16 million+ customers send, receive, spend and grow their money internationally with Wise. It's the fast, simple way to move money in 145+ countries and 45+ currencies. Send to 70+ countries with mid-market exchange rates. Hold 40 currencies and convert instantly at low fees.
This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
Quick Verdict
Best for: Everyday global transfers with on-device identity checks
What It Means For You
Financial transaction data, including balances and transfer amounts, was not observed reaching advertising networks, and no advertising SDK is present in the app. Biometric identity verification during account setup is processed on the device. Usage and crash data is shared with Firebase Analytics, Mixpanel, Braze, Facebook, and Sentry, with SDK-level opt-out controls for Braze and Singular built into the app.
Quick Verdict
Best for: Everyday global transfers with on-device identity checks
What It Means For You
Financial transaction data, including balances and transfer amounts, was not observed reaching advertising networks, and no advertising SDK is present in the app. Biometric identity verification during account setup is processed on the device. Usage and crash data is shared with Firebase Analytics, Mixpanel, Braze, Facebook, and Sentry, with SDK-level opt-out controls for Braze and Singular built into the app.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
2 totalNetwork Security
1 totalCode Security
2 totalPrivacy
3 totalThird-Party Risk
1 totalPermission Usage
1 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.transferwise.android
Version
9.36.2 (APK manifest: 9.19.3 / versionCode 1622)
Analysis Date
Aug 13, 2026
Classes Analyzed
38,744
Feedback helps us improve our analysis
CITT rates this build Trustworthy (85/100). Authentication data is protected using hardware-backed encryption, and network connection integrity controls cover the app's primary domains. The build includes integrations for fraud detection, analytics, marketing, and crash reporting; completed financial transaction data was not observed flowing to advertising networks in this analysis.
Data Security: 2 findings (2 low)
Network Security: 1 finding (1 low)
Code Safety: 2 findings (2 medium)
Privacy: 5 findings (1 medium, 4 low)
Third parties that may receive data from the app:
Security: 87/100
Privacy: 84/100
Observations about disclosure, each stated against the published guidance so a reader can compare:
Sardine AI not named in the Wise privacy policy
The Wise privacy policy (wise.com/privacy-policy, retrieved August 2026) discloses third-party data sharing in general terms but does not name Sardine AI as a recipient. Build 9.36.2 links the Sardine MDI SDK version 1.2.57, which is configured to submit device signals, including a non-resettable hardware identifier, behavioral touch data, and VPN-detection results, to Sardine AI's servers. Google Play's Data Safety guidelines ask developers to name all third parties that receive user data. Whether the current policy satisfies that requirement is a matter for the reader to compare against the policy text and the Play Store guidelines; CITT makes no compliance determination.
App inventory permission scope
Build 9.36.2 declares a broad installed-app visibility permission used by both the fraud-detection SDK and an internal integrity module. The same manifest already lists over 230 specific package names in targeted query blocks; the developer could evaluate whether those targeted blocks are sufficient for the fraud-detection use case, which would narrow the app's visibility into the installed-app list.
Strengthen Sardine cache storage protection
The Sardine SDK stores its device signal payload using a simple rotation cipher. Upgrading this to a strong storage method would reduce the exposure window on devices with elevated access privileges.
Evaluate payment web display interface scope
The payment web display registers JavaScript interfaces through a runtime delegate pattern, making the full interface surface difficult to audit from static analysis alone. A compile-time registry of permitted interfaces would improve future auditability.
App Type: International money transfer and multi-currency financial services (Finance)
Classes Analyzed: 38,744
Third-Party Services: 18
Context Tags: financial, sensitive_data, location
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of Android applications, intended to help people make informed decisions about app security and privacy.
Developer: Wise Payments Ltd.
Version: 9.36.2 (build 1622)
Analysis Date: 2026-08-13
Package: com.transferwise.android
Developer not yet contacted