Apps
96 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.
- 79out of 100unTRUSTED
Gummo
AndroidWhat it means for you
Location data stays on the device and is not shared with Sentry, Firebase, or any analytics service. No advertising network SDKs are present. Firebase handles push notifications, and the Play Install Referrer library is linked for install attribution.
- 7 findings
- Data Security 3
- Code Security 2
- Privacy 2
- 64out of 100unTRUSTED
Raiffeisen Bank SK
AndroidWhat it means for you
No advertising or behavioral tracking SDKs are bundled in build 341. Authentication keys and barcode scans remain on-device. Firebase Crashlytics is present for crash reporting; the code encrypts push notification content before handing it to the Firebase SDK, so Firebase does not see message content. The code for some banking requests may apply less protection than expected on public Wi-Fi.
- 9 findings
- Data Security 2
- Network Security 2
- Code Security 2
- Privacy 2
- Third-Party Risk 1
- 84out of 100unTRUSTED
My EYA
AndroidWhat it means for you
Camera frames for barcode and QR code scanning are processed on the device and not sent to external servers. No advertising or ad-targeting networks are linked in the build. The build includes code to send usage analytics and crash reports to PostHog and Sentry, Firebase Cloud Messaging handles push notifications, and Stream.io supports in-app messaging.
- 9 findings
- Data Security 1
- Code Security 6
- Privacy 2
- 81out of 100unTRUSTED
Yoti - your digital identity
AndroidWhat it means for you
Yes, on the evidence available. The build includes code to send precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. The build includes code to send another 13 data points to other third parties. None of the findings recorded rises to the level of putting a user at risk.
- 1006 findings
- Data Security 39
- Network Security 432
- Code Security 231
- Privacy 249
- Third-Party Risk 43
- Permission Usage 12
- 57out of 100unTRUSTED
Bendigo Bank
AndroidWhat it means for you
Read the findings in full first. The build includes code to send precise location to Google (platform Geocoder backend), and credentials to Datadog, Google Maps Platform and 2 other recipients. The build includes code to send another 12 data points to other third parties. 11 critical or high severity findings, 1 of them at critical, spread across 4 categories are worth reading before this build handles anything a user would want kept to themselves.
- 682 findings
- Data Security 78
- Network Security 82
- Code Security 199
- Privacy 153
- Third-Party Risk 157
- Permission Usage 13
- 82out of 100unTRUSTED
Akedo: Offline Games No WiFi
AndroidWhat it means for you
Gameplay runs offline after download, with no server calls needed during sessions. The app includes code to send device and usage data to Google Firebase and the developer's service at akedo.gg for analytics; the analysis found no code that reads health, location, financial, or contact data. Google AdMob is the only ad network present.
- 5 findings
- Data Security 1
- Network Security 1
- Code Security 1
- Privacy 1
- Third-Party Risk 1
- 84out of 100unTRUSTED
RemindMeWhere Reminders
AndroidWhat it means for you
Geofence locations and reminder data are stored on the device and are not shared with advertising networks. The app includes code to send usage data and authentication activity to Firebase Analytics and Facebook SDK. Cloud-synced data requires authentication before access.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 4
- Privacy 1
- Permission Usage 1
- 64out of 100unTRUSTED
Strava: Run, Bike, Walk
Android- 1952 findings
- Data Security 117
- Network Security 196
- Code Security 352
- Privacy 496
- Third-Party Risk 713
- Permission Usage 78
- 76out of 100unTRUSTED
- 852 findings
- Data Security 80
- Network Security 76
- Code Security 201
- Privacy 213
- Third-Party Risk 262
- Permission Usage 20
- 58out of 100unTRUSTED
myGMC
iOSWhat it means for you
The build includes code to send usage and session activity to Heap (ContentSquare), Adobe Experience Platform, and Salesforce for analytics and marketing. The binary links the Arity SDK, an Allstate subsidiary that specializes in driving behavior analysis. In some areas, user data may not be fully protected.
- 10 findings
- Data Security 6
- Code Security 2
- Third-Party Risk 2
- 78out of 100unTRUSTED
Meross
iOSWhat it means for you
Device commands route through the local network or Apple's end-to-end encrypted infrastructure, not through Meross servers. Account credentials are stored in the device's secure Keychain. The build includes code to send usage and crash data to Firebase Analytics, Firebase Crashlytics, and AWS services. No advertising network has access to usage data.
