Skip to content

Apps

146 app pages, the newest scanned on 1 October 2026. Each page covers one build: its score, its label and the file behind every finding.

  • 84
    out of 100TRUSTish

    Anker soundcore

    Android

    What it means for you

    The build includes code to send biometrics to soundcore/Anker cloud, and files to soundcore Anka AI. The build includes code to send another 4 data points to other third parties. Two findings are worth reading before this build handles anything a user would want kept to themselves. One is a high severity finding related to Network Security. One more is an open question the analysis could not settle.

    • 49 findings
    • Data Security 2
    • Network Security 10
    • Code Security 18
    • Privacy 7
    • Third-Party Risk 11
    • Permission Usage 1
  • 84
    out of 100NOT ASSESSED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 1 finding
    • Code Security 1
  • 84
    out of 100NOT ASSESSED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Network Security 1
    • Code Security 2
    • Privacy 3
    • Third-Party Risk 1
    • Permission Usage 1
  • 84
    out of 100unTRUSTED

    Money manager & expenses

    Android

    What it means for you

    The build includes the AppMetrica (Yandex), Facebook, and VK SDKs, whose code reads app usage data for analytics. Ads are served through Google AdMob and Yandex Mobile Ads. Locally stored data is well protected, though the app includes code that may send some app data with less protection than expected on certain connections.

    • 6 findings
    • Data Security 3
    • Network Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 84
    out of 100NOT ASSESSED

    Spending Tracker

    Android

    What it means for you

    The build includes the Firebase and Microsoft App Center SDKs, whose code reads usage and crash data. Ads are served via Google AdMob with a consent layer that defaults to non-personalised ads. Financial data stays on-device and is not backed up to cloud services automatically.

    • 3 findings
    • Data Security 2
    • Network Security 1
  • 84
    out of 100unTRUSTED

    My Orange Moldova

    Android

    What it means for you

    The build includes the Firebase Analytics and Batch SDKs, whose code reads app usage data for usage insights and push notifications, with analytics requiring explicit user consent before activation. Identity verification flows rely on AriadNext IDcheckio and Unissey, which may process document or biometric data. Some user data may not be fully protected in all transmission scenarios.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 4
    • Privacy 1
    • Third-Party Risk 1
  • 83
    out of 100TRUSTish

    WhatsApp Messenger

    iOS

    What it means for you

    Messages and calls are protected by end-to-end encryption, meaning Meta cannot read message content. No third-party analytics or advertising services are named in code as destinations for data; the telemetry code addresses only Meta's own infrastructure. The build includes code to send contacts only to Meta-owned systems, and the code reads no advertising identifier.

    • 3 findings
    • Code Security 3
  • 83
    out of 100TRUSTish

    What it means for you

    Note content is stored within Evernote's own infrastructure and is not passed to any third-party SDK, and no advertising identifier is collected. Firebase Analytics is disabled in this build, so usage data does not flow to Google. The build includes code to send crash reports to Firebase Crashlytics and Sentry, and to send App Store install attribution data to Apple AdServices and Bending Spoons.

    • 2 findings
    • Code Security 2
  • 83
    out of 100unTRUSTED

    Airbnb

    Android

    What it means for you

    Identity verification scans, including biometric checks and document images, are handled on the device via Google ML Kit and not routed to third-party servers. The app includes code to pass booking activity, device data, and location signals to Firebase, Google Analytics, Facebook, Singular, Branch, Incognia, and Bugsnag for analytics, fraud detection, and crash reporting.

    • 13 findings
    • Data Security 1
    • Network Security 2
    • Code Security 9
    • Privacy 1
  • 83
    out of 100unTRUSTED

    Reolink

    Android

    What it means for you

    Behavioral telemetry defaults to off and requires explicit opt-in. The code addresses usage data only to Reolink's own systems and names no third-party analytics or advertising networks as destinations. Camera location data is kept on the device and is not transmitted to Reolink servers.

