Knowledge · Check before you click or pay · 8 minutes
How to check if an app is safe: mobile apps and business SaaS
Mobile apps: source, publisher, permissions, Data safety label. Web apps for business: privacy policy, subprocessors, data location, DPA, who gets your data.
Last updated: October 5, 2026
How do you check if an app is safe?
A safe app does only what it says with your data and does not let the wrong people reach it. From the outside you cannot see the code or the servers, so you check signals: who is behind the app, what access it asks for, what it declares about data, and whether those declarations match what you can observe.
There are two different cases. A phone app asks for access to your device: camera, contacts, location. A web app, a browser-based subscription product (SaaS), keeps your company's data on someone else's servers. You assess the first in the store and in your phone settings, the second through the vendor's documents and what the site sends to third parties.
None of these methods gives a guarantee. They give an answer in three parts: what is known, what is not known, and what to ask.
Where to download a phone app and how to check the publisher
Install from Google Play or the App Store, not from a file sent in a message or a link in a text. An installer from outside the store skips the review the store runs at publication.
On the store page, check the publisher name. An app from a bank, a government office or a courier should be published by that organisation, not by a private person or a company with a similar name. The safest route is to open the organisation's official website and follow its link to the store. You can check the website address for free: domain age, presence on the CERT Polska warning list and similarity to known brands.
Look at the download count, the date of the last update and reviews from recent weeks. An app nobody has updated in years gets no security fixes. Fake reviews can be bought, so treat reviews as a signal, not proof.
What permissions does the app have on your phone
A permission is the system's consent for an app to reach part of the phone: camera, microphone, location, contacts, text messages. The rule is simple: the permission must fit the feature. A flashlight does not need contacts and a calculator does not need location.
On Android you change permissions in Settings under Apps, and according to Google's help pages you can limit location, camera and microphone to while the app is in use. The system can also remove permissions from apps you have not opened for a long time.
On iPhone, iOS 15.2 and later include App Privacy Report (Settings, Privacy and Security). According to Apple it shows how often apps accessed location, camera or microphone over the last 7 days and which domains they contacted. It is one of the few places where an ordinary user sees what an app actually does rather than what it declares.
Be especially careful with requests for text messages, accessibility services and device administrator rights. They give control over the phone and over bank codes, which is why malicious apps use them.
What the Google Play Data safety section and App Store App Privacy label tell you
Both describe what data the app collects, why, and whether it shares it. The App Store splits data into three groups: data used to track you, data linked to you and data not linked to you. Apple defines tracking as linking app data with other companies' data for advertising, or passing it to data brokers.
An important caveat: the developer fills in both sections. Google's help states that developers describe their own data collection and sharing there, and Apple says the developer is responsible for keeping answers up to date and can change them without submitting a new app version.
How to use them: compare the label with the permissions and the privacy policy. If the store says no data collected while the app asks for contacts and location, something does not add up. A missing label or a missing privacy policy is a separate warning sign.
How to check if a web app (SaaS) is safe for your business
With a business app the stake is customer and employee data, so the question is who will process it and where. Start with the documents a vendor should publish.
Privacy policy: who the controller is, what data, how long it is kept. Subprocessor list: the companies the vendor passes your data to, such as hosting, email, analytics or an AI model. Data location: the country or region and whether data leaves the European Economic Area. Data processing agreement (DPA): Article 28 of the GDPR requires one when the vendor processes personal data on your behalf.
A security.txt file is a short file at /.well-known/security.txt, defined in RFC 9116, with a contact for reporting vulnerabilities. Having one does not prove security, but it shows the company has a place to receive a bug report.
Then there is the technical layer any visitor can see: an encrypted connection, security headers, cookies and the domain's email protection (SPF, DMARC). More on that in how to check if a website is safe.
Who does the app send your data to
Every website and web app loads outside services: analytics, chat, advertising pixels, session recording tools. Each of them receives at least the visitor's IP address, and some receive what the visitor types. If that service is missing from the subprocessor list, the documents and reality do not match.
This is what the free arLET'S website or app check shows, with no account needed. It looks like an ordinary visitor, without logging in and without intrusion testing: encryption, headers, cookies, which third parties the site sends data to, whether there is a privacy policy, terms and company details, security.txt and DMARC. The result tells you what is visible from outside. It does not tell you what happens after login or on the vendor's servers.
The logged-in part, such as whether one customer can see another customer's data, needs a test authorised by the vendor. Typical failures in that layer are covered in what shows up in apps built fast.
What to ask the app vendor
You do not guess what you cannot see from outside. You ask and you keep the answer in writing. Good questions have a yes, a no or a we do not know as the answer:
1. Where are our data and backups physically stored? 2. Which subprocessors can access them, and will you notify us when the list changes? 3. Is our company's data separated from other customers' data, and how do you test that? 4. Does login require a second factor (2FA), and can we enforce it for everyone? 5. Does our data go into AI models, including for training? 6. When was the last external security test, and can we see a summary? 7. How quickly will you notify us of a data breach?
How to read answers, certificates and test reports is covered in how to read a vendor security assessment. If you are choosing a tool for your company and need an evidence-based assessment, see what arLET'S does for buyers.
In short
- Install phone apps only from the official store, ideally through the organisation's own website, and check the publisher name.
- Permissions must fit the feature. Access to text messages, accessibility services and device administration are the strongest warning signs.
- The data labels on Google Play and the App Store are filled in by the developer. Compare them with the permissions and the privacy policy.
- Judge a business web app by its documents: privacy policy, subprocessors, data location, DPA, security.txt.
- From outside you can see who the site sends data to. What happens after login cannot be judged without questions to the vendor or an authorised test.
Have a website, app or email address that looks suspicious?
Frequently asked questions
Is every app on Google Play or the App Store safe?
No. Stores review apps at publication, but the data label is written by the developer, and apps imitating known brands do get through. Check the publisher and the permissions.
How do I see what permissions an app has?
On Android: Settings, Apps, choose the app, Permissions. On iPhone: Settings, Privacy and Security, where you find the permission list and App Privacy Report.
Can I check an app online for free?
For a web app, yes, as far as what is visible from outside: encryption, headers, cookies, third-party services and documents. The arLET'S check does this without an account. It is not a penetration test.
What is a subprocessor?
A subprocessor is a company the app vendor passes customer data to for processing, such as a hosting, email or AI model provider. The subprocessor list should be public or available on request.
Does a business app need a data processing agreement (DPA)?
Yes, if the vendor processes personal data on your company's behalf. Article 28 of the GDPR requires it. Many SaaS vendors offer a standard template.
Sources
- Google Play Help: Data safety section
- Apple Developer: App privacy details on the App Store
- Apple Support: About App Privacy Report
- Android Help: Change app permissions on your Android phone
- Regulation (EU) 2016/679 (GDPR), Article 28: processor
- RFC 9116: A File Format to Aid in Security Vulnerability Disclosure (security.txt)
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.
See also
- How to check if a website is safe: 7 checks before you trust it
- How to read a vendor security assessment
- Five things that show up in apps built fast
- How to check if an email is real: sender, headers and DMARC
- Fake invoices and bank account change emails: how to check
- How to check if a link is safe before you click it