How detection works
privacycommand matches the bundle against an SDK fingerprint database. A fingerprint is a set of strings, symbols, framework names, and bundled resources characteristic of a particular SDK. Every detection is traceable: hover any SDK and you see the matched strings that produced it. There is no opaque score — if privacycommand claims Firebase is present, it will show you what it found. The families that reach this card are the analytics, advertising and attribution ones — Firebase Analytics, Mixpanel, Amplitude, Segment, PostHog, AdMob and AppsFlyer among them. The database is wider than the card. Crash reporters (Sentry, Crashlytics) and A/B platforms (LaunchDarkly, Optimizely, Firebase Remote Config) are fingerprinted too and appear in the SDK list on the Static tab, but they aren’t counted here — the heat grade is telemetry only.Reading the count
The number matters less than the mix, and the mix matters less than whether it matches the business model.Presence is not proof of transmission. An SDK can be linked and never
initialised, or gated behind a consent flow that never fires. The callout
tells you what shipped. To find out whether it phones home, do a
monitored run and watch the destinations.
Feature flags and trial state
Alongside the SDK count, privacycommand extracts the flag names the binary checks at runtime —isPro, isTrial, subscription_status, experiment_id,
and the vendor-specific equivalents for LaunchDarkly, Optimizely, Firebase
Remote Config, PostHog, Statsig and Unleash.
This is a separate scanner from the SDK fingerprints, and it lands in a separate
section. Statsig and Unleash in particular are only recognised here — they
have no fingerprint entry, so they will never appear in the telemetry count
above.
This is useful for a reason that isn’t really about privacy: it shows you which
behaviours the vendor can change remotely, without shipping an update.
A note on our own numbers
privacycommand ships zero analytics SDKs. Dropprivacycommand.app onto its
own window and the callout should come back empty. If it ever doesn’t, that is
a bug worth reporting — see Security.