Apps
146 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.
- 79out of 100unTRUSTED
Gummo
AndroidWhat it means for you
Location data stays on the device and is not shared with Sentry, Firebase, or any analytics service. No advertising network SDKs are present. Firebase handles push notifications, and the Play Install Referrer library is linked for install attribution.
- 7 findings
- Data Security 3
- Code Security 2
- Privacy 2
- 64out of 100unTRUSTED
Raiffeisen Bank SK
AndroidWhat it means for you
No advertising or behavioral tracking SDKs are bundled in build 341. Authentication keys and barcode scans remain on-device. Firebase Crashlytics is present for crash reporting; the code encrypts push notification content before handing it to the Firebase SDK, so Firebase does not see message content. The code for some banking requests may apply less protection than expected on public Wi-Fi.
- 9 findings
- Data Security 2
- Network Security 2
- Code Security 2
- Privacy 2
- Third-Party Risk 1
- 84out of 100unTRUSTED
My EYA
AndroidWhat it means for you
Camera frames for barcode and QR code scanning are processed on the device and not sent to external servers. No advertising or ad-targeting networks are linked in the build. The build includes code to send usage analytics and crash reports to PostHog and Sentry, Firebase Cloud Messaging handles push notifications, and Stream.io supports in-app messaging.
- 9 findings
- Data Security 1
- Code Security 6
- Privacy 2
- 81out of 100unTRUSTED
Yoti - your digital identity
AndroidWhat it means for you
Yes, on the evidence available. The build includes code to send precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. The build includes code to send another 13 data points to other third parties. None of the findings recorded rises to the level of putting a user at risk.
- 1006 findings
- Data Security 39
- Network Security 432
- Code Security 231
- Privacy 249
- Third-Party Risk 43
- Permission Usage 12
- 57out of 100unTRUSTED
Bendigo Bank
AndroidWhat it means for you
Read the findings in full first. The build includes code to send precise location to Google (platform Geocoder backend), and credentials to Datadog, Google Maps Platform and 2 other recipients. The build includes code to send another 12 data points to other third parties. 11 critical or high severity findings, 1 of them at critical, spread across 4 categories are worth reading before this build handles anything a user would want kept to themselves.
- 682 findings
- Data Security 78
- Network Security 82
- Code Security 199
- Privacy 153
- Third-Party Risk 157
- Permission Usage 13
- 82out of 100unTRUSTED
Akedo: Offline Games No WiFi
AndroidWhat it means for you
Gameplay runs offline after download, with no server calls needed during sessions. The app includes code to send device and usage data to Google Firebase and the developer's service at akedo.gg for analytics; the analysis found no code that reads health, location, financial, or contact data. Google AdMob is the only ad network present.
- 5 findings
- Data Security 1
- Network Security 1
- Code Security 1
- Privacy 1
- Third-Party Risk 1
- 84out of 100unTRUSTED
RemindMeWhere Reminders
AndroidWhat it means for you
Geofence locations and reminder data are stored on the device and are not shared with advertising networks. The app includes code to send usage data and authentication activity to Firebase Analytics and Facebook SDK. Cloud-synced data requires authentication before access.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 4
- Privacy 1
- Permission Usage 1
- 84out of 100TRUSTish
Anker soundcore
AndroidWhat it means for you
The build includes code to send biometrics to soundcore/Anker cloud, and files to soundcore Anka AI. The build includes code to send another 4 data points to other third parties. Two findings are worth reading before this build handles anything a user would want kept to themselves. One is a high severity finding related to Network Security. One more is an open question the analysis could not settle.
- 49 findings
- Data Security 2
- Network Security 10
- Code Security 18
- Privacy 7
- Third-Party Risk 11
- Permission Usage 1
- 95out of 100TRUSTish
What it means for you
Browsing history and tracker-block statistics stay on the device, with no third-party analytics, advertising, or crash-reporting SDKs present in this build. The bundled libraries (GRDB, Lottie, Kingfisher, and others) are utility components with no data-collection function. Telemetry is first-party and anonymous, with no persistent device identifiers and no search query content.
- 2 findings
- Code Security 2
- 94out of 100TRUSTish
What it means for you
Yes on the security of the code, with what the build includes code to send worth reading first. The build includes code to send financial data to RevenueCat, and advertising identifiers to RevenueCat. None of the findings recorded rises to the level of putting a user at risk.
