI assistant would attempt.
Result: Blocked by design.
After three attempts, one that quietly answered the wrong question and two that were blocked outright, Claude acknowledged the pattern plainly:
“This is now the fourth distinct technical barrier today on essentially the same category of question. I don’t think persisting with workarounds is going to get you a trustworthy answer.”
A question with real compliance implications had returned market commentary, two access blocks, and an honest but unsatisfying conclusion.

Asked directly via Ask Appnalysis.
The answer, per app, per platform, with sources:
For iOS, Appnalysis identified the actual top BNPL apps and broke down exactly what each one declares:
Each entry came with its governing regulatory framework cited directly: UK GDPR / Data Protection Act 2018, Apple’s App Tracking Transparency, PECR, and Apple’s App Privacy Details.
No rate limits. No bot detection. No confidently worded answer to a different question.
Here’s where this case study goes further than the first one.
Look again at those age ratings: 4+, 4+, 4+, 4+. Four out of five of these apps are rated suitable for all ages, despite collecting financial information, location data, identifiers, and in some cases browsing and search history.
That combination, a child-accessible age rating plus extensive financial and behavioural data collection, automatically brings these apps under the scope of the ICO Children’s Code, a regulatory framework most product and compliance teams wouldn’t think to check for a financial services app.
This isn’t a hypothetical risk. It’s a structural one, sitting quietly in App Store metadata, visible only if you know to look for the intersection of age rating and data collection scope.
A ranking question would never have surfaced this. Only a structured, cross-referenced analysis of permissions, declarations and regulatory mapping could.
This is the difference between data and intelligence.
It is also what it means to say Appnalysis is an Agent rather than a data source. The Children's Code finding was produced by Appnalysis reasoning across age ratings, data declarations and regulatory frameworks together, not by looking anything up.

We’ve written before about why software is becoming a more accountable industry, and why evidence is replacing declarations as the currency businesses, regulators and investors actually trust. (See: The Software Industry Is Growing Up)
This case study is that argument made concrete.
A compliance question that Claude could not reliably answer, not because it lacked intelligence, but because it lacked structured access to the right data, turned out to contain a genuine regulatory finding once asked through the right channel.
That’s not a coincidence. It’s the entire point. The questions that matter most to businesses today increasingly live exactly where general AI assistants can’t reach: behind JavaScript-rendered pages, behind rate limits, behind bot detection, and inside structured regulatory frameworks that require domain expertise to map correctly.
Decisions you can defend require evidence you can access.
Ask Appnalysis a compliance question your AI assistant couldn’t answer properly, and see what it might be missing.
Published by Appnalysis. Mobile intelligence for the agentic age.