Apps
96 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.
- 97out of 100unTRUSTED
SUUUUUU
AndroidWhat it means for you
The build includes code to authenticate users through Google Sign-In, Apple Sign-In, and SmartAuth, a third-party phone verification service. The app includes code to send app usage data to Firebase Analytics, and code to store user content in Google's Firestore cloud database. Push notification delivery is handled by Firebase Cloud Messaging.
- 1 finding
- Code Security 1
- 92out of 100unTRUSTED
Widgetsmith
iOSWhat it means for you
Health, calendar, contacts, reminders, and photos data stays on the device and is not transmitted to third parties. Location, when granted for weather widgets, is kept out of advertising and analytics flows. Ad delivery uses Google Mobile Ads with ATT-based consent, and the build includes code to manage subscriptions through RevenueCat and Superwall.
- 1 finding
- Code Security 1
- 91out of 100unTRUSTED
SAP for Me
AndroidWhat it means for you
The app includes code to send usage and interaction data to Firebase Analytics and Adobe Experience Platform for performance tracking, and to Qualtrics for optional in-app surveys. TrustArc consent management controls whether Adobe analytics tracking is active based on user preferences. Locally stored data is protected, and all traffic to company systems uses secure connections.
- 6 findings
- Data Security 1
- Network Security 1
- Code Security 2
- Privacy 2
- 90out of 100unTRUSTED
Revolut Business
AndroidWhat it means for you
The build includes code to send App usage, install attribution, and performance data to AppsFlyer, Firebase Analytics, Firebase Crashlytics, and Branch.io. The build includes code to send Identity verification data to Onfido during onboarding. Financial account and transaction data remain within Revolut's own infrastructure, and financial databases are stored in encrypted form on the device rather than backed up to third-party cloud services.
- 7 findings
- Network Security 2
- Code Security 5
- 88out of 100unTRUSTED
AAWireless for Android Auto™
AndroidWhat it means for you
The build includes code to send user data to the developer's own backend systems, and contains no code to sell it to data brokers or advertising networks. No vehicle telemetry is part of the app's data collection despite its automotive hardware integration. Firebase Crashlytics and Firebase Analytics are bundled for crash reporting and usage metrics.
- 11 findings
- Network Security 1
- Code Security 7
- Privacy 2
- Third-Party Risk 1
- 88out of 100unTRUSTED
What it means for you
Trip content, itineraries, and booking details are not shared with advertisers, data brokers, or cross-app tracking systems. AI-assisted features, including email parsing and itinerary suggestions, run entirely on the device. The build includes Mixpanel and Sentry code that reads usage and crash data to support app performance.
- 3 findings
- Data Security 1
- Code Security 2
- 88out of 100unTRUSTED
Kia Access
AndroidWhat it means for you
The build includes code to send usage and vehicle data to Firebase Analytics, Dynatrace, and LexisNexis Risk Solutions. The crash reports the code builds for Firebase Crashlytics include vehicle identifiers such as VIN and license plate numbers alongside the full vehicle record. The build includes code to send navigation activity to Google Maps and HERE Maps. SiriusXM integration handles entertainment connectivity.
- 13 findings
- Data Security 3
- Network Security 4
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 87out of 100unTRUSTED
Bono
AndroidWhat it means for you
Authentication is handled via Google Sign-In, Apple Sign-In, and FIDO2 passkeys. Push notifications are handled through Firebase, and the build includes code to pass a device identifier to Google. The app includes code to send install referral data to Google when the app is first installed.
- 8 findings
- Data Security 2
- Network Security 2
- Code Security 3
- Privacy 1
- 87out of 100unTRUSTED
What it means for you
Journal and note content is encrypted before syncing to the developer's own Firebase storage. No advertising, attribution, or broad analytics SDKs are present. Error reporting via Sentry is configured to limit behavioral data capture, and the build includes code for authentication through Google Sign-In and Firebase.
- 3 findings
- Network Security 1
- Code Security 1
- Privacy 1
- 86out of 100unTRUSTED
What it means for you
Firebase Analytics and AppsFlyer are configured to remain inactive until the user explicitly consents, so no analytics or attribution data is generated before that point. Biometric identity verification data is configured to route to Hinge's own servers rather than FaceTec's infrastructure. Firebase, Braze, Sendbird, and related services are integrated in the build for crash reporting, messaging, and performance measurement.
