Apps
106 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.
- 41out of 100unTRUSTED
What it means for you
The build includes code to send app usage and crash data to Firebase Analytics, Firebase Crashlytics, and Google ad measurement services. The build also bundles GeoSurf (Bright Data), a residential proxy network SDK. Whether this configuration routes external traffic through the device's internet connection was not tested. Push notifications are handled by OneSignal.
- 12 findings
- Data Security 2
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 2
- Permission Usage 1
- 75out of 100unTRUSTED
Wesper
AndroidWhat it means for you
Biometric health data, including sleep metrics and audio recordings, is addressed in code only to Wesper's own servers, and no advertising networks or data brokers are named as destinations. The app is configured to prevent health files from being extracted via device backup. The build includes code to send usage and app performance data to Firebase Analytics and Google services for diagnostics and improvement.
- 10 findings
- Data Security 2
- Code Security 1
- Privacy 5
- Third-Party Risk 2
- 69out of 100unTRUSTED
GoodLeap Home
AndroidWhat it means for you
No advertising network receives data to display targeted ads to users. The build includes code to send usage and activity data to analytics and marketing services including Facebook App Events, RudderStack, Pendo, and Salesforce Marketing Cloud. Some user data may not be fully protected in transit.
- 13 findings
- Data Security 3
- Network Security 1
- Code Security 5
- Privacy 3
- Permission Usage 1
- 83out of 100unTRUSTED
Reolink
AndroidWhat it means for you
Behavioral telemetry defaults to off and requires explicit opt-in. The code addresses usage data only to Reolink's own systems and names no third-party analytics or advertising networks as destinations. Camera location data is kept on the device and is not transmitted to Reolink servers.
- 8 findings
- Data Security 1
- Network Security 4
- Code Security 1
- Privacy 1
- Permission Usage 1
- 81out of 100unTRUSTED
Navy Federal Credit Union
AndroidWhat it means for you
The build includes code to send usage data and crash reports to Firebase, Adobe Analytics, Salesforce, and Qualtrics for performance monitoring and feedback. No behavioral advertising SDKs are included, so usage data does not flow to ad platforms. The build includes code to send fraud detection data to Navy Federal's own servers before third-party risk services are involved.
- 9 findings
- Data Security 1
- Network Security 4
- Code Security 4
- 86out of 100unTRUSTED
What it means for you
Firebase Analytics and AppsFlyer are configured to remain inactive until the user explicitly consents, so no analytics or attribution data is generated before that point. Biometric identity verification data is configured to route to Hinge's own servers rather than FaceTec's infrastructure. Firebase, Braze, Sendbird, and related services are integrated in the build for crash reporting, messaging, and performance measurement.
- 5 findings
- Code Security 4
- Third-Party Risk 1
- 89out of 100NOT ASSESSED
The White House
AndroidWhat it means for you
No advertising networks, attribution trackers, or behavioral analytics infrastructure is present in this build, and no data broker sharing is configured. The build links OneSignal and Firebase Cloud Messaging for push notifications, and Firebase Installations for device registration. Barcode scanning is configured for on-device processing only; authentication credentials are stored locally and excluded from cloud backup.
- 5 findings
- Data Security 1
- Network Security 1
- Code Security 3
- 87out of 100unTRUSTED
Bono
AndroidWhat it means for you
Authentication is handled via Google Sign-In, Apple Sign-In, and FIDO2 passkeys. Push notifications are handled through Firebase, and the build includes code to pass a device identifier to Google. The app includes code to send install referral data to Google when the app is first installed.
- 8 findings
- Data Security 2
- Network Security 2
- Code Security 3
- Privacy 1
- 79out of 100unTRUSTED
Glassdoor | Jobs & Careers
AndroidWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 5 findings
- Network Security 2
- Code Security 2
- Privacy 1
- 65out of 100unTRUSTED
Expensify - Travel & Expense
AndroidWhat it means for you
The build includes code to send in-app interaction and session data to FullStory, Firebase Analytics, and Urban Airship. Financial account connections are managed through Plaid, and identity verification through Onfido. The app also bundles Group-IB fraud detection and Sentry error reporting.