    • 8 findings
    • Data Security 1
    • Network Security 4
    • Code Security 1
    • Privacy 1
    • Permission Usage 1
  • 83
    out of 100unTRUSTED

    George Česko

    Android

    What it means for you

    The app includes code to send app usage and analytics data to PostHog, Sentry, and Dynatrace for behavioral analytics, crash reporting, and performance monitoring. Firebase is used only for push notifications, not for analytics tracking. The build includes the ThreatMark and Innovatrics SDKs, whose code reads device security signals for fraud protection. Some user data may not be fully protected in all scenarios.

    • 7 findings
    • Data Security 2
    • Network Security 1
    • Code Security 1
    • Privacy 1
    • Third-Party Risk 2
  • 82
    out of 100unTRUSTED

    Akedo: Offline Games No WiFi

    Android

    What it means for you

    Gameplay runs offline after download, with no server calls needed during sessions. The app includes code to send device and usage data to Google Firebase and the developer's service at akedo.gg for analytics; the analysis found no code that reads health, location, financial, or contact data. Google AdMob is the only ad network present.

    • 5 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    X

    Android

    What it means for you

    Direct messages are end-to-end encrypted and excluded from device cloud backups. Camera frames captured during identity verification are processed on the device. The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Branch.io, and Datadog for analytics, advertising, and crash reporting.

    • 11 findings
    • Data Security 1
    • Network Security 2
    • Code Security 6
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    Revolut: Spend, Save, Trade

    Android

    What it means for you

    Financial transaction data is addressed in code only to Revolut's own servers; the build includes no code to pass financial information to advertising networks or data brokers. Usage analytics through Firebase and AppsFlyer are off by default, with no data shared until user consent is given. The app includes code to pass identity verification data to third-party providers during account onboarding.

    • 12 findings
    • Data Security 3
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 2
  • 82
    out of 100unTRUSTED

    Grok

    Android

    What it means for you

    The app includes code to pass usage and interaction data to Mixpanel, AppsFlyer, and Braze for analytics, attribution, and marketing engagement. Login tokens are stored in the protected Android credential store, isolated from other apps. Google Analytics is configured to exclude advertising identifiers, and support chat identity data is encrypted with hardware-backed storage.

    • 7 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
    • Privacy 1
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    bitchat

    Android

    What it means for you

    Message content is end-to-end encrypted and the developer operates no servers that receive it. No user accounts, analytics, or advertising SDKs are present. The Nostr messaging feature is configured to connect to public relay servers (damus.io, primal.net, and others), which handle message relay as part of the open Nostr protocol.

    • 9 findings
    • Data Security 1
    • Network Security 2
    • Code Security 4
    • Privacy 2
  • 82
    out of 100unTRUSTED

    Philips Hue

    Android

    What it means for you

    Location data from geofence automations stays on the device and is not forwarded to advertising or analytics services. Bridge login credentials are stored in hardware-protected on-device storage, excluded from cloud and device backups. The build includes code to send usage and crash data to Amplitude, Firebase, Braze, and Sentry.

    • 11 findings
    • Data Security 1
    • Network Security 4
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 82
    out of 100unTRUSTED

    What it means for you

    Financial data syncs only to the user's own iCloud container. Receipt scanning and AI-powered features run entirely on the device. The only external service is Setapp, used for subscription management.

    • 4 findings
    • Data Security 2
    • Code Security 1
    • Privacy 1
  • 82
    out of 100unTRUSTED

    What it means for you

    In the build, login sessions and authentication data are handled by the developer's own systems and the code gives third-party services no access to them. Document scans used for identity verification are processed on the device without being transmitted externally. The build includes code to send usage and behavioral data to Firebase Analytics, Singular, and Sprig for analytics and attribution.

    • 9 findings
    • Network Security 1
    • Code Security 5
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 82
    out of 100NOT ASSESSED

    What it means for you

    The build includes code to pass gaming activity and device identifiers to over a dozen advertising networks including Facebook, AppLovin, Google AdMob, Unity Ads, and Chartboost. The build includes code to pass analytics data through Firebase and Unity to monitor in-app behavior. Singular handles install attribution across these ad partners.

