Skip to content

Apps

146 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.

  • 80
    out of 100unTRUSTED

    MetService NZ Weather

    Android

    What it means for you

    The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Nielsen, Prebid, and Rubicon for analytics and ad measurement. Precise GPS coordinates are not included in advertising requests. A paid subscription removes advertising tracking exposure, though user data may not be fully protected in all scenarios.

    • 3 findings
    • Network Security 2
    • Code Security 1
  • 49
    out of 100TRUSTish

    Bitwarden Authenticator

    Android

    What it means for you

    Authentication secrets and TOTP codes remain on the device. The build includes Firebase Crashlytics for crash reporting and Firebase Cloud Messaging for push notifications; no advertising or behavioral analytics SDKs are present. Cross-app data access is limited to other Bitwarden apps from the same developer.

    • 3 findings
    • Data Security 1
    • Code Security 2
  • 82
    out of 100unTRUSTED

    bitchat

    Android

    What it means for you

    Message content is end-to-end encrypted and the developer operates no servers that receive it. No user accounts, analytics, or advertising SDKs are present. The Nostr messaging feature is configured to connect to public relay servers (damus.io, primal.net, and others), which handle message relay as part of the open Nostr protocol.

    • 9 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Privacy 2
  • 51
    out of 100unTRUSTED

    Accolade, Inc.

    Android

    What it means for you

    Health records, appointments, and personal data are stored in an encrypted database and are protected from being copied via device backup. Sensitive health screens are blocked from appearing in the device task switcher. Build 334 bundles Firebase, Datadog, AppsFlyer, Segment, Braze, and Branch.io for analytics and crash reporting; Mixpanel integration routes through Accolade's own server.

    • 14 findings
    • Data Security 3
    • Network Security 3
    • Code Security 4
    • Privacy 4
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to pass booking activity and app usage data to Adobe Analytics, Adobe Audience Manager, Adobe Target, Firebase Analytics, Branch, Quantum Metric, and Rokt for analytics and advertising. Login credentials and session tokens are stored with device-level encryption and are excluded from cloud and local backups. The network configuration in the build specifies HTTPS only, with no cleartext connections permitted.

    • 11 findings
    • Data Security 1
    • Code Security 6
    • Privacy 4
  • 50
    out of 100unTRUSTED

    What it means for you

    Location data stays on the device, used only for WiFi network name comparison in the Trusted Networks feature. The app includes code to pass app usage and diagnostic data to Firebase Analytics and Crashlytics. Google Ad Services components are integrated in the build, but the app's configuration prevents linking analytics to the advertising ID.

    • 8 findings
    • Data Security 2
    • Network Security 2
    • Code Security 2
    • Privacy 2
  • 75
    out of 100unTRUSTED

    Kroger

    Android

    What it means for you

    Behavioral analytics code from the app's own system is directed only to Kroger's infrastructure, and the build includes no code to pass it to third parties. Pharmacy and biometric credentials are stored with hardware-backed encryption on the device. The build includes code to pass usage, crash, and device data to Firebase, Adobe Experience, Salesforce Marketing Cloud, and fraud-risk services including ThreatMetrix, Iovation, and Experian Accertify.

    • 12 findings
    • Data Security 2
    • Network Security 1
    • Code Security 6
    • Privacy 1
    • Third-Party Risk 2
  • 72
    out of 100unTRUSTED

    Fly Delta

    Android

    What it means for you

    Passport and boarding pass scanning is processed on the device, and trip itinerary calendar data is stored locally without being shared with Delta servers or third-party platforms. The build includes code to pass usage activity, device signals, and in-app behavior to analytics and performance services including Adobe Analytics, Firebase Analytics, Quantum Metric, and Dynatrace.

    • 7 findings
    • Data Security 1
    • Code Security 4
    • Third-Party Risk 2
  • 44
    out of 100unTRUSTED
    • 13 findings
    • Data Security 2
    • Network Security 3
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 2
  • 67
    out of 100unTRUSTED
    • 12 findings
    • Network Security 2
    • Code Security 7
    • Privacy 3
  • 74
    out of 100unTRUSTED

    What it means for you

    Downloaded audio content is secured with on-device encryption, and app backups are disabled to protect account data. The build includes code to send listening activity and usage data to Firebase Analytics, Conviva, Datadog, Salesforce Marketing Cloud, and Branch.io for analytics and attribution. The build includes code to send advertising data to AdsWizz.

