Apps
146 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.
- 80out of 100unTRUSTED
MetService NZ Weather
AndroidWhat it means for you
The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Nielsen, Prebid, and Rubicon for analytics and ad measurement. Precise GPS coordinates are not included in advertising requests. A paid subscription removes advertising tracking exposure, though user data may not be fully protected in all scenarios.
- 3 findings
- Network Security 2
- Code Security 1
- 49out of 100TRUSTish
Bitwarden Authenticator
AndroidWhat it means for you
Authentication secrets and TOTP codes remain on the device. The build includes Firebase Crashlytics for crash reporting and Firebase Cloud Messaging for push notifications; no advertising or behavioral analytics SDKs are present. Cross-app data access is limited to other Bitwarden apps from the same developer.
- 3 findings
- Data Security 1
- Code Security 2
- 82out of 100unTRUSTED
bitchat
AndroidWhat it means for you
Message content is end-to-end encrypted and the developer operates no servers that receive it. No user accounts, analytics, or advertising SDKs are present. The Nostr messaging feature is configured to connect to public relay servers (damus.io, primal.net, and others), which handle message relay as part of the open Nostr protocol.
- 9 findings
- Data Security 1
- Network Security 2
- Code Security 4
- Privacy 2
- 51out of 100unTRUSTED
Accolade, Inc.
AndroidWhat it means for you
Health records, appointments, and personal data are stored in an encrypted database and are protected from being copied via device backup. Sensitive health screens are blocked from appearing in the device task switcher. Build 334 bundles Firebase, Datadog, AppsFlyer, Segment, Braze, and Branch.io for analytics and crash reporting; Mixpanel integration routes through Accolade's own server.
- 14 findings
- Data Security 3
- Network Security 3
- Code Security 4
- Privacy 4
- 74out of 100unTRUSTED
What it means for you
The app includes code to pass booking activity and app usage data to Adobe Analytics, Adobe Audience Manager, Adobe Target, Firebase Analytics, Branch, Quantum Metric, and Rokt for analytics and advertising. Login credentials and session tokens are stored with device-level encryption and are excluded from cloud and local backups. The network configuration in the build specifies HTTPS only, with no cleartext connections permitted.
- 11 findings
- Data Security 1
- Code Security 6
- Privacy 4
- 50out of 100unTRUSTED
What it means for you
Location data stays on the device, used only for WiFi network name comparison in the Trusted Networks feature. The app includes code to pass app usage and diagnostic data to Firebase Analytics and Crashlytics. Google Ad Services components are integrated in the build, but the app's configuration prevents linking analytics to the advertising ID.
- 8 findings
- Data Security 2
- Network Security 2
- Code Security 2
- Privacy 2
- 75out of 100unTRUSTED
Kroger
AndroidWhat it means for you
Behavioral analytics code from the app's own system is directed only to Kroger's infrastructure, and the build includes no code to pass it to third parties. Pharmacy and biometric credentials are stored with hardware-backed encryption on the device. The build includes code to pass usage, crash, and device data to Firebase, Adobe Experience, Salesforce Marketing Cloud, and fraud-risk services including ThreatMetrix, Iovation, and Experian Accertify.
- 12 findings
- Data Security 2
- Network Security 1
- Code Security 6
- Privacy 1
- Third-Party Risk 2
- 72out of 100unTRUSTED
Fly Delta
AndroidWhat it means for you
Passport and boarding pass scanning is processed on the device, and trip itinerary calendar data is stored locally without being shared with Delta servers or third-party platforms. The build includes code to pass usage activity, device signals, and in-app behavior to analytics and performance services including Adobe Analytics, Firebase Analytics, Quantum Metric, and Dynatrace.
- 7 findings
- Data Security 1
- Code Security 4
- Third-Party Risk 2
- 44out of 100unTRUSTED
- 13 findings
- Data Security 2
- Network Security 3
- Code Security 5
- Privacy 1
- Third-Party Risk 2
- 67out of 100unTRUSTED
- 12 findings
- Network Security 2
- Code Security 7
- Privacy 3
- 74out of 100unTRUSTED
What it means for you
Downloaded audio content is secured with on-device encryption, and app backups are disabled to protect account data. The build includes code to send listening activity and usage data to Firebase Analytics, Conviva, Datadog, Salesforce Marketing Cloud, and Branch.io for analytics and attribution. The build includes code to send advertising data to AdsWizz.
