Skip to content

Apps

146 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.

  • 89
    out of 100TRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 4 findings
    • Data Security 1
    • Code Security 3
  • 66
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 10 findings
    • Data Security 1
    • Code Security 4
    • Privacy 3
    • Third-Party Risk 2
  • 92
    out of 100TRUSTish

    Session - Private Messenger

    Android

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
  • 92
    out of 100TRUSTish

    Proton Authenticator & 2FA

    Android

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 2 findings
    • Data Security 1
    • Code Security 1
  • 95
    out of 100TRUSTED

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 3 findings
    • Data Security 1
    • Code Security 2
  • 96
    out of 100TRUSTED

    Google Authenticator

    Android

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 3 findings
    • Code Security 2
    • Privacy 1
  • 92
    out of 100NOT ASSESSED

    Drop Authenticator

    Android

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 3 findings
    • Data Security 2
    • Code Security 1
  • 98
    out of 100TRUSTED

    Wikipedia

    iOS

    What it means for you

    App usage is tracked only by Wikipedia's own first-party analytics, with consent collected at onboarding. Donation payments are processed through Adyen and Apple Pay. The build includes no code to send user data to advertising networks, behavioral tracking companies, or third-party analytics services.

    • 1 finding
    • Code Security 1
  • 82
    out of 100NOT ASSESSED

    What it means for you

    The build includes code to pass gaming activity and device identifiers to over a dozen advertising networks including Facebook, AppLovin, Google AdMob, Unity Ads, and Chartboost. The build includes code to pass analytics data through Firebase and Unity to monitor in-app behavior. Singular handles install attribution across these ad partners.

    • 3 findings
    • Network Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 72
    out of 100unTRUSTED

    cred.ai

    iOS

    What it means for you

    Financial account connections via Plaid, document scans, and biometric checks are processed as part of identity verification. The app includes code to pass app usage and attribution data to AppsFlyer, Segment, and Google Tag Manager. The app includes code to pass fraud detection signals to TransUnion. User financial data may not be fully protected in all storage scenarios.

    • 11 findings
    • Data Security 5
    • Network Security 1
    • Code Security 3
    • Privacy 2
  • 88
    out of 100NOT ASSESSED

    What it means for you

    The app includes code to pass app usage data, including session behavior and feature interactions, to Firebase Analytics, Amplitude Analytics, and Google App Measurement. When the user consents via Apple's App Tracking Transparency prompt, the build includes code to pass attribution data to Adjust and Facebook SDK to measure ad campaigns. OneSignal handles push notifications, and the app includes code to pass subscription and paywall activity to RevenueCat and Superwall.

    • 6 findings
    • Data Security 1
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 2
  • 89
    out of 100NOT ASSESSED

    What it means for you

    The build includes the TelemetryDeck and Sentry SDKs, whose code reads app usage and crash data, both operating under GDPR-compliant terms with EU data residency and no personal identifiers. No advertising networks, behavioral trackers, or device fingerprinting tools are present. Health-related data is processed on-device only and not transmitted to external servers.

    • 7 findings
    • Data Security 2
    • Code Security 3
    • Privacy 2
  • 98
    out of 100TRUSTED

    What it means for you

    Signal stores messages, voice and video calls, and contact data on-device. The build includes no code to send user data to analytics, advertising, attribution, or crash-reporting services. Third-party libraries are limited to UI components (SDWebImage, Lottie, BonMot) and data utilities (SwiftProtobuf, GRDB, libPhoneNumber_iOS). MobileCoin handles optional peer-to-peer payments.

    • 3 findings
    • Data Security 1
    • Network Security 1
    • Permission Usage 1
  • 99
    out of 100TRUSTED

    Brotherhood Alchemist

    iOS

    What it means for you

    All gameplay activity remains on the device. No data is transmitted over the network, and no user information is retained after a session ends. UIDevice access is limited to detecting screen orientation for layout purposes.

    • 1 finding
    • Privacy 1
  • 86
    out of 100NOT ASSESSED

    Jenius

    iOS

    What it means for you

    The build includes code to pass usage and behavioral data to AppsFlyer, Google Analytics, MoEngage, and Firebase for analytics, attribution, and messaging. The build also includes code to pass transaction and device activity to NewRelic for performance monitoring. Identity verification is handled via ZOLOZ KYC, and three specialized services monitor for fraud.