- 4 findings
- Network Security 1
- Code Security 2
- Privacy 1
- 76out of 100unTRUSTED
meross
AndroidWhat it means for you
No advertising networks or data broker SDKs are present in this build. The build includes code to send device usage statistics and crash reports to Firebase Analytics and Crashlytics. The build includes code that processes smart home device data through Meross infrastructure and AWS, and names no third-party monetization service in code as a destination of user data.
- 11 findings
- Data Security 4
- Network Security 3
- Code Security 2
- Privacy 2
- 49out of 100unTRUSTED
What it means for you
Health, sleep, and step data from device sensors stays on the device with no evidence of transmission to third-party analytics providers. The app includes code to send usage and interaction data to Amplitude, Firebase, Adjust, and the Facebook SDK for analytics and ad attribution. All network connections use encrypted channels.
- 5 findings
- Code Security 3
- Privacy 2
- 72out of 100unTRUSTED
Wagoneer
AndroidWhat it means for you
Vehicle location, trip history, and account documents are kept encrypted on the device. The app includes code to send App activity and diagnostic data to Adobe, Firebase, Salesforce, and Facebook for analytics and marketing. Some account activity may be exposed with less protection than expected on public Wi-Fi.
- 11 findings
- Data Security 1
- Network Security 5
- Code Security 5
- 32out of 100unTRUSTED
BLOKK: Privacy VPN & Blocker
AndroidWhat it means for you
Call and text number blocking runs entirely on the device without a network lookup, and the build includes code to send analytics data only to the developer's own server rather than a third-party analytics vendor. The build also includes code to send usage data to several other analytics and advertising services, including Firebase, Google, Microsoft Clarity, and OneSignal. Some activity may be exposed with less protection than expected on public Wi-Fi.
- 12 findings
- Data Security 2
- Network Security 1
- Code Security 6
- Privacy 1
- Third-Party Risk 2
- 78out of 100unTRUSTED
What it means for you
Code shared across PayPal, Honey, and Xoom addresses only the developer's own infrastructure, and the build includes no code giving third-party ecosystems access to account credentials. Credentials and private keys are stored inside the device's Secure Enclave, not extractable from the device. The app includes code to pass usage, crash, and behavioral data to Firebase, Adjust, and Adobe for analytics and diagnostics.
- 6 findings
- Network Security 2
- Code Security 3
- Permission Usage 1
- 88out of 100unTRUSTED
AAWireless for Android Auto™
AndroidWhat it means for you
The build includes code to send user data to the developer's own backend systems, and contains no code to sell it to data brokers or advertising networks. No vehicle telemetry is part of the app's data collection despite its automotive hardware integration. Firebase Crashlytics and Firebase Analytics are bundled for crash reporting and usage metrics.
- 11 findings
- Network Security 1
- Code Security 7
- Privacy 2
- Third-Party Risk 1
- 77out of 100unTRUSTED
Oura
iOSWhat it means for you
Sleep staging, HRV, and readiness scores are computed on the device by a PyTorch Mobile model, so the code keeps raw biometric sensor data on the device and contains no path to send it to the cloud. The build includes code to send usage and activity data to Segment, Amplitude, and Braze for analytics and engagement. No advertising SDK is present and no advertising identifier is collected.
- 9 findings
- Data Security 1
- Code Security 4
- Third-Party Risk 3
- Permission Usage 1
- 44out of 100unTRUSTED
Urban VPN
iOSWhat it means for you
WireGuard session keys are kept in memory only and not written to disk, and usage data is not tied to an advertising identifier. The build includes code to send usage and device data to Firebase Analytics and Mixpanel, and advertising measurement services from Google and Singular are used for ad attribution. Branch.io and OneSignal are also bundled for attribution and push notifications.
- 2 findings
- Code Security 1
- Third-Party Risk 1
- 85out of 100unTRUSTED
What it means for you
No Meta Audience Network or Google AdMob SDK is bundled in this build; LinkedIn's advertising operates through its own infrastructure rather than external consumer ad networks. The build includes code to send usage, device, and attribution data to Singular, Apple AdServices, and Firebase Crashlytics. Qualtrics XM is also integrated for in-app surveys.
- 7 findings
- Network Security 3
- Code Security 3
- Privacy 1
- 73out of 100unTRUSTED
What it means for you
Health and medical data stays on-device and syncs to the user's own iCloud account, not to developer servers. No behavioral analytics or advertising networks are integrated. RevenueCat is linked for subscription and in-app purchase management.