- 20 findings
- Data Security 1
- Network Security 2
- Code Security 5
- Privacy 10
- Third-Party Risk 1
- Permission Usage 1
- 75out of 100TRUSTish
VLC for Android
AndroidWhat it means for you
The build includes code to send credentials to OpenSubtitles, and authentication tokens to OpenSubtitles. The build includes code to send another 3 data points to other third parties. Four high severity findings related to Data Security and Network Security are worth reading before this build handles anything a user would want kept to themselves.
- 370 findings
- Data Security 105
- Network Security 42
- Code Security 147
- Privacy 46
- Third-Party Risk 18
- Permission Usage 12
- 64out of 100unTRUSTED
Strava: Run, Bike, Walk
Android- 1952 findings
- Data Security 117
- Network Security 196
- Code Security 352
- Privacy 496
- Third-Party Risk 713
- Permission Usage 78
- 76out of 100unTRUSTED
- 852 findings
- Data Security 80
- Network Security 76
- Code Security 201
- Privacy 213
- Third-Party Risk 262
- Permission Usage 20
- 86out of 100TRUSTish
MyNISSAN®
iOSWhat it means for you
The build includes code to send vehicle commands and account data to Nissan's own servers, not third-party platforms. The build includes code to pass crash reports to Firebase, usage analytics to Adobe, and link attribution to Branch.io. An advertising identifier is made available to ad-measurement frameworks included in the app.
- 1 finding
- Data Security 1
- 86out of 100TRUSTish
CatLens - Cat Vision Filter
AndroidWhat it means for you
Camera images and photo effects are processed locally on the device, and the build contains no code to route photo or video frames to a cloud backend. Firebase is present for push notification delivery only, not behavioral tracking. The build includes code to pass usage data and device identifiers to Google AdMob for advertising and to OneSignal for targeted notifications.
- 6 findings
- Data Security 2
- Code Security 3
- Permission Usage 1
- 58out of 100unTRUSTED
myGMC
iOSWhat it means for you
The build includes code to send usage and session activity to Heap (ContentSquare), Adobe Experience Platform, and Salesforce for analytics and marketing. The binary links the Arity SDK, an Allstate subsidiary that specializes in driving behavior analysis. In some areas, user data may not be fully protected.
- 10 findings
- Data Security 6
- Code Security 2
- Third-Party Risk 2
- 78out of 100unTRUSTED
Meross
iOSWhat it means for you
Device commands route through the local network or Apple's end-to-end encrypted infrastructure, not through Meross servers. Account credentials are stored in the device's secure Keychain. The build includes code to send usage and crash data to Firebase Analytics, Firebase Crashlytics, and AWS services. No advertising network has access to usage data.
- 4 findings
- Network Security 1
- Code Security 2
- Privacy 1
- 76out of 100unTRUSTED
meross
AndroidWhat it means for you
No advertising networks or data broker SDKs are present in this build. The build includes code to send device usage statistics and crash reports to Firebase Analytics and Crashlytics. The build includes code that processes smart home device data through Meross infrastructure and AWS, and names no third-party monetization service in code as a destination of user data.
- 11 findings
- Data Security 4
- Network Security 3
- Code Security 2
- Privacy 2
- 49out of 100unTRUSTED
What it means for you
Health, sleep, and step data from device sensors stays on the device with no evidence of transmission to third-party analytics providers. The app includes code to send usage and interaction data to Amplitude, Firebase, Adjust, and the Facebook SDK for analytics and ad attribution. All network connections use encrypted channels.
- 5 findings
- Code Security 3
- Privacy 2
- 72out of 100unTRUSTED
Wagoneer
AndroidWhat it means for you
Vehicle location, trip history, and account documents are kept encrypted on the device. The app includes code to send App activity and diagnostic data to Adobe, Firebase, Salesforce, and Facebook for analytics and marketing. Some account activity may be exposed with less protection than expected on public Wi-Fi.
- 11 findings
- Data Security 1
- Network Security 5
- Code Security 5
- 32out of 100unTRUSTED
BLOKK: Privacy VPN & Blocker
AndroidWhat it means for you
Call and text number blocking runs entirely on the device without a network lookup, and the build includes code to send analytics data only to the developer's own server rather than a third-party analytics vendor. The build also includes code to send usage data to several other analytics and advertising services, including Firebase, Google, Microsoft Clarity, and OneSignal. Some activity may be exposed with less protection than expected on public Wi-Fi.
