Proton Mail
Proton sells privacy, so its APK deserves the audit: 12 verified scans across 9 devices, versions 7.9 through 7.10, consistently find three SDKs - Sentry for crash reporting, Firebase for push delivery on Play builds, and Google Sign-In classes. No advertising, attribution, or third-party product analytics. Proton documents that it runs crash reporting against its own infrastructure, but the Sentry classes themselves are what the bytecode shows. Permissions are a textbook match for a mail client: contacts for address completion, camera for attachments, biometrics for the app lock.
Read from the bytecode.
For an encrypted-mail flagship this is close to the minimum viable SDK surface: crash telemetry and the push plumbing Play Store builds need. Your mail content is end-to-end encrypted before any of this code sees anything. The one nuance worth knowing: on Play builds, the wake-up signal for new mail transits Google infrastructure - the mail itself does not.
This is static analysis of the APK bytecode installed on real devices: it proves which SDK classes and manifest permissions ship in the app, not what the app transmits at runtime. Traffic analysis is a different measurement.
Hidden inside the code.
What it asks for.
Address completion while composing - opt-in, expected for mail
Photographing attachments and QR scanning - expected
Biometric app lock - protective feature
Keep reading.
The messaging app exodus nobody saw coming
WhatsApp lost 25 million users in one week after a single policy change. Here's where they went and why it matters for y...
The Privacy-First App Stack: What I Actually Use Instead of the Defaults
Real alternatives to tracker-heavy apps tested over 18 months. Specific recommendations for messaging, email, maps, and ...
Similar risk profiles.
Scan Proton Mail yourself.
Get the full report on your device - with real-time DEX analysis, permission auditing, and breach monitoring. Free, no account needed.