Skip to content

Apps

96 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.

  • 65
    out of 100unTRUSTED

    Anker eufy

    Android

    What it means for you

    Firebase Analytics and crash reporting are disabled by default, so no usage telemetry leaves the device via those channels. The Sensors Analytics SDK, a Chinese behavioral analytics platform, is integrated into this build. No advertising networks are present, and some user data may not be fully protected.

    • 12 findings
    • Data Security 3
    • Network Security 3
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    Philips Hue

    Android

    What it means for you

    Location data from geofence automations stays on the device and is not forwarded to advertising or analytics services. Bridge login credentials are stored in hardware-protected on-device storage, excluded from cloud and device backups. The build includes code to send usage and crash data to Amplitude, Firebase, Braze, and Sentry.

    • 11 findings
    • Data Security 1
    • Network Security 4
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 85
    out of 100unTRUSTED

    MyBible

    Android

    What it means for you

    Bible reading progress, notes, and history stay on the device and are not accessible to the developer or sold to data brokers. Reading habits are not shared with ad networks. Firebase Analytics and Crashlytics are integrated for performance monitoring.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 41
    out of 100unTRUSTED

    What it means for you

    The build includes code to send app usage and crash data to Firebase Analytics, Firebase Crashlytics, and Google ad measurement services. The build also bundles GeoSurf (Bright Data), a residential proxy network SDK. Whether this configuration routes external traffic through the device's internet connection was not tested. Push notifications are handled by OneSignal.

    • 12 findings
    • Data Security 2
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 2
    • Permission Usage 1
  • 75
    out of 100unTRUSTED

    Wesper

    Android

    What it means for you

    Biometric health data, including sleep metrics and audio recordings, is addressed in code only to Wesper's own servers, and no advertising networks or data brokers are named as destinations. The app is configured to prevent health files from being extracted via device backup. The build includes code to send usage and app performance data to Firebase Analytics and Google services for diagnostics and improvement.

    • 10 findings
    • Data Security 2
    • Code Security 1
    • Privacy 5
    • Third-Party Risk 2
  • 69
    out of 100unTRUSTED

    GoodLeap Home

    Android

    What it means for you

    No advertising network receives data to display targeted ads to users. The build includes code to send usage and activity data to analytics and marketing services including Facebook App Events, RudderStack, Pendo, and Salesforce Marketing Cloud. Some user data may not be fully protected in transit.

    • 13 findings
    • Data Security 3
    • Network Security 1
    • Code Security 5
    • Privacy 3
    • Permission Usage 1
  • 83
    out of 100unTRUSTED

    Reolink

    Android

    What it means for you

    Behavioral telemetry defaults to off and requires explicit opt-in. The code addresses usage data only to Reolink's own systems and names no third-party analytics or advertising networks as destinations. Camera location data is kept on the device and is not transmitted to Reolink servers.

    • 8 findings
    • Data Security 1
    • Network Security 4
    • Code Security 1
    • Privacy 1
    • Permission Usage 1
  • 81
    out of 100unTRUSTED

    Navy Federal Credit Union

    Android

    What it means for you

    The build includes code to send usage data and crash reports to Firebase, Adobe Analytics, Salesforce, and Qualtrics for performance monitoring and feedback. No behavioral advertising SDKs are included, so usage data does not flow to ad platforms. The build includes code to send fraud detection data to Navy Federal's own servers before third-party risk services are involved.

    • 9 findings
    • Data Security 1
    • Network Security 4
    • Code Security 4
  • 86
    out of 100unTRUSTED

    What it means for you

    Firebase Analytics and AppsFlyer are configured to remain inactive until the user explicitly consents, so no analytics or attribution data is generated before that point. Biometric identity verification data is configured to route to Hinge's own servers rather than FaceTec's infrastructure. Firebase, Braze, Sendbird, and related services are integrated in the build for crash reporting, messaging, and performance measurement.

    • 5 findings
    • Code Security 4
    • Third-Party Risk 1
  • 76
    out of 100unTRUSTED

    Instagram

    iOS

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Privacy 4
  • 87
    out of 100unTRUSTED

    Bono

    Android

    What it means for you

    Authentication is handled via Google Sign-In, Apple Sign-In, and FIDO2 passkeys. Push notifications are handled through Firebase, and the build includes code to pass a device identifier to Google. The app includes code to send install referral data to Google when the app is first installed.