- 5 findings
- Code Security 4
- Third-Party Risk 1
- 85out of 100unTRUSTED
What it means for you
No Meta Audience Network or Google AdMob SDK is bundled in this build; LinkedIn's advertising operates through its own infrastructure rather than external consumer ad networks. The build includes code to send usage, device, and attribution data to Singular, Apple AdServices, and Firebase Crashlytics. Qualtrics XM is also integrated for in-app surveys.
- 7 findings
- Network Security 3
- Code Security 3
- Privacy 1
- 85out of 100unTRUSTED
What it means for you
Financial transaction data, including balances and transfer amounts, was not observed reaching advertising networks, and no advertising SDK is present in the app. Biometric identity verification during account setup is processed on the device. The app includes code to pass usage and crash data to Firebase Analytics, Mixpanel, Braze, Facebook, and Sentry, with SDK-level opt-out controls for Braze and Singular built into the app.
- 10 findings
- Data Security 2
- Network Security 1
- Code Security 2
- Privacy 3
- Third-Party Risk 1
- Permission Usage 1
- 85out of 100unTRUSTED
Keeper Password Manager
AndroidWhat it means for you
Passwords, notes, and credentials are stored as ciphertext on the device, with Android backup disabled to block vault data from cloud or device-transfer backups. Payment card scanning is handled on-device with no card data reaching external servers. The build includes code to report app usage to Singular for attribution only; no advertising network SDK is present, and Firebase is limited to push notifications.
- 8 findings
- Network Security 2
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 85out of 100unTRUSTED
MyBible
AndroidWhat it means for you
Bible reading progress, notes, and history stay on the device and are not accessible to the developer or sold to data brokers. Reading habits are not shared with ad networks. Firebase Analytics and Crashlytics are integrated for performance monitoring.
- 4 findings
- Data Security 1
- Network Security 1
- Code Security 1
- Privacy 1
- 85out of 100unTRUSTED
WHOOP
iOSWhat it means for you
The build includes code to direct health and biometric data, including heart rate, HRV, sleep, and GPS, only to WHOOP's own infrastructure, and contains no code to pass it to advertising or analytics networks. The build includes code to send usage data to Amplitude for product analytics and to Sentry for crash reporting. The build contains no code that reads advertising identifiers, and internal performance telemetry is processed locally; the build contains no code to send it to third-party clo…
- 5 findings
- Data Security 1
- Network Security 1
- Code Security 3
- 84out of 100unTRUSTED
My EYA
AndroidWhat it means for you
Camera frames for barcode and QR code scanning are processed on the device and not sent to external servers. No advertising or ad-targeting networks are linked in the build. The build includes code to send usage analytics and crash reports to PostHog and Sentry, Firebase Cloud Messaging handles push notifications, and Stream.io supports in-app messaging.
- 9 findings
- Data Security 1
- Code Security 6
- Privacy 2
- 84out of 100unTRUSTED
RemindMeWhere Reminders
AndroidWhat it means for you
Geofence locations and reminder data are stored on the device and are not shared with advertising networks. The app includes code to send usage data and authentication activity to Firebase Analytics and Facebook SDK. Cloud-synced data requires authentication before access.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 4
- Privacy 1
- Permission Usage 1
- 84out of 100unTRUSTED
Money manager & expenses
AndroidWhat it means for you
The build includes the AppMetrica (Yandex), Facebook, and VK SDKs, whose code reads app usage data for analytics. Ads are served through Google AdMob and Yandex Mobile Ads. Locally stored data is well protected, though the app includes code that may send some app data with less protection than expected on certain connections.
