Skip to content

Can I trust My EYA?

unTRUSTED 84 Android Version 0.0.56 (versionCode 67) app.eya.buyer Scanned

This app did not meet two or more trust checks, has a critical issue in one, or has a red flag.

What it means for you
Camera frames for barcode and QR code scanning are processed on the device and not sent to external servers. No advertising or ad-targeting networks are linked in the build. The build includes code to send usage analytics and crash reports to PostHog and Sentry, Firebase Cloud Messaging handles push notifications, and Stream.io supports in-app messaging.
Main concern
OTA updates lack code signing, enabling silent full app replacement by attackers
The developer's description
EYA's new app is a modern digital companion to your EYA home. For EYA Buyers: your EYA buyer app is the digital companion to your new home purchase. Track construction and closing, receive multimedia updates from your EYA team, access all of your home documents from the palm of your hand, and more.
Third-party services
8
Findings rated low or higher
9

How the score and the label work

Open on Google PlayOpens the app's listing on Google Play in a new tab.

Full findings

Open this scan in your dashboard

The account that ran this scan sees every finding and the Rescan button there.

Trust checks

  • Secure by Design

    One criterion not met

    Security gaps detected

    Why this result

    This check looks for security issues at high severity or above in the code of this build, and at least one was recorded. Issues of this kind include a credential or token another app on the device can reach, sensitive data stored without protection, and network paths that expose information in transit.

  • Data Minimization

    One criterion not met

    Tracking lacks clear disclosure

    Why this result

    This build contains analytics or attribution code written to send data to companies other than the developer. No consent step was found before that code runs, and the app's disclosures do not describe the collection in full. Tracking by itself is ordinary; what this check reports is the combination of collection, recipient and absent disclosure.

  • Manifest Mismatch

    An item rated high or above is open

    Disclosure incomplete or contradicted

    Why this result

    The check compares the app's privacy disclosures against what the code does, and at least one claim did not match in this build. Mismatches of this kind include a data category collected but not disclosed, a recipient the disclosure omits, and an identifier attached to data the disclosure describes as anonymous.

  • User Control

    One criterion not met

    Hard to leave

    Why this result

    The check looks for a way to export the data an account has accumulated and a way to delete the account itself. At least one of the two was not found in this build. Leaving therefore means either abandoning the data or contacting the developer to ask for it.

Red flags

  • The app's privacy declarations do not match its code

    Why this result

    The privacy declarations shipped in this build, or the ones on the store listing, state less than the code does. Declarations of this kind are what a store, a regulator and a person comparing two apps rely on.

Strengths

  • Login tokens are encrypted with AES-256-GCM using Android Keystore hardware-backed keys
  • All network traffic uses HTTPS with no cleartext HTTP permitted
  • WebView correctly rejects invalid SSL certificates rather than silently accepting them
  • OAuth login redirect is scoped to the app's package name, preventing interception by other apps
  • Barcode and QR code scanning processes camera frames entirely on the device with no data sent to external servers
  • No advertising networks or ad-targeting SDKs are present
  • Zero known CVEs detected across all 17 native libraries via Binary Ninja analysis
  • Native libraries load directly from the APK, preventing disk-level replacement on non-rooted devices

What the app contains

  • 8 services

    Third-party services the scan names in the build:

    • Auth0
    • Firebase Cloud Messaging
    • Firebase Installations
    • Google ML Kit
    • Sentry
    • Expo Updates
    • PostHog
    • Stream.io

Libraries

Libraries in the build of My EYA
LibraryVersionAdvisory
Roomnot recordednone confirmed
Apollo GraphQLnot recordednone confirmed
Auth0not recordednone confirmed
Fresconot recordednone confirmed
Glidenot recordednone confirmed
Datatransportnot recordednone confirmed
Google Sign-In12451000none confirmed
Google Play Services12451000none confirmed
Material Componentsnot recordednone confirmed
Gsonnot recordednone confirmed
Show all 22 libraries

Method and limits

Static analysis: the decompiled code, manifest and resources of this build, read file by file. Network traffic at run time is established by a capture of the running app.

Build SHA-256
73855eb41f6865cf41d55ec2827c08f68854c4cf7c358dfe6a25650188cd15b5
Rule pack
citt-ruleset-2026-08-v1
Files decompiled
23,967
Scan date
15 September 2026

Corrections

No correction is published for this app.

Developer response

No response is published for this app.

Report an error Opens an email to [email protected] that names this app and this scan.