    • 8 findings
    • Data Security 2
    • Network Security 2
    • Code Security 3
    • Privacy 1
  • 79
    out of 100unTRUSTED

    Glassdoor | Jobs & Careers

    Android

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
  • 65
    out of 100unTRUSTED

    What it means for you

    The build includes code to send in-app interaction and session data to FullStory, Firebase Analytics, and Urban Airship. Financial account connections are managed through Plaid, and identity verification through Onfido. The app also bundles Group-IB fraud detection and Sentry error reporting.

    • 9 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 87
    out of 100unTRUSTED

    Reflect Notes

    iOS

    What it means for you

    Journal and note content is encrypted before syncing to the developer's own Firebase storage. No advertising, attribution, or broad analytics SDKs are present. Error reporting via Sentry is configured to limit behavioral data capture, and the build includes code for authentication through Google Sign-In and Firebase.

    • 3 findings
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 55
    out of 100unTRUSTED

    Hearoes

    Android

    What it means for you

    Hearing training data, exercise progress, game scores, and user profiles are stored in the developer's own Firebase systems and not shared with data brokers or advertising networks. The build includes code to send usage and crash data to Firebase Analytics and Firebase Crashlytics, and purchase activity is handled by RevenueCat. Some data on the device may not be fully protected. All network requests in the code use encrypted connections.

    • 9 findings
    • Data Security 1
    • Code Security 6
    • Privacy 1
    • Permission Usage 1
  • 82
    out of 100unTRUSTED

    What it means for you

    Financial data syncs only to the user's own iCloud container. Receipt scanning and AI-powered features run entirely on the device. The only external service is Setapp, used for subscription management.

    • 4 findings
    • Data Security 2
    • Code Security 1
    • Privacy 1
  • 92
    out of 100unTRUSTED

    Widgetsmith

    iOS

    What it means for you

    Health, calendar, contacts, reminders, and photos data stays on the device and is not transmitted to third parties. Location, when granted for weather widgets, is kept out of advertising and analytics flows. Ad delivery uses Google Mobile Ads with ATT-based consent, and the build includes code to manage subscriptions through RevenueCat and Superwall.

    • 1 finding
    • Code Security 1
  • 88
    out of 100unTRUSTED

    What it means for you

    Trip content, itineraries, and booking details are not shared with advertisers, data brokers, or cross-app tracking systems. AI-assisted features, including email parsing and itinerary suggestions, run entirely on the device. The build includes Mixpanel and Sentry code that reads usage and crash data to support app performance.

    • 3 findings
    • Data Security 1
    • Code Security 2
  • 64
    out of 100unTRUSTED

    MOVAhome

    iOS

    What it means for you

    Widget data is shared only within the developer's own systems, with no third-party access. Login session credentials are stored in the iOS Keychain rather than in plaintext. The build includes code to send usage and device data to analytics and advertising services from ByteDance, Umeng (Alibaba), Baidu, and Facebook.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 6
  • 85
    out of 100unTRUSTED

    WHOOP

    iOS

    What it means for you

    The build includes code to direct health and biometric data, including heart rate, HRV, sleep, and GPS, only to WHOOP's own infrastructure, and contains no code to pass it to advertising or analytics networks. The build includes code to send usage data to Amplitude for product analytics and to Sentry for crash reporting. The build contains no code that reads advertising identifiers, and internal performance telemetry is processed locally; the build contains no code to send it to third-party clo…

    • 5 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
  • 57
    out of 100unTRUSTED

    What it means for you

    Auth tokens and login sessions are encrypted on the device and cannot be extracted, and financial data is blocked from device backup systems. The build includes code to send usage and activity data to Firebase, Amplitude, AppsFlyer, and Facebook for analytics and advertising. Some financial data may not be fully protected across all areas of the app.

    • 8 findings
    • Data Security 1
    • Code Security 3
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 2
  • 66
    out of 100unTRUSTED

    What it means for you

    Financial data and session tokens are protected against extraction through device backup systems, and contacts data stays on the device without being transmitted to external services. The build includes code to send usage, referral, and performance data to Firebase, Branch.io, UserExperior, and Datadog, among others.