- 8 findings
- Data Security 1
- Network Security 2
- Code Security 4
- Third-Party Risk 1
- 85out of 100unTRUSTED
Keeper Password Manager
AndroidWhat it means for you
Passwords, notes, and credentials are stored as ciphertext on the device, with Android backup disabled to block vault data from cloud or device-transfer backups. Payment card scanning is handled on-device with no card data reaching external servers. The build includes code to report app usage to Singular for attribution only; no advertising network SDK is present, and Firebase is limited to push notifications.
- 8 findings
- Network Security 2
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 71out of 100unTRUSTED
Temper Staff
AndroidWhat it means for you
AppsFlyer, Mixpanel, and Sentry are gated behind in-app consent and do not load until the user grants permission. When the user consents to Mixpanel, the build includes code to send analytics data to EU-region servers. The build includes code to send usage and device data to Firebase, Intercom, and Salesforce Marketing Cloud as part of the service.
- 6 findings
- Data Security 1
- Network Security 2
- Code Security 3
- 73out of 100unTRUSTED
What it means for you
GPS location data is not passed to analytics or advertising services and remains within the app's own systems. The build includes code to send usage and device data to Firebase, AppsFlyer, CleverTap, Mixpanel, and Facebook for analytics and ad attribution. The build includes code to send Mixpanel data to EU-resident servers.
- 12 findings
- Data Security 3
- Code Security 7
- Privacy 1
- Third-Party Risk 1
- 65out of 100unTRUSTED
Anker eufy
AndroidWhat it means for you
Firebase Analytics and crash reporting are disabled by default, so no usage telemetry leaves the device via those channels. The Sensors Analytics SDK, a Chinese behavioral analytics platform, is integrated into this build. No advertising networks are present, and some user data may not be fully protected.
- 12 findings
- Data Security 3
- Network Security 3
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 82out of 100unTRUSTED
Philips Hue
AndroidWhat it means for you
Location data from geofence automations stays on the device and is not forwarded to advertising or analytics services. Bridge login credentials are stored in hardware-protected on-device storage, excluded from cloud and device backups. The build includes code to send usage and crash data to Amplitude, Firebase, Braze, and Sentry.
- 11 findings
- Data Security 1
- Network Security 4
- Code Security 3
- Privacy 2
- Third-Party Risk 1
- 85out of 100unTRUSTED
MyBible
AndroidWhat it means for you
Bible reading progress, notes, and history stay on the device and are not accessible to the developer or sold to data brokers. Reading habits are not shared with ad networks. Firebase Analytics and Crashlytics are integrated for performance monitoring.
- 4 findings
- Data Security 1
- Network Security 1
- Code Security 1
- Privacy 1
- 41out of 100unTRUSTED
What it means for you
The build includes code to send app usage and crash data to Firebase Analytics, Firebase Crashlytics, and Google ad measurement services. The build also bundles GeoSurf (Bright Data), a residential proxy network SDK. Whether this configuration routes external traffic through the device's internet connection was not tested. Push notifications are handled by OneSignal.
- 12 findings
- Data Security 2
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 2
- Permission Usage 1
- 75out of 100unTRUSTED
Wesper
AndroidWhat it means for you
Biometric health data, including sleep metrics and audio recordings, is addressed in code only to Wesper's own servers, and no advertising networks or data brokers are named as destinations. The app is configured to prevent health files from being extracted via device backup. The build includes code to send usage and app performance data to Firebase Analytics and Google services for diagnostics and improvement.
- 10 findings
- Data Security 2
- Code Security 1
- Privacy 5
- Third-Party Risk 2
- 69out of 100unTRUSTED
GoodLeap Home
AndroidWhat it means for you
No advertising network receives data to display targeted ads to users. The build includes code to send usage and activity data to analytics and marketing services including Facebook App Events, RudderStack, Pendo, and Salesforce Marketing Cloud. Some user data may not be fully protected in transit.
- 13 findings
- Data Security 3
- Network Security 1
- Code Security 5
- Privacy 3
- Permission Usage 1
- 83out of 100unTRUSTED
Reolink
AndroidWhat it means for you
Behavioral telemetry defaults to off and requires explicit opt-in. The code addresses usage data only to Reolink's own systems and names no third-party analytics or advertising networks as destinations. Camera location data is kept on the device and is not transmitted to Reolink servers.
- 8 findings
- Data Security 1
- Network Security 4
- Code Security 1
- Privacy 1
- Permission Usage 1
- 81out of 100unTRUSTED
Navy Federal Credit Union
AndroidWhat it means for you
The build includes code to send usage data and crash reports to Firebase, Adobe Analytics, Salesforce, and Qualtrics for performance monitoring and feedback. No behavioral advertising SDKs are included, so usage data does not flow to ad platforms. The build includes code to send fraud detection data to Navy Federal's own servers before third-party risk services are involved.