    • 8 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Third-Party Risk 1
  • 85
    out of 100unTRUSTED

    Keeper Password Manager

    Android

    What it means for you

    Passwords, notes, and credentials are stored as ciphertext on the device, with Android backup disabled to block vault data from cloud or device-transfer backups. Payment card scanning is handled on-device with no card data reaching external servers. The build includes code to report app usage to Singular for attribution only; no advertising network SDK is present, and Firebase is limited to push notifications.

    • 8 findings
    • Network Security 2
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 71
    out of 100unTRUSTED

    Temper Staff

    Android

    What it means for you

    AppsFlyer, Mixpanel, and Sentry are gated behind in-app consent and do not load until the user grants permission. When the user consents to Mixpanel, the build includes code to send analytics data to EU-region servers. The build includes code to send usage and device data to Firebase, Intercom, and Salesforce Marketing Cloud as part of the service.

    • 6 findings
    • Data Security 1
    • Network Security 2
    • Code Security 3
  • 73
    out of 100unTRUSTED

    What it means for you

    GPS location data is not passed to analytics or advertising services and remains within the app's own systems. The build includes code to send usage and device data to Firebase, AppsFlyer, CleverTap, Mixpanel, and Facebook for analytics and ad attribution. The build includes code to send Mixpanel data to EU-resident servers.

    • 12 findings
    • Data Security 3
    • Code Security 7
    • Privacy 1
    • Third-Party Risk 1
  • 65
    out of 100unTRUSTED

    Anker eufy

    Android

    What it means for you

    Firebase Analytics and crash reporting are disabled by default, so no usage telemetry leaves the device via those channels. The Sensors Analytics SDK, a Chinese behavioral analytics platform, is integrated into this build. No advertising networks are present, and some user data may not be fully protected.

    • 12 findings
    • Data Security 3
    • Network Security 3
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    Philips Hue

    Android

    What it means for you

    Location data from geofence automations stays on the device and is not forwarded to advertising or analytics services. Bridge login credentials are stored in hardware-protected on-device storage, excluded from cloud and device backups. The build includes code to send usage and crash data to Amplitude, Firebase, Braze, and Sentry.

    • 11 findings
    • Data Security 1
    • Network Security 4
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 85
    out of 100unTRUSTED

    MyBible

    Android

    What it means for you

    Bible reading progress, notes, and history stay on the device and are not accessible to the developer or sold to data brokers. Reading habits are not shared with ad networks. Firebase Analytics and Crashlytics are integrated for performance monitoring.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 41
    out of 100unTRUSTED

    What it means for you

    The build includes code to send app usage and crash data to Firebase Analytics, Firebase Crashlytics, and Google ad measurement services. The build also bundles GeoSurf (Bright Data), a residential proxy network SDK. Whether this configuration routes external traffic through the device's internet connection was not tested. Push notifications are handled by OneSignal.

    • 12 findings
    • Data Security 2
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 2
    • Permission Usage 1
  • 75
    out of 100unTRUSTED

    Wesper

    Android

    What it means for you

    Biometric health data, including sleep metrics and audio recordings, is addressed in code only to Wesper's own servers, and no advertising networks or data brokers are named as destinations. The app is configured to prevent health files from being extracted via device backup. The build includes code to send usage and app performance data to Firebase Analytics and Google services for diagnostics and improvement.

    • 10 findings
    • Data Security 2
    • Code Security 1
    • Privacy 5
    • Third-Party Risk 2
  • 69
    out of 100unTRUSTED

    GoodLeap Home

    Android

    What it means for you

    No advertising network receives data to display targeted ads to users. The build includes code to send usage and activity data to analytics and marketing services including Facebook App Events, RudderStack, Pendo, and Salesforce Marketing Cloud. Some user data may not be fully protected in transit.

    • 13 findings
    • Data Security 3
    • Network Security 1
    • Code Security 5
    • Privacy 3
    • Permission Usage 1
  • 83
    out of 100unTRUSTED

    Reolink

    Android

    What it means for you

    Behavioral telemetry defaults to off and requires explicit opt-in. The code addresses usage data only to Reolink's own systems and names no third-party analytics or advertising networks as destinations. Camera location data is kept on the device and is not transmitted to Reolink servers.

