Skip to content

Apps

40 app pages, the newest scanned on 10 September 2026. Each page covers one build: its score, its label and the file behind every finding.

  • 95
    out of 100TRUSTish

    What it means for you

    Browsing history and tracker-block statistics stay on the device, with no third-party analytics, advertising, or crash-reporting SDKs present in this build. The bundled libraries (GRDB, Lottie, Kingfisher, and others) are utility components with no data-collection function. Telemetry is first-party and anonymous, with no persistent device identifiers and no search query content.

    • 2 findings
    • Code Security 2
  • 94
    out of 100TRUSTish

    What it means for you

    Yes on the security of the code, with what the build includes code to send worth reading first. The build includes code to send financial data to RevenueCat, and advertising identifiers to RevenueCat. None of the findings recorded rises to the level of putting a user at risk.

    • 20 findings
    • Data Security 1
    • Network Security 2
    • Code Security 5
    • Privacy 10
    • Third-Party Risk 1
    • Permission Usage 1
  • 86
    out of 100TRUSTish

    MyNISSAN®

    iOS

    What it means for you

    The build includes code to send vehicle commands and account data to Nissan's own servers, not third-party platforms. The build includes code to pass crash reports to Firebase, usage analytics to Adobe, and link attribution to Branch.io. An advertising identifier is made available to ad-measurement frameworks included in the app.

    • 1 finding
    • Data Security 1
  • 58
    out of 100unTRUSTED

    myGMC

    iOS

    What it means for you

    The build includes code to send usage and session activity to Heap (ContentSquare), Adobe Experience Platform, and Salesforce for analytics and marketing. The binary links the Arity SDK, an Allstate subsidiary that specializes in driving behavior analysis. In some areas, user data may not be fully protected.

    • 10 findings
    • Data Security 6
    • Code Security 2
    • Third-Party Risk 2
  • 78
    out of 100unTRUSTED

    Meross

    iOS

    What it means for you

    Device commands route through the local network or Apple's end-to-end encrypted infrastructure, not through Meross servers. Account credentials are stored in the device's secure Keychain. The build includes code to send usage and crash data to Firebase Analytics, Firebase Crashlytics, and AWS services. No advertising network has access to usage data.

    • 4 findings
    • Network Security 1
    • Code Security 2
    • Privacy 1
  • 78
    out of 100unTRUSTED

    What it means for you

    Code shared across PayPal, Honey, and Xoom addresses only the developer's own infrastructure, and the build includes no code giving third-party ecosystems access to account credentials. Credentials and private keys are stored inside the device's Secure Enclave, not extractable from the device. The app includes code to pass usage, crash, and behavioral data to Firebase, Adjust, and Adobe for analytics and diagnostics.

    • 6 findings
    • Network Security 2
    • Code Security 3
    • Permission Usage 1
  • 77
    out of 100unTRUSTED

    Oura

    iOS

    What it means for you

    Sleep staging, HRV, and readiness scores are computed on the device by a PyTorch Mobile model, so the code keeps raw biometric sensor data on the device and contains no path to send it to the cloud. The build includes code to send usage and activity data to Segment, Amplitude, and Braze for analytics and engagement. No advertising SDK is present and no advertising identifier is collected.

    • 9 findings
    • Data Security 1
    • Code Security 4
    • Third-Party Risk 3
    • Permission Usage 1
  • 44
    out of 100unTRUSTED

    Urban VPN

    iOS

    What it means for you

    WireGuard session keys are kept in memory only and not written to disk, and usage data is not tied to an advertising identifier. The build includes code to send usage and device data to Firebase Analytics and Mixpanel, and advertising measurement services from Google and Singular are used for ad attribution. Branch.io and OneSignal are also bundled for attribution and push notifications.

    • 2 findings
    • Code Security 1
    • Third-Party Risk 1
  • 61
    out of 100TRUSTish

    What it means for you

    Message content is not stored on Viber's servers, and media files are encrypted on the device. Calls are end-to-end encrypted. The build includes code to send usage and device data to advertising and analytics services including Adjust, Firebase, Braze, Mixpanel, Facebook Audience Network, and real-time ad bidding platforms.

    • 3 findings
    • Code Security 2
    • Privacy 1
  • 83
    out of 100TRUSTish

    WhatsApp Messenger

    iOS

    What it means for you

    Messages and calls are protected by end-to-end encryption, meaning Meta cannot read message content. No third-party analytics or advertising services are named in code as destinations for data; the telemetry code addresses only Meta's own infrastructure. The build includes code to send contacts only to Meta-owned systems, and the code reads no advertising identifier.

    • 3 findings
    • Code Security 3
  • 85
    out of 100unTRUSTED

    What it means for you

    No Meta Audience Network or Google AdMob SDK is bundled in this build; LinkedIn's advertising operates through its own infrastructure rather than external consumer ad networks. The build includes code to send usage, device, and attribution data to Singular, Apple AdServices, and Firebase Crashlytics. Qualtrics XM is also integrated for in-app surveys.

