Skip to content

Apps

106 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.

  • 97
    out of 100unTRUSTED

    SUUUUUU

    Android

    What it means for you

    The build includes code to authenticate users through Google Sign-In, Apple Sign-In, and SmartAuth, a third-party phone verification service. The app includes code to send app usage data to Firebase Analytics, and code to store user content in Google's Firestore cloud database. Push notification delivery is handled by Firebase Cloud Messaging.

    • 1 finding
    • Code Security 1
  • 96
    out of 100TRUSTED

    Google Authenticator

    Android

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 3 findings
    • Code Security 2
    • Privacy 1
  • 95
    out of 100TRUSTED

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 3 findings
    • Data Security 1
    • Code Security 2
  • 95
    out of 100TRUSTED

    Proton Drive: Cloud Storage

    Android

    What it means for you

    File content, names, sizes, and metadata are end-to-end encrypted, meaning Proton cannot read stored files. The app includes code to send crash diagnostics to Sentry using a random identifier that cannot be linked to a Proton account. The build includes no code to send data from normal use to advertising, analytics, or attribution companies.

    • 3 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
  • 93
    out of 100NOT ASSESSED

    George Romania

    Android

    What it means for you

    The build includes code to send analytics data to BCR's own infrastructure rather than directly to third-party companies, limiting external data exposure. Sentry, PostHog, and LUX telemetry are all proxied server-side. Firebase analytics collection is disabled by default.

    • 8 findings
    • Data Security 2
    • Network Security 1
    • Code Security 4
    • Third-Party Risk 1
  • 92
    out of 100TRUSTish

    Session - Private Messenger

    Android

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
  • 92
    out of 100TRUSTish

    Proton Authenticator & 2FA

    Android

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 2 findings
    • Data Security 1
    • Code Security 1
  • 92
    out of 100NOT ASSESSED

    Drop Authenticator

    Android

    What it means for you

    The build may include code to pass usage data and device activity to the app developer and any integrated services. Review the category summary below for details.

    • 3 findings
    • Data Security 2
    • Code Security 1
  • 92
    out of 100TRUSTish

    What it means for you

    Financial transactions and budget data are stored in Firebase and optionally synced via Dropbox. Analytics and crash reporting through Firebase are disabled until the user explicitly consents, and ad networks (Google AdMob, Facebook Audience Network) are never activated for paying subscribers. Users who connect bank accounts do so through Salt Edge, a third-party financial data aggregation service.

    • 3 findings
    • Data Security 1
    • Code Security 1
    • Third-Party Risk 1
  • 92
    out of 100NOT ASSESSED

    Lumo by Proton

    Android

    What it means for you

    The app includes code to send crash reports to Proton's own GDPR-governed servers, not to external analytics companies. On-device speech processing via Vosk means audio never leaves the device. Google Play services handle billing and app delivery, with no third-party advertising, analytics, or behavioral tracking SDKs present.

    • 3 findings
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 91
    out of 100NOT ASSESSED

    SAP Analytics Cloud

    Android

    What it means for you

    The app includes code to exchange data with the user's organization SAP backend over HTTPS. Firebase Installations registers a device identifier with Google as part of app setup. Enterprise usage telemetry is collected only when enabled by an organization administrator and requires a consent screen before activation.

    • 4 findings
    • Data Security 3
    • Code Security 1
  • 91
    out of 100unTRUSTED

    SAP for Me

    Android

    What it means for you

    The app includes code to send usage and interaction data to Firebase Analytics and Adobe Experience Platform for performance tracking, and to Qualtrics for optional in-app surveys. TrustArc consent management controls whether Adobe analytics tracking is active based on user preferences. Locally stored data is protected, and all traffic to company systems uses secure connections.

    • 6 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Privacy 2
  • 90
    out of 100unTRUSTED

    Revolut Business

    Android

    What it means for you

    The build includes code to send App usage, install attribution, and performance data to AppsFlyer, Firebase Analytics, Firebase Crashlytics, and Branch.io. The build includes code to send Identity verification data to Onfido during onboarding. Financial account and transaction data remain within Revolut's own infrastructure, and financial databases are stored in encrypted form on the device rather than backed up to third-party cloud services.

