Skip to content

Apps

96 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.

  • 79
    out of 100unTRUSTED

    Gummo

    Android

    What it means for you

    Location data stays on the device and is not shared with Sentry, Firebase, or any analytics service. No advertising network SDKs are present. Firebase handles push notifications, and the Play Install Referrer library is linked for install attribution.

    • 7 findings
    • Data Security 3
    • Code Security 2
    • Privacy 2
  • 64
    out of 100unTRUSTED

    Raiffeisen Bank SK

    Android

    What it means for you

    No advertising or behavioral tracking SDKs are bundled in build 341. Authentication keys and barcode scans remain on-device. Firebase Crashlytics is present for crash reporting; the code encrypts push notification content before handing it to the Firebase SDK, so Firebase does not see message content. The code for some banking requests may apply less protection than expected on public Wi-Fi.

    • 9 findings
    • Data Security 2
    • Network Security 2
    • Code Security 2
    • Privacy 2
    • Third-Party Risk 1
  • 84
    out of 100unTRUSTED

    My EYA

    Android

    What it means for you

    Camera frames for barcode and QR code scanning are processed on the device and not sent to external servers. No advertising or ad-targeting networks are linked in the build. The build includes code to send usage analytics and crash reports to PostHog and Sentry, Firebase Cloud Messaging handles push notifications, and Stream.io supports in-app messaging.

    • 9 findings
    • Data Security 1
    • Code Security 6
    • Privacy 2
  • 81
    out of 100unTRUSTED

    Yoti - your digital identity

    Android

    What it means for you

    Yes, on the evidence available. The build includes code to send precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. The build includes code to send another 13 data points to other third parties. None of the findings recorded rises to the level of putting a user at risk.

    • 1006 findings
    • Data Security 39
    • Network Security 432
    • Code Security 231
    • Privacy 249
    • Third-Party Risk 43
    • Permission Usage 12
  • 57
    out of 100unTRUSTED

    Bendigo Bank

    Android

    What it means for you

    Read the findings in full first. The build includes code to send precise location to Google (platform Geocoder backend), and credentials to Datadog, Google Maps Platform and 2 other recipients. The build includes code to send another 12 data points to other third parties. 11 critical or high severity findings, 1 of them at critical, spread across 4 categories are worth reading before this build handles anything a user would want kept to themselves.

    • 682 findings
    • Data Security 78
    • Network Security 82
    • Code Security 199
    • Privacy 153
    • Third-Party Risk 157
    • Permission Usage 13
  • 82
    out of 100unTRUSTED

    Akedo: Offline Games No WiFi

    Android

    What it means for you

    Gameplay runs offline after download, with no server calls needed during sessions. The app includes code to send device and usage data to Google Firebase and the developer's service at akedo.gg for analytics; the analysis found no code that reads health, location, financial, or contact data. Google AdMob is the only ad network present.

    • 5 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 84
    out of 100unTRUSTED

    RemindMeWhere Reminders

    Android

    What it means for you

    Geofence locations and reminder data are stored on the device and are not shared with advertising networks. The app includes code to send usage data and authentication activity to Firebase Analytics and Facebook SDK. Cloud-synced data requires authentication before access.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 4
    • Privacy 1
    • Permission Usage 1
  • 64
    out of 100unTRUSTED

    Strava: Run, Bike, Walk

    Android
    • 1952 findings
    • Data Security 117
    • Network Security 196
    • Code Security 352
    • Privacy 496
    • Third-Party Risk 713
    • Permission Usage 78
  • 76
    out of 100unTRUSTED
    • 852 findings
    • Data Security 80
    • Network Security 76
    • Code Security 201
    • Privacy 213
    • Third-Party Risk 262
    • Permission Usage 20
  • 58
    out of 100unTRUSTED

    myGMC

    iOS

    What it means for you

    The build includes code to send usage and session activity to Heap (ContentSquare), Adobe Experience Platform, and Salesforce for analytics and marketing. The binary links the Arity SDK, an Allstate subsidiary that specializes in driving behavior analysis. In some areas, user data may not be fully protected.

    • 10 findings
    • Data Security 6
    • Code Security 2
    • Third-Party Risk 2
  • 78
    out of 100unTRUSTED

    Meross

    iOS

    What it means for you

    Device commands route through the local network or Apple's end-to-end encrypted infrastructure, not through Meross servers. Account credentials are stored in the device's secure Keychain. The build includes code to send usage and crash data to Firebase Analytics, Firebase Crashlytics, and AWS services. No advertising network has access to usage data.

