ReNotify - your android notification center
▲ 13 r/droidappshowcase+2 crossposts

ReNotify - your android notification center

I built ReNotify because I kept swiping notifications away on autopilot and then spending five minutes trying to remember what the thing even was. I also tried for days and weeks to collect RevnueCat Notifications to make a screenvideo for my X account, sadly they dissapeared after 1 Week if I remember correctly.

So I came up with this, I saw there are a few others, but I wanted to create my own.

Most notification history apps are just logs. You can read what you missed, but that is it. ReNotify actually pushes notifications back into your notification bar, with the original timestamp, the original app icon, and tap-to-open the source app. So it lands exactly where you expect it, not in some separate list you have to remember to check. It shows trends to your notifications as well, but it can do a few things more:

What it does:

- Records every incoming notification: app, title, message, exact time
- Resend one, several, or all of them back into the bar
- Snooze any notification like an alarm ("in 1 hour", or an exact time)
- Create your own notifications with a custom title, message and date
- Search the whole history by app, title or message text
- Notification Trends

Privacy side, since this app sees everything:

- Local-first, all data stays on the device
- No account, no sign-up, no cloud
- Per-app filter so you can exclude sensitive apps from being recorded
- CSV export if you want your data out

Two things worth being upfront about: it needs notification access, which is
requested on first launch and can be revoked any time. And whether every
notification gets captured depends on your OEM battery management, so the
app walks you through the relevant settings.

Play Store: ReNotify

u/MahereMarley — 2 days ago

My App Reached 5,000 Downloads with 78 Reviews

After ~5 months of publishing my app on Google Play, it has reached 5,000 downloads and 78 reviews, most of them positive (4.5★).

I built a privacy scanner for Android. It analyzes the actual APK bytecode of your installed apps on your device and shows what's inside:

hidden tracker SDKs, dangerous permissions, repackaged or fake APKs, and known stalkerware with a plain-language explanation for every finding.
Nothing gets uploaded from your phone.

I know 5,000 downloads may not seem like a huge number, but for me it's an important milestone and a great motivation to keep improving.

What worked best so far was writing about actual scan findings instead of promoting the app itself - people care about what's inside the apps they
already use.

If you have any advice on how to grow faster, I'd love to hear your suggestions. Happy to answer questions about the technical side too.

App

u/MahereMarley — 22 days ago
▲ 0 r/apps

I built an Android app that scans your installed apps for hidden trackers, spyware and fake APKs

Hey everyone,

I'm a solo dev from Germany. I built AppXpose because I kept reading studies showing that Play Store privacy labels don't match what apps
actually do and there was no tool a normal person could use to check. Everything that existed was built for security researchers.

How it works:

- You pick the apps you want to check, scan takes a few seconds
- It analyzes the actual APK bytecode on your device nothing gets uploaded
- You get a risk score 0-100 plus what's actually inside: hidden tracker SDKs (270+ signatures), dangerous or out-of-place permissions, repackaged/fake APKs, known stalkerware
- Every finding comes with a plain-language explanation instead of a permission wall nobody reads
- Detection improves without app updates: unknown SDK signatures found across devices get confirmed and synced daily

I also just shipped a spyware & stalkerware check that runs against public surveillance-app lists.

Been at it a 5 months now, 4960 installs, and I'm still fixing things based on feedback, if you try it and something feels off, tell me.

Play Store: https://play.google.com/store/apps/details?id=com.appxpose.app

Website https://appxpose.app

u/MahereMarley — 22 days ago

[OC] I analyzed 5,000+ Android apps: every dot is an app, plotted by verified trackers in its code vs. privacy risk - the outliers surprised me

Data source: On-device APK bytecode scans from users of a privacy scanner I built. The tracker counts are DEX-verified - each one means the tracker SDK was found in the app's actual code on a real device, matched against 274 signatures (136 from public tracker lists, 138 discovered through community scans and only counted once the same code signature surfaced in 3+ independent apps).

