AppXpose AppXpose
← All scans
Verified scan · DEX

Proton Mail

ch.protonmail.android · v7.10.4

Proton sells privacy, so its APK deserves the audit: 12 verified scans across 9 devices, versions 7.9 through 7.10, consistently find three SDKs - Sentry for crash reporting, Firebase for push delivery on Play builds, and Google Sign-In classes. No advertising, attribution, or third-party product analytics. Proton documents that it runs crash reporting against its own infrastructure, but the Sentry classes themselves are what the bytecode shows. Permissions are a textbook match for a mail client: contacts for address completion, camera for attachments, biometrics for the app lock.

3
verified trackers
3
Trackers Found
3
Dangerous Permissions
9
Devices
12
Verified Scans
Verified evidence

12 verified scans from 9 devices. Latest verified version 7.10.4, as of August 2026.

Read from the bytecode.

For an encrypted-mail flagship this is close to the minimum viable SDK surface: crash telemetry and the push plumbing Play Store builds need. Your mail content is end-to-end encrypted before any of this code sees anything. The one nuance worth knowing: on Play builds, the wake-up signal for new mail transits Google infrastructure - the mail itself does not.

This is static analysis of the APK bytecode installed on real devices: it proves which SDK classes and manifest permissions ship in the app, not what the app transmits at runtime. Traffic analysis is a different measurement.

Trackers

3 SDKs detected

Hidden inside the code.

Sentry Crash Reporting
Google Firebase Push (FCM)
Google Sign-In Authentication
Permissions

3 flagged

What it asks for.

medium
READ_CONTACTS

Address completion while composing - opt-in, expected for mail

medium
CAMERA

Photographing attachments and QR scanning - expected

medium
USE_BIOMETRIC

Biometric app lock - protective feature

Scan Proton Mail yourself.

Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.