    • 7 findings
    • Network Security 2
    • Code Security 5
  • 90
    out of 100NOT ASSESSED

    Mastodon

    Android

    What it means for you

    The binary bundles no third-party analytics, advertising, or tracking SDKs, and static analysis finds no data-broker or ad-network endpoints. Network traffic in the binary is directed only to the user's chosen Mastodon instance and the developer's own infrastructure. The build includes code that encrypts push notification content on the device, so the request built for Google's notification service contains only routing metadata in readable form.

    • 7 findings
    • Data Security 1
    • Network Security 1
    • Code Security 4
    • Privacy 1
  • 89
    out of 100NOT ASSESSED

    The White House

    Android

    What it means for you

    No advertising networks, attribution trackers, or behavioral analytics infrastructure is present in this build, and no data broker sharing is configured. The build links OneSignal and Firebase Cloud Messaging for push notifications, and Firebase Installations for device registration. Barcode scanning is configured for on-device processing only; authentication credentials are stored locally and excluded from cloud backup.

    • 5 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
  • 89
    out of 100TRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 4 findings
    • Data Security 1
    • Code Security 3
  • 89
    out of 100NOT ASSESSED

    mBank SK

    Android

    What it means for you

    The build includes code to pass performance and push notification data to Firebase, which has Analytics explicitly disabled, limiting telemetry to delivery and performance metrics. The Synerise customer engagement platform is named in code as the destination of behavioral data used to personalize the user experience. Biometric authentication uses the FaceTec face recognition SDK for identity verification.

    • 6 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Third-Party Risk 1
    • Permission Usage 1
  • 88
    out of 100unTRUSTED

    What it means for you

    The build includes code to send user data to the developer's own backend systems, and contains no code to sell it to data brokers or advertising networks. No vehicle telemetry is part of the app's data collection despite its automotive hardware integration. Firebase Crashlytics and Firebase Analytics are bundled for crash reporting and usage metrics.

    • 11 findings
    • Network Security 1
    • Code Security 7
    • Privacy 2
    • Third-Party Risk 1
  • 88
    out of 100unTRUSTED

    Kia Access

    Android

    What it means for you

    The build includes code to send usage and vehicle data to Firebase Analytics, Dynatrace, and LexisNexis Risk Solutions. The crash reports the code builds for Firebase Crashlytics include vehicle identifiers such as VIN and license plate numbers alongside the full vehicle record. The build includes code to send navigation activity to Google Maps and HERE Maps. SiriusXM integration handles entertainment connectivity.

    • 13 findings
    • Data Security 3
    • Network Security 4
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 88
    out of 100TRUSTish

    What it means for you

    Financial data is stored locally on the device, and no developer-owned server is named in code as a destination for it. The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. For users who consent to ads, the app includes code to send ad interaction data to Google AdMob; premium subscribers bypass ads entirely.

    • 1 finding
    • Data Security 1
  • 87
    out of 100unTRUSTED

    Bono

    Android

    What it means for you

    Authentication is handled via Google Sign-In, Apple Sign-In, and FIDO2 passkeys. Push notifications are handled through Firebase, and the build includes code to pass a device identifier to Google. The app includes code to send install referral data to Google when the app is first installed.

    • 8 findings
    • Data Security 2
    • Network Security 2
    • Code Security 3
    • Privacy 1
  • 86
    out of 100TRUSTish

    CatLens - Cat Vision Filter

    Android

    What it means for you

    Camera images and photo effects are processed locally on the device, and the build contains no code to route photo or video frames to a cloud backend. Firebase is present for push notification delivery only, not behavioral tracking. The build includes code to pass usage data and device identifiers to Google AdMob for advertising and to OneSignal for targeted notifications.

