AppXpose AppXpose
FILE 001 / TRACKERS / EVIDENCE LOG
Issue No. 1

Your phone is
talking. To
strangers.

The average Android app you installed today ships with 7 third-party tracker SDKs baked into its bytecode. AppXpose tears the app apart on your device and shows you exactly which ones, before they start phoning home.

WATCH DEMO · TAP TO PLAY
II. The evidence

The Mozilla number below. Three more studies behind the link.

80%

of Google Play's privacy labels are inaccurate or incomplete.

In 2023, Mozilla compared the Data Safety labels of the 40 most-downloaded apps on Google Play with their own privacy policies. For 16 of them, including Minecraft, Twitter and Facebook, the two documents didn't match. Store labels are self-declared. Nobody verifies them.

Mozilla Foundation · February 2023 · "See No Evil"

Read four studies →
EXPOSED ↓
↓ EXPOSED
google.firebase.analytics DETECTED facebook.appevents DETECTED com.adjust.sdk DETECTED com.appsflyer DETECTED io.branch.referral DETECTED com.onesignal DETECTED com.mixpanel.android DETECTED com.amplitude.api DETECTED com.crashlytics DETECTED com.huawei.hms DETECTED com.flurry.android DETECTED com.unity3d.ads DETECTED com.applovin.sdk DETECTED com.ironsource DETECTED com.tapjoy DETECTED com.singular.sdk DETECTED google.firebase.analytics DETECTED facebook.appevents DETECTED com.adjust.sdk DETECTED com.appsflyer DETECTED io.branch.referral DETECTED com.onesignal DETECTED com.mixpanel.android DETECTED com.amplitude.api DETECTED com.crashlytics DETECTED com.huawei.hms DETECTED com.flurry.android DETECTED com.unity3d.ads DETECTED com.applovin.sdk DETECTED com.ironsource DETECTED com.tapjoy DETECTED com.singular.sdk DETECTED
III. Live corpus

Real-time data from production. Every scan feeds the models.

Full dossier →
Connecting...
IV. Our data

5,820 apps scanned. Every chart from real production data.

Full research →
62.3%

of apps score MEDIUM or higher risk

274

verified tracker signatures detected

8,013

verified tracker detections across the corpus

VI. Always-on protection / GUARD
€9,99 / month · €49,99 / year

Five alerts.
Watching the apps
while you don't.

GUARD is the part of AppXpose that runs while you're not looking. Breach checks and tracker change detection are powered by the community: when any user scans an app, every GUARD user with the same app benefits. Permission changes, app removals, and signing certificate changes are monitored locally on your device. When something changes you get one clear notification.

Get GUARD →
A1
Breach Alert
Continuous
Our server checks developer domains against HIBP centrally. When a new breach is detected, every GUARD user with an affected app gets notified. You don't need to scan yourself.
A2
Tracker Change Alert
Community-driven
When any AppXpose user scans an app and it has more trackers than the previous version, all GUARD users with that app are alerted. One scan protects everyone.
A3
Permission Change Alert
Every 24h
A flashlight app suddenly wants your contacts? You hear about it the moment the manifest changes after an update.
A4
App Removed Alert
Every 24h
When Google pulls an app from the Play Store, you get the story. Usually before the news writes about it.
A5
Developer Change Alert
Every 24h
Apps get sold all the time. New owner means a different signing certificate. We monitor the cert and flag when it changes.
VII. Pricing

No tiers labelled "Enterprise". No "Contact sales". No upsells.

Two plans.
Honest prices.

T1
Free

For the curious.

0 incl. VAT
forever
GET IT ON Google Play
  • 5 scans per week
  • Basic scan results
  • Community verdict
  • Watch an ad for bonus scans
RECOMMENDED
T2
GUARD

For the responsible.

9,99 incl. VAT
monthly · 49,99 / year
Subscribe →
  • Unlimited scans
  • Scan up to 50 apps at once
  • App Index with full scan history
  • 5 background alerts
  • Community-powered breach + tracker alerts
  • Daily app diffs
  • No ads. Ever.
  • Cancel anytime
Summer special. Ends Sep 30
GUARD Lifetime

One payment. All future GUARD features. Forever. No subscription, so there is nothing to cancel and nothing to forget about.

99,99 once
Get GUARD Lifetime →

Prices include VAT. Google Play sets prices per country, so the exact amount can differ where you live. Play shows the final price before you confirm.

Billed via Google Play. Cancel anytime in Play → Subscriptions.

VII. Frequent questions

If yours isn't here, write us. We'll add it.

What people
always ask first.

Q1

Does AppXpose upload my apps to a server?

+
No. The DEX bytecode analysis runs entirely on your device. We only contact our edge for cached metadata (tracker signatures, breach status), and those requests are anonymized via HMAC-signed device fingerprints. No email, no Google account, no advertising ID.
Q2

How is this different from network ad blockers?

+
Ad blockers stop network requests after they fire. AppXpose tells you which trackers are baked into the app itself, even ones that only fire on certain conditions. Diagnosis vs. treatment.
Q3

Why pay if scanning is local?

+
Only the bytecode analysis is local. Everything that makes the scan readable is server-side and AI-assisted: the paywall and monetization breakdown, the developer profile (who they are, where their servers live, GDPR posture), the risk score reasoning, the data-sharing probabilities, and the natural-language explanations next to every finding. Each scan triggers calls to LLM APIs, the HIBP proxy, the Exodus tracker database, and our cached signature store on Cloudflare D1. We also run five GUARD background workers and a community vote system. None of that runs for free. The free tier covers casual checks; Pro and GUARD cover people who want the full pipeline without rationing.
Q4

Is the source code public?

+
Not yet. AppXpose is a solo project still in heavy development. The scan pipeline was rewritten multiple times in recent months because better detection approaches kept surfacing. Publishing it now would mean publishing a moving target. The plan: once the detection engine's interfaces stabilize (signature format, scoring inputs, pipeline boundaries), it gets opened. In the meantime, the full scoring model (the detection methodology, data sources, and architecture), detection methodology, data sources, and architecture are documented at appxpose.app/how-it-works. The code is closed. The methodology is not.
Q5

iOS version?

+
No. iOS's sandbox model prevents the kind of bytecode analysis AppXpose performs. It's Android-only and likely will stay that way.
VIII. Final note

Trust no app.
Verify them all.

AppXpose is free to install and free to try. Five scans a week, full results, no signup, no card. The whole thing took longer to download than to use.

END OF FILE 001
⊕ FILED · INDEPENDENT · BERLIN