- 9 findings
- Data Security 1
- Network Security 4
- Code Security 4
- 86out of 100unTRUSTED
What it means for you
Firebase Analytics and AppsFlyer are configured to remain inactive until the user explicitly consents, so no analytics or attribution data is generated before that point. Biometric identity verification data is configured to route to Hinge's own servers rather than FaceTec's infrastructure. Firebase, Braze, Sendbird, and related services are integrated in the build for crash reporting, messaging, and performance measurement.
- 5 findings
- Code Security 4
- Third-Party Risk 1
- 89out of 100NOT ASSESSED
The White House
AndroidWhat it means for you
No advertising networks, attribution trackers, or behavioral analytics infrastructure is present in this build, and no data broker sharing is configured. The build links OneSignal and Firebase Cloud Messaging for push notifications, and Firebase Installations for device registration. Barcode scanning is configured for on-device processing only; authentication credentials are stored locally and excluded from cloud backup.
- 5 findings
- Data Security 1
- Network Security 1
- Code Security 3
- 88out of 100TRUSTish
Airbnb
iOSWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 5 findings
- Data Security 1
- Network Security 2
- Code Security 1
- Privacy 1
- 88out of 100TRUSTish
ChatGPT
iOSWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 76out of 100unTRUSTED
Instagram
iOSWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 2
- Privacy 4
- 87out of 100unTRUSTED
Bono
AndroidWhat it means for you
Authentication is handled via Google Sign-In, Apple Sign-In, and FIDO2 passkeys. Push notifications are handled through Firebase, and the build includes code to pass a device identifier to Google. The app includes code to send install referral data to Google when the app is first installed.
- 8 findings
- Data Security 2
- Network Security 2
- Code Security 3
- Privacy 1
- 79out of 100unTRUSTED
Glassdoor | Jobs & Careers
AndroidWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 5 findings
- Network Security 2
- Code Security 2
- Privacy 1
- 65out of 100unTRUSTED
Expensify - Travel & Expense
AndroidWhat it means for you
The build includes code to send in-app interaction and session data to FullStory, Firebase Analytics, and Urban Airship. Financial account connections are managed through Plaid, and identity verification through Onfido. The app also bundles Group-IB fraud detection and Sentry error reporting.
- 9 findings
- Data Security 1
- Network Security 2
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 87out of 100unTRUSTED
What it means for you
Journal and note content is encrypted before syncing to the developer's own Firebase storage. No advertising, attribution, or broad analytics SDKs are present. Error reporting via Sentry is configured to limit behavioral data capture, and the build includes code for authentication through Google Sign-In and Firebase.
- 3 findings
- Network Security 1
- Code Security 1
- Privacy 1
- 55out of 100unTRUSTED
Hearoes
AndroidWhat it means for you
Hearing training data, exercise progress, game scores, and user profiles are stored in the developer's own Firebase systems and not shared with data brokers or advertising networks. The build includes code to send usage and crash data to Firebase Analytics and Firebase Crashlytics, and purchase activity is handled by RevenueCat. Some data on the device may not be fully protected. All network requests in the code use encrypted connections.
- 9 findings
- Data Security 1
- Code Security 6
- Privacy 1
- Permission Usage 1
- 82out of 100unTRUSTED
What it means for you
Financial data syncs only to the user's own iCloud container. Receipt scanning and AI-powered features run entirely on the device. The only external service is Setapp, used for subscription management.
- 4 findings
- Data Security 2
- Code Security 1
- Privacy 1
- 92out of 100unTRUSTED
Widgetsmith
iOSWhat it means for you
Health, calendar, contacts, reminders, and photos data stays on the device and is not transmitted to third parties. Location, when granted for weather widgets, is kept out of advertising and analytics flows. Ad delivery uses Google Mobile Ads with ATT-based consent, and the build includes code to manage subscriptions through RevenueCat and Superwall.
- 1 finding
- Code Security 1
- 88out of 100unTRUSTED
What it means for you
Trip content, itineraries, and booking details are not shared with advertisers, data brokers, or cross-app tracking systems. AI-assisted features, including email parsing and itinerary suggestions, run entirely on the device. The build includes Mixpanel and Sentry code that reads usage and crash data to support app performance.
