Skip to content
For privacy researchers and journalists

Is this app recording screens before consent, renting its users' bandwidth, profiling kids for ad auctions, shipping a foreign-adversary SDK, or a VPN with a data broker inside?

Ask any question about an iOS or Android app. Get the answer with citations.

Rule results for an Android app in about a minute.

BLOKK: Privacy VPN & Blocker · com.revokevpnapp · AndroidModel answer

Asked
Is it CIPA-exposed?
Answer
BLOKK, a privacy VPN and tracker blocker, registers Microsoft Clarity, a session-replay SDK, in PackageList.java. The build contains Clarity's default ingest URL, https://www.clarity.ms/eus2/, and the manifest declares its UploadSessionJob service. Rules android.sessionreplay.clarity.sdk_present and android.sessionreplay.ingest_host matched. BLOKK's Play Data safety section states "No data shared with third parties." CIPA status: might not be compliant; final confirmation requires a network capture.

Cited · 4 of 4 found in the code

  • PackageList.java: new ClarityPackage()
  • DynamicConfig.java: "INGEST_URL", "https://www.clarity.ms/eus2/"
  • clarity/g/s0.java: https://clarity.microsoft.com/
  • AndroidManifest.xml: com.microsoft.clarity.jobs.UploadSessionJob
  • Bulk scans of app lists
  • Law and policy rule sets
  • Claude Code and Codex plugin

01 / Projects

Upload a list of apps. Ask every app one question.

Project steps
New project form with a project name and a pasted list of apps
Project progress with the apps settled and the download jobs done and running

Where does this build store login tokens or keys?

One question asked of every app in the project, with each app's answer beside its package

02 / Evidence

Every answer cites the code. Every capture lists the requests.

Answer

Every claim in an answer cites the file, the line and the code at that line.

A question about the build, its model answer, and two citations with the file, the line and the quoted code

Network capture

An automated capture installs the app on a test device and records each request with its URL and the fields it sends. Requests made before the consent prompt is answered are counted and marked.

Before consent24 requests

Network capture filtered to the requests made before consent, with the method and URL of each

Fields sent

Network capture requests with the URL of each and the fields each request sends

03 / Questions

Ask any question about an app. The answer cites its code.

Questions are the main way to investigate. Ask one app, or every app in a project, about anything in its build.

How to check an answer

  • Open in Evidence

    Each citation opens the decompiled file at the cited line, with the evidence line marked.

  • Ask a follow-up

    Up to 20 turns on the same build, each answer cited the same way.

  • Scrutinize

    Select findings and queue a separate review. Each finding gets a verdict (confirmed, false positive, inconclusive or needs runtime) with its rationale and citations.

  • Source labels

    Rule findings come from the rule pack and repeat on every run of the same build. Model findings come from Deep and Ultra-deep scans; prompt findings come from questions.

A model writes each answer. Before it is saved, every line it cites is checked against the decompiled build, and an answer that cites a missing line is rejected.

First answer in about 30 minutes. Follow-ups in about 5.

04 / Deep scan

Deep scan targets the code that contacts outside servers.

A Deep scan is a 7-stage AI pipeline.

It follows the app's main code paths, skips library internals and analyses each file that contacts an outside server, tracing those calls back through the code. It returns up to 30 findings, each citing its file.

  1. 1

    The build is downloaded from the store, or uploaded.

  2. 2

    The build is decompiled.

  3. 3

    A call graph is built from app startup.

  4. 4

    A lead agent maps the app and assigns the code paths behind its network requests, ads and links.

  5. 5

    Investigator agents follow those code paths in parallel.

  6. 6

    A false-positive check runs on every finding.

  7. 7

    Scores and the report are written.

Findings

A table filtered by source, severity, category and verdict. Each filtered view has its own URL, so a link reopens it.

Deep scan findings filters for source, severity, category and verdict

Native libraries

An option that adds the app's native libraries to the scan.

The new-scan option that adds the app's native libraries to the scan

Evidence

The decompiled file tree, and the SDKs, keys and IDs, hosts and permissions the build contains.

  • SDKs
  • keys and IDs
  • hosts
  • permissions

Activity

Every scan, question, review and export on the build, with its time in UTC.

05 / Ultra-deep scan

Ultra-deep targets every file and code path of one app.

An Ultra-deep scan targets 100% code coverage of one app.

  • Coverage

    The result header shows the files reviewed out of the app's analysable files: 29,612 of 29,737 in the run shown.

  • Tokens

    About 10 times the tokens of a Deep scan.

  • Time

    A run can take a few hours.

  • Findings

    Hundreds to thousands, because every behaviour in the code becomes a finding: used and unused code, data sources and every permission the app requests.

Meant for examining one app in full; across a large set of apps, each app returns hundreds to thousands of findings.

Ultra-deep3,301 findingsCoverage: 29,612 of 29,737 analysable files reviewed
  • critical6
  • high105
  • medium629
  • low872
  • info1,689

06 / Rule sets

Check a whole project against 31 rule sets.

Each app in a project gets one status per rule set, based on the evidence in its build and store listing.

  • Rules

    565 rules in 32 families are matched against an Android app's decompiled code or an iOS app's decrypted build, and the store listing. Each finding is a rule match.

  • Laws

    510 rules name a law or platform policy, and 263 name a jurisdiction.

  • Research

    The rules are written from 642 laws, platform policies, regulator decisions, court cases and researcher reports, dated October 2026. 488 of the 565 rules cite a research file.

  • Coverage

    US federal and state law, the EU, the UK, Brazil, China, India, Kenya and the Philippines, Google Play and App Store policies, and ad-industry contract terms.

  • Statuses

    Each rule set that applies to an app gets one of four statuses, with the rules and store facts it is based on. Where the build alone is not enough for a status, the status names the evidence still needed: a network capture or the privacy policy text.

Among the 31:

  • COPPA
  • GDPR and ePrivacy Directive
  • UK GDPR and Age Appropriate Design Code
  • CCPA as amended by CPRA
  • CIPA
  • Washington My Health My Data Act
  • Video Privacy Protection Act
  • PADFA and the DOJ bulk data rule
  • China app personal information rules
  • India RBI Digital Lending Directions
  • Google Play Families policy
  • Apple App Store Review Guideline 5.1

Statuses are screening results from a static scan: they state what the package and listing contain.

07 / Plugin

Run full investigations from Claude Code or Codex.

The CanITrustThat plugin adds the citt command to Claude Code or Codex, on the harness's own models. The command starts scans, lists findings, asks questions and downloads exports for the account.

Start free, no credit card.

Rules and checks written by researchers. AI models for Deep scans and questions.