This repository contains the results of a July 2021 investigation into Android apps that are utilized for opioid addiction treatment and recovery. This research was conducted by Sean O'Brien of the ExpressVPN Digital Security Lab with the aid of Esther Onfroy of the Defensive Lab Agency. Findings are described on our website.
We encourage users to independently validate the investigation results. This information is released for consumer awareness only and should be interpreted by security professionals.
Consumers: Consult our findings summary.
Researchers: Consult the files below.
- All Apps: JSON | CSV - Findings for all apps
- SDK Signatures: List of SDK signatures identified in apps
- Bicycle Health:
bicycle-health_1.0.5.apk
- Boulder Care:
boulder-care_1.141.0.apk
- Confidant Health:
confidant-health_2.0.14.apk
- DynamiCare Health:
dynamicare-health_1.0.186.apk
- Kaden Health:
kaden-health_21.3.30.apk
- Loosid:
loosidapp_3.8.20.apk
- Pear Reset-o:
pear-reset-o®_1.6.1.apk
- PursueCare:
pursuecare_1.0.0.apk
- Sober Grid:
sobergrid_3.3.82(212).apk
- Workit Health:
workit_1.8.0.apk
Inside every directory of findings about each app, you will find:
*.apk.256sum
: SHA-256 checksum for the Android APK installercall-graphs
directory: Call graphs for the Android app in digraph and PNG formatexodus-report.json
: Exodus Privacy report in JSON format
If you have any questions or suggestions regarding these findings, email us at digital-security-lab@expressvpn.com.