Skip to content

Apps

106 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.

  • 80
    out of 100TRUSTish
    • 3 findings
    • Data Security 2
    • Code Security 1
  • 80
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app usage and behavioral data to Braze and AppsFlyer for marketing and attribution purposes. Bank account connectivity is handled through Plaid and Mastercard Open Banking. The app includes code to send crash reports to Bugsnag, and Optimizely runs A/B tests on user interactions within the app.

    • 5 findings
    • Data Security 1
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
  • 79
    out of 100unTRUSTED

    Gummo

    Android

    What it means for you

    Location data stays on the device and is not shared with Sentry, Firebase, or any analytics service. No advertising network SDKs are present. Firebase handles push notifications, and the Play Install Referrer library is linked for install attribution.

    • 7 findings
    • Data Security 3
    • Code Security 2
    • Privacy 2
  • 79
    out of 100unTRUSTED

    Glassdoor | Jobs & Careers

    Android

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
  • 79
    out of 100TRUSTish

    IBKR Mobile

    Android

    What it means for you

    The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. Financial document processing via MiSnap and QR scanning via ML Kit are handled on-device without sending image data externally. One data storage concern was identified where user data may not be fully protected at rest.

    • 7 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 2
  • 78
    out of 100NOT ASSESSED

    WHOOP

    Android

    What it means for you

    Biometric health data, including heart rate, HRV, sleep stages, and blood oxygen levels, is not transmitted to third-party analytics or advertising services. GPS workout routes remain within WHOOP's own systems. The build includes code to send behavioral usage events to Amplitude and Sentry for analytics and error reporting.

    • 7 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
  • 76
    out of 100unTRUSTED
    • 852 findings
    • Data Security 80
    • Network Security 76
    • Code Security 201
    • Privacy 213
    • Third-Party Risk 262
    • Permission Usage 20
  • 76
    out of 100unTRUSTED

    meross

    Android

    What it means for you

    No advertising networks or data broker SDKs are present in this build. The build includes code to send device usage statistics and crash reports to Firebase Analytics and Crashlytics. The build includes code that processes smart home device data through Meross infrastructure and AWS, and names no third-party monetization service in code as a destination of user data.

    • 11 findings
    • Data Security 4
    • Network Security 3
    • Code Security 2
    • Privacy 2
  • 75
    out of 100TRUSTish

    VLC for Android

    Android

    What it means for you

    The build includes code to send credentials to OpenSubtitles, and authentication tokens to OpenSubtitles. The build includes code to send another 3 data points to other third parties. Four high severity findings related to Data Security and Network Security are worth reading before this build handles anything a user would want kept to themselves.

    • 370 findings
    • Data Security 105
    • Network Security 42
    • Code Security 147
    • Privacy 46
    • Third-Party Risk 18
    • Permission Usage 12
  • 75
    out of 100unTRUSTED

    United Airlines

    Android

    What it means for you

    Analytics and advertising SDKs from Google, Kochava, Quantum Metric, Mixpanel, and Snowplow are bundled in the build alongside core trip features. Location access requires a current trip context and an explicit permission grant from the user. Account credentials and reservation details are protected by device-level encryption.

    • 10 findings
    • Data Security 3
    • Network Security 2
    • Code Security 5
  • 75
    out of 100unTRUSTED

    Rakuten Viber Messenger

    Android

    What it means for you

    The app includes code to pass messaging activity and device data to advertising and analytics partners including Braze, Adjust, Facebook, and multiple ad networks. Firebase Analytics collection is disabled by default in the build manifest, and Mixpanel is configured to route through Viber's own CDN proxy, preventing Mixpanel from directly observing individual IP addresses. Payment authorization requires biometric authentication, and sensitive databases are excluded from cloud backups.

    • 11 findings
    • Data Security 1
    • Network Security 4
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 75
    out of 100unTRUSTED

    Kroger

    Android

    What it means for you

    Behavioral analytics code from the app's own system is directed only to Kroger's infrastructure, and the build includes no code to pass it to third parties. Pharmacy and biometric credentials are stored with hardware-backed encryption on the device. The build includes code to pass usage, crash, and device data to Firebase, Adobe Experience, Salesforce Marketing Cloud, and fraud-risk services including ThreatMetrix, Iovation, and Experian Accertify.