    • 13 findings
    • Data Security 4
    • Network Security 2
    • Code Security 4
    • Privacy 2
    • Third-Party Risk 1
  • 94
    out of 100TRUSTED

    What it means for you

    Ente Auth stores two-factor authentication secrets locally with strong encryption, excluded from iCloud backups by default. The app includes code to send crash reports to Sentry, with code that strips authentication tokens and cookies from them first. The build includes no code to send user data to advertising, analytics, or attribution services.

    • 0 findings
  • 97
    out of 100unTRUSTED

    SUUUUUU

    Android

    What it means for you

    The build includes code to authenticate users through Google Sign-In, Apple Sign-In, and SmartAuth, a third-party phone verification service. The app includes code to send app usage data to Firebase Analytics, and code to store user content in Google's Firestore cloud database. Push notification delivery is handled by Firebase Cloud Messaging.

    • 1 finding
    • Code Security 1
  • 86
    out of 100NOT ASSESSED

    What it means for you

    Analytics collection is permanently disabled in this build. Active Firebase components for push notifications and performance monitoring include code to send functional data to Google. Behavioral and usage data processed by the Synerise CRM module remains on mBank-controlled servers and requires explicit GDPR consent.

    • 4 findings
    • Data Security 1
    • Code Security 1
    • Privacy 2
  • 89
    out of 100NOT ASSESSED

    mBank SK

    Android

    What it means for you

    The build includes code to pass performance and push notification data to Firebase, which has Analytics explicitly disabled, limiting telemetry to delivery and performance metrics. The Synerise customer engagement platform is named in code as the destination of behavioral data used to personalize the user experience. Biometric authentication uses the FaceTec face recognition SDK for identity verification.

    • 6 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Third-Party Risk 1
    • Permission Usage 1
  • 85
    out of 100NOT ASSESSED

    mBank CZ

    Android

    What it means for you

    The build includes code to pass behavioral and CRM data through the Synerise SDK to mBank-controlled servers, keeping it within the bank's own infrastructure. Firebase Analytics collection is explicitly disabled. The build includes code to pass install and referral data to Google via AdServices and Play Install Referrer. Stored account data remains on-device with strong protections in place.

    • 7 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 85
    out of 100NOT ASSESSED

    Fio Smartbanking CZ

    Android

    What it means for you

    No analytics, advertising, or behavioral tracking SDKs are present. Firebase is used only for push notifications, with analytics explicitly disabled. User data stays on device, and bank servers are the only destination named in code, with no code to send it to third parties detected.

    • 4 findings
    • Data Security 3
    • Code Security 1
  • 93
    out of 100NOT ASSESSED

    George Romania

    Android

    What it means for you

    The build includes code to send analytics data to BCR's own infrastructure rather than directly to third-party companies, limiting external data exposure. Sentry, PostHog, and LUX telemetry are all proxied server-side. Firebase analytics collection is disabled by default.

    • 8 findings
    • Data Security 2
    • Network Security 1
    • Code Security 4
    • Third-Party Risk 1
  • 83
    out of 100unTRUSTED

    George Česko

    Android

    What it means for you

    The app includes code to send app usage and analytics data to PostHog, Sentry, and Dynatrace for behavioral analytics, crash reporting, and performance monitoring. Firebase is used only for push notifications, not for analytics tracking. The build includes the ThreatMark and Innovatrics SDKs, whose code reads device security signals for fraud protection. Some user data may not be fully protected in all scenarios.

    • 7 findings
    • Data Security 2
    • Network Security 1
    • Code Security 1
    • Privacy 1
    • Third-Party Risk 2
  • 69
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app usage and crash data to Firebase Analytics, Crashlytics, and Sentry. The app includes code to send purchase and subscription activity to RevenueCat. Users can optionally sync financial records to Dropbox or Google Drive. Stored financial data may not be fully protected on device.

    • 7 findings
    • Data Security 3
    • Code Security 1
    • Privacy 2
    • Third-Party Risk 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage data and session activity to Firebase Analytics. The app includes code to read an advertising identifier and pass it to Google's ad attribution services. Locally stored financial data may not be fully protected, which is worth considering if the device could be accessed by others.