    • 7 findings
    • Network Security 3
    • Code Security 3
    • Privacy 1
  • 73
    out of 100unTRUSTED

    What it means for you

    Health and medical data stays on-device and syncs to the user's own iCloud account, not to developer servers. No behavioral analytics or advertising networks are integrated. RevenueCat is linked for subscription and in-app purchase management.

  • 89
    out of 100TRUSTish

    What it means for you

    HealthKit and workout GPS route data stays on the device and is not shared with advertising networks or data brokers. Analytics and in-app messaging are integrated with TelemetryDeck (privacy-preserving hashed identifiers) and Customer.io (EU data residency), with subscription management via RevenueCat. The backend runs on developer-controlled infrastructure at fitwoody.camp, keeping user data outside third-party cloud services.

    • 2 findings
    • Code Security 1
    • Privacy 1
  • 83
    out of 100TRUSTish

    What it means for you

    Note content is stored within Evernote's own infrastructure and is not passed to any third-party SDK, and no advertising identifier is collected. Firebase Analytics is disabled in this build, so usage data does not flow to Google. The build includes code to send crash reports to Firebase Crashlytics and Sentry, and to send App Store install attribution data to Apple AdServices and Bending Spoons.

    • 2 findings
    • Code Security 2
  • 80
    out of 100TRUSTish

    What it means for you

    The build includes code that restricts financial transaction data and app behavior to Revolut's own infrastructure; Firebase Analytics is disabled, so the build contains no code path to send transaction activity to Google. The build includes code that may send install attribution data to AppsFlyer and Branch.io, and includes code to send crash reports to Firebase Crashlytics. Google AdMob, an advertising network, is also linked in the build.

    • 4 findings
    • Data Security 2
    • Code Security 1
    • Permission Usage 1
  • 51
    out of 100TRUSTish

    What it means for you

    VPN credentials are stored in device hardware and never leave the chip. No advertising or behavioral tracking SDKs are present in the binary. The build includes code to send crash reports to Proton's own infrastructure, and the destinations named in code for other data are all within the Proton developer ecosystem.

    • 2 findings
    • Network Security 1
    • Code Security 1
  • 73
    out of 100unTRUSTED

    What it means for you

    Health and workout data stays on the device and does not flow to third-party analytics or advertising services. The build includes code to send usage and behavioral data to analytics and marketing services including AppsFlyer, Amplitude, and Mixpanel for attribution and engagement measurement. Firebase Analytics is disabled in the build, and EU-region routing is configured for Amplitude and Customer.io.

    • 5 findings
    • Data Security 1
    • Code Security 3
    • Third-Party Risk 1
  • 88
    out of 100TRUSTish

    Airbnb

    iOS

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Data Security 1
    • Network Security 2
    • Code Security 1
    • Privacy 1
  • 88
    out of 100TRUSTish

    ChatGPT

    iOS

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

  • 76
    out of 100unTRUSTED

    Instagram

    iOS

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Privacy 4
  • 87
    out of 100unTRUSTED

    Reflect Notes

    iOS

    What it means for you

    Journal and note content is encrypted before syncing to the developer's own Firebase storage. No advertising, attribution, or broad analytics SDKs are present. Error reporting via Sentry is configured to limit behavioral data capture, and the build includes code for authentication through Google Sign-In and Firebase.

    • 3 findings
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 82
    out of 100unTRUSTED

    What it means for you

    Financial data syncs only to the user's own iCloud container. Receipt scanning and AI-powered features run entirely on the device. The only external service is Setapp, used for subscription management.

    • 4 findings
    • Data Security 2
    • Code Security 1
    • Privacy 1
  • 92
    out of 100unTRUSTED

    Widgetsmith

    iOS

    What it means for you

    Health, calendar, contacts, reminders, and photos data stays on the device and is not transmitted to third parties. Location, when granted for weather widgets, is kept out of advertising and analytics flows. Ad delivery uses Google Mobile Ads with ATT-based consent, and the build includes code to manage subscriptions through RevenueCat and Superwall.

    • 1 finding
    • Code Security 1
  • 88
    out of 100unTRUSTED

    What it means for you

    Trip content, itineraries, and booking details are not shared with advertisers, data brokers, or cross-app tracking systems. AI-assisted features, including email parsing and itinerary suggestions, run entirely on the device. The build includes Mixpanel and Sentry code that reads usage and crash data to support app performance.