    • 4 findings
    • Network Security 1
    • Code Security 2
    • Privacy 1
  • 76
    out of 100unTRUSTED

    meross

    Android

    What it means for you

    No advertising networks or data broker SDKs are present in this build. The build includes code to send device usage statistics and crash reports to Firebase Analytics and Crashlytics. The build includes code that processes smart home device data through Meross infrastructure and AWS, and names no third-party monetization service in code as a destination of user data.

    • 11 findings
    • Data Security 4
    • Network Security 3
    • Code Security 2
    • Privacy 2
  • 49
    out of 100unTRUSTED

    What it means for you

    Health, sleep, and step data from device sensors stays on the device with no evidence of transmission to third-party analytics providers. The app includes code to send usage and interaction data to Amplitude, Firebase, Adjust, and the Facebook SDK for analytics and ad attribution. All network connections use encrypted channels.

    • 5 findings
    • Code Security 3
    • Privacy 2
  • 72
    out of 100unTRUSTED

    Wagoneer

    Android

    What it means for you

    Vehicle location, trip history, and account documents are kept encrypted on the device. The app includes code to send App activity and diagnostic data to Adobe, Firebase, Salesforce, and Facebook for analytics and marketing. Some account activity may be exposed with less protection than expected on public Wi-Fi.

    • 11 findings
    • Data Security 1
    • Network Security 5
    • Code Security 5
  • 32
    out of 100unTRUSTED

    What it means for you

    Call and text number blocking runs entirely on the device without a network lookup, and the build includes code to send analytics data only to the developer's own server rather than a third-party analytics vendor. The build also includes code to send usage data to several other analytics and advertising services, including Firebase, Google, Microsoft Clarity, and OneSignal. Some activity may be exposed with less protection than expected on public Wi-Fi.

    • 12 findings
    • Data Security 2
    • Network Security 1
    • Code Security 6
    • Privacy 1
    • Third-Party Risk 2
  • 78
    out of 100unTRUSTED

    What it means for you

    Code shared across PayPal, Honey, and Xoom addresses only the developer's own infrastructure, and the build includes no code giving third-party ecosystems access to account credentials. Credentials and private keys are stored inside the device's Secure Enclave, not extractable from the device. The app includes code to pass usage, crash, and behavioral data to Firebase, Adjust, and Adobe for analytics and diagnostics.

    • 6 findings
    • Network Security 2
    • Code Security 3
    • Permission Usage 1
  • 88
    out of 100unTRUSTED

    What it means for you

    The build includes code to send user data to the developer's own backend systems, and contains no code to sell it to data brokers or advertising networks. No vehicle telemetry is part of the app's data collection despite its automotive hardware integration. Firebase Crashlytics and Firebase Analytics are bundled for crash reporting and usage metrics.

    • 11 findings
    • Network Security 1
    • Code Security 7
    • Privacy 2
    • Third-Party Risk 1
  • 77
    out of 100unTRUSTED

    Oura

    iOS

    What it means for you

    Sleep staging, HRV, and readiness scores are computed on the device by a PyTorch Mobile model, so the code keeps raw biometric sensor data on the device and contains no path to send it to the cloud. The build includes code to send usage and activity data to Segment, Amplitude, and Braze for analytics and engagement. No advertising SDK is present and no advertising identifier is collected.

    • 9 findings
    • Data Security 1
    • Code Security 4
    • Third-Party Risk 3
    • Permission Usage 1
  • 44
    out of 100unTRUSTED

    Urban VPN

    iOS

    What it means for you

    WireGuard session keys are kept in memory only and not written to disk, and usage data is not tied to an advertising identifier. The build includes code to send usage and device data to Firebase Analytics and Mixpanel, and advertising measurement services from Google and Singular are used for ad attribution. Branch.io and OneSignal are also bundled for attribution and push notifications.

    • 2 findings
    • Code Security 1
    • Third-Party Risk 1
  • 85
    out of 100unTRUSTED

    What it means for you

    No Meta Audience Network or Google AdMob SDK is bundled in this build; LinkedIn's advertising operates through its own infrastructure rather than external consumer ad networks. The build includes code to send usage, device, and attribution data to Singular, Apple AdServices, and Firebase Crashlytics. Qualtrics XM is also integrated for in-app surveys.

    • 7 findings
    • Network Security 3
    • Code Security 3
    • Privacy 1
  • 73
    out of 100unTRUSTED

    What it means for you

    Health and medical data stays on-device and syncs to the user's own iCloud account, not to developer servers. No behavioral analytics or advertising networks are integrated. RevenueCat is linked for subscription and in-app purchase management.

