Mobile applications (apps) require users to provide sensitive data such as home address, phone number, or credit card numbers, for offering full-fledged functionality. This data is stored on servers outside users' purview, once provided, users have little or no control over what happens to the data, which exposes both users and app developers to privacy risks. This project exposes and aims to reduce such issues/risks in mobile apps and their corresponding servers. The project's novelties are computing the minimal amount of information required for app functioning, inferring server-side behavior, and exposing unauthorized data collection. The project's broader significance and importance are protecting the users from wide and unauthorized data collection, and improving the state-of-practice in secure development toward more privacy-friendly data collection and data retention practices. The project consists of two thrusts. The first thrust uses program analysis to compute the minimal personal information required for proper functioning: this allows identifying unnecessary, excessively collected information. This thrust also exposes unauthorized collection, via novel in-tandem modeling of app policy and implementation, to identify temporal violations such as data collection prior to user consent. This approach is generalizable in other contexts, such as identification of discrepancies between software implementations and their stated or governing policies. The second