# Can I trust these apps?

**URL:** https://discuss.privacyguides.net/t/can-i-trust-these-apps/25190
**Category:** Off Topic
**Tags:** software
**Created:** 2025-02-21T14:01:57Z
**Posts:** 16

## Post 1 by @PrivacyEnthusiast — 2025-02-21T14:01:58Z

**1. What do I want to protect?**

I aim to protect the following assets:

- **Files, Documents, and Notes:** These include personal, sensitive information stored on my device.
- **Usage Patterns and Choices/Interests:** I want to keep my digital behavior and preferences private.
- **Digital Identity:** Safeguarding my identity to prevent misuse or theft.

* * *

**2. Who do I want to protect it from?**

My potential adversaries include:

**OSINTers** , **Government** , **Big-Tech companies**

* * *

**3. How likely is it that I will need to protect it?**

The likelihood of needing protection varies:

- **High Risk:** For sensitive files, documents, and notes(mostly unique project details), where compromise could lead to dire consequences.
- **Moderate Risk:** For usage patterns and app choices, where single app compromises are less impactful but still concerning.
- **Critical Importance:** For protecting my digital identity, as identity theft is a severe threat.

* * *

**4. How bad are the consequences if I fail?**

The consequences of failing to protect my assets are severe:

- **Identity Theft:** Could lead to financial loss, loss of non-patented projects, reputation damage, and legal issues.
- **Loss of Confidentiality:** Compromise of sensitive files could result in personal or professional repercussions.
- **Privacy Breach:** Unauthorized access to usage patterns could expose my digital behavior, leading to targeted advertising or surveillance.

* * *

**5. How much trouble am I willing to go through to prevent potential consequences?**

I am willing to:

- **Implement Complex Configurations:** Use advanced privacy tools and encryption methods.
- **Undergo Multiple Layers of Encryption:** To ensure robust protection of my data.
- **Sacrifice Some Convenience:** If it means enhancing security and privacy.

* * *

I prefer to stay anonymous and also want to avoid censorship , so I use InviziblePro with Tor and DNSscrypt enabled.

I use File Explorer[[File Explorer - IzzyOnDroid F-Droid Repository](https://apt.izzysoft.de/fdroid/index/apk/com.raival.compose.file.explorer/)], Proton drive, EasyNotes[[Easy Notes | F-Droid - Free and Open Source Android App Repository](https://f-droid.org/packages/com.kin.easynotes/)] and Notesnook for managing essential assets.

**App Evaluations:**

1. **Book’s-story [[Book's Story | F-Droid - Free and Open Source Android App Repository](https://f-droid.org/packages/ua.acclorite.book_story/)]:**

2. **Lichess [[lichess | F-Droid - Free and Open Source Android App Repository](https://f-droid.org/packages/org.lichess.mobileapp.free/)]:**

3. **TrackerControl [[TrackerControl - IzzyOnDroid F-Droid Repository](https://apt.izzysoft.de/fdroid/index/apk/net.kollnig.missioncontrol/)]:**

4. **PHONK [[PHONK - IzzyOnDroid F-Droid Repository](https://apt.izzysoft.de/fdroid/index/apk/io.phonk.extended/)]:**

5. **OpenAthena™ [[OpenAthena™ for Android | F-Droid - Free and Open Source Android App Repository](https://f-droid.org/packages/com.openathena/)]:**

* * *

---

## Post 2 by @anon29374801 — 2025-02-21T18:01:01Z

This reads like a low effort post where you want other users to do all the research for you.

What is your threat model? Trust is going to be relative to that.

What about these apps concerns you? Have you read their privacy policies?

What apps are you currently using and why are you considering replacing them with the ones listed?

---

## Post 3 by @user1 — 2025-02-21T18:44:00Z

> [@PrivacyEnthusiast](#):
>
> Lichess[[lichess | F-Droid - Free and Open Source Android App Repository](https://f-droid.org/packages/org.lichess.mobileapp.free/)]

Lichess on Fdroid is and old deprecated app and you would be better using the PWA which works quite nicely. There is a [new android beta app](https://github.com/lichess-org/mobile) in development but it’s not full featured yet.

---

## Post 4 by @BluePhoenix — 2025-02-21T19:01:51Z

+1, and the new application is better.  
Lichess is opensource and community founded.  
The [presentation](https://lichess.org/@/Lichess/blog/the-new-mobile-app/KXlgb3X2)  
[Exodus](https://reports.exodus-privacy.eu.org/en/reports/org.lichess.mobileV2/latest/) reports 1 “tracker” used for crash reporting  
The permissions are minimal.

