What your apps actually do.
Real scan reports from AppXpose. Every tracker, permission, and risk factor extracted from live APK analysis - not estimated, not self-reported by developers.
Meta-owned, 7 trackers, FTC $5B fine - your browsing history funds the ad machine.
Score 68/100 HIGH - $5B FTC fine, €422M GDPR fines, and "severe" data exposure.
X (Twitter)
9 trackers, unencrypted DMs, a 5.4M-user data breach, and aggressive ad profiling.
Adobe Acrobat
Camera, microphone, and 7 ad trackers on a PDF reader - plus a 152M-account data breach.
Snapchat
9 trackers, background location access, and a 2014 breach exposing 4.6M users.
Messenger
9 trackers including AdMob, GPS location on a messaging app, and two Facebook data breaches exposing 500M+ users.
Telegram
71 permissions requested, 4 trackers detected - strong encryption partially offsets aggressive data access.
Audio recording, location tracking, and 7 ad trackers on a text-based social platform.
Binance
13 trackers including TikTok SDK and WeChat SDK - your crypto app talks to Chinese ad networks.
Amazon Shopping
11 trackers, background location, and WeChat SDK - Amazon knows where you shop, online and off.
PayPal
13 trackers including Meta SDK and Adjust - your payment app shares data with ad networks.
Uber
57M-user breach cover-up, persistent location tracking, and payment data shared with analytics firms.
AliExpress
Chinese jurisdiction, 5 ad trackers, thousands of vendors accessing buyer data, and opaque data governance.
Google Maps
6 trackers including Meta SDK, background GPS tracking, and contact harvesting on a navigation app.
E2E encrypted messages, but Meta harvests your metadata - who you talk to, when, and where.
ChatGPT
GPS location, screen capture detection, and ad tracking on a text chat app - plus conversations stored on OpenAI servers.
Spotify
9 trackers, location access on a music app - Spotify profiles your listening and your movements.
Netflix
Microphone and camera on a video player - plus ad-tech integrations that profile your viewing habits.
Microsoft 365
Facebook SDK, Google AdMob, and Microsoft telemetry in your Office suite - plus AD_ID tracking.
Discord
E2E encrypted DMs, but metadata collection and ad-tech SDKs feed behavioral profiling.
Airbnb
Minor permission overreach and 5 ad trackers - standard for a major travel platform.
Canva
Zero dangerous permissions and cloud-based design - minor ad-tech trackers typical of freemium apps.
Brave Browser
Open-source, built-in ad blocker, and only 3 essential trackers - a privacy-first browser.
Google Docs
No dangerous permissions, but Google reads your documents - no end-to-end encryption option.
Firefox
Open-source, non-profit, Enhanced Tracking Protection by default - privacy built into the foundation.
Outlook
Zero dangerous permissions and enterprise-grade encryption - one of the safest email clients scanned.
Google Wallet
Zero dangerous permissions and strong encryption - one of the safest financial apps scanned.
DuckDuckGo
Zero trackers, zero dangerous permissions, zero search history stored - the gold standard for private search.
Bitwarden
Zero trackers, zero permissions, open-source, and end-to-end encrypted - the safest credential manager.
Claude
6 verified SDKs across 15 devices: Segment, Sentry, Datadog, plus a manifest that declares 25 Health Connect read permissions.
Steam
4 verified SDKs including the Meta SDK - Facebook code in your gaming companion - plus a READ_PHONE_STATE permission most apps retired years ago.
Signal
3 verified SDKs, all Google infrastructure: FCM push transport, Sign-In classes, and Maps for location sharing. Zero ad-tech, verified across 8 devices.
Tor Browser
3 verified SDK signatures - Sentry, Firebase, Google Sign-In - all Firefox inheritance riding along in the bytecode of the anonymity browser.
Proton Mail
3 verified SDKs - Sentry, Firebase push, Google Sign-In classes - and zero ad-tech. The permission list reads like a mail client and nothing more.
Google Authenticator
2 verified SDKs across 27 devices - Firebase and Google Sign-In, both riding on the cloud-sync feature a TOTP app would not otherwise need.
1.1.1.1 + WARP
A privacy VPN carrying verified Google AdMob classes and advertising-ID permissions in its manifest. No visible ads - but the code ships.
Google Play Store
2 verified trackers in Google's own app store · AdMob and Maps ship in the bytecode.
Gemini
One verified SDK and an almost empty manifest - because the real Gemini lives in the Google app and on Google servers, not in this APK.
AdGuard
One verified SDK - Sentry crash reporting - in the tool that strips everyone else's. The heavy permissions are the product doing its job.
Call text on other devices
Samsung's cross-device call/SMS bridge ships 1 ad tracker - Google AdMob - inside a system-level service.
Clock
A stock alarm app with 1 tracker - Meta SDK - and broader permissions than the category suggests.
Aurora Store
A privacy-focused Play client with 1 verified tracker - Meta SDK - present in bytecode.
F-Droid
0 verified tracker SDKs across 9 devices. The baseline every other scan report on this site can be measured against.
Calculatrice
Samsung's popup calculator · 0 trackers, 2 permissions, clean bytecode across 8 scans.
Network Storage Manager
Samsung NAS utility · 0 trackers · 2 permissions, both expected for the job.
Files
Google's built-in file manager: 0 trackers, 2 permissions, nothing unexpected.
Biometrics
Samsung's biometric settings manager: 0 trackers, no third-party code, permissions match the job.
Scan your apps.
These are just 47 of the 2,000+ apps scanned with AppXpose. Download the app and scan anything on your phone - free, no account needed.
JETZT BEI Google Play