- 6 findings
- Data Security 3
- Network Security 1
- Privacy 1
- Third-Party Risk 1
- 84out of 100unTRUSTED
My Orange Moldova
AndroidWhat it means for you
The build includes the Firebase Analytics and Batch SDKs, whose code reads app usage data for usage insights and push notifications, with analytics requiring explicit user consent before activation. Identity verification flows rely on AriadNext IDcheckio and Unissey, which may process document or biometric data. Some user data may not be fully protected in all transmission scenarios.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 83out of 100unTRUSTED
Airbnb
AndroidWhat it means for you
Identity verification scans, including biometric checks and document images, are handled on the device via Google ML Kit and not routed to third-party servers. The app includes code to pass booking activity, device data, and location signals to Firebase, Google Analytics, Facebook, Singular, Branch, Incognia, and Bugsnag for analytics, fraud detection, and crash reporting.
- 13 findings
- Data Security 1
- Network Security 2
- Code Security 9
- Privacy 1
- 83out of 100unTRUSTED
Reolink
AndroidWhat it means for you
Behavioral telemetry defaults to off and requires explicit opt-in. The code addresses usage data only to Reolink's own systems and names no third-party analytics or advertising networks as destinations. Camera location data is kept on the device and is not transmitted to Reolink servers.
- 8 findings
- Data Security 1
- Network Security 4
- Code Security 1
- Privacy 1
- Permission Usage 1
- 83out of 100unTRUSTED
George Česko
AndroidWhat it means for you
The app includes code to send app usage and analytics data to PostHog, Sentry, and Dynatrace for behavioral analytics, crash reporting, and performance monitoring. Firebase is used only for push notifications, not for analytics tracking. The build includes the ThreatMark and Innovatrics SDKs, whose code reads device security signals for fraud protection. Some user data may not be fully protected in all scenarios.
- 7 findings
- Data Security 2
- Network Security 1
- Code Security 1
- Privacy 1
- Third-Party Risk 2
- 82out of 100unTRUSTED
Akedo: Offline Games No WiFi
AndroidWhat it means for you
Gameplay runs offline after download, with no server calls needed during sessions. The app includes code to send device and usage data to Google Firebase and the developer's service at akedo.gg for analytics; the analysis found no code that reads health, location, financial, or contact data. Google AdMob is the only ad network present.
- 5 findings
- Data Security 1
- Network Security 1
- Code Security 1
- Privacy 1
- Third-Party Risk 1
- 82out of 100unTRUSTED
X
AndroidWhat it means for you
Direct messages are end-to-end encrypted and excluded from device cloud backups. Camera frames captured during identity verification are processed on the device. The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Branch.io, and Datadog for analytics, advertising, and crash reporting.
- 11 findings
- Data Security 1
- Network Security 2
- Code Security 6
- Privacy 1
- Third-Party Risk 1
- 82out of 100unTRUSTED
Revolut: Spend, Save, Trade
AndroidWhat it means for you
Financial transaction data is addressed in code only to Revolut's own servers; the build includes no code to pass financial information to advertising networks or data brokers. Usage analytics through Firebase and AppsFlyer are off by default, with no data shared until user consent is given. The app includes code to pass identity verification data to third-party providers during account onboarding.
- 12 findings
- Data Security 3
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 2
- 82out of 100unTRUSTED
Grok
AndroidWhat it means for you
The app includes code to pass usage and interaction data to Mixpanel, AppsFlyer, and Braze for analytics, attribution, and marketing engagement. Login tokens are stored in the protected Android credential store, isolated from other apps. Google Analytics is configured to exclude advertising identifiers, and support chat identity data is encrypted with hardware-backed storage.
- 7 findings
- Data Security 1
- Network Security 1
- Code Security 3
- Privacy 1
- Third-Party Risk 1
- 82out of 100unTRUSTED
bitchat
AndroidWhat it means for you
Message content is end-to-end encrypted and the developer operates no servers that receive it. No user accounts, analytics, or advertising SDKs are present. The Nostr messaging feature is configured to connect to public relay servers (damus.io, primal.net, and others), which handle message relay as part of the open Nostr protocol.
- 9 findings
- Data Security 1
- Network Security 2
- Code Security 4
- Privacy 2
- 82out of 100unTRUSTED
Philips Hue
AndroidWhat it means for you
Location data from geofence automations stays on the device and is not forwarded to advertising or analytics services. Bridge login credentials are stored in hardware-protected on-device storage, excluded from cloud and device backups. The build includes code to send usage and crash data to Amplitude, Firebase, Braze, and Sentry.
