# Can I trust My EYA?

My EYA for Android, version 0.0.56 (versionCode 67) (scanned 15 September 2026) is labelled unTRUSTED, with a score of 84 out of 100. This app did not meet two or more trust checks, has a critical issue in one, or has a red flag. The scan names 8 third-party services: Auth0, Firebase Cloud Messaging, Firebase Installations, Google ML Kit, Sentry, Expo Updates, PostHog and Stream.io. It recorded 9 findings rated low or higher across 3 categories, 3 of them rated medium or higher. A static scan shows what the app's code and manifest contain; the app's network traffic needs a capture of the running app.

- Package: `app.eya.buyer`
- Platform: Android
- Version: 0.0.56 (versionCode 67)
- Scanned: 15 September 2026
- Label and score: unTRUSTED, 84 of 100 (criteria: https://canitrustthat.com/methodology)

## Trust checks

- Secure by Design: One criterion not met
  - Security gaps detected
  - This check looks for security issues at high severity or above in the code of this build, and at least one was recorded. Issues of this kind include a credential or token another app on the device can reach, sensitive data stored without protection, and network paths that expose information in transit.
- Data Minimization: One criterion not met
  - Tracking lacks clear disclosure
  - This build contains analytics or attribution code written to send data to companies other than the developer. No consent step was found before that code runs, and the app's disclosures do not describe the collection in full. Tracking by itself is ordinary; what this check reports is the combination of collection, recipient and absent disclosure.
- Manifest Mismatch: An item rated high or above is open
  - Disclosure incomplete or contradicted
  - The check compares the app's privacy disclosures against what the code does, and at least one claim did not match in this build. Mismatches of this kind include a data category collected but not disclosed, a recipient the disclosure omits, and an identifier attached to data the disclosure describes as anonymous.
- User Control: One criterion not met
  - Hard to leave
  - The check looks for a way to export the data an account has accumulated and a way to delete the account itself. At least one of the two was not found in this build. Leaving therefore means either abandoning the data or contacting the developer to ask for it.

## Red flags

- The app's privacy declarations do not match its code
  - The privacy declarations shipped in this build, or the ones on the store listing, state less than the code does. Declarations of this kind are what a store, a regulator and a person comparing two apps rely on.

## Summary

- What it means for you: Camera frames for barcode and QR code scanning are processed on the device and not sent to external servers. No advertising or ad-targeting networks are linked in the build. The build includes code to send usage analytics and crash reports to PostHog and Sentry, Firebase Cloud Messaging handles push notifications, and Stream.io supports in-app messaging.
- Main concern: OTA updates lack code signing, enabling silent full app replacement by attackers
- The developer's description: EYA's new app is a modern digital companion to your EYA home. For EYA Buyers: your EYA buyer app is the digital companion to your new home purchase. Track construction and closing, receive multimedia updates from your EYA team, access all of your home documents from the palm of your hand, and more.

## Strengths

- Login tokens are encrypted with AES-256-GCM using Android Keystore hardware-backed keys
- All network traffic uses HTTPS with no cleartext HTTP permitted
- WebView correctly rejects invalid SSL certificates rather than silently accepting them
- OAuth login redirect is scoped to the app's package name, preventing interception by other apps
- Barcode and QR code scanning processes camera frames entirely on the device with no data sent to external servers
- No advertising networks or ad-targeting SDKs are present
- Zero known CVEs detected across all 17 native libraries via Binary Ninja analysis
- Native libraries load directly from the APK, preventing disk-level replacement on non-rooted devices

## What the app contains

- Auth0
- Firebase Cloud Messaging
- Firebase Installations
- Google ML Kit
- Sentry
- Expo Updates
- PostHog
- Stream.io

## Libraries

- Room
- Apollo GraphQL
- Auth0
- Fresco
- Glide
- Datatransport
- Google Sign-In 12451000
- Google Play Services 12451000
- Material Components
- Gson
- Firebase 12451000
- Google ML Kit
- OkHttp 4.12.0
- Okio
- Coil 3
- Koin
- Sentry
- Apache Commons
- BouncyCastle
- Kotlin Coroutines
- Kotlin Serialization
- React Native

## Corrections

No correction is published for this app.

## Method and limits

Static analysis: the decompiled code, manifest and resources of this build, read file by file. Network traffic at run time is established by a capture of the running app.

Build SHA-256: `73855eb41f6865cf41d55ec2827c08f68854c4cf7c358dfe6a25650188cd15b5`
Rule pack: `citt-ruleset-2026-08-v1`

HTML page: https://canitrustthat.com/apps/app.eya.buyer