- 12 findings
- Data Security 2
- Network Security 1
- Code Security 6
- Privacy 1
- Third-Party Risk 2
- 78out of 100unTRUSTED
What it means for you
Code shared across PayPal, Honey, and Xoom addresses only the developer's own infrastructure, and the build includes no code giving third-party ecosystems access to account credentials. Credentials and private keys are stored inside the device's Secure Enclave, not extractable from the device. The app includes code to pass usage, crash, and behavioral data to Firebase, Adjust, and Adobe for analytics and diagnostics.
- 6 findings
- Network Security 2
- Code Security 3
- Permission Usage 1
- 88out of 100unTRUSTED
AAWireless for Android Auto™
AndroidWhat it means for you
The build includes code to send user data to the developer's own backend systems, and contains no code to sell it to data brokers or advertising networks. No vehicle telemetry is part of the app's data collection despite its automotive hardware integration. Firebase Crashlytics and Firebase Analytics are bundled for crash reporting and usage metrics.
- 11 findings
- Network Security 1
- Code Security 7
- Privacy 2
- Third-Party Risk 1
- 77out of 100unTRUSTED
Oura
iOSWhat it means for you
Sleep staging, HRV, and readiness scores are computed on the device by a PyTorch Mobile model, so the code keeps raw biometric sensor data on the device and contains no path to send it to the cloud. The build includes code to send usage and activity data to Segment, Amplitude, and Braze for analytics and engagement. No advertising SDK is present and no advertising identifier is collected.
- 9 findings
- Data Security 1
- Code Security 4
- Third-Party Risk 3
- Permission Usage 1
- 44out of 100unTRUSTED
Urban VPN
iOSWhat it means for you
WireGuard session keys are kept in memory only and not written to disk, and usage data is not tied to an advertising identifier. The build includes code to send usage and device data to Firebase Analytics and Mixpanel, and advertising measurement services from Google and Singular are used for ad attribution. Branch.io and OneSignal are also bundled for attribution and push notifications.
- 2 findings
- Code Security 1
- Third-Party Risk 1
- 61out of 100TRUSTish
What it means for you
Message content is not stored on Viber's servers, and media files are encrypted on the device. Calls are end-to-end encrypted. The build includes code to send usage and device data to advertising and analytics services including Adjust, Firebase, Braze, Mixpanel, Facebook Audience Network, and real-time ad bidding platforms.
- 3 findings
- Code Security 2
- Privacy 1
- 83out of 100TRUSTish
What it means for you
Messages and calls are protected by end-to-end encryption, meaning Meta cannot read message content. No third-party analytics or advertising services are named in code as destinations for data; the telemetry code addresses only Meta's own infrastructure. The build includes code to send contacts only to Meta-owned systems, and the code reads no advertising identifier.
- 3 findings
- Code Security 3
- 85out of 100unTRUSTED
What it means for you
No Meta Audience Network or Google AdMob SDK is bundled in this build; LinkedIn's advertising operates through its own infrastructure rather than external consumer ad networks. The build includes code to send usage, device, and attribution data to Singular, Apple AdServices, and Firebase Crashlytics. Qualtrics XM is also integrated for in-app surveys.
- 7 findings
- Network Security 3
- Code Security 3
- Privacy 1
- 73out of 100unTRUSTED
What it means for you
Health and medical data stays on-device and syncs to the user's own iCloud account, not to developer servers. No behavioral analytics or advertising networks are integrated. RevenueCat is linked for subscription and in-app purchase management.
- 82out of 100unTRUSTED
X
AndroidWhat it means for you
Direct messages are end-to-end encrypted and excluded from device cloud backups. Camera frames captured during identity verification are processed on the device. The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Branch.io, and Datadog for analytics, advertising, and crash reporting.
- 11 findings
- Data Security 1
- Network Security 2
- Code Security 6
- Privacy 1
- Third-Party Risk 1
- 89out of 100TRUSTish
What it means for you
HealthKit and workout GPS route data stays on the device and is not shared with advertising networks or data brokers. Analytics and in-app messaging are integrated with TelemetryDeck (privacy-preserving hashed identifiers) and Customer.io (EU data residency), with subscription management via RevenueCat. The backend runs on developer-controlled infrastructure at fitwoody.camp, keeping user data outside third-party cloud services.
- 2 findings
- Code Security 1
- Privacy 1
- 83out of 100TRUSTish
What it means for you
Note content is stored within Evernote's own infrastructure and is not passed to any third-party SDK, and no advertising identifier is collected. Firebase Analytics is disabled in this build, so usage data does not flow to Google. The build includes code to send crash reports to Firebase Crashlytics and Sentry, and to send App Store install attribution data to Apple AdServices and Bending Spoons.