- 11 findings
- Data Security 1
- Network Security 4
- Code Security 3
- Privacy 2
- Third-Party Risk 1
- 82out of 100unTRUSTED
What it means for you
Financial data syncs only to the user's own iCloud container. Receipt scanning and AI-powered features run entirely on the device. The only external service is Setapp, used for subscription management.
- 4 findings
- Data Security 2
- Code Security 1
- Privacy 1
- 82out of 100unTRUSTED
Trump Accounts: Official App
AndroidWhat it means for you
In the build, login sessions and authentication data are handled by the developer's own systems and the code gives third-party services no access to them. Document scans used for identity verification are processed on the device without being transmitted externally. The build includes code to send usage and behavioral data to Firebase Analytics, Singular, and Sprig for analytics and attribution.
- 9 findings
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 1
- Permission Usage 1
- 81out of 100unTRUSTED
Yoti - your digital identity
AndroidWhat it means for you
Yes, on the evidence available. The build includes code to send precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. The build includes code to send another 13 data points to other third parties. None of the findings recorded rises to the level of putting a user at risk.
- 1006 findings
- Data Security 39
- Network Security 432
- Code Security 231
- Privacy 249
- Third-Party Risk 43
- Permission Usage 12
- 81out of 100unTRUSTED
Navy Federal Credit Union
AndroidWhat it means for you
The build includes code to send usage data and crash reports to Firebase, Adobe Analytics, Salesforce, and Qualtrics for performance monitoring and feedback. No behavioral advertising SDKs are included, so usage data does not flow to ad platforms. The build includes code to send fraud detection data to Navy Federal's own servers before third-party risk services are involved.
- 9 findings
- Data Security 1
- Network Security 4
- Code Security 4
- 80out of 100unTRUSTED
CNN: Live & Breaking News
AndroidWhat it means for you
The app includes code to pass viewing and interaction data to analytics and advertising services including Firebase Analytics, Adobe Analytics, AppsFlyer, Google AdMob, comScore, and Snowplow. The build includes a full consent-before-tracking flow via OneTrust for EU users, and code that blocks all advertising and analytics SDKs when the consent system does not confirm permission. Firebase Advertising ID collection is disabled in the build.
- 6 findings
- Data Security 1
- Code Security 5
- 80out of 100unTRUSTED
MetService NZ Weather
AndroidWhat it means for you
The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Nielsen, Prebid, and Rubicon for analytics and ad measurement. Precise GPS coordinates are not included in advertising requests. A paid subscription removes advertising tracking exposure, though user data may not be fully protected in all scenarios.
- 3 findings
- Network Security 2
- Code Security 1
- 80out of 100unTRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 5 findings
- Data Security 2
- Network Security 1
- Code Security 1
- Privacy 1
- 80out of 100unTRUSTED
What it means for you
The app includes code to send app usage and behavioral data to Braze and AppsFlyer for marketing and attribution purposes. Bank account connectivity is handled through Plaid and Mastercard Open Banking. The app includes code to send crash reports to Bugsnag, and Optimizely runs A/B tests on user interactions within the app.
- 5 findings
- Data Security 1
- Code Security 2
- Privacy 1
- Third-Party Risk 1
- 79out of 100unTRUSTED
Gummo
AndroidWhat it means for you
Location data stays on the device and is not shared with Sentry, Firebase, or any analytics service. No advertising network SDKs are present. Firebase handles push notifications, and the Play Install Referrer library is linked for install attribution.
- 7 findings
- Data Security 3
- Code Security 2
- Privacy 2
- 79out of 100unTRUSTED
Glassdoor | Jobs & Careers
AndroidWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 5 findings
- Network Security 2
- Code Security 2
- Privacy 1
- 78out of 100unTRUSTED
Meross
iOSWhat it means for you
Device commands route through the local network or Apple's end-to-end encrypted infrastructure, not through Meross servers. Account credentials are stored in the device's secure Keychain. The build includes code to send usage and crash data to Firebase Analytics, Firebase Crashlytics, and AWS services. No advertising network has access to usage data.