    • 3 findings
    • Network Security 1
    • Privacy 1
    • Third-Party Risk 1
  • 81
    out of 100unTRUSTED

    Yoti - your digital identity

    Android

    What it means for you

    Yes, on the evidence available. The build includes code to send precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. The build includes code to send another 13 data points to other third parties. None of the findings recorded rises to the level of putting a user at risk.

    • 1006 findings
    • Data Security 39
    • Network Security 432
    • Code Security 231
    • Privacy 249
    • Third-Party Risk 43
    • Permission Usage 12
  • 81
    out of 100unTRUSTED

    Navy Federal Credit Union

    Android

    What it means for you

    The build includes code to send usage data and crash reports to Firebase, Adobe Analytics, Salesforce, and Qualtrics for performance monitoring and feedback. No behavioral advertising SDKs are included, so usage data does not flow to ad platforms. The build includes code to send fraud detection data to Navy Federal's own servers before third-party risk services are involved.

    • 9 findings
    • Data Security 1
    • Network Security 4
    • Code Security 4
  • 80
    out of 100TRUSTish

    What it means for you

    The build includes code that restricts financial transaction data and app behavior to Revolut's own infrastructure; Firebase Analytics is disabled, so the build contains no code path to send transaction activity to Google. The build includes code that may send install attribution data to AppsFlyer and Branch.io, and includes code to send crash reports to Firebase Crashlytics. Google AdMob, an advertising network, is also linked in the build.

    • 4 findings
    • Data Security 2
    • Code Security 1
    • Permission Usage 1
  • 80
    out of 100unTRUSTED

    CNN: Live & Breaking News

    Android

    What it means for you

    The app includes code to pass viewing and interaction data to analytics and advertising services including Firebase Analytics, Adobe Analytics, AppsFlyer, Google AdMob, comScore, and Snowplow. The build includes a full consent-before-tracking flow via OneTrust for EU users, and code that blocks all advertising and analytics SDKs when the consent system does not confirm permission. Firebase Advertising ID collection is disabled in the build.

    • 6 findings
    • Data Security 1
    • Code Security 5
  • 80
    out of 100unTRUSTED

    MetService NZ Weather

    Android

    What it means for you

    The app includes code to pass usage and device data to Firebase Analytics, Google AdMob, Nielsen, Prebid, and Rubicon for analytics and ad measurement. Precise GPS coordinates are not included in advertising requests. A paid subscription removes advertising tracking exposure, though user data may not be fully protected in all scenarios.

    • 3 findings
    • Network Security 2
    • Code Security 1
  • 80
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Data Security 2
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 80
    out of 100TRUSTish
    • 3 findings
    • Data Security 2
    • Code Security 1
  • 80
    out of 100unTRUSTED

    What it means for you

    The app includes code to send app usage and behavioral data to Braze and AppsFlyer for marketing and attribution purposes. Bank account connectivity is handled through Plaid and Mastercard Open Banking. The app includes code to send crash reports to Bugsnag, and Optimizely runs A/B tests on user interactions within the app.

    • 5 findings
    • Data Security 1
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
  • 79
    out of 100unTRUSTED

    Gummo

    Android

    What it means for you

    Location data stays on the device and is not shared with Sentry, Firebase, or any analytics service. No advertising network SDKs are present. Firebase handles push notifications, and the Play Install Referrer library is linked for install attribution.

    • 7 findings
    • Data Security 3
    • Code Security 2
    • Privacy 2
  • 79
    out of 100unTRUSTED

    Glassdoor | Jobs & Careers

    Android

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 5 findings
    • Network Security 2
    • Code Security 2
    • Privacy 1
  • 79
    out of 100TRUSTish

    IBKR Mobile

    Android

    What it means for you

    The app includes code to send app usage and crash data to Firebase Analytics and Crashlytics. Financial document processing via MiSnap and QR scanning via ML Kit are handled on-device without sending image data externally. One data storage concern was identified where user data may not be fully protected at rest.

