This app did not meet one of the trust checks in this assessment.
The five trust checks
What It Means For You
The code sends biometrics to soundcore/Anker cloud, and files to soundcore Anka AI. Another 4 data points are sent out to other third parties. Two findings are worth reading before this build handles anything a user would want kept to themselves. One is a high severity finding related to Network Security. One more is an open question the analysis could not settle.
What It Means For You
The code sends biometrics to soundcore/Anker cloud, and files to soundcore Anka AI. Another 4 data points are sent out to other third parties. Two findings are worth reading before this build handles anything a user would want kept to themselves. One is a high severity finding related to Network Security. One more is an open question the analysis could not settle.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalNetwork Security
10 totalCode Security
18 totalPrivacy
7 totalThird-Party Risk
11 totalPermission Usage
1 totalVersion diff is on the Developer plan. See developer plans.
Package
com.oceanwing.soundcore
Analysis Date
Sep 10, 2026
Feedback helps us improve our analysis
The code sends biometrics to soundcore/Anker cloud; files to soundcore Anka AI; microphone input to soundcore/Anker cloud and unnamed third-party AI translation processors; and device identifiers to Google Firebase Cloud Messaging. Another 2 data points are sent out to other third parties.
Other findings record data arriving from a server.
The code sends data out of the device to third-party recipients. Some of those flows are recorded on paths that lack a consent step.
Two findings related to Code Security, Network Security and Third-Party Risk are worth reading before this build handles anything a user would want kept to themselves.
One finding needs attention, on how the app connects to servers. The detailed report states each of these in full.
CITT examined 206 files, traced 11 data flows and recorded 52 findings.
On whether the user was asked first, across the 11 flows recorded, not only the outbound ones: 10 have an unsettled consent state either way; 1 runs on paths recorded without a consent step.
This assessment was produced by CITT (Can I Trust That), an independent analysis service. Each statement above comes from one recorded claim, given here as a summary of what was found rather than as the evidence for it.
Developer not yet contacted