myGov Security & Privacy Scorecard
Android
Usage data is shared with Google Analytics, Firebase Analytics, and Adobe Experience Cloud. Activity on public Wi-Fi networks may be sent without full protection. Users retain strong control over their account data within the app.
Best for
Australians managing government services online
Avoid if
Users frequently on public Wi-Fi
Findings
- 4 critical
- 4 high
- 7 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- OAuth Refresh Tokens Stored Unencrypted
- WebView JavaScript Interface Exposure (RCE Risk)
- SSL Error Handling Does Not Cancel Connections
Top privacy issues
- Multiple Analytics SDKs (Privacy Concern)
- Extensive User Behavior Profiling (Adobe)
- Adobe ECID and FCM Token Stored Unencrypted
Full analysis
myGov
Package: au.gov.mygov.mygovapp | Version: 1.35.0 | Platform: Android
Security Score: 45/100 | Privacy Score: 72/100
What This Means for You
Usage data is shared with Google Analytics, Firebase Analytics, and Adobe Experience Cloud. Activity on public Wi-Fi networks may be sent without full protection. Users retain strong control over their account data within the app.
Recommendation: Use With Caution
Best For: Australians managing government services online
Avoid If: Users frequently on public Wi-Fi
Key Findings
Data Security - 4 findings (1 critical, 2 high, 1 medium)
Network Security - 2 findings (2 critical)
Code Safety - 0 findings
Privacy - 3 findings (1 high, 2 medium)
Privacy Concerns
What Data is Collected
The app collects usage and behavioral data including how users navigate government services, session activity, and device identifiers. This information is used for analytics, performance monitoring, and service improvement.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Google Analytics - Tracks how users interact with the app for usage analysis
- Firebase Analytics - Monitors app engagement and records in-app events
- Adobe Experience Cloud - Measures user experience for marketing and service analytics
- Firebase Cloud Messaging - Delivers push notifications to users' devices
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 72/100 |
| Data Security | 50/100 |
| Network Security | 40/100 |
| Code Safety | 45/100 |
| Data Collection | 75/100 |
| Data Sharing | 75/100 |
| User Control | 85/100 |
Positive Security Features
- The app uses an encrypted local database (SQLCipher) to protect data stored on the device.
- Device integrity checks are in place to help detect if the app is running in a compromised environment.
- Standards-based secure authentication (OpenID AppAuth) is used for government account login.
- Secure session handling libraries are in place to protect active login sessions.
Areas for Improvement
- Network communications should use stronger protections to keep government data private when the app is accessed on public or shared Wi-Fi networks.
- Usage data is shared with multiple third-party analytics platforms, meaning several companies outside of government receive information about how users interact with the app.
- Some data storage practices could be strengthened to better protect personal information saved locally on the device.
About This Analysis
This report was generated by automated security analysis of the app's code and behaviour at the time of the scan. Scores and findings reflect the state of the app as of the scan date and may change with future app updates.
App Details
| Field | Value |
|---|---|
| App Name | myGov |
| Package ID | au.gov.mygov.mygovapp |
| Version | 1.35.0 |
| Scan Date | 2026-02-02 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 58/100 |