    • 11 findings
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 4
  • 70
    out of 100unTRUSTED

    What it means for you

    The build includes code to send usage patterns and behavioral events to Firebase Analytics, Amplitude, Segment, AppsFlyer, and Facebook. The content of mood entries, journals, and sleep records is not passed to those services. Some stored user data may not be fully protected.

    • 13 findings
    • Data Security 2
    • Code Security 7
    • Privacy 3
    • Third-Party Risk 1
  • 88
    out of 100unTRUSTED

    Kia Access

    Android

    What it means for you

    The build includes code to send usage and vehicle data to Firebase Analytics, Dynatrace, and LexisNexis Risk Solutions. The crash reports the code builds for Firebase Crashlytics include vehicle identifiers such as VIN and license plate numbers alongside the full vehicle record. The build includes code to send navigation activity to Google Maps and HERE Maps. SiriusXM integration handles entertainment connectivity.

    • 13 findings
    • Data Security 3
    • Network Security 4
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    What it means for you

    In the build, login sessions and authentication data are handled by the developer's own systems and the code gives third-party services no access to them. Document scans used for identity verification are processed on the device without being transmitted externally. The build includes code to send usage and behavioral data to Firebase Analytics, Singular, and Sprig for analytics and attribution.

    • 9 findings
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 76
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 75
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 12 findings
    • Network Security 4
    • Code Security 3
    • Privacy 4
    • Permission Usage 1
  • 80
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Data Security 2
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 76
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 66
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 10 findings
    • Data Security 1
    • Code Security 4
    • Privacy 3
    • Third-Party Risk 2
  • 72
    out of 100unTRUSTED

    cred.ai

    iOS

    What it means for you

    Financial account connections via Plaid, document scans, and biometric checks are processed as part of identity verification. The app includes code to pass app usage and attribution data to AppsFlyer, Segment, and Google Tag Manager. The app includes code to pass fraud detection signals to TransUnion. User financial data may not be fully protected in all storage scenarios.

    • 11 findings
    • Data Security 5
    • Network Security 1
    • Code Security 3
    • Privacy 2
  • 97
    out of 100unTRUSTED

    SUUUUUU

    Android

    What it means for you

    The build includes code to authenticate users through Google Sign-In, Apple Sign-In, and SmartAuth, a third-party phone verification service. The app includes code to send app usage data to Firebase Analytics, and code to store user content in Google's Firestore cloud database. Push notification delivery is handled by Firebase Cloud Messaging.

    • 1 finding
    • Code Security 1
  • 83
    out of 100unTRUSTED

    George Česko

    Android

    What it means for you

    The app includes code to send app usage and analytics data to PostHog, Sentry, and Dynatrace for behavioral analytics, crash reporting, and performance monitoring. Firebase is used only for push notifications, not for analytics tracking. The build includes the ThreatMark and Innovatrics SDKs, whose code reads device security signals for fraud protection. Some user data may not be fully protected in all scenarios.

    • 7 findings
    • Data Security 2
    • Network Security 1
    • Code Security 1
    • Privacy 1
    • Third-Party Risk 2
  • 69
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app usage and crash data to Firebase Analytics, Crashlytics, and Sentry. The app includes code to send purchase and subscription activity to RevenueCat. Users can optionally sync financial records to Dropbox or Google Drive. Stored financial data may not be fully protected on device.

    • 7 findings
    • Data Security 3
    • Code Security 1
    • Privacy 2
    • Third-Party Risk 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage data and session activity to Firebase Analytics. The app includes code to read an advertising identifier and pass it to Google's ad attribution services. Locally stored financial data may not be fully protected, which is worth considering if the device could be accessed by others.

    • 2 findings
    • Data Security 1
    • Privacy 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage and event data to Firebase Analytics, Facebook SDK, Amplitude, and Tenjin for analytics and attribution. The app includes code for financial transactions through Stripe and Plaid. Location data may be collected in the background via a geolocation service. Receipt images are processed on-device and not sent to the cloud.