The risk score (y-axis / risk charts) is AI-assessed from the scan findings (trackers, permissions, integrity checks) labeled as such in the charts, since that's a different kind of measurement than the verified tracker counts.

Tools: Python, Matplotlib.

Numbers: 5,055 fully scored apps. 62.3% score MEDIUM or higher, 613 apps (1 in 8) are HIGH risk. Zero apps hit CRITICAL, which honestly surprised me. In the HIGH-risk group, the most common permissions are pure ad infrastructure: advertising ID (62%), install-source tracking (58%), ad attribution (54%) cameras and microphones come far behind.

The finding I didn't expect: smart home companion apps. The apps controlling cheap smart light bulbs carry as many verified trackers as Google's own Analytics app the most tracker-packed app in the corpus.

Full Research: https://appxpose.app/research/q3-2026

Happy to answer methodology questions

u/MahereMarley — 1 month ago
▲ 3 r/droidappshowcase+3 crossposts

ERA ME, an AI journal that remembers you

Hey everyone, solo dev here. Just launched my first app on the Play Store and wanted to show it off.

ERA ME is a journal with memory. You write, and the book writes back. Over time it learns your recurring themes, the people in your life, and how you've changed, and it reflects that back to you. There's a heart that fills up the more it knows you, 30-day "arcs" built around things like boundaries or self-worth, and a little wrapped-style recap when you finish a chapter.

The whole thing has a dark grimoire aesthetic, gold and violet, more magical artifact than productivity tool. Built with Kotlin and Jetpack Compose, backend on Cloudflare Workers, reflections powered by Claude.

Writing and streaks are free, the AI reflections are part of Pro.

Play Store: https://play.google.com/store/apps/details?id=com.fluxare.erame

Happy to answer anything about the app or the build. Honest feedback very welcome

u/MahereMarley — 2 months ago

scanned Roblox to see why kids end up spending hundreds of dollars on it. the monetization flags are wild

my younger cousin racked up like 200 bucks
in Robux without anyone noticing so i got
curious and ran Roblox through a privacy
and monetization scanner

the paywall got flagged as "predatory" and
honestly the breakdown explains a lot:

- aggressive monetization specifically
targeting minors
- limited-time offers, battle passes, game
passes designed to create urgency
- no built-in purchase limits
- spending can escalate fast with basically
no friction
- documented cases of kids spending hundreds
without parents knowing

monetization aggressiveness scored +16 on
the risk breakdown. child safety and
moderation +14. estimated trackers +18.

to be fair some stuff came back fine. breach
risk was 0, encryption was decent, developer
reputation wasnt terrible. it's not malware.
it's just built to extract money from kids
who don't understand what they're spending.

IAP range goes from $0.99 all the way to
$99.99+ per purchase.

if you've got kids playing this, the in-app
purchase limit in Android settings is worth
setting up. you can cap or require a password
for every purchase.

anyone else dealt with surprise Robux charges?
curious how common this actually is

u/MahereMarley — 2 months ago

why does my phone get warm and drain battery after closing certain apps?

been noticing this for a while. some apps i
close and the phone is fine. others i close
and like 20 min later the phone is warm and
the battery dropped way more than it should.

mostly happens after social apps and one
crypto app i use.

i checked battery usage in settings and a
couple apps were still running in the
background way after i closed them. one still
had location active even though i wasnt using
it.

started going through permissions one by one
and revoked background location for everything
that didnt need it. helped a bit.

then i scanned a few apps with AppXpose to see
what was actually inside them and some had way
more trackers than i expected. one had the
meta sdk in it even though its not a meta app.

so now im wondering - is the background
activity the main reason for the battery
drain, or is it the trackers constantly
pinging servers? or both?

anyone know whats actually causing the warmth
and drain? trying to figure out if its worth
restricting these apps further or if im just
being paranoid

reddit.com
u/MahereMarley — 2 months ago

The White House ordered its app on every federal employee’s phone. I scanned the APK. There’s GPS tracking code inside. It’s just “not active yet.”

in May 2026 the FAA told employees their government phones would automatically install
the White House app "as mandated by the
White House." no action required. no opt-out.

