Castify enables casting videos, music, and photos to Chromecast, Roku, Fire TV, and compatible smart TVs. Features include screen mirroring, in-app browser for discovering media, and AI-powered subtitle generation and translation. Pro removes ads.
This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.
Quick Verdict
Best for: General use with standard privacy expectations
What It Means For You
Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Network Security
4 totalCode Security
3 totalPrivacy
4 totalPermission Usage
1 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.castify
Version
12.299 (versionCode 10299)
Analysis Date
Jul 18, 2026
Classes Analyzed
18,575
Feedback helps us improve our analysis
Castify works well for streaming media to Chromecast, Roku, Fire TV, and compatible smart TVs. The app shares device and behavioral data with Google advertising and analytics services prior to consent, and the Play Store privacy disclosures understate the actual scope of third-party data sharing. The in-app browser's open file-access settings and unvalidated link handling are the main technical areas that could be strengthened.
Data Security: 0 findings
Network Security: 4 findings (3 medium, 1 low)
Code Safety: 4 findings (3 high, 1 low)
Privacy: 4 findings (1 medium, 3 low)
Third parties that may receive data from the app:
Security: 72/100
Privacy: 81/100
The app's privacy practices could be strengthened by:
Accurate Play Store Privacy Disclosures
The Play Store Data Safety section declares no third-party data sharing, but device identifiers, behavioral data, and crash reports are shared with Google's advertising and analytics services. Updating the disclosure to accurately reflect actual data flows would improve transparency for users.
Consent-Gated Crash Reporting
Firebase Crashlytics initializes and begins transmitting diagnostic data on first launch, before any user consent dialog can execute. Deferring initialization until after consent is obtained would better align with privacy regulations.
In-App Browser File Access Restrictions
The in-app browser is configured to allow scripts on loaded pages to read local device files. Disabling universal file access in the browser settings would significantly reduce the risk associated with opening untrusted links.
Link Validation Before Loading
External links routed into the in-app browser are loaded without any domain validation or user confirmation. Restricting which domains can be opened automatically, or confirming with the user before loading external URLs, would reduce exposure.
App Type: Media casting and streaming utility
Classes Analyzed: 18,575
Third-Party Services: 13
Context Tags: streaming, casting, ads, media
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of Android applications, intended to help people make informed decisions about app security and privacy.
Developer: CASTIFY INC.
Version: 12.299 (versionCode 10299)
Analysis Date: 2026-07-18
Package: com.castify
Developer not yet contacted