Auto Secure LoginPlatform

Practical guide

Check where an Android app sends your data

A practical review checklist for local files, optional exports, accounts and server analysis, illustrated with published ASL Android workflows.

Reviewed October 7, 2026

Follow one piece of data through the workflow

“Private” is not one switch. A file can remain local while an optional export creates a copy elsewhere, or an app can offer local mode alongside a connected service. Start with a harmless sample and write down where it enters, where analysis happens and what leaves when you press each button.

Four questions to ask

  1. What is selected? A single APK, a journal entry, a photo or a network inventory are different data types. Record what you deliberately provided and what the app generated.
  2. Where does processing happen? Distinguish device-local inspection from analysis submitted to a server. Do not infer this from the app being installed on a phone.
  3. What action creates a copy? Sign-in, submission, export, sharing and backup can cross different boundaries. An exported file may be readable by the destination app even when the original app protects its own storage.
  4. What remains afterward? Review local history, chosen exports, account records and the service’s retention terms. Clearing one screen does not prove every copy was deleted.

Examples from the ASL catalog

WorkflowPublished boundaryUseful review question
X-Ray LiteLocal static APK inspectionDoes the report distinguish permissions, evidence and analysis coverage from observed runtime behavior?
X-Ray ProAuthorized account and confirmed upload to a private analysis serviceWhat exact file was submitted, what job was created and which report was exported?
Kavanah JournalEncrypted device-local journal with chosen exportsWhere did the chosen export go, and how is that copy protected?
StubSafeLocal document creation and explicit exportDoes the exported document contain only the accurate, authorized records you intended?
Network SentinelLocal Wi-Fi scan or separately configured connected monitoringWhich mode did you use, and where did its inventory or alert record live?
Pillow PairLocal guest assessment; optional account features have a separate boundaryWhich photos stayed on-device and which result records, if any, did you choose to save to an account?
AyaAccount-based checks using credits and supported sourcesWhat input did you approve, what did it cost and which conclusions remain uncertain?

Make a checkable review record

Record the app ID and installed version, Android version, selected mode, permissions you granted, the input sample and every deliberate export or submission. Compare your observations with the current store listing, in-app help and privacy notice. A visual walkthrough is useful evidence of that workflow; it is not an independent security audit or proof that no network traffic occurred.

Keep product limits in the conclusion

Static APK findings do not guarantee safety. A network scan can miss devices. A caller-risk signal is not proof of identity. Pillow-fit estimates are not clinically validated. State the question each tool helped answer and the questions your review left open.

Open the 13 Android listings · Read APK permissions and findings · Inspect a labelled APK report example

Help / Ayuda