Apps
21 app pages, the newest scanned on 10 September 2026. Each page covers one build: its score, its label and the file behind every finding.
- 95out of 100TRUSTish
What it means for you
Browsing history and tracker-block statistics stay on the device, with no third-party analytics, advertising, or crash-reporting SDKs present in this build. The bundled libraries (GRDB, Lottie, Kingfisher, and others) are utility components with no data-collection function. Telemetry is first-party and anonymous, with no persistent device identifiers and no search query content.
- 2 findings
- Code Security 2
- 94out of 100TRUSTish
What it means for you
Yes on the security of the code, with what the build includes code to send worth reading first. The build includes code to send financial data to RevenueCat, and advertising identifiers to RevenueCat. None of the findings recorded rises to the level of putting a user at risk.
- 20 findings
- Data Security 1
- Network Security 2
- Code Security 5
- Privacy 10
- Third-Party Risk 1
- Permission Usage 1
- 92out of 100TRUSTish
Session - Private Messenger
AndroidWhat it means for you
The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.
- 4 findings
- Data Security 1
- Network Security 1
- Code Security 2
- 92out of 100TRUSTish
Proton Authenticator & 2FA
AndroidWhat it means for you
The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.
- 2 findings
- Data Security 1
- Code Security 1
- 92out of 100TRUSTish
What it means for you
Financial transactions and budget data are stored in Firebase and optionally synced via Dropbox. Analytics and crash reporting through Firebase are disabled until the user explicitly consents, and ad networks (Google AdMob, Facebook Audience Network) are never activated for paying subscribers. Users who connect bank accounts do so through Salt Edge, a third-party financial data aggregation service.
- 3 findings
- Data Security 1
- Code Security 1
- Third-Party Risk 1
- 89out of 100TRUSTish
What it means for you
HealthKit and workout GPS route data stays on the device and is not shared with advertising networks or data brokers. Analytics and in-app messaging are integrated with TelemetryDeck (privacy-preserving hashed identifiers) and Customer.io (EU data residency), with subscription management via RevenueCat. The backend runs on developer-controlled infrastructure at fitwoody.camp, keeping user data outside third-party cloud services.
- 2 findings
- Code Security 1
- Privacy 1
- 88out of 100TRUSTish
Airbnb
iOSWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 5 findings
- Data Security 1
- Network Security 2
- Code Security 1
- Privacy 1
- 88out of 100TRUSTish
ChatGPT
iOSWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 88out of 100TRUSTish
What it means for you
Financial data is stored locally on the device, and no developer-owned server is named in code as a destination for it. The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. For users who consent to ads, the app includes code to send ad interaction data to Google AdMob; premium subscribers bypass ads entirely.
- 1 finding
- Data Security 1
- 86out of 100TRUSTish
MyNISSAN®
iOSWhat it means for you
The build includes code to send vehicle commands and account data to Nissan's own servers, not third-party platforms. The build includes code to pass crash reports to Firebase, usage analytics to Adobe, and link attribution to Branch.io. An advertising identifier is made available to ad-measurement frameworks included in the app.
- 1 finding
- Data Security 1
- 86out of 100TRUSTish
CatLens - Cat Vision Filter
AndroidWhat it means for you
Camera images and photo effects are processed locally on the device, and the build contains no code to route photo or video frames to a cloud backend. Firebase is present for push notification delivery only, not behavioral tracking. The build includes code to pass usage data and device identifiers to Google AdMob for advertising and to OneSignal for targeted notifications.
- 6 findings
- Data Security 2
- Code Security 3
- Permission Usage 1
- 84out of 100TRUSTish
Anker soundcore
AndroidWhat it means for you
The build includes code to send biometrics to soundcore/Anker cloud, and files to soundcore Anka AI. The build includes code to send another 4 data points to other third parties. Two findings are worth reading before this build handles anything a user would want kept to themselves. One is a high severity finding related to Network Security. One more is an open question the analysis could not settle.
- 49 findings
- Data Security 2
- Network Security 10
- Code Security 18
- Privacy 7
- Third-Party Risk 11
- Permission Usage 1
- 83out of 100TRUSTish
What it means for you
Messages and calls are protected by end-to-end encryption, meaning Meta cannot read message content. No third-party analytics or advertising services are named in code as destinations for data; the telemetry code addresses only Meta's own infrastructure. The build includes code to send contacts only to Meta-owned systems, and the code reads no advertising identifier.
- 3 findings
- Code Security 3
- 83out of 100TRUSTish
What it means for you
Note content is stored within Evernote's own infrastructure and is not passed to any third-party SDK, and no advertising identifier is collected. Firebase Analytics is disabled in this build, so usage data does not flow to Google. The build includes code to send crash reports to Firebase Crashlytics and Sentry, and to send App Store install attribution data to Apple AdServices and Bending Spoons.
- 2 findings
- Code Security 2
- 80out of 100TRUSTish
What it means for you
The build includes code that restricts financial transaction data and app behavior to Revolut's own infrastructure; Firebase Analytics is disabled, so the build contains no code path to send transaction activity to Google. The build includes code that may send install attribution data to AppsFlyer and Branch.io, and includes code to send crash reports to Firebase Crashlytics. Google AdMob, an advertising network, is also linked in the build.
- 4 findings
- Data Security 2
- Code Security 1
- Permission Usage 1
- 80out of 100TRUSTish
- 3 findings
- Data Security 2
- Code Security 1
- 79out of 100TRUSTish
IBKR Mobile
AndroidWhat it means for you
The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. Financial document processing via MiSnap and QR scanning via ML Kit are handled on-device without sending image data externally. One data storage concern was identified where user data may not be fully protected at rest.
- 7 findings
- Data Security 1
- Network Security 2
- Code Security 2
- Privacy 2
- 75out of 100TRUSTish
VLC for Android
AndroidWhat it means for you
The build includes code to send credentials to OpenSubtitles, and authentication tokens to OpenSubtitles. The build includes code to send another 3 data points to other third parties. Four high severity findings related to Data Security and Network Security are worth reading before this build handles anything a user would want kept to themselves.
- 370 findings
- Data Security 105
- Network Security 42
- Code Security 147
- Privacy 46
- Third-Party Risk 18
- Permission Usage 12
- 61out of 100TRUSTish
What it means for you
Message content is not stored on Viber's servers, and media files are encrypted on the device. Calls are end-to-end encrypted. The build includes code to send usage and device data to advertising and analytics services including Adjust, Firebase, Braze, Mixpanel, Facebook Audience Network, and real-time ad bidding platforms.
- 3 findings
- Code Security 2
- Privacy 1
- 51out of 100TRUSTish
What it means for you
VPN credentials are stored in device hardware and never leave the chip. No advertising or behavioral tracking SDKs are present in the binary. The build includes code to send crash reports to Proton's own infrastructure, and the destinations named in code for other data are all within the Proton developer ecosystem.
- 2 findings
- Network Security 1
- Code Security 1
- 49out of 100TRUSTish
Bitwarden Authenticator
AndroidWhat it means for you
Authentication secrets and TOTP codes remain on the device. The build includes Firebase Crashlytics for crash reporting and Firebase Cloud Messaging for push notifications; no advertising or behavioral analytics SDKs are present. Cross-app data access is limited to other Bitwarden apps from the same developer.
- 3 findings
- Data Security 1
- Code Security 2