    • 7 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 2
  • 78
    out of 100unTRUSTED

    Meross

    iOS

    What it means for you

    Device commands route through the local network or Apple's end-to-end encrypted infrastructure, not through Meross servers. Account credentials are stored in the device's secure Keychain. The build includes code to send usage and crash data to Firebase Analytics, Firebase Crashlytics, and AWS services. No advertising network has access to usage data.

    • 4 findings
    • Network Security 1
    • Code Security 2
    • Privacy 1
  • 78
    out of 100unTRUSTED

    What it means for you

    Code shared across PayPal, Honey, and Xoom addresses only the developer's own infrastructure, and the build includes no code giving third-party ecosystems access to account credentials. Credentials and private keys are stored inside the device's Secure Enclave, not extractable from the device. The app includes code to pass usage, crash, and behavioral data to Firebase, Adjust, and Adobe for analytics and diagnostics.

    • 6 findings
    • Network Security 2
    • Code Security 3
    • Permission Usage 1
  • 78
    out of 100NOT ASSESSED

    WHOOP

    Android

    What it means for you

    Biometric health data, including heart rate, HRV, sleep stages, and blood oxygen levels, is not transmitted to third-party analytics or advertising services. GPS workout routes remain within WHOOP's own systems. The build includes code to send behavioral usage events to Amplitude and Sentry for analytics and error reporting.

    • 7 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
  • 77
    out of 100unTRUSTED

    Oura

    iOS

    What it means for you

    Sleep staging, HRV, and readiness scores are computed on the device by a PyTorch Mobile model, so the code keeps raw biometric sensor data on the device and contains no path to send it to the cloud. The build includes code to send usage and activity data to Segment, Amplitude, and Braze for analytics and engagement. No advertising SDK is present and no advertising identifier is collected.

    • 9 findings
    • Data Security 1
    • Code Security 4
    • Third-Party Risk 3
    • Permission Usage 1
  • 76
    out of 100unTRUSTED
    • 852 findings
    • Data Security 80
    • Network Security 76
    • Code Security 201
    • Privacy 213
    • Third-Party Risk 262
    • Permission Usage 20
  • 76
    out of 100unTRUSTED

    meross

    Android

    What it means for you

    No advertising networks or data broker SDKs are present in this build. The build includes code to send device usage statistics and crash reports to Firebase Analytics and Crashlytics. The build includes code that processes smart home device data through Meross infrastructure and AWS, and names no third-party monetization service in code as a destination of user data.

    • 11 findings
    • Data Security 4
    • Network Security 3
    • Code Security 2
    • Privacy 2
  • 76
    out of 100unTRUSTED

    Instagram

    iOS

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 2
    • Privacy 4
  • 76
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 4 findings
    • Data Security 1
    • Network Security 1
    • Code Security 1
    • Privacy 1
  • 76
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 8 findings
    • Data Security 1
    • Network Security 1
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 75
    out of 100TRUSTish

    VLC for Android

    Android

    What it means for you

    The build includes code to send credentials to OpenSubtitles, and authentication tokens to OpenSubtitles. The build includes code to send another 3 data points to other third parties. Four high severity findings related to Data Security and Network Security are worth reading before this build handles anything a user would want kept to themselves.

    • 370 findings
    • Data Security 105
    • Network Security 42
    • Code Security 147
    • Privacy 46
    • Third-Party Risk 18
    • Permission Usage 12
  • 75
    out of 100unTRUSTED

    United Airlines

    Android

    What it means for you

    Analytics and advertising SDKs from Google, Kochava, Quantum Metric, Mixpanel, and Snowplow are bundled in the build alongside core trip features. Location access requires a current trip context and an explicit permission grant from the user. Account credentials and reservation details are protected by device-level encryption.