    • 12 findings
    • Data Security 2
    • Network Security 1
    • Code Security 6
    • Privacy 1
    • Third-Party Risk 2
  • 75
    out of 100unTRUSTED

    Wesper

    Android

    What it means for you

    Biometric health data, including sleep metrics and audio recordings, is addressed in code only to Wesper's own servers, and no advertising networks or data brokers are named as destinations. The app is configured to prevent health files from being extracted via device backup. The build includes code to send usage and app performance data to Firebase Analytics and Google services for diagnostics and improvement.

    • 10 findings
    • Data Security 2
    • Code Security 1
    • Privacy 5
    • Third-Party Risk 2
  • 75
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 12 findings
    • Network Security 4
    • Code Security 3
    • Privacy 4
    • Permission Usage 1
  • 75
    out of 100NOT ASSESSED

    What it means for you

    The build includes code to send usage and behavioral data to multiple advertising networks, including Facebook Audience Network, AppLovin, Vungle, and Yandex Mobile Ads, for targeted advertising. The build also includes code to send analytics to Firebase Analytics and Yandex AppMetrica, a Russian analytics provider. All backend communication uses HTTPS, and Google Drive backup is gated behind explicit user consent.

    • 10 findings
    • Data Security 5
    • Network Security 1
    • Code Security 2
    • Third-Party Risk 2
  • 75
    out of 100NOT ASSESSED

    EVO

    Android

    What it means for you

    The build includes Firebase Analytics and Crashlytics, whose code reads app usage statistics and crash reports. Google Ad Services is also present alongside these tools. One data storage concern means some user data may not be fully protected, though authentication credentials are encrypted and the app prevents backup access to sensitive data.

    • 8 findings
    • Data Security 3
    • Network Security 2
    • Code Security 3
  • 75
    out of 100unTRUSTED

    My Vodafone Romania

    Android

    What it means for you

    The app includes code to send app usage and account activity to Firebase Analytics, Adjust, Facebook, Tealium, Huawei HiAnalytics, Medallia, and Urban Airship for analytics, marketing attribution, and push messaging. Some code may send activity with less protection than expected on certain network paths. Account authentication uses hardware-backed key storage on the device.

    • 8 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 74
    out of 100unTRUSTED

    What it means for you

    Dating profile data, messages, and auth credentials are excluded from Google cloud backup and device transfers. Facial recognition processing occurs entirely on the device, and the build includes no code to pass raw biometric photos to third-party services. The app includes code to pass usage and behavioral data to advertising and attribution networks including Google Ad Manager, AppsFlyer, and LiveRamp, though seven tracking integrations are individually consent-gated.

    • 13 findings
    • Network Security 1
    • Code Security 8
    • Privacy 1
    • Third-Party Risk 2
    • Permission Usage 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to pass booking activity and app usage data to Adobe Analytics, Adobe Audience Manager, Adobe Target, Firebase Analytics, Branch, Quantum Metric, and Rokt for analytics and advertising. Login credentials and session tokens are stored with device-level encryption and are excluded from cloud and local backups. The network configuration in the build specifies HTTPS only, with no cleartext connections permitted.

    • 11 findings
    • Data Security 1
    • Code Security 6
    • Privacy 4
  • 74
    out of 100unTRUSTED

    What it means for you

    Downloaded audio content is secured with on-device encryption, and app backups are disabled to protect account data. The build includes code to send listening activity and usage data to Firebase Analytics, Conviva, Datadog, Salesforce Marketing Cloud, and Branch.io for analytics and attribution. The build includes code to send advertising data to AdsWizz.

    • 8 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Third-Party Risk 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage data and session activity to Firebase Analytics. The app includes code to read an advertising identifier and pass it to Google's ad attribution services. Locally stored financial data may not be fully protected, which is worth considering if the device could be accessed by others.

    • 2 findings
    • Data Security 1
    • Privacy 1
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage and event data to Firebase Analytics, Facebook SDK, Amplitude, and Tenjin for analytics and attribution. The app includes code for financial transactions through Stripe and Plaid. Location data may be collected in the background via a geolocation service. Receipt images are processed on-device and not sent to the cloud.