    • 8 findings
    • Data Security 1
    • Network Security 4
    • Code Security 1
    • Privacy 1
    • Permission Usage 1
  • 81
    out of 100unTRUSTED

    Navy Federal Credit Union

    Android

    What it means for you

    The build includes code to send usage data and crash reports to Firebase, Adobe Analytics, Salesforce, and Qualtrics for performance monitoring and feedback. No behavioral advertising SDKs are included, so usage data does not flow to ad platforms. The build includes code to send fraud detection data to Navy Federal's own servers before third-party risk services are involved.

    • 9 findings
    • Data Security 1
    • Network Security 4
    • Code Security 4
  • 86
    out of 100unTRUSTED

    What it means for you

    Firebase Analytics and AppsFlyer are configured to remain inactive until the user explicitly consents, so no analytics or attribution data is generated before that point. Biometric identity verification data is configured to route to Hinge's own servers rather than FaceTec's infrastructure. Firebase, Braze, Sendbird, and related services are integrated in the build for crash reporting, messaging, and performance measurement.

    • 5 findings
    • Code Security 4
    • Third-Party Risk 1
  • 89
    out of 100NOT ASSESSED

    The White House

    Android

    What it means for you

    No advertising networks, attribution trackers, or behavioral analytics infrastructure is present in this build, and no data broker sharing is configured. The build links OneSignal and Firebase Cloud Messaging for push notifications, and Firebase Installations for device registration. Barcode scanning is configured for on-device processing only; authentication credentials are stored locally and excluded from cloud backup.

    • 5 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
  • 88
    out of 100TRUSTish

    Airbnb

    iOS

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Data Security 1
    • Network Security 2
    • Code Security 1
    • Privacy 1
  • 88
    out of 100TRUSTish

    ChatGPT

    iOS

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

  • 76
    out of 100unTRUSTED

    Instagram

    iOS

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Privacy 4
  • 87
    out of 100unTRUSTED

    Bono

    Android

    What it means for you

    Authentication is handled via Google Sign-In, Apple Sign-In, and FIDO2 passkeys. Push notifications are handled through Firebase, and the build includes code to pass a device identifier to Google. The app includes code to send install referral data to Google when the app is first installed.

    • 8 findings
    • Data Security 2
    • Network Security 2
    • Code Security 3
    • Privacy 1
  • 79
    out of 100unTRUSTED

    Glassdoor | Jobs & Careers

    Android

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
  • 65
    out of 100unTRUSTED

    What it means for you

    The build includes code to send in-app interaction and session data to FullStory, Firebase Analytics, and Urban Airship. Financial account connections are managed through Plaid, and identity verification through Onfido. The app also bundles Group-IB fraud detection and Sentry error reporting.

    • 9 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 87
    out of 100unTRUSTED

    Reflect Notes

    iOS

    What it means for you

    Journal and note content is encrypted before syncing to the developer's own Firebase storage. No advertising, attribution, or broad analytics SDKs are present. Error reporting via Sentry is configured to limit behavioral data capture, and the build includes code for authentication through Google Sign-In and Firebase.

    • 3 findings
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 55
    out of 100unTRUSTED

    Hearoes

    Android

    What it means for you

    Hearing training data, exercise progress, game scores, and user profiles are stored in the developer's own Firebase systems and not shared with data brokers or advertising networks. The build includes code to send usage and crash data to Firebase Analytics and Firebase Crashlytics, and purchase activity is handled by RevenueCat. Some data on the device may not be fully protected. All network requests in the code use encrypted connections.

    • 9 findings
    • Data Security 1
    • Code Security 6
    • Privacy 1
    • Permission Usage 1
  • 82
    out of 100unTRUSTED

    What it means for you

    Financial data syncs only to the user's own iCloud container. Receipt scanning and AI-powered features run entirely on the device. The only external service is Setapp, used for subscription management.

    • 4 findings
    • Data Security 2
    • Code Security 1
    • Privacy 1
  • 92
    out of 100unTRUSTED

    Widgetsmith

    iOS

    What it means for you

    Health, calendar, contacts, reminders, and photos data stays on the device and is not transmitted to third parties. Location, when granted for weather widgets, is kept out of advertising and analytics flows. Ad delivery uses Google Mobile Ads with ATT-based consent, and the build includes code to manage subscriptions through RevenueCat and Superwall.