I scanned the APK

permissions that are GRANTED automatically:
- starts on every device boot
- prevents device from sleeping
- microphone in the manifest

the part nobody is talking about:

independent researchers found GPS tracking
code inside the bundled OneSignal SDK.
set to poll location every 4.5 minutes
while in the foreground.

the app does not currently request location
permission. the function is not active.

but the code is there

an app with boot access, wake lock, microphone permission, and dormant GPS polling code. mandatory on millions of federal phones. bypassing normal agency security review.

"government retains plaintext for review"
that's a direct quote from the privacy analysis of the APK.

draw your own conclusions.

sources:
- Government Executive (May 22, 2026)
- FAA internal email ("as mandated by
the White House")
- AppXpose APK scan (gov.whitehouse.app)
- FedTools independent analysis

reddit.com
u/MahereMarley — 3 months ago

The White House ordered its app on every federal employee’s phone. I scanned the APK. There’s GPS tracking code inside. It’s just “not active yet.”

in May 2026 the FAA told employees their government phones would automatically install
the White House app "as mandated by the
White House." no action required. no opt-out.

I scanned the APK

permissions that are GRANTED automatically:
- starts on every device boot
- prevents device from sleeping
- microphone in the manifest

the part nobody is talking about:

independent researchers found GPS tracking
code inside the bundled OneSignal SDK.
set to poll location every 4.5 minutes
while in the foreground.

the app does not currently request location
permission. the function is not active.

but the code is there

an app with boot access, wake lock, microphone permission, and dormant GPS polling code. mandatory on millions of federal phones. bypassing normal agency security review.

"government retains plaintext for review"
that's a direct quote from the privacy analysis of the APK.

draw your own conclusions.

sources:
- Government Executive (May 22, 2026)
- FAA internal email ("as mandated by
the White House")
- AppXpose APK scan (gov.whitehouse.app)
- FedTools independent analysis

reddit.com
u/MahereMarley — 3 months ago

built our own payment processor after getting tired of frozen accounts and useless support

had our payments frozen out of nowhere twice in one year. no warning, no real explanation, just an automated email and a 10 business day hold.

called support both times. first time got an AI bot. second time a human who just read from a script and couldn't tell me anything. meanwhile suppliers waiting, bills due, nothing you can do.

at some point you just get tired of building your business on infrastructure that can pull the rug whenever their algorithm decides you're suspicious.

so we built our own. live now, 24h payouts, no frozen accounts.

anyone else just completely done with relying on stripe and paypal? how are you handling it?

reddit.com
u/MahereMarley — 3 months ago

I scanned 20 mobile games to see how predatory they actually are. here’s what the data says

we all feel it. the countdown timers. the
"limited offer" popups. the battle pass that
expires in 3 days. but how bad is it really?

i ran 20 popular mobile games through a
privacy and monetization scanner. here's
what came back:

every single one had aggressive FOMO design
flagged. artificial scarcity, time pressure,
loss aversion triggers baked into the UI.

the tracker situation was also wild:
- average 6-8 third party trackers per game
- most had 2-3 dedicated ad SDKs running
in the background
- a few flagged for known malware signatures
on abuse.ch

the worst part: none of this shows up in
the Play Store listing. the data safety
section is basically self-reported.

games i scanned included some you definitely
have installed. the pattern was consistent
across casual, mid-core, and gacha games.

if you want to check your own games:
- AppXpose( scans the APK directly, flags
FOMO patterns, trackers, and malware hashes)

what game are you most curious about?
drop it below and i'll scan it 👇

reddit.com
u/MahereMarley — 3 months ago

got banned by 3 payment processors in 2 years - what are you guys using for high risk products?

