Skip to content

Publishing policy and corrections

Last updated 2 October 2026

A public Deep scan of a store app is published at /apps/{package} when the scan finishes. A free rule scan stays in the account that started it. Uploaded builds and scans for customer projects are never published; a private scan is published only when its owner chooses. A page is removed or edited only on the three grounds listed under Removal grounds.

Which scans become public pages

ScanPublic page at /apps/{package}
A public Deep scan of an app listed in a public storeYes, when the scan finishes. The person who requests it is told at submission that the result is public.
A free rule scanNo. Its results are visible in the account that started it.
A scan CanITrustThat runs for a teardown, a category sweep or the catalogueYes, as above.
A private scan on a paid planNo, until its owner chooses to make it public and the app is in a public store.
An uploaded APK, XAPK or IPANo, ever. The build may be unreleased or internal.
A scan run for a customer's research projectNo, ever. CanITrustThat runs its own public scan instead.
An app no longer in its storeThe page stays with the date of removal and the last scanned version, and is kept out of search indexes.

What a public page never shows

  • Secret values found in an app (API keys, account ids, tokens, private keys, secret files), whole, masked or hashed. A page states the kind and the count.
  • Personal data found in the app's strings or resources.
  • Decompiled source beyond a file path and a line number.
  • Anything from a customer's project, or the fact that a customer scanned an app.
  • A compliance status under any law or regulation.

Right of reply

A developer replies to a page, or reports a factual error, by email to [email protected] from an address at the app's own domain or the contact address of its store listing, naming the page.

A reply is published beside the page as written, with its date, after a check for abuse and personal data. A reported error opens a review of the rule match. A developer may also ask for a rescan of a newer build. CanITrustThat contacts no developer about a page.

Update cadence

A page changes only when a public scan completes: after a new store version, a free rescan request, or the scheduled rescan of every public app. Each update keeps the previous scan as a dated entry, and nothing earlier is rewritten without a dated note.

Removal grounds

A page is removed or edited only when:

  • the scanned package is not the app the page names;
  • the page shows data this policy excludes;
  • a court or authority orders it.

A removal request on other grounds is answered with the right of reply, and the request is recorded.

Corrections

A correction that alters a published statement is recorded with its date, the rule id and version, what changed and how many app pages it affected, and each page it changed shows a dated note.