    • 1 finding
    • Code Security 1
  • 88
    out of 100unTRUSTED

    What it means for you

    Trip content, itineraries, and booking details are not shared with advertisers, data brokers, or cross-app tracking systems. AI-assisted features, including email parsing and itinerary suggestions, run entirely on the device. The build includes Mixpanel and Sentry code that reads usage and crash data to support app performance.

    • 3 findings
    • Data Security 1
    • Code Security 2
  • 64
    out of 100unTRUSTED

    MOVAhome

    iOS

    What it means for you

    Widget data is shared only within the developer's own systems, with no third-party access. Login session credentials are stored in the iOS Keychain rather than in plaintext. The build includes code to send usage and device data to analytics and advertising services from ByteDance, Umeng (Alibaba), Baidu, and Facebook.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 6
  • 85
    out of 100unTRUSTED

    WHOOP

    iOS

    What it means for you

    The build includes code to direct health and biometric data, including heart rate, HRV, sleep, and GPS, only to WHOOP's own infrastructure, and contains no code to pass it to advertising or analytics networks. The build includes code to send usage data to Amplitude for product analytics and to Sentry for crash reporting. The build contains no code that reads advertising identifiers, and internal performance telemetry is processed locally; the build contains no code to send it to third-party clo…

    • 5 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
  • 57
    out of 100unTRUSTED

    What it means for you

    Auth tokens and login sessions are encrypted on the device and cannot be extracted, and financial data is blocked from device backup systems. The build includes code to send usage and activity data to Firebase, Amplitude, AppsFlyer, and Facebook for analytics and advertising. Some financial data may not be fully protected across all areas of the app.

    • 8 findings
    • Data Security 1
    • Code Security 3
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 2
  • 66
    out of 100unTRUSTED

    What it means for you

    Financial data and session tokens are protected against extraction through device backup systems, and contacts data stays on the device without being transmitted to external services. The build includes code to send usage, referral, and performance data to Firebase, Branch.io, UserExperior, and Datadog, among others.

    • 11 findings
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 4
  • 78
    out of 100NOT ASSESSED

    WHOOP

    Android

    What it means for you

    Biometric health data, including heart rate, HRV, sleep stages, and blood oxygen levels, is not transmitted to third-party analytics or advertising services. GPS workout routes remain within WHOOP's own systems. The build includes code to send behavioral usage events to Amplitude and Sentry for analytics and error reporting.

    • 7 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
  • 70
    out of 100unTRUSTED

    What it means for you

    The build includes code to send usage patterns and behavioral events to Firebase Analytics, Amplitude, Segment, AppsFlyer, and Facebook. The content of mood entries, journals, and sleep records is not passed to those services. Some stored user data may not be fully protected.

    • 13 findings
    • Data Security 2
    • Code Security 7
    • Privacy 3
    • Third-Party Risk 1
  • 88
    out of 100unTRUSTED

    Kia Access

    Android

    What it means for you

    The build includes code to send usage and vehicle data to Firebase Analytics, Dynatrace, and LexisNexis Risk Solutions. The crash reports the code builds for Firebase Crashlytics include vehicle identifiers such as VIN and license plate numbers alongside the full vehicle record. The build includes code to send navigation activity to Google Maps and HERE Maps. SiriusXM integration handles entertainment connectivity.

    • 13 findings
    • Data Security 3
    • Network Security 4
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    What it means for you

    In the build, login sessions and authentication data are handled by the developer's own systems and the code gives third-party services no access to them. Document scans used for identity verification are processed on the device without being transmitted externally. The build includes code to send usage and behavioral data to Firebase Analytics, Singular, and Sprig for analytics and attribution.

    • 9 findings
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 92
    out of 100TRUSTED

    What it means for you

    Health and workout metrics stay on the device and are not sent to any third-party service. The app includes code to send app usage and session data to Mixpanel for analytics and to Adjust for attribution. Advertising identifier access requires explicit user consent before it can be activated.

  • 76
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 84
    out of 100NOT ASSESSED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 1 finding
    • Code Security 1
  • 75
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 12 findings
    • Network Security 4
    • Code Security 3
    • Privacy 4
    • Permission Usage 1
  • 80
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Data Security 2
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 76
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 84
    out of 100NOT ASSESSED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Network Security 1
    • Code Security 2
    • Privacy 3
    • Third-Party Risk 1
    • Permission Usage 1