selling digital products and fashion. stripe banned me, paypal froze my account, shopify payments same story.

eventually got tired of it and found a processor that actually works for my niche. approval was fast, payouts next day, no monthly fees. Sellstein is its name

curious what others in similar situations are using - seems like this is a pretty common problem but nobody talks about solutions

reddit.com
u/MahereMarley — 3 months ago

I built a Shopify alternative with a built-in payment processor after getting banned by Stripe

got rejected by stripe paypal and shopify payments too many times. so I built my own

SellStein is two things: a full e-commerce platform (store builder, products, orders, analytics, marketing) and a payment processor built for merchants stripe keeps rejecting.

registration open. payments live. 42 countries. approval under 15min. 24h payouts. no monthly fee. high risk welcome. We are looking for early first testers - dm me here, email us on the website, use the contact formula or join the discord server

if you've ever seen "your account presents a high level of risk" - this was built for you💪🏽

need people to break it and tell me what sucks.

sellstein.com

reddit.com
u/MahereMarley — 3 months ago
▲ 5 r/websitefeedback+2 crossposts

[BETA] Built a payment processor after getting banned by Stripe 25 times - need 5-10 testers

got banned by stripe paypal and shopify payments. so i built my own processor.

its called SellStein. shopify alternative + own payment processor in one. high risk friendly, 42 countries, approval under 15min, payouts next day, no monthly fee.

need 5-10 people to test the whole thing before launch. store builder, payments, dashboard, onboarding, all of it. break it, tell me whats wrong.

free access + founding member badge if you help.

dm me. sellstein.com

u/MahereMarley — 3 months ago

been playing since day 1. my phone kept acting weird after every session. took me a while to figure out why

battery dying faster than usual. phone warm after raids. lag that wouldn't go away even

after closing the app. blamed the update. then the next update. eventually started actually looking into it.

background location was the first thing. pogo keeps tracking your GPS after you close it.

that alone explains the battery drain most people complain about.

then i checked the full permission list. 142 MB app. 42 permissions. the ad stack alone:

ACCESS_ADSERVICES_ATTRIBUTION

ACCESS_ADSERVICES_AD_ID

ACCESS_ADSERVICES_CUSTOM_AUDIENCE

ACCESS_ADSERVICES_TOPICS

AD_ID

5 separate ad permissions. for a pokemon game. but the one i still can't explain: READ_CONTACTS. no feature in the game uses your contacts. people flagged this back in 2016. niantic never addressed it. you can revoke it in settings and literally nothing breaks.

niantic is a real company, not some shady startup. but pogo is also one of the largest real-world location mapping operations ever built. every walk you take feeds that.

if you want to check for yourself:

- android settings → apps → pokemon go →permissions (check background location)

- AppXpose if you want to see the full APK breakdown

- revoke contacts permission, game runs fine

still day 1 player. not going anywhere.

just thought more people should know this.

u/MahereMarley — 3 months ago

The Binance Android app is a Chinese surveillance suite with a trading interface bolted on top

Was setting up a fresh Pixel for a friend getting into crypto. Pulled the APKs of his installed apps through a tracker scanner before handing it back. Binance was the worst by a wide margin.

The official Binance Android APK ships with SDKs from ByteDance (TikTok parent) and Tencent (WeChat parent), plus more than a dozen other trackers. Checked the AndroidManifest, they're declared at install time, not loaded dynamically. AppsFlyer, Branch, Adjust, Sensors Data, ByteDance Applog, Tencent Beacon.

Ad-tech SDKs aren't passive. They collect device fingerprints, behavioral signals, and can read clipboard contents on Android 9 and older without any prompt. On Android 10+ clipboard access still works while the app is in the foreground, which is most of the time you're using a crypto app. The clipboard is where wallet addresses and seed phrases get pasted.

