Can I trust My EYA?
This app did not meet two or more trust checks, has a critical issue in one, or has a red flag.
- What it means for you
- Camera frames for barcode and QR code scanning are processed on the device and not sent to external servers. No advertising or ad-targeting networks are linked in the build. The build includes code to send usage analytics and crash reports to PostHog and Sentry, Firebase Cloud Messaging handles push notifications, and Stream.io supports in-app messaging.
- Main concern
- OTA updates lack code signing, enabling silent full app replacement by attackers
- The developer's description
- EYA's new app is a modern digital companion to your EYA home. For EYA Buyers: your EYA buyer app is the digital companion to your new home purchase. Track construction and closing, receive multimedia updates from your EYA team, access all of your home documents from the palm of your hand, and more.
- Third-party services
- 8
- Findings rated low or higher
- 9
Open on Google PlayOpens the app's listing on Google Play in a new tab.
Full findings
Open this scan in your dashboardThe account that ran this scan sees every finding and the Rescan button there.
Trust checks
Secure by Design
One criterion not metSecurity gaps detected
Why this result
This check looks for security issues at high severity or above in the code of this build, and at least one was recorded. Issues of this kind include a credential or token another app on the device can reach, sensitive data stored without protection, and network paths that expose information in transit.
Data Minimization
One criterion not metTracking lacks clear disclosure
Why this result
This build contains analytics or attribution code written to send data to companies other than the developer. No consent step was found before that code runs, and the app's disclosures do not describe the collection in full. Tracking by itself is ordinary; what this check reports is the combination of collection, recipient and absent disclosure.
Manifest Mismatch
An item rated high or above is openDisclosure incomplete or contradicted
Why this result
The check compares the app's privacy disclosures against what the code does, and at least one claim did not match in this build. Mismatches of this kind include a data category collected but not disclosed, a recipient the disclosure omits, and an identifier attached to data the disclosure describes as anonymous.
User Control
One criterion not metHard to leave
Why this result
The check looks for a way to export the data an account has accumulated and a way to delete the account itself. At least one of the two was not found in this build. Leaving therefore means either abandoning the data or contacting the developer to ask for it.
Red flags
The app's privacy declarations do not match its code
Why this result
The privacy declarations shipped in this build, or the ones on the store listing, state less than the code does. Declarations of this kind are what a store, a regulator and a person comparing two apps rely on.
Strengths
- Login tokens are encrypted with AES-256-GCM using Android Keystore hardware-backed keys
- All network traffic uses HTTPS with no cleartext HTTP permitted
- WebView correctly rejects invalid SSL certificates rather than silently accepting them
- OAuth login redirect is scoped to the app's package name, preventing interception by other apps
- Barcode and QR code scanning processes camera frames entirely on the device with no data sent to external servers
- No advertising networks or ad-targeting SDKs are present
- Zero known CVEs detected across all 17 native libraries via Binary Ninja analysis
- Native libraries load directly from the APK, preventing disk-level replacement on non-rooted devices
What the app contains
8 services
Third-party services the scan names in the build:
- Auth0
- Firebase Cloud Messaging
- Firebase Installations
- Google ML Kit
- Sentry
- Expo Updates
- PostHog
- Stream.io
Libraries
| Library | Version | Advisory |
|---|---|---|
| Room | not recorded | none confirmed |
| Apollo GraphQL | not recorded | none confirmed |
| Auth0 | not recorded | none confirmed |
| Fresco | not recorded | none confirmed |
| Glide | not recorded | none confirmed |
| Datatransport | not recorded | none confirmed |
| Google Sign-In | 12451000 | none confirmed |
| Google Play Services | 12451000 | none confirmed |
| Material Components | not recorded | none confirmed |
| Gson | not recorded | none confirmed |
Show all 22 librariesShow fewer
Method and limits
Static analysis: the decompiled code, manifest and resources of this build, read file by file. Network traffic at run time is established by a capture of the running app.
- Build SHA-256
- 73855eb41f6865cf41d55ec2827c08f68854c4cf7c358dfe6a25650188cd15b5
- Rule pack
- citt-ruleset-2026-08-v1
- Files decompiled
- 23,967
- Scan date
- 15 September 2026
Corrections
No correction is published for this app.
Developer response
No response is published for this app.
Report an error Opens an email to [email protected] that names this app and this scan.