    • 14 findings
    • Data Security 2
    • Network Security 2
    • Code Security 4
    • Privacy 3
    • Third-Party Risk 1
    • Permission Usage 2
  • 74
    out of 100unTRUSTED

    What it means for you

    The app includes code to send usage and crash data to Firebase Analytics and Crashlytics, and the Facebook SDK is present, whose code may send behavioral data to Meta. Financial data entered by the user is stored via Firebase cloud services. Permission access to device features beyond core tracking needs has been identified.

    • 6 findings
    • Data Security 2
    • Code Security 1
    • Third-Party Risk 2
    • Permission Usage 1
  • 73
    out of 100unTRUSTED

    Free Download Manager - FDM

    Android

    What it means for you

    No advertising networks are bundled, and download activity is not sold to data brokers. The only external data recipient is Google, via Firebase Analytics for app performance measurement. Camera access is limited to local QR code scanning with no image data leaving the device, and microphone access is used only for audio device routing. Some connection activity may carry less protection than expected on public networks.

    • 9 findings
    • Data Security 3
    • Network Security 2
    • Code Security 1
    • Privacy 3
  • 73
    out of 100unTRUSTED

    What it means for you

    GPS location data is not passed to analytics or advertising services and remains within the app's own systems. The build includes code to send usage and device data to Firebase, AppsFlyer, CleverTap, Mixpanel, and Facebook for analytics and ad attribution. The build includes code to send Mixpanel data to EU-resident servers.

    • 12 findings
    • Data Security 3
    • Code Security 7
    • Privacy 1
    • Third-Party Risk 1
  • 73
    out of 100unTRUSTED

    Mój Orange

    Android

    What it means for you

    The app includes code to send app usage and behavioral data to AppsFlyer, Firebase Analytics, Synerise, QuantumMetric, and Google Tag Manager for analytics, CRM, and marketing purposes. Session interactions within the app are recorded by QuantumMetric for behavioral analysis. Some code may send network activity with less protection than expected on public Wi-Fi.

    • 7 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 2
  • 72
    out of 100unTRUSTED

    Wagoneer

    Android

    What it means for you

    Vehicle location, trip history, and account documents are kept encrypted on the device. The app includes code to send App activity and diagnostic data to Adobe, Firebase, Salesforce, and Facebook for analytics and marketing. Some account activity may be exposed with less protection than expected on public Wi-Fi.

    • 11 findings
    • Data Security 1
    • Network Security 5
    • Code Security 5
  • 72
    out of 100unTRUSTED

    FreeReels - Dramas & Reels

    Android

    What it means for you

    Behavioral analytics code is directed to the developer's own servers rather than a third-party analytics vendor, and cloud backup is disabled. The binary integrates multiple advertising networks including Google AdMob, AppLovin, Pangle, Unity Ads, Vungle, and Facebook Audience Network, each linked for ad delivery and device signal processing. The binary also bundles Ishumei SmAntiFraud and Tencent LiteAV components.

    • 12 findings
    • Data Security 1
    • Network Security 2
    • Code Security 6
    • Privacy 2
    • Third-Party Risk 1
  • 72
    out of 100unTRUSTED

    Fly Delta

    Android

    What it means for you

    Passport and boarding pass scanning is processed on the device, and trip itinerary calendar data is stored locally without being shared with Delta servers or third-party platforms. The build includes code to pass usage activity, device signals, and in-app behavior to analytics and performance services including Adobe Analytics, Firebase Analytics, Quantum Metric, and Dynatrace.

    • 7 findings
    • Data Security 1
    • Code Security 4
    • Third-Party Risk 2
  • 72
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app activity to six advertising networks, including Facebook Audience Network, AppLovin, and Google AdMob, alongside Firebase Analytics. Usage patterns and in-app behavior may inform ad targeting across these networks. Some locally stored data may not be fully protected.

    • 12 findings
    • Data Security 4
    • Network Security 2
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 71
    out of 100unTRUSTED

    Temper Staff

    Android

    What it means for you

    AppsFlyer, Mixpanel, and Sentry are gated behind in-app consent and do not load until the user grants permission. When the user consents to Mixpanel, the build includes code to send analytics data to EU-region servers. The build includes code to send usage and device data to Firebase, Intercom, and Salesforce Marketing Cloud as part of the service.