- 82out of 100unTRUSTED
X
AndroidWhat it means for you
Direct messages are end-to-end encrypted and excluded from device cloud backups. Camera frames captured during identity verification are processed on the device. The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Branch.io, and Datadog for analytics, advertising, and crash reporting.
- 11 findings
- Data Security 1
- Network Security 2
- Code Security 6
- Privacy 1
- Third-Party Risk 1
- 83out of 100unTRUSTED
Airbnb
AndroidWhat it means for you
Identity verification scans, including biometric checks and document images, are handled on the device via Google ML Kit and not routed to third-party servers. The app includes code to pass booking activity, device data, and location signals to Firebase, Google Analytics, Facebook, Singular, Branch, Incognia, and Bugsnag for analytics, fraud detection, and crash reporting.
- 13 findings
- Data Security 1
- Network Security 2
- Code Security 9
- Privacy 1
- 82out of 100unTRUSTED
Revolut: Spend, Save, Trade
AndroidWhat it means for you
Financial transaction data is addressed in code only to Revolut's own servers; the build includes no code to pass financial information to advertising networks or data brokers. Usage analytics through Firebase and AppsFlyer are off by default, with no data shared until user consent is given. The app includes code to pass identity verification data to third-party providers during account onboarding.
- 12 findings
- Data Security 3
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 2
- 51out of 100unTRUSTED
What it means for you
Firebase Analytics, Crashlytics, and performance monitoring are switched off by default and require user consent to turn on; when marketing consent is declined, AppsFlyer is shut down and Braze data is wiped from the device. First-party analytics (Moose, Nudler) include code that names only NordVPN's own servers as destinations. When marketing consent is granted, the build includes code to send data to Braze and AppsFlyer.
- 7 findings
- Data Security 3
- Code Security 2
- Third-Party Risk 2
- 90out of 100unTRUSTED
Revolut Business
AndroidWhat it means for you
The build includes code to send App usage, install attribution, and performance data to AppsFlyer, Firebase Analytics, Firebase Crashlytics, and Branch.io. The build includes code to send Identity verification data to Onfido during onboarding. Financial account and transaction data remain within Revolut's own infrastructure, and financial databases are stored in encrypted form on the device rather than backed up to third-party cloud services.
- 7 findings
- Network Security 2
- Code Security 5
- 74out of 100unTRUSTED
What it means for you
Dating profile data, messages, and auth credentials are excluded from Google cloud backup and device transfers. Facial recognition processing occurs entirely on the device, and the build includes no code to pass raw biometric photos to third-party services. The app includes code to pass usage and behavioral data to advertising and attribution networks including Google Ad Manager, AppsFlyer, and LiveRamp, though seven tracking integrations are individually consent-gated.
- 13 findings
- Network Security 1
- Code Security 8
- Privacy 1
- Third-Party Risk 2
- Permission Usage 1
- 80out of 100unTRUSTED
CNN: Live & Breaking News
AndroidWhat it means for you
The app includes code to pass viewing and interaction data to analytics and advertising services including Firebase Analytics, Adobe Analytics, AppsFlyer, Google AdMob, comScore, and Snowplow. The build includes a full consent-before-tracking flow via OneTrust for EU users, and code that blocks all advertising and analytics SDKs when the consent system does not confirm permission. Firebase Advertising ID collection is disabled in the build.
- 6 findings
- Data Security 1
- Code Security 5
- 82out of 100unTRUSTED
Grok
AndroidWhat it means for you
The app includes code to pass usage and interaction data to Mixpanel, AppsFlyer, and Braze for analytics, attribution, and marketing engagement. Login tokens are stored in the protected Android credential store, isolated from other apps. Google Analytics is configured to exclude advertising identifiers, and support chat identity data is encrypted with hardware-backed storage.
- 7 findings
- Data Security 1
- Network Security 1
- Code Security 3
- Privacy 1
- Third-Party Risk 1
- 72out of 100unTRUSTED
FreeReels - Dramas & Reels
AndroidWhat it means for you
Behavioral analytics code is directed to the developer's own servers rather than a third-party analytics vendor, and cloud backup is disabled. The binary integrates multiple advertising networks including Google AdMob, AppLovin, Pangle, Unity Ads, Vungle, and Facebook Audience Network, each linked for ad delivery and device signal processing. The binary also bundles Ishumei SmAntiFraud and Tencent LiteAV components.