- 3 findings
- Data Security 1
- Code Security 2
- 64out of 100unTRUSTED
MOVAhome
iOSWhat it means for you
Widget data is shared only within the developer's own systems, with no third-party access. Login session credentials are stored in the iOS Keychain rather than in plaintext. The build includes code to send usage and device data to analytics and advertising services from ByteDance, Umeng (Alibaba), Baidu, and Facebook.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 6
- 85out of 100unTRUSTED
WHOOP
iOSWhat it means for you
The build includes code to direct health and biometric data, including heart rate, HRV, sleep, and GPS, only to WHOOP's own infrastructure, and contains no code to pass it to advertising or analytics networks. The build includes code to send usage data to Amplitude for product analytics and to Sentry for crash reporting. The build contains no code that reads advertising identifiers, and internal performance telemetry is processed locally; the build contains no code to send it to third-party clo…
- 5 findings
- Data Security 1
- Network Security 1
- Code Security 3
- 57out of 100unTRUSTED
Kikoff: Build Credit Quickly
AndroidWhat it means for you
Auth tokens and login sessions are encrypted on the device and cannot be extracted, and financial data is blocked from device backup systems. The build includes code to send usage and activity data to Firebase, Amplitude, AppsFlyer, and Facebook for analytics and advertising. Some financial data may not be fully protected across all areas of the app.
- 8 findings
- Data Security 1
- Code Security 3
- Privacy 1
- Third-Party Risk 1
- Permission Usage 2
- 66out of 100unTRUSTED
What it means for you
Financial data and session tokens are protected against extraction through device backup systems, and contacts data stays on the device without being transmitted to external services. The build includes code to send usage, referral, and performance data to Firebase, Branch.io, UserExperior, and Datadog, among others.
- 11 findings
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 4
- 78out of 100NOT ASSESSED
WHOOP
AndroidWhat it means for you
Biometric health data, including heart rate, HRV, sleep stages, and blood oxygen levels, is not transmitted to third-party analytics or advertising services. GPS workout routes remain within WHOOP's own systems. The build includes code to send behavioral usage events to Amplitude and Sentry for analytics and error reporting.
- 7 findings
- Data Security 1
- Network Security 2
- Code Security 2
- Privacy 1
- Third-Party Risk 1
- 70out of 100unTRUSTED
What it means for you
The build includes code to send usage patterns and behavioral events to Firebase Analytics, Amplitude, Segment, AppsFlyer, and Facebook. The content of mood entries, journals, and sleep records is not passed to those services. Some stored user data may not be fully protected.
- 13 findings
- Data Security 2
- Code Security 7
- Privacy 3
- Third-Party Risk 1
- 88out of 100unTRUSTED
Kia Access
AndroidWhat it means for you
The build includes code to send usage and vehicle data to Firebase Analytics, Dynatrace, and LexisNexis Risk Solutions. The crash reports the code builds for Firebase Crashlytics include vehicle identifiers such as VIN and license plate numbers alongside the full vehicle record. The build includes code to send navigation activity to Google Maps and HERE Maps. SiriusXM integration handles entertainment connectivity.
- 13 findings
- Data Security 3
- Network Security 4
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 82out of 100unTRUSTED
Trump Accounts: Official App
AndroidWhat it means for you
In the build, login sessions and authentication data are handled by the developer's own systems and the code gives third-party services no access to them. Document scans used for identity verification are processed on the device without being transmitted externally. The build includes code to send usage and behavioral data to Firebase Analytics, Singular, and Sprig for analytics and attribution.
- 9 findings
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 1
- Permission Usage 1
- 92out of 100TRUSTED
What it means for you
Health and workout metrics stay on the device and are not sent to any third-party service. The app includes code to send app usage and session data to Mixpanel for analytics and to Adjust for attribution. Advertising identifier access requires explicit user consent before it can be activated.
- 76out of 100unTRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 4 findings
- Data Security 1
- Network Security 1
- Code Security 1
- Privacy 1
- 84out of 100NOT ASSESSED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 1 finding
- Code Security 1
- 75out of 100unTRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 12 findings
- Network Security 4
- Code Security 3
- Privacy 4
- Permission Usage 1
- 80out of 100unTRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 5 findings
- Data Security 2
- Network Security 1
- Code Security 1
- Privacy 1
- 76out of 100unTRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 3
- Privacy 2
- Third-Party Risk 1
- 84out of 100NOT ASSESSED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 8 findings
- Network Security 1
- Code Security 2
- Privacy 3
- Third-Party Risk 1
- Permission Usage 1