From the PTKD Journal

    Field notes on mobile app security.

    What we're learning from scanning real APKs and IPAs — the patterns that recur, the controls that hold up, and where the new wave of AI-coded apps is breaking older assumptions.

    A phone after logout with a checklist of tokens, caches, database files and push registrations being removed.

    Latest · Privacy

    What to clear on logout in a mobile app: the full list

    A logout that only shows the login screen leaves tokens, caches and push registrations behind. What to revoke on the server and wipe on the device.

    Laurens Dauchy · October 6, 2026 · 10 min read

    More posts