    • 6 findings
    • Data Security 2
    • Code Security 3
    • Permission Usage 1
  • 86
    out of 100unTRUSTED

    What it means for you

    Firebase Analytics and AppsFlyer are configured to remain inactive until the user explicitly consents, so no analytics or attribution data is generated before that point. Biometric identity verification data is configured to route to Hinge's own servers rather than FaceTec's infrastructure. Firebase, Braze, Sendbird, and related services are integrated in the build for crash reporting, messaging, and performance measurement.

    • 5 findings
    • Code Security 4
    • Third-Party Risk 1
  • 86
    out of 100NOT ASSESSED

    What it means for you

    Analytics collection is permanently disabled in this build. Active Firebase components for push notifications and performance monitoring include code to send functional data to Google. Behavioral and usage data processed by the Synerise CRM module remains on mBank-controlled servers and requires explicit GDPR consent.

    • 4 findings
    • Data Security 1
    • Code Security 1
    • Privacy 2
  • 85
    out of 100unTRUSTED

    What it means for you

    Financial transaction data, including balances and transfer amounts, was not observed reaching advertising networks, and no advertising SDK is present in the app. Biometric identity verification during account setup is processed on the device. The app includes code to pass usage and crash data to Firebase Analytics, Mixpanel, Braze, Facebook, and Sentry, with SDK-level opt-out controls for Braze and Singular built into the app.

    • 10 findings
    • Data Security 2
    • Network Security 1
    • Code Security 2
    • Privacy 3
    • Third-Party Risk 1
    • Permission Usage 1
  • 85
    out of 100unTRUSTED

    Keeper Password Manager

    Android

    What it means for you

    Passwords, notes, and credentials are stored as ciphertext on the device, with Android backup disabled to block vault data from cloud or device-transfer backups. Payment card scanning is handled on-device with no card data reaching external servers. The build includes code to report app usage to Singular for attribution only; no advertising network SDK is present, and Firebase is limited to push notifications.

    • 8 findings
    • Network Security 2
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 85
    out of 100unTRUSTED

    MyBible

    Android

    What it means for you

    Bible reading progress, notes, and history stay on the device and are not accessible to the developer or sold to data brokers. Reading habits are not shared with ad networks. Firebase Analytics and Crashlytics are integrated for performance monitoring.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 85
    out of 100NOT ASSESSED

    mBank CZ

    Android

    What it means for you

    The build includes code to pass behavioral and CRM data through the Synerise SDK to mBank-controlled servers, keeping it within the bank's own infrastructure. Firebase Analytics collection is explicitly disabled. The build includes code to pass install and referral data to Google via AdServices and Play Install Referrer. Stored account data remains on-device with strong protections in place.

    • 7 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 85
    out of 100NOT ASSESSED

    Fio Smartbanking CZ

    Android

    What it means for you

    No analytics, advertising, or behavioral tracking SDKs are present. Firebase is used only for push notifications, with analytics explicitly disabled. User data stays on device, and bank servers are the only destination named in code, with no code to send it to third parties detected.

    • 4 findings
    • Data Security 3
    • Code Security 1
  • 84
    out of 100unTRUSTED

    My EYA

    Android

    What it means for you

    Camera frames for barcode and QR code scanning are processed on the device and not sent to external servers. No advertising or ad-targeting networks are linked in the build. The build includes code to send usage analytics and crash reports to PostHog and Sentry, Firebase Cloud Messaging handles push notifications, and Stream.io supports in-app messaging.

    • 9 findings
    • Data Security 1
    • Code Security 6
    • Privacy 2
  • 84
    out of 100unTRUSTED

    RemindMeWhere Reminders

    Android

    What it means for you

    Geofence locations and reminder data are stored on the device and are not shared with advertising networks. The app includes code to send usage data and authentication activity to Firebase Analytics and Facebook SDK. Cloud-synced data requires authentication before access.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 4
    • Privacy 1
    • Permission Usage 1
  • 84
    out of 100TRUSTish

    Anker soundcore

    Android

    What it means for you

    The build includes code to send biometrics to soundcore/Anker cloud, and files to soundcore Anka AI. The build includes code to send another 4 data points to other third parties. Two findings are worth reading before this build handles anything a user would want kept to themselves. One is a high severity finding related to Network Security. One more is an open question the analysis could not settle.