- 4 findings
- Network Security 1
- Code Security 2
- Privacy 1
- 78out of 100unTRUSTED
What it means for you
Code shared across PayPal, Honey, and Xoom addresses only the developer's own infrastructure, and the build includes no code giving third-party ecosystems access to account credentials. Credentials and private keys are stored inside the device's Secure Enclave, not extractable from the device. The app includes code to pass usage, crash, and behavioral data to Firebase, Adjust, and Adobe for analytics and diagnostics.
- 6 findings
- Network Security 2
- Code Security 3
- Permission Usage 1
- 77out of 100unTRUSTED
Oura
iOSWhat it means for you
Sleep staging, HRV, and readiness scores are computed on the device by a PyTorch Mobile model, so the code keeps raw biometric sensor data on the device and contains no path to send it to the cloud. The build includes code to send usage and activity data to Segment, Amplitude, and Braze for analytics and engagement. No advertising SDK is present and no advertising identifier is collected.
- 9 findings
- Data Security 1
- Code Security 4
- Third-Party Risk 3
- Permission Usage 1
- 76out of 100unTRUSTED
- 852 findings
- Data Security 80
- Network Security 76
- Code Security 201
- Privacy 213
- Third-Party Risk 262
- Permission Usage 20
- 76out of 100unTRUSTED
meross
AndroidWhat it means for you
No advertising networks or data broker SDKs are present in this build. The build includes code to send device usage statistics and crash reports to Firebase Analytics and Crashlytics. The build includes code that processes smart home device data through Meross infrastructure and AWS, and names no third-party monetization service in code as a destination of user data.
- 11 findings
- Data Security 4
- Network Security 3
- Code Security 2
- Privacy 2
- 76out of 100unTRUSTED
Instagram
iOSWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 2
- Privacy 4
- 76out of 100unTRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 4 findings
- Data Security 1
- Network Security 1
- Code Security 1
- Privacy 1
- 76out of 100unTRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 3
- Privacy 2
- Third-Party Risk 1
- 75out of 100unTRUSTED
United Airlines
AndroidWhat it means for you
Analytics and advertising SDKs from Google, Kochava, Quantum Metric, Mixpanel, and Snowplow are bundled in the build alongside core trip features. Location access requires a current trip context and an explicit permission grant from the user. Account credentials and reservation details are protected by device-level encryption.
- 10 findings
- Data Security 3
- Network Security 2
- Code Security 5
- 75out of 100unTRUSTED
Rakuten Viber Messenger
AndroidWhat it means for you
The app includes code to pass messaging activity and device data to advertising and analytics partners including Braze, Adjust, Facebook, and multiple ad networks. Firebase Analytics collection is disabled by default in the build manifest, and Mixpanel is configured to route through Viber's own CDN proxy, preventing Mixpanel from directly observing individual IP addresses. Payment authorization requires biometric authentication, and sensitive databases are excluded from cloud backups.
- 11 findings
- Data Security 1
- Network Security 4
- Code Security 3
- Privacy 2
- Third-Party Risk 1
- 75out of 100unTRUSTED
Kroger
AndroidWhat it means for you
Behavioral analytics code from the app's own system is directed only to Kroger's infrastructure, and the build includes no code to pass it to third parties. Pharmacy and biometric credentials are stored with hardware-backed encryption on the device. The build includes code to pass usage, crash, and device data to Firebase, Adobe Experience, Salesforce Marketing Cloud, and fraud-risk services including ThreatMetrix, Iovation, and Experian Accertify.
- 12 findings
- Data Security 2
- Network Security 1
- Code Security 6
- Privacy 1
- Third-Party Risk 2
- 75out of 100unTRUSTED
Wesper
AndroidWhat it means for you
Biometric health data, including sleep metrics and audio recordings, is addressed in code only to Wesper's own servers, and no advertising networks or data brokers are named as destinations. The app is configured to prevent health files from being extracted via device backup. The build includes code to send usage and app performance data to Firebase Analytics and Google services for diagnostics and improvement.
- 10 findings
- Data Security 2
- Code Security 1
- Privacy 5
- Third-Party Risk 2