Gemini
The Gemini APK is a shell. Across 14 verified scans it contains just over 5,000 classes - Signal ships twelve times that - and exactly one detectable SDK: Google Sign-In. Its manifest requests almost nothing: no location, no camera, no contacts. That is not because Gemini collects little. The actual assistant runs inside the Google app and Google Play Services, where a scan of this package cannot see it, and data collection happens server-side against your Google account. The honest finding is the architecture: there is nothing to catch in this APK because the interesting parts live elsewhere.
Read from the bytecode.
Do not read one SDK as one data flow. This APK is a thin client: what Gemini learns about you is governed by your Google account settings and processed on Google servers, outside what any on-device scan of this package can prove. Static analysis is honest about its limits here - the binary is clean because the binary does almost nothing.
This is static analysis of the APK bytecode installed on real devices: it proves which SDK classes and manifest permissions ship in the app, not what the app transmits at runtime. Traffic analysis is a different measurement.
Hidden inside the code.
Keep reading.
The anatomy of a background ping: what your phone tells Google at 3am
Most Android phones send data while you sleep. Here's what one hour of nighttime pings revealed about Google Play Servic...
The False Negative Problem: Why Most Spyware Scans Miss What Matters
Most Android spyware detection tools check the wrong things. Here's why 73% of privacy violations hide in plain sight an...
Similar risk profiles.
Scan Gemini yourself.
Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.