- 2 findings
- Code Security 2
- 80out of 100TRUSTish
What it means for you
The build includes code that restricts financial transaction data and app behavior to Revolut's own infrastructure; Firebase Analytics is disabled, so the build contains no code path to send transaction activity to Google. The build includes code that may send install attribution data to AppsFlyer and Branch.io, and includes code to send crash reports to Firebase Crashlytics. Google AdMob, an advertising network, is also linked in the build.
- 4 findings
- Data Security 2
- Code Security 1
- Permission Usage 1
- 83out of 100unTRUSTED
Airbnb
AndroidWhat it means for you
Identity verification scans, including biometric checks and document images, are handled on the device via Google ML Kit and not routed to third-party servers. The app includes code to pass booking activity, device data, and location signals to Firebase, Google Analytics, Facebook, Singular, Branch, Incognia, and Bugsnag for analytics, fraud detection, and crash reporting.
- 13 findings
- Data Security 1
- Network Security 2
- Code Security 9
- Privacy 1
- 51out of 100TRUSTish
What it means for you
VPN credentials are stored in device hardware and never leave the chip. No advertising or behavioral tracking SDKs are present in the binary. The build includes code to send crash reports to Proton's own infrastructure, and the destinations named in code for other data are all within the Proton developer ecosystem.
- 2 findings
- Network Security 1
- Code Security 1
- 82out of 100unTRUSTED
Revolut: Spend, Save, Trade
AndroidWhat it means for you
Financial transaction data is addressed in code only to Revolut's own servers; the build includes no code to pass financial information to advertising networks or data brokers. Usage analytics through Firebase and AppsFlyer are off by default, with no data shared until user consent is given. The app includes code to pass identity verification data to third-party providers during account onboarding.
- 12 findings
- Data Security 3
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 2
- 51out of 100unTRUSTED
What it means for you
Firebase Analytics, Crashlytics, and performance monitoring are switched off by default and require user consent to turn on; when marketing consent is declined, AppsFlyer is shut down and Braze data is wiped from the device. First-party analytics (Moose, Nudler) include code that names only NordVPN's own servers as destinations. When marketing consent is granted, the build includes code to send data to Braze and AppsFlyer.
- 7 findings
- Data Security 3
- Code Security 2
- Third-Party Risk 2
- 90out of 100unTRUSTED
Revolut Business
AndroidWhat it means for you
The build includes code to send App usage, install attribution, and performance data to AppsFlyer, Firebase Analytics, Firebase Crashlytics, and Branch.io. The build includes code to send Identity verification data to Onfido during onboarding. Financial account and transaction data remain within Revolut's own infrastructure, and financial databases are stored in encrypted form on the device rather than backed up to third-party cloud services.
- 7 findings
- Network Security 2
- Code Security 5
- 74out of 100unTRUSTED
What it means for you
Dating profile data, messages, and auth credentials are excluded from Google cloud backup and device transfers. Facial recognition processing occurs entirely on the device, and the build includes no code to pass raw biometric photos to third-party services. The app includes code to pass usage and behavioral data to advertising and attribution networks including Google Ad Manager, AppsFlyer, and LiveRamp, though seven tracking integrations are individually consent-gated.
- 13 findings
- Network Security 1
- Code Security 8
- Privacy 1
- Third-Party Risk 2
- Permission Usage 1
- 80out of 100unTRUSTED
CNN: Live & Breaking News
AndroidWhat it means for you
The app includes code to pass viewing and interaction data to analytics and advertising services including Firebase Analytics, Adobe Analytics, AppsFlyer, Google AdMob, comScore, and Snowplow. The build includes a full consent-before-tracking flow via OneTrust for EU users, and code that blocks all advertising and analytics SDKs when the consent system does not confirm permission. Firebase Advertising ID collection is disabled in the build.
- 6 findings
- Data Security 1
- Code Security 5
- 82out of 100unTRUSTED
Grok
AndroidWhat it means for you
The app includes code to pass usage and interaction data to Mixpanel, AppsFlyer, and Braze for analytics, attribution, and marketing engagement. Login tokens are stored in the protected Android credential store, isolated from other apps. Google Analytics is configured to exclude advertising identifiers, and support chat identity data is encrypted with hardware-backed storage.
- 7 findings
- Data Security 1
- Network Security 1
- Code Security 3
- Privacy 1
- Third-Party Risk 1
- 72out of 100unTRUSTED
FreeReels - Dramas & Reels
AndroidWhat it means for you
Behavioral analytics code is directed to the developer's own servers rather than a third-party analytics vendor, and cloud backup is disabled. The binary integrates multiple advertising networks including Google AdMob, AppLovin, Pangle, Unity Ads, Vungle, and Facebook Audience Network, each linked for ad delivery and device signal processing. The binary also bundles Ishumei SmAntiFraud and Tencent LiteAV components.