    • 2 findings
    • Data Security 1
    • Privacy 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage and event data to Firebase Analytics, Facebook SDK, Amplitude, and Tenjin for analytics and attribution. The app includes code for financial transactions through Stripe and Plaid. Location data may be collected in the background via a geolocation service. Receipt images are processed on-device and not sent to the cloud.

    • 14 findings
    • Data Security 2
    • Network Security 2
    • Code Security 4
    • Privacy 3
    • Third-Party Risk 1
    • Permission Usage 2
  • 84
    out of 100unTRUSTED

    Money manager & expenses

    Android

    What it means for you

    The build includes the AppMetrica (Yandex), Facebook, and VK SDKs, whose code reads app usage data for analytics. Ads are served through Google AdMob and Yandex Mobile Ads. Locally stored data is well protected, though the app includes code that may send some app data with less protection than expected on certain connections.

    • 6 findings
    • Data Security 3
    • Network Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage and crash data to Firebase Analytics and Crashlytics, and the Facebook SDK is present, whose code may send behavioral data to Meta. Financial data entered by the user is stored via Firebase cloud services. Permission access to device features beyond core tracking needs has been identified.

    • 6 findings
    • Data Security 2
    • Code Security 1
    • Third-Party Risk 2
    • Permission Usage 1
  • 72
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app activity to six advertising networks, including Facebook Audience Network, AppLovin, and Google AdMob, alongside Firebase Analytics. Usage patterns and in-app behavior may inform ad targeting across these networks. Some locally stored data may not be fully protected.

    • 12 findings
    • Data Security 4
    • Network Security 2
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 88
    out of 100TRUSTish

    What it means for you

    Financial data is stored locally on the device, and no developer-owned server is named in code as a destination for it. The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. For users who consent to ads, the app includes code to send ad interaction data to Google AdMob; premium subscribers bypass ads entirely.

    • 1 finding
    • Data Security 1
  • 84
    out of 100NOT ASSESSED

    Spending Tracker

    Android

    What it means for you

    The build includes the Firebase and Microsoft App Center SDKs, whose code reads usage and crash data. Ads are served via Google AdMob with a consent layer that defaults to non-personalised ads. Financial data stays on-device and is not backed up to cloud services automatically.

    • 3 findings
    • Data Security 2
    • Network Security 1
  • 80
    out of 100TRUSTish
    • 3 findings
    • Data Security 2
    • Code Security 1
  • 92
    out of 100TRUSTish

    What it means for you

    Financial transactions and budget data are stored in Firebase and optionally synced via Dropbox. Analytics and crash reporting through Firebase are disabled until the user explicitly consents, and ad networks (Google AdMob, Facebook Audience Network) are never activated for paying subscribers. Users who connect bank accounts do so through Salt Edge, a third-party financial data aggregation service.

    • 3 findings
    • Data Security 1
    • Code Security 1
    • Third-Party Risk 1
  • 80
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app usage and behavioral data to Braze and AppsFlyer for marketing and attribution purposes. Bank account connectivity is handled through Plaid and Mastercard Open Banking. The app includes code to send crash reports to Bugsnag, and Optimizely runs A/B tests on user interactions within the app.

    • 5 findings
    • Data Security 1
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
  • 75
    out of 100NOT ASSESSED

    What it means for you

    The build includes code to send usage and behavioral data to multiple advertising networks, including Facebook Audience Network, AppLovin, Vungle, and Yandex Mobile Ads, for targeted advertising. The build also includes code to send analytics to Firebase Analytics and Yandex AppMetrica, a Russian analytics provider. All backend communication uses HTTPS, and Google Drive backup is gated behind explicit user consent.

    • 10 findings
    • Data Security 5
    • Network Security 1
    • Code Security 2
    • Third-Party Risk 2
  • 73
    out of 100unTRUSTED

    Mój Orange

    Android

    What it means for you

    The app includes code to send app usage and behavioral data to AppsFlyer, Firebase Analytics, Synerise, QuantumMetric, and Google Tag Manager for analytics, CRM, and marketing purposes. Session interactions within the app are recorded by QuantumMetric for behavioral analysis. Some code may send network activity with less protection than expected on public Wi-Fi.