- 9 findings
- Data Security 1
- Network Security 2
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 55out of 100unTRUSTED
Hearoes
AndroidWhat it means for you
Hearing training data, exercise progress, game scores, and user profiles are stored in the developer's own Firebase systems and not shared with data brokers or advertising networks. The build includes code to send usage and crash data to Firebase Analytics and Firebase Crashlytics, and purchase activity is handled by RevenueCat. Some data on the device may not be fully protected. All network requests in the code use encrypted connections.
- 9 findings
- Data Security 1
- Code Security 6
- Privacy 1
- Permission Usage 1
- 57out of 100unTRUSTED
Kikoff: Build Credit Quickly
AndroidWhat it means for you
Auth tokens and login sessions are encrypted on the device and cannot be extracted, and financial data is blocked from device backup systems. The build includes code to send usage and activity data to Firebase, Amplitude, AppsFlyer, and Facebook for analytics and advertising. Some financial data may not be fully protected across all areas of the app.
- 8 findings
- Data Security 1
- Code Security 3
- Privacy 1
- Third-Party Risk 1
- Permission Usage 2
- 66out of 100unTRUSTED
What it means for you
Financial data and session tokens are protected against extraction through device backup systems, and contacts data stays on the device without being transmitted to external services. The build includes code to send usage, referral, and performance data to Firebase, Branch.io, UserExperior, and Datadog, among others.
- 11 findings
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 4
- 78out of 100NOT ASSESSED
WHOOP
AndroidWhat it means for you
Biometric health data, including heart rate, HRV, sleep stages, and blood oxygen levels, is not transmitted to third-party analytics or advertising services. GPS workout routes remain within WHOOP's own systems. The build includes code to send behavioral usage events to Amplitude and Sentry for analytics and error reporting.
- 7 findings
- Data Security 1
- Network Security 2
- Code Security 2
- Privacy 1
- Third-Party Risk 1
- 70out of 100unTRUSTED
What it means for you
The build includes code to send usage patterns and behavioral events to Firebase Analytics, Amplitude, Segment, AppsFlyer, and Facebook. The content of mood entries, journals, and sleep records is not passed to those services. Some stored user data may not be fully protected.
- 13 findings
- Data Security 2
- Code Security 7
- Privacy 3
- Third-Party Risk 1
- 88out of 100unTRUSTED
Kia Access
AndroidWhat it means for you
The build includes code to send usage and vehicle data to Firebase Analytics, Dynatrace, and LexisNexis Risk Solutions. The crash reports the code builds for Firebase Crashlytics include vehicle identifiers such as VIN and license plate numbers alongside the full vehicle record. The build includes code to send navigation activity to Google Maps and HERE Maps. SiriusXM integration handles entertainment connectivity.
- 13 findings
- Data Security 3
- Network Security 4
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 82out of 100unTRUSTED
Trump Accounts: Official App
AndroidWhat it means for you
In the build, login sessions and authentication data are handled by the developer's own systems and the code gives third-party services no access to them. Document scans used for identity verification are processed on the device without being transmitted externally. The build includes code to send usage and behavioral data to Firebase Analytics, Singular, and Sprig for analytics and attribution.
- 9 findings
- Network Security 1
- Code Security 5
- Privacy 1
- Third-Party Risk 1
- Permission Usage 1
- 75out of 100unTRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 12 findings
- Network Security 4
- Code Security 3
- Privacy 4
- Permission Usage 1
- 89out of 100TRUSTED
What it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 4 findings
- Data Security 1
- Code Security 3
- 66out of 100unTRUSTED
Gener8 - Earn From Your Data
AndroidWhat it means for you
The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.