    • 3 findings
    • Data Security 1
    • Code Security 2
  • 64
    out of 100unTRUSTED

    MOVAhome

    iOS

    What it means for you

    Widget data is shared only within the developer's own systems, with no third-party access. Login session credentials are stored in the iOS Keychain rather than in plaintext. The build includes code to send usage and device data to analytics and advertising services from ByteDance, Umeng (Alibaba), Baidu, and Facebook.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 6
  • 85
    out of 100unTRUSTED

    WHOOP

    iOS

    What it means for you

    The build includes code to direct health and biometric data, including heart rate, HRV, sleep, and GPS, only to WHOOP's own infrastructure, and contains no code to pass it to advertising or analytics networks. The build includes code to send usage data to Amplitude for product analytics and to Sentry for crash reporting. The build contains no code that reads advertising identifiers, and internal performance telemetry is processed locally; the build contains no code to send it to third-party clo…

    • 5 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
  • 92
    out of 100TRUSTED

    What it means for you

    Health and workout metrics stay on the device and are not sent to any third-party service. The app includes code to send app usage and session data to Mixpanel for analytics and to Adjust for attribution. Advertising identifier access requires explicit user consent before it can be activated.

  • 76
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 84
    out of 100NOT ASSESSED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 1 finding
    • Code Security 1
  • 80
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Data Security 2
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 76
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 84
    out of 100NOT ASSESSED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Network Security 1
    • Code Security 2
    • Privacy 3
    • Third-Party Risk 1
    • Permission Usage 1
  • 98
    out of 100TRUSTED

    Wikipedia

    iOS

    What it means for you

    App usage is tracked only by Wikipedia's own first-party analytics, with consent collected at onboarding. Donation payments are processed through Adyen and Apple Pay. The build includes no code to send user data to advertising networks, behavioral tracking companies, or third-party analytics services.

    • 1 finding
    • Code Security 1
  • 72
    out of 100unTRUSTED

    cred.ai

    iOS

    What it means for you

    Financial account connections via Plaid, document scans, and biometric checks are processed as part of identity verification. The app includes code to pass app usage and attribution data to AppsFlyer, Segment, and Google Tag Manager. The app includes code to pass fraud detection signals to TransUnion. User financial data may not be fully protected in all storage scenarios.

    • 11 findings
    • Data Security 5
    • Network Security 1
    • Code Security 3
    • Privacy 2
  • 88
    out of 100NOT ASSESSED

    What it means for you

    The app includes code to pass app usage data, including session behavior and feature interactions, to Firebase Analytics, Amplitude Analytics, and Google App Measurement. When the user consents via Apple's App Tracking Transparency prompt, the build includes code to pass attribution data to Adjust and Facebook SDK to measure ad campaigns. OneSignal handles push notifications, and the app includes code to pass subscription and paywall activity to RevenueCat and Superwall.

    • 6 findings
    • Data Security 1
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 2
  • 89
    out of 100NOT ASSESSED

    What it means for you

    The build includes the TelemetryDeck and Sentry SDKs, whose code reads app usage and crash data, both operating under GDPR-compliant terms with EU data residency and no personal identifiers. No advertising networks, behavioral trackers, or device fingerprinting tools are present. Health-related data is processed on-device only and not transmitted to external servers.

    • 7 findings
    • Data Security 2
    • Code Security 3
    • Privacy 2
  • 98
    out of 100TRUSTED

    What it means for you

    Signal stores messages, voice and video calls, and contact data on-device. The build includes no code to send user data to analytics, advertising, attribution, or crash-reporting services. Third-party libraries are limited to UI components (SDWebImage, Lottie, BonMot) and data utilities (SwiftProtobuf, GRDB, libPhoneNumber_iOS). MobileCoin handles optional peer-to-peer payments.

    • 3 findings
    • Data Security 1
    • Network Security 1
    • Permission Usage 1
  • 99
    out of 100TRUSTED

    Brotherhood Alchemist

    iOS

    What it means for you

    All gameplay activity remains on the device. No data is transmitted over the network, and no user information is retained after a session ends. UIDevice access is limited to detecting screen orientation for layout purposes.

    • 1 finding
    • Privacy 1
  • 86
    out of 100NOT ASSESSED

    Jenius

    iOS

    What it means for you

    The build includes code to pass usage and behavioral data to AppsFlyer, Google Analytics, MoEngage, and Firebase for analytics, attribution, and messaging. The build also includes code to pass transaction and device activity to NewRelic for performance monitoring. Identity verification is handled via ZOLOZ KYC, and three specialized services monitor for fraud.

    • 13 findings
    • Data Security 4
    • Network Security 2
    • Code Security 4
    • Privacy 2
    • Third-Party Risk 1
  • 94
    out of 100TRUSTED

    What it means for you

    Ente Auth stores two-factor authentication secrets locally with strong encryption, excluded from iCloud backups by default. The app includes code to send crash reports to Sentry, with code that strips authentication tokens and cookies from them first. The build includes no code to send user data to advertising, analytics, or attribution services.

    • 0 findings