- 12 findings
- Data Security 1
- Network Security 2
- Code Security 6
- Privacy 2
- Third-Party Risk 1
- 69out of 100unTRUSTED
Davivienda
AndroidWhat it means for you
The app includes code to pass session data and device data to multiple third-party services, including AppsFlyer (attribution), Braze (marketing), BioCatch and Cobrowse.io (session monitoring), Dynatrace, and Sentry. Firebase Analytics is linked but configured to be inactive at launch; biometric identity checks are handled by FaceTec and Incode. Some user data may not be fully protected in all scenarios.
- 14 findings
- Data Security 1
- Network Security 2
- Code Security 7
- Privacy 3
- Third-Party Risk 1
- 73out of 100unTRUSTED
Free Download Manager - FDM
AndroidWhat it means for you
No advertising networks are bundled, and download activity is not sold to data brokers. The only external data recipient is Google, via Firebase Analytics for app performance measurement. Camera access is limited to local QR code scanning with no image data leaving the device, and microphone access is used only for audio device routing. Some connection activity may carry less protection than expected on public networks.
- 9 findings
- Data Security 3
- Network Security 2
- Code Security 1
- Privacy 3
- 75out of 100unTRUSTED
United Airlines
AndroidWhat it means for you
Analytics and advertising SDKs from Google, Kochava, Quantum Metric, Mixpanel, and Snowplow are bundled in the build alongside core trip features. Location access requires a current trip context and an explicit permission grant from the user. Account credentials and reservation details are protected by device-level encryption.
- 10 findings
- Data Security 3
- Network Security 2
- Code Security 5
- 85out of 100unTRUSTED
What it means for you
Financial transaction data, including balances and transfer amounts, was not observed reaching advertising networks, and no advertising SDK is present in the app. Biometric identity verification during account setup is processed on the device. The app includes code to pass usage and crash data to Firebase Analytics, Mixpanel, Braze, Facebook, and Sentry, with SDK-level opt-out controls for Braze and Singular built into the app.
- 10 findings
- Data Security 2
- Network Security 1
- Code Security 2
- Privacy 3
- Third-Party Risk 1
- Permission Usage 1
- 75out of 100unTRUSTED
Rakuten Viber Messenger
AndroidWhat it means for you
The app includes code to pass messaging activity and device data to advertising and analytics partners including Braze, Adjust, Facebook, and multiple ad networks. Firebase Analytics collection is disabled by default in the build manifest, and Mixpanel is configured to route through Viber's own CDN proxy, preventing Mixpanel from directly observing individual IP addresses. Payment authorization requires biometric authentication, and sensitive databases are excluded from cloud backups.
- 11 findings
- Data Security 1
- Network Security 4
- Code Security 3
- Privacy 2
- Third-Party Risk 1
- 64out of 100unTRUSTED
Interbank APP
AndroidWhat it means for you
Core financial data, including account balances, transactions, and card details, is processed on Interbank's own servers and is not passed to any analytics platform. The build includes code to pass install and usage data to services including Firebase Analytics, AppsFlyer, Adobe, and Microsoft Clarity. Camera-based features like barcode scanning use on-device processing with no data leaving the device.
- 11 findings
- Data Security 1
- Network Security 1
- Code Security 8
- Privacy 1
- 73out of 100unTRUSTED
What it means for you
Health and workout data stays on the device and does not flow to third-party analytics or advertising services. The build includes code to send usage and behavioral data to analytics and marketing services including AppsFlyer, Amplitude, and Mixpanel for attribution and engagement measurement. Firebase Analytics is disabled in the build, and EU-region routing is configured for Amplitude and Customer.io.
- 5 findings
- Data Security 1
- Code Security 3
- Third-Party Risk 1
- 80out of 100unTRUSTED
MetService NZ Weather
AndroidWhat it means for you
The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Nielsen, Prebid, and Rubicon for analytics and ad measurement. Precise GPS coordinates are not included in advertising requests. A paid subscription removes advertising tracking exposure, though user data may not be fully protected in all scenarios.
- 3 findings
- Network Security 2
- Code Security 1
- 82out of 100unTRUSTED
bitchat
AndroidWhat it means for you
Message content is end-to-end encrypted and the developer operates no servers that receive it. No user accounts, analytics, or advertising SDKs are present. The Nostr messaging feature is configured to connect to public relay servers (damus.io, primal.net, and others), which handle message relay as part of the open Nostr protocol.
- 9 findings
- Data Security 1
- Network Security 2
- Code Security 4
- Privacy 2
- 51out of 100unTRUSTED
Accolade, Inc.