ByteDance and Tencent have spent years under US and EU scrutiny over data handovers. Embedding their telemetry into an app holding user funds, KYC documents, and 2FA seeds is a different risk surface than a video app.

if you want to verify this yourself:

- Exodus Privacy (reports exodus-privacy& search "Binance")

- NetGuard (no-root firewall, see which domains apps reach in real time)

- AppXpose (scans installed APKs directly on your Android device)

- PCAPdroid (capture and inspect actual network traffic from any app)

good luck sleeping after that

u/MahereMarley — 3 months ago

I scanned the Netflix Android app - here's what's actually inside

Was curious what Netflix actually does on my phone. Scanned the APK directly. Here's what came back:

Risk Score: 34/100 - MEDIUM

5 trackers found:

- Google Analytics

- Firebase Analytics

- Google AdMob

- AppsFlyer

- Crashlytics

Permissions that stood out:

- Microphone — likely for voice search

- Camera — no clear reason for a streaming app

- Nearby WiFi — for Chromecast discovery

- Bluetooth — for casting and audio devices

0 known data breaches which is actually rare.

The AdMob integration is the most interesting part - Netflix is a paid subscription service, so why is an advertising SDK embedded?

Scanned with AppXpose if anyone wants to check their own apps:
https://play.google.com/store/apps/details?id=com.appxpose.app&referrer=ref_apitest

u/MahereMarley — 3 months ago

[OC] I analyzed 3,745 Android apps for privacy: here's what the permission data actually shows

Been building an Android APK scanner as a side project. After 3,745 scans, looked at which permissions each app category requests most.

Some make obvious sense:

- Maps at 96% GPS = navigation needs location

- Finance at 100% Camera = KYC verification

- Audio at 92% Foreground Service = background playback

Others are harder to explain:

- News apps: 75% Auto-Start on Boot

- Games: 39% Ad Tracking ID

- Shopping: 94% Camera + 72% Microphone

The tracker SDK data was also interesting: unrecognized SDKs average 6.6 trackers per app, 3x more than known Ad SDKs.

Charts in the images above = permission heatmap by category, tracker distribution, and risk score breakdown.

Full interactive version: appxpose.app/research

Methodology: static APK analysis, permissions declared in manifest not necessarily all actively used.

Happy to answer questions about the approach.

u/MahereMarley — 3 months ago

[OC] 2,000+ Android users scanned ~4,000 apps. Here's what the data reveals about trackers, permissions and privacy risk

Data source: Anonymous aggregated data from real Android device scans via AppXpose. Results aggregated across 3,800+ unique apps from 2,000+ devices.

Tools: Python, Matplotlib

Methodology: Each app was analyzed at APK bytecode level: tracker SDKs, dangerous permissions, and a composite risk score (0–100) based on tracker count, permission types, developer breach history and certificate integrity.

No personal data collected all results are aggregated per app, not per user.

u/MahereMarley — 4 months ago
▲ 30 r/startups_promotion+2 crossposts

I built AppXpose after realizing that Google’s Data Safety labels, the things supposed to tell you what an app collects, are entirely self-reported.

Four peer-reviewed studies later confirmed what I suspected: there’s a massive gap between what apps claim and what they actually do.

So I built a scanner that looks inside the APK directly.

Some highlights from the data:

•	Instagram: 68/100 HIGH risk

•	Most “free” apps embed 5-15 tracker SDKs you’ve never heard of

•	Signing certificates that don’t match what they should

•	Apps flagged in MalwareBazaar that are still live on the Play Store

The tracker detection runs fully on-device. Nothing gets uploaded. ~140 SDK signatures, growing via community discovery.

2,000+ installs, 4.6⭐ so far. Still early.

Happy to answer questions about what I found or how the scanner works.

Website for all infos -> https://appxpose.app

App dowloandlink -> https://play.google.com/store/apps/details?id=com.appxpose.app

u/MahereMarley — 3 months ago