    • 6 findings
    • Data Security 1
    • Network Security 2
    • Code Security 3
  • 70
    out of 100unTRUSTED

    What it means for you

    The build includes code to send usage patterns and behavioral events to Firebase Analytics, Amplitude, Segment, AppsFlyer, and Facebook. The content of mood entries, journals, and sleep records is not passed to those services. Some stored user data may not be fully protected.

    • 13 findings
    • Data Security 2
    • Code Security 7
    • Privacy 3
    • Third-Party Risk 1
  • 69
    out of 100unTRUSTED

    Davivienda

    Android

    What it means for you

    The app includes code to pass session data and device data to multiple third-party services, including AppsFlyer (attribution), Braze (marketing), BioCatch and Cobrowse.io (session monitoring), Dynatrace, and Sentry. Firebase Analytics is linked but configured to be inactive at launch; biometric identity checks are handled by FaceTec and Incode. Some user data may not be fully protected in all scenarios.

    • 14 findings
    • Data Security 1
    • Network Security 2
    • Code Security 7
    • Privacy 3
    • Third-Party Risk 1
  • 69
    out of 100unTRUSTED

    GoodLeap Home

    Android

    What it means for you

    No advertising network receives data to display targeted ads to users. The build includes code to send usage and activity data to analytics and marketing services including Facebook App Events, RudderStack, Pendo, and Salesforce Marketing Cloud. Some user data may not be fully protected in transit.

    • 13 findings
    • Data Security 3
    • Network Security 1
    • Code Security 5
    • Privacy 3
    • Permission Usage 1
  • 69
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app usage and crash data to Firebase Analytics, Crashlytics, and Sentry. The app includes code to send purchase and subscription activity to RevenueCat. Users can optionally sync financial records to Dropbox or Google Drive. Stored financial data may not be fully protected on device.

    • 7 findings
    • Data Security 3
    • Code Security 1
    • Privacy 2
    • Third-Party Risk 1
  • 67
    out of 100unTRUSTED
    • 12 findings
    • Network Security 2
    • Code Security 7
    • Privacy 3
  • 66
    out of 100unTRUSTED

    What it means for you

    Financial data and session tokens are protected against extraction through device backup systems, and contacts data stays on the device without being transmitted to external services. The build includes code to send usage, referral, and performance data to Firebase, Branch.io, UserExperior, and Datadog, among others.

    • 11 findings
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 4
  • 66
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 10 findings
    • Data Security 1
    • Code Security 4
    • Privacy 3
    • Third-Party Risk 2
  • 65
    out of 100unTRUSTED

    Anker eufy

    Android

    What it means for you

    Firebase Analytics and crash reporting are disabled by default, so no usage telemetry leaves the device via those channels. The Sensors Analytics SDK, a Chinese behavioral analytics platform, is integrated into this build. No advertising networks are present, and some user data may not be fully protected.

    • 12 findings
    • Data Security 3
    • Network Security 3
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 65
    out of 100unTRUSTED

    What it means for you

    The build includes code to send in-app interaction and session data to FullStory, Firebase Analytics, and Urban Airship. Financial account connections are managed through Plaid, and identity verification through Onfido. The app also bundles Group-IB fraud detection and Sentry error reporting.

    • 9 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 64
    out of 100unTRUSTED

    Raiffeisen Bank SK

    Android

    What it means for you

    No advertising or behavioral tracking SDKs are bundled in build 341. Authentication keys and barcode scans remain on-device. Firebase Crashlytics is present for crash reporting; the code encrypts push notification content before handing it to the Firebase SDK, so Firebase does not see message content. The code for some banking requests may apply less protection than expected on public Wi-Fi.