AndroidWhat it means for you
Health records, appointments, and personal data are stored in an encrypted database and are protected from being copied via device backup. Sensitive health screens are blocked from appearing in the device task switcher. Build 334 bundles Firebase, Datadog, AppsFlyer, Segment, Braze, and Branch.io for analytics and crash reporting; Mixpanel integration routes through Accolade's own server.
- 14 findings
- Data Security 3
- Network Security 3
- Code Security 4
- Privacy 4
- 74out of 100unTRUSTED
What it means for you
The app includes code to pass booking activity and app usage data to Adobe Analytics, Adobe Audience Manager, Adobe Target, Firebase Analytics, Branch, Quantum Metric, and Rokt for analytics and advertising. Login credentials and session tokens are stored with device-level encryption and are excluded from cloud and local backups. The network configuration in the build specifies HTTPS only, with no cleartext connections permitted.
- 11 findings
- Data Security 1
- Code Security 6
- Privacy 4
- 50out of 100unTRUSTED
What it means for you
Location data stays on the device, used only for WiFi network name comparison in the Trusted Networks feature. The app includes code to pass app usage and diagnostic data to Firebase Analytics and Crashlytics. Google Ad Services components are integrated in the build, but the app's configuration prevents linking analytics to the advertising ID.
- 8 findings
- Data Security 2
- Network Security 2
- Code Security 2
- Privacy 2
- 75out of 100unTRUSTED
Kroger
AndroidWhat it means for you
Behavioral analytics code from the app's own system is directed only to Kroger's infrastructure, and the build includes no code to pass it to third parties. Pharmacy and biometric credentials are stored with hardware-backed encryption on the device. The build includes code to pass usage, crash, and device data to Firebase, Adobe Experience, Salesforce Marketing Cloud, and fraud-risk services including ThreatMetrix, Iovation, and Experian Accertify.
- 12 findings
- Data Security 2
- Network Security 1
- Code Security 6
- Privacy 1
- Third-Party Risk 2
- 72out of 100unTRUSTED
Fly Delta
AndroidWhat it means for you
Passport and boarding pass scanning is processed on the device, and trip itinerary calendar data is stored locally without being shared with Delta servers or third-party platforms. The build includes code to pass usage activity, device signals, and in-app behavior to analytics and performance services including Adobe Analytics, Firebase Analytics, Quantum Metric, and Dynatrace.
- 7 findings
- Data Security 1
- Code Security 4
- Third-Party Risk 2
- 44out of 100unTRUSTED
- 13 findings
- Data Security 2
- Network Security 3
- Code Security 5
- Privacy 1
- Third-Party Risk 2
- 67out of 100unTRUSTED
- 12 findings
- Network Security 2
- Code Security 7
- Privacy 3
- 74out of 100unTRUSTED
What it means for you
Downloaded audio content is secured with on-device encryption, and app backups are disabled to protect account data. The build includes code to send listening activity and usage data to Firebase Analytics, Conviva, Datadog, Salesforce Marketing Cloud, and Branch.io for analytics and attribution. The build includes code to send advertising data to AdsWizz.
- 8 findings
- Data Security 1
- Network Security 2
- Code Security 4
- Third-Party Risk 1
- 85out of 100unTRUSTED
Keeper Password Manager
AndroidWhat it means for you
Passwords, notes, and credentials are stored as ciphertext on the device, with Android backup disabled to block vault data from cloud or device-transfer backups. Payment card scanning is handled on-device with no card data reaching external servers. The build includes code to report app usage to Singular for attribution only; no advertising network SDK is present, and Firebase is limited to push notifications.
- 8 findings
- Network Security 2
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 71out of 100unTRUSTED
Temper Staff
AndroidWhat it means for you
AppsFlyer, Mixpanel, and Sentry are gated behind in-app consent and do not load until the user grants permission. When the user consents to Mixpanel, the build includes code to send analytics data to EU-region servers. The build includes code to send usage and device data to Firebase, Intercom, and Salesforce Marketing Cloud as part of the service.
- 6 findings
- Data Security 1
- Network Security 2
- Code Security 3
- 73out of 100unTRUSTED
What it means for you
GPS location data is not passed to analytics or advertising services and remains within the app's own systems. The build includes code to send usage and device data to Firebase, AppsFlyer, CleverTap, Mixpanel, and Facebook for analytics and ad attribution. The build includes code to send Mixpanel data to EU-resident servers.
- 12 findings
- Data Security 3
- Code Security 7
- Privacy 1
- Third-Party Risk 1