    • 49 findings
    • Data Security 2
    • Network Security 10
    • Code Security 18
    • Privacy 7
    • Third-Party Risk 11
    • Permission Usage 1
  • 84
    out of 100unTRUSTED

    Money manager & expenses

    Android

    What it means for you

    The build includes the AppMetrica (Yandex), Facebook, and VK SDKs, whose code reads app usage data for analytics. Ads are served through Google AdMob and Yandex Mobile Ads. Locally stored data is well protected, though the app includes code that may send some app data with less protection than expected on certain connections.

    • 6 findings
    • Data Security 3
    • Network Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 84
    out of 100NOT ASSESSED

    Spending Tracker

    Android

    What it means for you

    The build includes the Firebase and Microsoft App Center SDKs, whose code reads usage and crash data. Ads are served via Google AdMob with a consent layer that defaults to non-personalised ads. Financial data stays on-device and is not backed up to cloud services automatically.

    • 3 findings
    • Data Security 2
    • Network Security 1
  • 84
    out of 100unTRUSTED

    My Orange Moldova

    Android

    What it means for you

    The build includes the Firebase Analytics and Batch SDKs, whose code reads app usage data for usage insights and push notifications, with analytics requiring explicit user consent before activation. Identity verification flows rely on AriadNext IDcheckio and Unissey, which may process document or biometric data. Some user data may not be fully protected in all transmission scenarios.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 83
    out of 100unTRUSTED

    Airbnb

    Android

    What it means for you

    Identity verification scans, including biometric checks and document images, are handled on the device via Google ML Kit and not routed to third-party servers. The app includes code to pass booking activity, device data, and location signals to Firebase, Google Analytics, Facebook, Singular, Branch, Incognia, and Bugsnag for analytics, fraud detection, and crash reporting.

    • 13 findings
    • Data Security 1
    • Network Security 2
    • Code Security 9
    • Privacy 1
  • 83
    out of 100unTRUSTED

    Reolink

    Android

    What it means for you

    Behavioral telemetry defaults to off and requires explicit opt-in. The code addresses usage data only to Reolink's own systems and names no third-party analytics or advertising networks as destinations. Camera location data is kept on the device and is not transmitted to Reolink servers.

    • 8 findings
    • Data Security 1
    • Network Security 4
    • Code Security 1
    • Privacy 1
    • Permission Usage 1
  • 83
    out of 100unTRUSTED

    George Česko

    Android

    What it means for you

    The app includes code to send app usage and analytics data to PostHog, Sentry, and Dynatrace for behavioral analytics, crash reporting, and performance monitoring. Firebase is used only for push notifications, not for analytics tracking. The build includes the ThreatMark and Innovatrics SDKs, whose code reads device security signals for fraud protection. Some user data may not be fully protected in all scenarios.

    • 7 findings
    • Data Security 2
    • Network Security 1
    • Code Security 1
    • Privacy 1
    • Third-Party Risk 2
  • 82
    out of 100unTRUSTED

    Akedo: Offline Games No WiFi

    Android

    What it means for you

    Gameplay runs offline after download, with no server calls needed during sessions. The app includes code to send device and usage data to Google Firebase and the developer's service at akedo.gg for analytics; the analysis found no code that reads health, location, financial, or contact data. Google AdMob is the only ad network present.

    • 5 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    X

    Android

    What it means for you

    Direct messages are end-to-end encrypted and excluded from device cloud backups. Camera frames captured during identity verification are processed on the device. The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Branch.io, and Datadog for analytics, advertising, and crash reporting.

    • 11 findings
    • Data Security 1
    • Network Security 2
    • Code Security 6
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    Revolut: Spend, Save, Trade

    Android

    What it means for you

    Financial transaction data is addressed in code only to Revolut's own servers; the build includes no code to pass financial information to advertising networks or data brokers. Usage analytics through Firebase and AppsFlyer are off by default, with no data shared until user consent is given. The app includes code to pass identity verification data to third-party providers during account onboarding.