---

## Post 5 by @anon42475305 — 2025-02-21T19:11:31Z

These types of posts are frowned upon. Please understand that this forum does not exist to replace doing your own research. Only you can decide whether you believe the aforementioned apps are trustworthy. If you have specific questions about these apps, then we may be able to help you.

I strongly recommend against getting your apps from F-Droid. And you should use apps with more than a handful of users which are also actively maintained.

---

## Post 6 by @PrivacyEnthusiast — 2025-02-21T19:13:00Z

Got it! What about now?

---

## Post 7 by @PrivacyEnthusiast — 2025-02-21T19:19:41Z

I’m extremely sorry and sincerely apologize for it. I hope the edited version meets the requirements of self-research & specific questions.

---

## Post 8 by @KevPham — 2025-02-21T19:32:35Z

Even with your edits, we don’t really know what you are looking for specifically. Your threat model isn’t a description of the devices you own but rather the actors you are trying to protect yourself against.

Regarding your concerns on “non-free” services or usability, it’s up to you whether these sacrifices are worth the trade-off. You seemed to be concerned about both security and free software, but you might need to make compromises.

Ask yourself questions like: “Can this application function offline?” or “When was the latest update?”

---

## Post 9 by @anon29374801 — 2025-02-21T20:27:09Z

As @KevPham mentioned, you did not really provide a threat model. I think it would be beneficial to you to read through [Threat Modeling: The First Step on Your Privacy Journey - Privacy Guides](https://www.privacyguides.org/en/basics/threat-modeling/) and then come back and edit this post. :slight_smile:

---

## Post 10 by @PrivacyEnthusiast — 2025-02-22T05:43:30Z

I really really hope this one follows the suggestions.

---

## Post 11 by @anon29374801 — 2025-02-22T22:41:39Z

Looks good!

A few things

> [@anon42475305](#):
>
> I strongly recommend against getting your apps from F-Droid.

Maybe look into using [Obtainium](https://github.com/ImranR98/Obtainium) to get these apps.

> [@user1](#):
>
> Lichess on Fdroid is and old deprecated app

As @user1 suggests maybe use a PWA.

> [@PrivacyEnthusiast](#):
>
> TrackerControl

You may want to consider a private DNS solution instead. Check [DNS Resolvers - Privacy Guides](https://www.privacyguides.org/en/dns/)

> [@PrivacyEnthusiast](#):
>
> OpenAthena

[privacy policy](https://opentopography.org/privacypolicy)

I don’t know anything about drones but it seems like based on what the app does its going to need a lot of permissions to gather the data.

They do share randomized data that they collect. The app appears to be in beta. Those would be the things to consider, from what I can tell.

---

## Post 12 by @PrivacyEnthusiast — 2025-02-23T13:37:54Z

What are your thoughts on PHONK and Book’s story?

---

## Post 13 by @overdrawn98901 — 2025-02-23T14:38:03Z

I’ll reframe it the question to you - what about PHONK and Books story are you unsure about? Is there specifically something unclear, or unsure how to evaluate these entities from the ground up?

I think it might be a good time to learn how to determine if you should trust an app for your use case, and see what specific unknown you are deferring. I’m also thinking is this a skill set that PG could write about in a blog :thinking:

---

## Post 14 by @anon29374801 — 2025-02-23T17:23:06Z

> [@PrivacyEnthusiast](#):
>
> What are your thoughts on PHONK and Book’s story?

PHONK is just not at all in my realm so I did not feel comfortable speaking on it. Maybe someone more aware of its use cases or more knowledgeable about phone permissions will speak on it.

Book’s Story links did not work for me. If I was going to use an ebook reader (more of an Audio book on phone type) I would probably just remove all permissions and use it offline (not sure if that works for you). In that case its just about finding an aesthetic that you like.

have you looked at [PocketReader](https://pocketbook.ch/en-ch/app) or [koreader](https://github.com/koreader/koreader)?

---

## Post 15 by @PrivacyEnthusiast — 2025-02-23T18:11:01Z

Ok, I understood it. What specifcally bothers me about phonk are: Will it leave a penetrable hole in my anonymous network? What are these permission required for exactly? Will they review or do something with my codes(like IdK, feeding the code to AI)? Are they gonna secretly track my activity if leave any door(vulnearablity in my network) open?

---

## Post 16 by @PrivacyEnthusiast — 2025-02-23T18:19:34Z

Pocket Readers privacy-policy concerns me(they might share data to third-party-services). Koreader isn’t visually appealing to me at all.