    • 9 findings
    • Data Security 2
    • Network Security 2
    • Code Security 2
    • Privacy 2
    • Third-Party Risk 1
  • 64
    out of 100unTRUSTED

    Strava: Run, Bike, Walk

    Android
    • 1952 findings
    • Data Security 117
    • Network Security 196
    • Code Security 352
    • Privacy 496
    • Third-Party Risk 713
    • Permission Usage 78
  • 64
    out of 100unTRUSTED

    Interbank APP

    Android

    What it means for you

    Core financial data, including account balances, transactions, and card details, is processed on Interbank's own servers and is not passed to any analytics platform. The build includes code to pass install and usage data to services including Firebase Analytics, AppsFlyer, Adobe, and Microsoft Clarity. Camera-based features like barcode scanning use on-device processing with no data leaving the device.

    • 11 findings
    • Data Security 1
    • Network Security 1
    • Code Security 8
    • Privacy 1
  • 64
    out of 100unTRUSTED

    my moldcell

    Android

    What it means for you

    The app includes code to send account and usage data to Firebase Analytics, Facebook, and Google Ad Services for analytics and advertising purposes. Some code may send activity with less protection than expected on some network connections. An EVAM SDK also includes code to route data to a third-party provider outside major platform ecosystems.

    • 10 findings
    • Data Security 3
    • Network Security 2
    • Code Security 2
    • Third-Party Risk 2
    • Permission Usage 1
  • 58
    out of 100unTRUSTED

    What it means for you

    In-app behavior, including taps and screen interactions, is recorded by FullStory and Heap Analytics. The build includes code to send user activity to Salesforce Marketing Cloud for targeted messaging and to Firebase for performance tracking. The build includes multiple third-party SDKs whose code observes financial account interactions.

    • 7 findings
    • Data Security 2
    • Code Security 2
    • Privacy 3
  • 57
    out of 100unTRUSTED

    Bendigo Bank

    Android

    What it means for you

    Read the findings in full first. The build includes code to send precise location to Google (platform Geocoder backend), and credentials to Datadog, Google Maps Platform and 2 other recipients. The build includes code to send another 12 data points to other third parties. 11 critical or high severity findings, 1 of them at critical, spread across 4 categories are worth reading before this build handles anything a user would want kept to themselves.

    • 682 findings
    • Data Security 78
    • Network Security 82
    • Code Security 199
    • Privacy 153
    • Third-Party Risk 157
    • Permission Usage 13
  • 57
    out of 100unTRUSTED

    What it means for you

    Auth tokens and login sessions are encrypted on the device and cannot be extracted, and financial data is blocked from device backup systems. The build includes code to send usage and activity data to Firebase, Amplitude, AppsFlyer, and Facebook for analytics and advertising. Some financial data may not be fully protected across all areas of the app.

    • 8 findings
    • Data Security 1
    • Code Security 3
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 2
  • 55
    out of 100unTRUSTED

    Hearoes

    Android

    What it means for you

    Hearing training data, exercise progress, game scores, and user profiles are stored in the developer's own Firebase systems and not shared with data brokers or advertising networks. The build includes code to send usage and crash data to Firebase Analytics and Firebase Crashlytics, and purchase activity is handled by RevenueCat. Some data on the device may not be fully protected. All network requests in the code use encrypted connections.

    • 9 findings
    • Data Security 1
    • Code Security 6
    • Privacy 1
    • Permission Usage 1
  • 51
    out of 100unTRUSTED

    What it means for you

    Firebase Analytics, Crashlytics, and performance monitoring are switched off by default and require user consent to turn on; when marketing consent is declined, AppsFlyer is shut down and Braze data is wiped from the device. First-party analytics (Moose, Nudler) include code that names only NordVPN's own servers as destinations. When marketing consent is granted, the build includes code to send data to Braze and AppsFlyer.

    • 7 findings
    • Data Security 3
    • Code Security 2
    • Third-Party Risk 2
  • 51
    out of 100unTRUSTED

    Accolade, Inc.

    Android

    What it means for you

    Health records, appointments, and personal data are stored in an encrypted database and are protected from being copied via device backup. Sensitive health screens are blocked from appearing in the device task switcher. Build 334 bundles Firebase, Datadog, AppsFlyer, Segment, Braze, and Branch.io for analytics and crash reporting; Mixpanel integration routes through Accolade's own server.

    • 14 findings
    • Data Security 3
    • Network Security 3
    • Code Security 4
    • Privacy 4