  • 82
    out of 100unTRUSTED

    X

    Android

    What it means for you

    Direct messages are end-to-end encrypted and excluded from device cloud backups. Camera frames captured during identity verification are processed on the device. The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Branch.io, and Datadog for analytics, advertising, and crash reporting.

    • 11 findings
    • Data Security 1
    • Network Security 2
    • Code Security 6
    • Privacy 1
    • Third-Party Risk 1
  • 83
    out of 100unTRUSTED

    Airbnb

    Android

    What it means for you

    Identity verification scans, including biometric checks and document images, are handled on the device via Google ML Kit and not routed to third-party servers. The app includes code to pass booking activity, device data, and location signals to Firebase, Google Analytics, Facebook, Singular, Branch, Incognia, and Bugsnag for analytics, fraud detection, and crash reporting.

    • 13 findings
    • Data Security 1
    • Network Security 2
    • Code Security 9
    • Privacy 1
  • 82
    out of 100unTRUSTED

    Revolut: Spend, Save, Trade

    Android

    What it means for you

    Financial transaction data is addressed in code only to Revolut's own servers; the build includes no code to pass financial information to advertising networks or data brokers. Usage analytics through Firebase and AppsFlyer are off by default, with no data shared until user consent is given. The app includes code to pass identity verification data to third-party providers during account onboarding.

    • 12 findings
    • Data Security 3
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 2
  • 51
    out of 100unTRUSTED

    What it means for you

    Firebase Analytics, Crashlytics, and performance monitoring are switched off by default and require user consent to turn on; when marketing consent is declined, AppsFlyer is shut down and Braze data is wiped from the device. First-party analytics (Moose, Nudler) include code that names only NordVPN's own servers as destinations. When marketing consent is granted, the build includes code to send data to Braze and AppsFlyer.

    • 7 findings
    • Data Security 3
    • Code Security 2
    • Third-Party Risk 2
  • 90
    out of 100unTRUSTED

    Revolut Business

    Android

    What it means for you

    The build includes code to send App usage, install attribution, and performance data to AppsFlyer, Firebase Analytics, Firebase Crashlytics, and Branch.io. The build includes code to send Identity verification data to Onfido during onboarding. Financial account and transaction data remain within Revolut's own infrastructure, and financial databases are stored in encrypted form on the device rather than backed up to third-party cloud services.

    • 7 findings
    • Network Security 2
    • Code Security 5
  • 74
    out of 100unTRUSTED

    What it means for you

    Dating profile data, messages, and auth credentials are excluded from Google cloud backup and device transfers. Facial recognition processing occurs entirely on the device, and the build includes no code to pass raw biometric photos to third-party services. The app includes code to pass usage and behavioral data to advertising and attribution networks including Google Ad Manager, AppsFlyer, and LiveRamp, though seven tracking integrations are individually consent-gated.

    • 13 findings
    • Network Security 1
    • Code Security 8
    • Privacy 1
    • Third-Party Risk 2
    • Permission Usage 1
  • 80
    out of 100unTRUSTED

    CNN: Live & Breaking News

    Android

    What it means for you

    The app includes code to pass viewing and interaction data to analytics and advertising services including Firebase Analytics, Adobe Analytics, AppsFlyer, Google AdMob, comScore, and Snowplow. The build includes a full consent-before-tracking flow via OneTrust for EU users, and code that blocks all advertising and analytics SDKs when the consent system does not confirm permission. Firebase Advertising ID collection is disabled in the build.

    • 6 findings
    • Data Security 1
    • Code Security 5
  • 82
    out of 100unTRUSTED

    Grok

    Android

    What it means for you

    The app includes code to pass usage and interaction data to Mixpanel, AppsFlyer, and Braze for analytics, attribution, and marketing engagement. Login tokens are stored in the protected Android credential store, isolated from other apps. Google Analytics is configured to exclude advertising identifiers, and support chat identity data is encrypted with hardware-backed storage.

    • 7 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
    • Privacy 1
    • Third-Party Risk 1
  • 72
    out of 100unTRUSTED

    FreeReels - Dramas & Reels

    Android

    What it means for you

    Behavioral analytics code is directed to the developer's own servers rather than a third-party analytics vendor, and cloud backup is disabled. The binary integrates multiple advertising networks including Google AdMob, AppLovin, Pangle, Unity Ads, Vungle, and Facebook Audience Network, each linked for ad delivery and device signal processing. The binary also bundles Ishumei SmAntiFraud and Tencent LiteAV components.