- 12 findings
- Data Security 1
- Network Security 2
- Code Security 6
- Privacy 2
- Third-Party Risk 1
- 69out of 100unTRUSTED
Davivienda
AndroidWhat it means for you
The app includes code to pass session data and device data to multiple third-party services, including AppsFlyer (attribution), Braze (marketing), BioCatch and Cobrowse.io (session monitoring), Dynatrace, and Sentry. Firebase Analytics is linked but configured to be inactive at launch; biometric identity checks are handled by FaceTec and Incode. Some user data may not be fully protected in all scenarios.
- 14 findings
- Data Security 1
- Network Security 2
- Code Security 7
- Privacy 3
- Third-Party Risk 1
- 73out of 100unTRUSTED
Free Download Manager - FDM
AndroidWhat it means for you
No advertising networks are bundled, and download activity is not sold to data brokers. The only external data recipient is Google, via Firebase Analytics for app performance measurement. Camera access is limited to local QR code scanning with no image data leaving the device, and microphone access is used only for audio device routing. Some connection activity may carry less protection than expected on public networks.
- 9 findings
- Data Security 3
- Network Security 2
- Code Security 1
- Privacy 3
- 75out of 100unTRUSTED
United Airlines
AndroidWhat it means for you
Analytics and advertising SDKs from Google, Kochava, Quantum Metric, Mixpanel, and Snowplow are bundled in the build alongside core trip features. Location access requires a current trip context and an explicit permission grant from the user. Account credentials and reservation details are protected by device-level encryption.
- 10 findings
- Data Security 3
- Network Security 2
- Code Security 5
- 85out of 100unTRUSTED
What it means for you
Financial transaction data, including balances and transfer amounts, was not observed reaching advertising networks, and no advertising SDK is present in the app. Biometric identity verification during account setup is processed on the device. The app includes code to pass usage and crash data to Firebase Analytics, Mixpanel, Braze, Facebook, and Sentry, with SDK-level opt-out controls for Braze and Singular built into the app.
- 10 findings
- Data Security 2
- Network Security 1
- Code Security 2
- Privacy 3
- Third-Party Risk 1
- Permission Usage 1
- 75out of 100unTRUSTED
Rakuten Viber Messenger
AndroidWhat it means for you
The app includes code to pass messaging activity and device data to advertising and analytics partners including Braze, Adjust, Facebook, and multiple ad networks. Firebase Analytics collection is disabled by default in the build manifest, and Mixpanel is configured to route through Viber's own CDN proxy, preventing Mixpanel from directly observing individual IP addresses. Payment authorization requires biometric authentication, and sensitive databases are excluded from cloud backups.
- 11 findings
- Data Security 1
- Network Security 4
- Code Security 3
- Privacy 2
- Third-Party Risk 1
- 90out of 100NOT ASSESSED
Mastodon
AndroidWhat it means for you
The binary bundles no third-party analytics, advertising, or tracking SDKs, and static analysis finds no data-broker or ad-network endpoints. Network traffic in the binary is directed only to the user's chosen Mastodon instance and the developer's own infrastructure. The build includes code that encrypts push notification content on the device, so the request built for Google's notification service contains only routing metadata in readable form.
- 7 findings
- Data Security 1
- Network Security 1
- Code Security 4
- Privacy 1
- 64out of 100unTRUSTED
Interbank APP
AndroidWhat it means for you
Core financial data, including account balances, transactions, and card details, is processed on Interbank's own servers and is not passed to any analytics platform. The build includes code to pass install and usage data to services including Firebase Analytics, AppsFlyer, Adobe, and Microsoft Clarity. Camera-based features like barcode scanning use on-device processing with no data leaving the device.
- 11 findings
- Data Security 1
- Network Security 1
- Code Security 8
- Privacy 1
- 73out of 100unTRUSTED
What it means for you
Health and workout data stays on the device and does not flow to third-party analytics or advertising services. The build includes code to send usage and behavioral data to analytics and marketing services including AppsFlyer, Amplitude, and Mixpanel for attribution and engagement measurement. Firebase Analytics is disabled in the build, and EU-region routing is configured for Amplitude and Customer.io.
- 5 findings
- Data Security 1
- Code Security 3
- Third-Party Risk 1