    • 14 findings
    • Data Security 2
    • Network Security 2
    • Code Security 4
    • Privacy 3
    • Third-Party Risk 1
    • Permission Usage 2
  • 84
    out of 100unTRUSTED

    Money manager & expenses

    Android

    What it means for you

    The build includes the AppMetrica (Yandex), Facebook, and VK SDKs, whose code reads app usage data for analytics. Ads are served through Google AdMob and Yandex Mobile Ads. Locally stored data is well protected, though the app includes code that may send some app data with less protection than expected on certain connections.

    • 6 findings
    • Data Security 3
    • Network Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage and crash data to Firebase Analytics and Crashlytics, and the Facebook SDK is present, whose code may send behavioral data to Meta. Financial data entered by the user is stored via Firebase cloud services. Permission access to device features beyond core tracking needs has been identified.

    • 6 findings
    • Data Security 2
    • Code Security 1
    • Third-Party Risk 2
    • Permission Usage 1
  • 72
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app activity to six advertising networks, including Facebook Audience Network, AppLovin, and Google AdMob, alongside Firebase Analytics. Usage patterns and in-app behavior may inform ad targeting across these networks. Some locally stored data may not be fully protected.

    • 12 findings
    • Data Security 4
    • Network Security 2
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 80
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app usage and behavioral data to Braze and AppsFlyer for marketing and attribution purposes. Bank account connectivity is handled through Plaid and Mastercard Open Banking. The app includes code to send crash reports to Bugsnag, and Optimizely runs A/B tests on user interactions within the app.

    • 5 findings
    • Data Security 1
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
  • 73
    out of 100unTRUSTED

    Mój Orange

    Android

    What it means for you

    The app includes code to send app usage and behavioral data to AppsFlyer, Firebase Analytics, Synerise, QuantumMetric, and Google Tag Manager for analytics, CRM, and marketing purposes. Session interactions within the app are recorded by QuantumMetric for behavioral analysis. Some code may send network activity with less protection than expected on public Wi-Fi.

    • 7 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 2
  • 84
    out of 100unTRUSTED

    My Orange Moldova

    Android

    What it means for you

    The build includes the Firebase Analytics and Batch SDKs, whose code reads app usage data for usage insights and push notifications, with analytics requiring explicit user consent before activation. Identity verification flows rely on AriadNext IDcheckio and Unissey, which may process document or biometric data. Some user data may not be fully protected in all transmission scenarios.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 75
    out of 100unTRUSTED

    My Vodafone Romania

    Android

    What it means for you

    The app includes code to send app usage and account activity to Firebase Analytics, Adjust, Facebook, Tealium, Huawei HiAnalytics, Medallia, and Urban Airship for analytics, marketing attribution, and push messaging. Some code may send activity with less protection than expected on certain network paths. Account authentication uses hardware-backed key storage on the device.

    • 8 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 64
    out of 100unTRUSTED

    my moldcell

    Android

    What it means for you

    The app includes code to send account and usage data to Firebase Analytics, Facebook, and Google Ad Services for analytics and advertising purposes. Some code may send activity with less protection than expected on some network connections. An EVAM SDK also includes code to route data to a third-party provider outside major platform ecosystems.

    • 10 findings
    • Data Security 3
    • Network Security 2
    • Code Security 2
    • Third-Party Risk 2
    • Permission Usage 1
  • 91
    out of 100unTRUSTED

    SAP for Me

    Android

    What it means for you

    The app includes code to send usage and interaction data to Firebase Analytics and Adobe Experience Platform for performance tracking, and to Qualtrics for optional in-app surveys. TrustArc consent management controls whether Adobe analytics tracking is active based on user preferences. Locally stored data is protected, and all traffic to company systems uses secure connections.

    • 6 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Privacy 2
  • 58
    out of 100unTRUSTED

    What it means for you

    In-app behavior, including taps and screen interactions, is recorded by FullStory and Heap Analytics. The build includes code to send user activity to Salesforce Marketing Cloud for targeted messaging and to Firebase for performance tracking. The build includes multiple third-party SDKs whose code observes financial account interactions.

    • 7 findings
    • Data Security 2
    • Code Security 2
    • Privacy 3