    • 12 findings
    • Data Security 1
    • Network Security 2
    • Code Security 6
    • Privacy 2
    • Third-Party Risk 1
  • 69
    out of 100unTRUSTED

    Davivienda

    Android

    What it means for you

    The app includes code to pass session data and device data to multiple third-party services, including AppsFlyer (attribution), Braze (marketing), BioCatch and Cobrowse.io (session monitoring), Dynatrace, and Sentry. Firebase Analytics is linked but configured to be inactive at launch; biometric identity checks are handled by FaceTec and Incode. Some user data may not be fully protected in all scenarios.

    • 14 findings
    • Data Security 1
    • Network Security 2
    • Code Security 7
    • Privacy 3
    • Third-Party Risk 1
  • 73
    out of 100unTRUSTED

    Free Download Manager - FDM

    Android

    What it means for you

    No advertising networks are bundled, and download activity is not sold to data brokers. The only external data recipient is Google, via Firebase Analytics for app performance measurement. Camera access is limited to local QR code scanning with no image data leaving the device, and microphone access is used only for audio device routing. Some connection activity may carry less protection than expected on public networks.

    • 9 findings
    • Data Security 3
    • Network Security 2
    • Code Security 1
    • Privacy 3
  • 75
    out of 100unTRUSTED

    United Airlines

    Android

    What it means for you

    Analytics and advertising SDKs from Google, Kochava, Quantum Metric, Mixpanel, and Snowplow are bundled in the build alongside core trip features. Location access requires a current trip context and an explicit permission grant from the user. Account credentials and reservation details are protected by device-level encryption.

    • 10 findings
    • Data Security 3
    • Network Security 2
    • Code Security 5
  • 85
    out of 100unTRUSTED

    What it means for you

    Financial transaction data, including balances and transfer amounts, was not observed reaching advertising networks, and no advertising SDK is present in the app. Biometric identity verification during account setup is processed on the device. The app includes code to pass usage and crash data to Firebase Analytics, Mixpanel, Braze, Facebook, and Sentry, with SDK-level opt-out controls for Braze and Singular built into the app.

    • 10 findings
    • Data Security 2
    • Network Security 1
    • Code Security 2
    • Privacy 3
    • Third-Party Risk 1
    • Permission Usage 1
  • 75
    out of 100unTRUSTED

    Rakuten Viber Messenger

    Android

    What it means for you

    The app includes code to pass messaging activity and device data to advertising and analytics partners including Braze, Adjust, Facebook, and multiple ad networks. Firebase Analytics collection is disabled by default in the build manifest, and Mixpanel is configured to route through Viber's own CDN proxy, preventing Mixpanel from directly observing individual IP addresses. Payment authorization requires biometric authentication, and sensitive databases are excluded from cloud backups.

    • 11 findings
    • Data Security 1
    • Network Security 4
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 64
    out of 100unTRUSTED

    Interbank APP

    Android

    What it means for you

    Core financial data, including account balances, transactions, and card details, is processed on Interbank's own servers and is not passed to any analytics platform. The build includes code to pass install and usage data to services including Firebase Analytics, AppsFlyer, Adobe, and Microsoft Clarity. Camera-based features like barcode scanning use on-device processing with no data leaving the device.

    • 11 findings
    • Data Security 1
    • Network Security 1
    • Code Security 8
    • Privacy 1
  • 73
    out of 100unTRUSTED

    What it means for you

    Health and workout data stays on the device and does not flow to third-party analytics or advertising services. The build includes code to send usage and behavioral data to analytics and marketing services including AppsFlyer, Amplitude, and Mixpanel for attribution and engagement measurement. Firebase Analytics is disabled in the build, and EU-region routing is configured for Amplitude and Customer.io.

    • 5 findings
    • Data Security 1
    • Code Security 3
    • Third-Party Risk 1
  • 80
    out of 100unTRUSTED

    MetService NZ Weather

    Android

    What it means for you

    The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Nielsen, Prebid, and Rubicon for analytics and ad measurement. Precise GPS coordinates are not included in advertising requests. A paid subscription removes advertising tracking exposure, though user data may not be fully protected in all scenarios.

    • 3 findings
    • Network Security 2
    • Code Security 1
  • 82
    out of 100unTRUSTED

    bitchat

    Android

    What it means for you

    Message content is end-to-end encrypted and the developer operates no servers that receive it. No user accounts, analytics, or advertising SDKs are present. The Nostr messaging feature is configured to connect to public relay servers (damus.io, primal.net, and others), which handle message relay as part of the open Nostr protocol.

    • 9 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Privacy 2
  • 51
    out of 100unTRUSTED

    Accolade, Inc.