- 10 findings
- Data Security 1
- Code Security 4
- Privacy 3
- Third-Party Risk 2
- 92out of 100TRUSTish
Session - Private Messenger
AndroidWhat it means for you
The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.
- 4 findings
- Data Security 1
- Network Security 1
- Code Security 2
- 92out of 100TRUSTish
Proton Authenticator & 2FA
AndroidWhat it means for you
The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.
- 2 findings
- Data Security 1
- Code Security 1
- 95out of 100TRUSTED
What it means for you
The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.
- 3 findings
- Data Security 1
- Code Security 2
- 96out of 100TRUSTED
Google Authenticator
AndroidWhat it means for you
The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.
- 3 findings
- Code Security 2
- Privacy 1
- 92out of 100NOT ASSESSED
Drop Authenticator
AndroidWhat it means for you
The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.
- 3 findings
- Data Security 2
- Code Security 1
- 82out of 100NOT ASSESSED
RuPaul's Drag Race Superstar
AndroidWhat it means for you
The build includes code to pass gaming activity and device identifiers to over a dozen advertising networks including Facebook, AppLovin, Google AdMob, Unity Ads, and Chartboost. The build includes code to pass analytics data through Firebase and Unity to monitor in-app behavior. Singular handles install attribution across these ad partners.
- 3 findings
- Network Security 1
- Privacy 1
- Third-Party Risk 1
- 97out of 100unTRUSTED
SUUUUUU
AndroidWhat it means for you
The build includes code to authenticate users through Google Sign-In, Apple Sign-In, and SmartAuth, a third-party phone verification service. The app includes code to send app usage data to Firebase Analytics, and code to store user content in Google's Firestore cloud database. Push notification delivery is handled by Firebase Cloud Messaging.
- 1 finding
- Code Security 1
- 86out of 100NOT ASSESSED
What it means for you
Analytics collection is permanently disabled in this build. Active Firebase components for push notifications and performance monitoring include code to send functional data to Google. Behavioral and usage data processed by the Synerise CRM module remains on mBank-controlled servers and requires explicit GDPR consent.
- 4 findings
- Data Security 1
- Code Security 1
- Privacy 2
- 89out of 100NOT ASSESSED
mBank SK
AndroidWhat it means for you
The build includes code to pass performance and push notification data to Firebase, which has Analytics explicitly disabled, limiting telemetry to delivery and performance metrics. The Synerise customer engagement platform is named in code as the destination of behavioral data used to personalize the user experience. Biometric authentication uses the FaceTec face recognition SDK for identity verification.
- 6 findings
- Data Security 1
- Network Security 1
- Code Security 2
- Third-Party Risk 1
- Permission Usage 1
- 85out of 100NOT ASSESSED
mBank CZ
AndroidWhat it means for you
The build includes code to pass behavioral and CRM data through the Synerise SDK to mBank-controlled servers, keeping it within the bank's own infrastructure. Firebase Analytics collection is explicitly disabled. The build includes code to pass install and referral data to Google via AdServices and Play Install Referrer. Stored account data remains on-device with strong protections in place.
- 7 findings
- Network Security 2
- Code Security 2
- Privacy 1
- Third-Party Risk 1
- Permission Usage 1
- 85out of 100NOT ASSESSED
Fio Smartbanking CZ
AndroidWhat it means for you
No analytics, advertising, or behavioral tracking SDKs are present. Firebase is used only for push notifications, with analytics explicitly disabled. User data stays on device, and bank servers are the only destination named in code, with no code to send it to third parties detected.
- 4 findings
- Data Security 3
- Code Security 1
- 93out of 100NOT ASSESSED
George Romania
AndroidWhat it means for you
The build includes code to send analytics data to BCR's own infrastructure rather than directly to third-party companies, limiting external data exposure. Sentry, PostHog, and LUX telemetry are all proxied server-side. Firebase analytics collection is disabled by default.