    • 12 findings
    • Data Security 3
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 2
  • 82
    out of 100unTRUSTED

    Grok

    Android

    What it means for you

    The app includes code to pass usage and interaction data to Mixpanel, AppsFlyer, and Braze for analytics, attribution, and marketing engagement. Login tokens are stored in the protected Android credential store, isolated from other apps. Google Analytics is configured to exclude advertising identifiers, and support chat identity data is encrypted with hardware-backed storage.

    • 7 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    bitchat

    Android

    What it means for you

    Message content is end-to-end encrypted and the developer operates no servers that receive it. No user accounts, analytics, or advertising SDKs are present. The Nostr messaging feature is configured to connect to public relay servers (damus.io, primal.net, and others), which handle message relay as part of the open Nostr protocol.

    • 9 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Privacy 2
  • 82
    out of 100unTRUSTED

    Philips Hue

    Android

    What it means for you

    Location data from geofence automations stays on the device and is not forwarded to advertising or analytics services. Bridge login credentials are stored in hardware-protected on-device storage, excluded from cloud and device backups. The build includes code to send usage and crash data to Amplitude, Firebase, Braze, and Sentry.

    • 11 findings
    • Data Security 1
    • Network Security 4
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    What it means for you

    In the build, login sessions and authentication data are handled by the developer's own systems and the code gives third-party services no access to them. Document scans used for identity verification are processed on the device without being transmitted externally. The build includes code to send usage and behavioral data to Firebase Analytics, Singular, and Sprig for analytics and attribution.

    • 9 findings
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 82
    out of 100NOT ASSESSED

    What it means for you

    The build includes code to pass gaming activity and device identifiers to over a dozen advertising networks including Facebook, AppLovin, Google AdMob, Unity Ads, and Chartboost. The build includes code to pass analytics data through Firebase and Unity to monitor in-app behavior. Singular handles install attribution across these ad partners.

    • 3 findings
    • Network Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 81
    out of 100unTRUSTED

    Yoti - your digital identity

    Android

    What it means for you

    Yes, on the evidence available. The build includes code to send precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. The build includes code to send another 13 data points to other third parties. None of the findings recorded rises to the level of putting a user at risk.

    • 1006 findings
    • Data Security 39
    • Network Security 432
    • Code Security 231
    • Privacy 249
    • Third-Party Risk 43
    • Permission Usage 12
  • 81
    out of 100unTRUSTED

    Navy Federal Credit Union

    Android

    What it means for you

    The build includes code to send usage data and crash reports to Firebase, Adobe Analytics, Salesforce, and Qualtrics for performance monitoring and feedback. No behavioral advertising SDKs are included, so usage data does not flow to ad platforms. The build includes code to send fraud detection data to Navy Federal's own servers before third-party risk services are involved.

    • 9 findings
    • Data Security 1
    • Network Security 4
    • Code Security 4
  • 80
    out of 100unTRUSTED

    CNN: Live & Breaking News

    Android

    What it means for you

    The app includes code to pass viewing and interaction data to analytics and advertising services including Firebase Analytics, Adobe Analytics, AppsFlyer, Google AdMob, comScore, and Snowplow. The build includes a full consent-before-tracking flow via OneTrust for EU users, and code that blocks all advertising and analytics SDKs when the consent system does not confirm permission. Firebase Advertising ID collection is disabled in the build.

    • 6 findings
    • Data Security 1
    • Code Security 5
  • 80
    out of 100unTRUSTED

    MetService NZ Weather

    Android

    What it means for you

    The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Nielsen, Prebid, and Rubicon for analytics and ad measurement. Precise GPS coordinates are not included in advertising requests. A paid subscription removes advertising tracking exposure, though user data may not be fully protected in all scenarios.

    • 3 findings
    • Network Security 2
    • Code Security 1