← Measured in the wild

ntfy.gdfsecurity.com

classified as unknown · 2

This page aggregates measured, corroborated evidence: donors' iPhones recorded apps contacting this domain, every claim below was reported by separate accepted donations and published under a human verdict (later rows for an approved app inherit its verdict). A contact is a measurement, not an accusation — it does not show what data was sent.

What our research panel found AI-drafted · human-reviewed

We ask several independent AI models the same question and publish their answers separately — cross-vendor agreement is evidence against fabrication, and disagreement is worth seeing. 3 of 3 models answered, overall confidence medium — classification split: anthropic=unknown, openai=unknown, gemini=first-party. A human reviewed this domain's claims before anything here published.

Anthropic Claude — unknown

The hostname pattern (ntfy.<domain>) is consistent with a self-hosted ntfy server instance that a user or organization configured in the app rather than a tracking, ad, or CDN endpoint, but I do not know who owns gdfsecurity.com, so the classification is ambiguous. Since ntfy is an open-source push-notification client whose server endpoint is user-configurable and this contact appears to serve core functionality rather than an inferable analytics/advertising data flow, I would not call it undisclosed on the evidence given.

OpenAI — unknown

The owner and purpose of ntfy.gdfsecurity.com are not provided, so its role is ambiguous. With no evidence of what data the contact transmits, an undisclosed data flow cannot be established.

Google Gemini — first-party

The contacted domain appears to be a functional backend or self-hosted ntfy server instance used for push notification delivery. Essential operational traffic to a backend server does not inherently imply undisclosed data collection.

Apps measured contacting this domain

AppLabel gapDonationsContactsSeen
io.heckel.ntfy42082026-07-28 → 2026-07-29

The corpus grows one report at a time: donate your App Privacy Report — anonymous by design.

Think something here is wrong?

Evidence and research improve when people push back. Tell us what to re-check — a misattributed domain, an outdated classification, a claim about your own app — and a human will review it. Responses can take up to 30 days.

If you leave an email it is encrypted at rest and opened only to answer you — never shared, never used for anything else. It is erased 30 days after we resolve this (or 180 days if it is still open) without you asking, and you can erase it sooner at any time; either way your correction stays, anonymously. Leave it blank and your request is fully anonymous from the start (we store no IP address either way).