    • 10 findings
    • Data Security 3
    • Network Security 2
    • Code Security 5
  • 75
    out of 100unTRUSTED

    Rakuten Viber Messenger

    Android

    What it means for you

    The app includes code to pass messaging activity and device data to advertising and analytics partners including Braze, Adjust, Facebook, and multiple ad networks. Firebase Analytics collection is disabled by default in the build manifest, and Mixpanel is configured to route through Viber's own CDN proxy, preventing Mixpanel from directly observing individual IP addresses. Payment authorization requires biometric authentication, and sensitive databases are excluded from cloud backups.

    • 11 findings
    • Data Security 1
    • Network Security 4
    • Code Security 3
    • Privacy 2
    • Third-Party Risk 1
  • 75
    out of 100unTRUSTED

    Kroger

    Android

    What it means for you

    Behavioral analytics code from the app's own system is directed only to Kroger's infrastructure, and the build includes no code to pass it to third parties. Pharmacy and biometric credentials are stored with hardware-backed encryption on the device. The build includes code to pass usage, crash, and device data to Firebase, Adobe Experience, Salesforce Marketing Cloud, and fraud-risk services including ThreatMetrix, Iovation, and Experian Accertify.

    • 12 findings
    • Data Security 2
    • Network Security 1
    • Code Security 6
    • Privacy 1
    • Third-Party Risk 2
  • 75
    out of 100unTRUSTED

    Wesper

    Android

    What it means for you

    Biometric health data, including sleep metrics and audio recordings, is addressed in code only to Wesper's own servers, and no advertising networks or data brokers are named as destinations. The app is configured to prevent health files from being extracted via device backup. The build includes code to send usage and app performance data to Firebase Analytics and Google services for diagnostics and improvement.

    • 10 findings
    • Data Security 2
    • Code Security 1
    • Privacy 5
    • Third-Party Risk 2
  • 75
    out of 100unTRUSTED

    What it means for you

    The app may include code to pass standard usage and device data to the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    • 12 findings
    • Network Security 4
    • Code Security 3
    • Privacy 4
    • Permission Usage 1
  • 75
    out of 100NOT ASSESSED

    What it means for you

    The build includes code to send usage and behavioral data to multiple advertising networks, including Facebook Audience Network, AppLovin, Vungle, and Yandex Mobile Ads, for targeted advertising. The build also includes code to send analytics to Firebase Analytics and Yandex AppMetrica, a Russian analytics provider. All backend communication uses HTTPS, and Google Drive backup is gated behind explicit user consent.

    • 10 findings
    • Data Security 5
    • Network Security 1
    • Code Security 2
    • Third-Party Risk 2
  • 75
    out of 100NOT ASSESSED

    EVO

    Android

    What it means for you

    The build includes Firebase Analytics and Crashlytics, whose code reads app usage statistics and crash reports. Google Ad Services is also present alongside these tools. One data storage concern means some user data may not be fully protected, though authentication credentials are encrypted and the app prevents backup access to sensitive data.

    • 8 findings
    • Data Security 3
    • Network Security 2
    • Code Security 3
  • 75
    out of 100unTRUSTED

    My Vodafone Romania

    Android

    What it means for you

    The app includes code to send app usage and account activity to Firebase Analytics, Adjust, Facebook, Tealium, Huawei HiAnalytics, Medallia, and Urban Airship for analytics, marketing attribution, and push messaging. Some code may send activity with less protection than expected on certain network paths. Account authentication uses hardware-backed key storage on the device.

    • 8 findings
    • Data Security 1
    • Network Security 2
    • Code Security 2
    • Privacy 1
    • Third-Party Risk 1
    • Permission Usage 1
  • 74
    out of 100unTRUSTED

    What it means for you

    Dating profile data, messages, and auth credentials are excluded from Google cloud backup and device transfers. Facial recognition processing occurs entirely on the device, and the build includes no code to pass raw biometric photos to third-party services. The app includes code to pass usage and behavioral data to advertising and attribution networks including Google Ad Manager, AppsFlyer, and LiveRamp, though seven tracking integrations are individually consent-gated.

    • 13 findings
    • Network Security 1
    • Code Security 8
    • Privacy 1
    • Third-Party Risk 2
    • Permission Usage 1