- 8 findings
- Data Security 2
- Network Security 1
- Code Security 4
- Third-Party Risk 1
- 83out of 100unTRUSTED
George Česko
AndroidWhat it means for you
The app includes code to send app usage and analytics data to PostHog, Sentry, and Dynatrace for behavioral analytics, crash reporting, and performance monitoring. Firebase is used only for push notifications, not for analytics tracking. The build includes the ThreatMark and Innovatrics SDKs, whose code reads device security signals for fraud protection. Some user data may not be fully protected in all scenarios.
- 7 findings
- Data Security 2
- Network Security 1
- Code Security 1
- Privacy 1
- Third-Party Risk 2
- 69out of 100unTRUSTED
What it means for you
The app includes code to send app usage and crash data to Firebase Analytics, Crashlytics, and Sentry. The app includes code to send purchase and subscription activity to RevenueCat. Users can optionally sync financial records to Dropbox or Google Drive. Stored financial data may not be fully protected on device.
- 7 findings
- Data Security 3
- Code Security 1
- Privacy 2
- Third-Party Risk 1
- 74out of 100unTRUSTED
What it means for you
The app includes code to send usage data and session activity to Firebase Analytics. The app includes code to read an advertising identifier and pass it to Google's ad attribution services. Locally stored financial data may not be fully protected, which is worth considering if the device could be accessed by others.
- 2 findings
- Data Security 1
- Privacy 1
- 74out of 100unTRUSTED
What it means for you
The app includes code to send usage and event data to Firebase Analytics, Facebook SDK, Amplitude, and Tenjin for analytics and attribution. The app includes code for financial transactions through Stripe and Plaid. Location data may be collected in the background via a geolocation service. Receipt images are processed on-device and not sent to the cloud.
- 14 findings
- Data Security 2
- Network Security 2
- Code Security 4
- Privacy 3
- Third-Party Risk 1
- Permission Usage 2
- 84out of 100unTRUSTED
Money manager & expenses
AndroidWhat it means for you
The build includes the AppMetrica (Yandex), Facebook, and VK SDKs, whose code reads app usage data for analytics. Ads are served through Google AdMob and Yandex Mobile Ads. Locally stored data is well protected, though the app includes code that may send some app data with less protection than expected on certain connections.
- 6 findings
- Data Security 3
- Network Security 1
- Privacy 1
- Third-Party Risk 1
- 74out of 100unTRUSTED
Monthly Budget & Expense App
AndroidWhat it means for you
The app includes code to send usage and crash data to Firebase Analytics and Crashlytics, and the Facebook SDK is present, whose code may send behavioral data to Meta. Financial data entered by the user is stored via Firebase cloud services. Permission access to device features beyond core tracking needs has been identified.
- 6 findings
- Data Security 2
- Code Security 1
- Third-Party Risk 2
- Permission Usage 1
- 72out of 100unTRUSTED
What it means for you
The app includes code to send app activity to six advertising networks, including Facebook Audience Network, AppLovin, and Google AdMob, alongside Firebase Analytics. Usage patterns and in-app behavior may inform ad targeting across these networks. Some locally stored data may not be fully protected.
- 12 findings
- Data Security 4
- Network Security 2
- Code Security 3
- Privacy 2
- Third-Party Risk 1
- 88out of 100TRUSTish
What it means for you
Financial data is stored locally on the device, and no developer-owned server is named in code as a destination for it. The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. For users who consent to ads, the app includes code to send ad interaction data to Google AdMob; premium subscribers bypass ads entirely.
- 1 finding
- Data Security 1
- 84out of 100NOT ASSESSED
Spending Tracker
AndroidWhat it means for you
The build includes the Firebase and Microsoft App Center SDKs, whose code reads usage and crash data. Ads are served via Google AdMob with a consent layer that defaults to non-personalised ads. Financial data stays on-device and is not backed up to cloud services automatically.