    Android

    What it means for you

    Health records, appointments, and personal data are stored in an encrypted database and are protected from being copied via device backup. Sensitive health screens are blocked from appearing in the device task switcher. Build 334 bundles Firebase, Datadog, AppsFlyer, Segment, Braze, and Branch.io for analytics and crash reporting; Mixpanel integration routes through Accolade's own server.

    • 14 findings
    • Data Security 3
    • Network Security 3
    • Code Security 4
    • Privacy 4
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to pass booking activity and app usage data to Adobe Analytics, Adobe Audience Manager, Adobe Target, Firebase Analytics, Branch, Quantum Metric, and Rokt for analytics and advertising. Login credentials and session tokens are stored with device-level encryption and are excluded from cloud and local backups. The network configuration in the build specifies HTTPS only, with no cleartext connections permitted.

    • 11 findings
    • Data Security 1
    • Code Security 6
    • Privacy 4
  • 50
    out of 100unTRUSTED

    What it means for you

    Location data stays on the device, used only for WiFi network name comparison in the Trusted Networks feature. The app includes code to pass app usage and diagnostic data to Firebase Analytics and Crashlytics. Google Ad Services components are integrated in the build, but the app's configuration prevents linking analytics to the advertising ID.

    • 8 findings
    • Data Security 2
    • Network Security 2
    • Code Security 2
    • Privacy 2
  • 75
    out of 100unTRUSTED

    Kroger

    Android

    What it means for you

    Behavioral analytics code from the app's own system is directed only to Kroger's infrastructure, and the build includes no code to pass it to third parties. Pharmacy and biometric credentials are stored with hardware-backed encryption on the device. The build includes code to pass usage, crash, and device data to Firebase, Adobe Experience, Salesforce Marketing Cloud, and fraud-risk services including ThreatMetrix, Iovation, and Experian Accertify.

    • 12 findings
    • Data Security 2
    • Network Security 1
    • Code Security 6
    • Privacy 1
    • Third-Party Risk 2
  • 72
    out of 100unTRUSTED

    Fly Delta

    Android

    What it means for you

    Passport and boarding pass scanning is processed on the device, and trip itinerary calendar data is stored locally without being shared with Delta servers or third-party platforms. The build includes code to pass usage activity, device signals, and in-app behavior to analytics and performance services including Adobe Analytics, Firebase Analytics, Quantum Metric, and Dynatrace.

    • 7 findings
    • Data Security 1
    • Code Security 4
    • Third-Party Risk 2
  • 44
    out of 100unTRUSTED
    • 13 findings
    • Data Security 2
    • Network Security 3
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 2
  • 67
    out of 100unTRUSTED
    • 12 findings
    • Network Security 2
    • Code Security 7
    • Privacy 3
  • 74
    out of 100unTRUSTED

    What it means for you

    Downloaded audio content is secured with on-device encryption, and app backups are disabled to protect account data. The build includes code to send listening activity and usage data to Firebase Analytics, Conviva, Datadog, Salesforce Marketing Cloud, and Branch.io for analytics and attribution. The build includes code to send advertising data to AdsWizz.

    • 8 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Third-Party Risk 1
  • 85
    out of 100unTRUSTED

    Keeper Password Manager

    Android

    What it means for you

    Passwords, notes, and credentials are stored as ciphertext on the device, with Android backup disabled to block vault data from cloud or device-transfer backups. Payment card scanning is handled on-device with no card data reaching external servers. The build includes code to report app usage to Singular for attribution only; no advertising network SDK is present, and Firebase is limited to push notifications.

    • 8 findings
    • Network Security 2
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 71
    out of 100unTRUSTED

    Temper Staff

    Android

    What it means for you

    AppsFlyer, Mixpanel, and Sentry are gated behind in-app consent and do not load until the user grants permission. When the user consents to Mixpanel, the build includes code to send analytics data to EU-region servers. The build includes code to send usage and device data to Firebase, Intercom, and Salesforce Marketing Cloud as part of the service.

    • 6 findings
    • Data Security 1
    • Network Security 2
    • Code Security 3
  • 73
    out of 100unTRUSTED

    What it means for you

    GPS location data is not passed to analytics or advertising services and remains within the app's own systems. The build includes code to send usage and device data to Firebase, AppsFlyer, CleverTap, Mixpanel, and Facebook for analytics and ad attribution. The build includes code to send Mixpanel data to EU-resident servers.

    • 12 findings
    • Data Security 3
    • Code Security 7
    • Privacy 1
    • Third-Party Risk 1