We continuously scan the most popular Android apps in every category for credentials that are still live, then privately email the developer contacts on file for each affected app. Here you can see what kinds of secrets show up and where, in aggregate. No app names, no secret values.