- 3 findings
- Data Security 2
- Network Security 1
- 80out of 100TRUSTish
- 3 findings
- Data Security 2
- Code Security 1
- 92out of 100TRUSTish
What it means for you
Financial transactions and budget data are stored in Firebase and optionally synced via Dropbox. Analytics and crash reporting through Firebase are disabled until the user explicitly consents, and ad networks (Google AdMob, Facebook Audience Network) are never activated for paying subscribers. Users who connect bank accounts do so through Salt Edge, a third-party financial data aggregation service.
- 3 findings
- Data Security 1
- Code Security 1
- Third-Party Risk 1
- 80out of 100unTRUSTED
What it means for you
The app includes code to send app usage and behavioral data to Braze and AppsFlyer for marketing and attribution purposes. Bank account connectivity is handled through Plaid and Mastercard Open Banking. The app includes code to send crash reports to Bugsnag, and Optimizely runs A/B tests on user interactions within the app.
- 5 findings
- Data Security 1
- Code Security 2
- Privacy 1
- Third-Party Risk 1
- 75out of 100NOT ASSESSED
What it means for you
The build includes code to send usage and behavioral data to multiple advertising networks, including Facebook Audience Network, AppLovin, Vungle, and Yandex Mobile Ads, for targeted advertising. The build also includes code to send analytics to Firebase Analytics and Yandex AppMetrica, a Russian analytics provider. All backend communication uses HTTPS, and Google Drive backup is gated behind explicit user consent.
- 10 findings
- Data Security 5
- Network Security 1
- Code Security 2
- Third-Party Risk 2
- 73out of 100unTRUSTED
Mój Orange
AndroidWhat it means for you
The app includes code to send app usage and behavioral data to AppsFlyer, Firebase Analytics, Synerise, QuantumMetric, and Google Tag Manager for analytics, CRM, and marketing purposes. Session interactions within the app are recorded by QuantumMetric for behavioral analysis. Some code may send network activity with less protection than expected on public Wi-Fi.
- 7 findings
- Network Security 2
- Code Security 2
- Privacy 1
- Third-Party Risk 2
- 84out of 100unTRUSTED
My Orange Moldova
AndroidWhat it means for you
The build includes the Firebase Analytics and Batch SDKs, whose code reads app usage data for usage insights and push notifications, with analytics requiring explicit user consent before activation. Identity verification flows rely on AriadNext IDcheckio and Unissey, which may process document or biometric data. Some user data may not be fully protected in all transmission scenarios.
- 8 findings
- Data Security 1
- Network Security 1
- Code Security 4
- Privacy 1
- Third-Party Risk 1
- 79out of 100TRUSTish
IBKR Mobile
AndroidWhat it means for you
The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. Financial document processing via MiSnap and QR scanning via ML Kit are handled on-device without sending image data externally. One data storage concern was identified where user data may not be fully protected at rest.
- 7 findings
- Data Security 1
- Network Security 2
- Code Security 2
- Privacy 2
- 75out of 100NOT ASSESSED
EVO
AndroidWhat it means for you
The build includes Firebase Analytics and Crashlytics, whose code reads app usage statistics and crash reports. Google Ad Services is also present alongside these tools. One data storage concern means some user data may not be fully protected, though authentication credentials are encrypted and the app prevents backup access to sensitive data.
- 8 findings
- Data Security 3
- Network Security 2
- Code Security 3
- 75out of 100unTRUSTED
My Vodafone Romania
AndroidWhat it means for you
The app includes code to send app usage and account activity to Firebase Analytics, Adjust, Facebook, Tealium, Huawei HiAnalytics, Medallia, and Urban Airship for analytics, marketing attribution, and push messaging. Some code may send activity with less protection than expected on certain network paths. Account authentication uses hardware-backed key storage on the device.
- 8 findings
- Data Security 1
- Network Security 2
- Code Security 2
- Privacy 1
- Third-Party Risk 1
- Permission Usage 1