    • 7 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 2
  • 84
    out of 100unTRUSTED

    My Orange Moldova

    Android

    What it means for you

    The build includes the Firebase Analytics and Batch SDKs, whose code reads app usage data for usage insights and push notifications, with analytics requiring explicit user consent before activation. Identity verification flows rely on AriadNext IDcheckio and Unissey, which may process document or biometric data. Some user data may not be fully protected in all transmission scenarios.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 79
    out of 100TRUSTish

    IBKR Mobile

    Android

    What it means for you

    The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. Financial document processing via MiSnap and QR scanning via ML Kit are handled on-device without sending image data externally. One data storage concern was identified where user data may not be fully protected at rest.

    • 7 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 2
  • 75
    out of 100NOT ASSESSED

    EVO

    Android

    What it means for you

    The build includes Firebase Analytics and Crashlytics, whose code reads app usage statistics and crash reports. Google Ad Services is also present alongside these tools. One data storage concern means some user data may not be fully protected, though authentication credentials are encrypted and the app prevents backup access to sensitive data.

    • 8 findings
    • Data Security 3
    • Network Security 2
    • Code Security 3
  • 75
    out of 100unTRUSTED

    My Vodafone Romania

    Android

    What it means for you

    The app includes code to send app usage and account activity to Firebase Analytics, Adjust, Facebook, Tealium, Huawei HiAnalytics, Medallia, and Urban Airship for analytics, marketing attribution, and push messaging. Some code may send activity with less protection than expected on certain network paths. Account authentication uses hardware-backed key storage on the device.

    • 8 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 64
    out of 100unTRUSTED

    my moldcell

    Android

    What it means for you

    The app includes code to send account and usage data to Firebase Analytics, Facebook, and Google Ad Services for analytics and advertising purposes. Some code may send activity with less protection than expected on some network connections. An EVAM SDK also includes code to route data to a third-party provider outside major platform ecosystems.

    • 10 findings
    • Data Security 3
    • Network Security 2
    • Code Security 2
    • Third-Party Risk 2
    • Permission Usage 1
  • 95
    out of 100TRUSTED

    Proton Drive: Cloud Storage

    Android

    What it means for you

    File content, names, sizes, and metadata are end-to-end encrypted, meaning Proton cannot read stored files. The app includes code to send crash diagnostics to Sentry using a random identifier that cannot be linked to a Proton account. The build includes no code to send data from normal use to advertising, analytics, or attribution companies.

    • 3 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
  • 91
    out of 100NOT ASSESSED

    SAP Analytics Cloud

    Android

    What it means for you

    The app includes code to exchange data with the user's organization SAP backend over HTTPS. Firebase Installations registers a device identifier with Google as part of app setup. Enterprise usage telemetry is collected only when enabled by an organization administrator and requires a consent screen before activation.

    • 4 findings
    • Data Security 3
    • Code Security 1
  • 91
    out of 100unTRUSTED

    SAP for Me

    Android

    What it means for you

    The app includes code to send usage and interaction data to Firebase Analytics and Adobe Experience Platform for performance tracking, and to Qualtrics for optional in-app surveys. TrustArc consent management controls whether Adobe analytics tracking is active based on user preferences. Locally stored data is protected, and all traffic to company systems uses secure connections.

    • 6 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Privacy 2
  • 92
    out of 100NOT ASSESSED

    Lumo by Proton

    Android

    What it means for you

    The app includes code to send crash reports to Proton's own GDPR-governed servers, not to external analytics companies. On-device speech processing via Vosk means audio never leaves the device. Google Play services handle billing and app delivery, with no third-party advertising, analytics, or behavioral tracking SDKs present.

    • 3 findings
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 58
    out of 100unTRUSTED

    What it means for you

    In-app behavior, including taps and screen interactions, is recorded by FullStory and Heap Analytics. The build includes code to send user activity to Salesforce Marketing Cloud for targeted messaging and to Firebase for performance tracking. The build includes multiple third-party SDKs whose code observes financial account interactions.

    • 7 findings
    • Data Security 2
    • Code Security 2
    • Privacy 3