AppXpose AppXpose
← All scans
MEDIUM Risk · Score 38/100

ChatGPT

com.openai.chatgpt

ChatGPT is a legitimate productivity app from OpenAI with strong encryption, but requests several permissions that exceed typical chat app needs - location, camera, media access, and screen capture detection. Conversations are stored on OpenAI servers for service improvement, and the app includes ad-tech integrations.

38
out of 100
4
Trackers Found
5
Dangerous Permissions
8
Risk Factors
0
Known Breaches
Warning

Regulatory & Legal

Conversations may be reviewed by OpenAI staff for safety and improvement purposes. Location permission requested without clear justification for text chat functionality.

Score Breakdown

+18
Excessive Permissions

7 dangerous permissions including location, camera, and screen capture detection

+12
Data Collection & Retention

Conversations stored on OpenAI servers for safety and improvement

+8
Trackers & Analytics

Firebase, Mixpanel, Segment, and AD_ID permission for ad targeting

+8
Aggressive Monetization

ChatGPT Plus subscription paywall with usage limits on free tier

-8
Encryption & Transport

TLS 1.2+ encryption in transit; data encrypted at rest on OpenAI servers

-6
Developer Reputation

OpenAI - transparent privacy policies and regular security audits

-4
Update Frequency

Active development with consistent security patching

-2
GDPR Compliance

GDPR-compliant; users can request data access and deletion

Trackers

4 SDKs detected

Hidden inside the code.

Google Analytics (Firebase) Analytics
Google Crashlytics Crash Reporting
Mixpanel Analytics
Segment Analytics
Permissions

5 flagged

What it asks for.

medium
ACCESS_FINE_LOCATION

Precise GPS - not needed for a text chat app

medium
ACCESS_COARSE_LOCATION

Approximate location tracking for analytics

medium
CAMERA

Image analysis features, but granted by default

medium
RECORD_AUDIO

Voice chat features - granted by default

medium
DETECT_SCREEN_CAPTURE

Unusual for a chat app - may prevent screenshot sharing

Scan ChatGPT yourself.

Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.