We set up a MITM proxy and captured the decrypted HTTPS traffic from the official White House iOS app. On a single browsing session it contacts multiple Elfsight domains, sends your device fingerprint to OneSignal, and loads Google DoubleClick ad tracking. The privacy manifest says it collects nothing.
Why would a government-funded app even have adware?? Is the contractor that made the app double-dipping?
Probably. Given who the app was made for, should we really expect anything less?