PostFinance App Security & Privacy Scorecard

Android

52
Overall trust score
Use With Caution
55
Security
50
Privacy

User devices are fingerprinted by ThreatMetrix for fraud detection. App performance and crash data are shared with Firebase Crashlytics and Splunk. User financial data may not be fully protected within the app, a consideration given the sensitivity of the banking information this app manages.

Best for

PostFinance customers comfortable with usage analytics

Findings

  • 0 critical
  • 0 high
  • 0 medium
  • 0 low
  • 0 info

1 issue identified across security and privacy analysis.

Top security issues

  • OAuth Token Storage Security Unknown
  • JavaScript Bridge Exposes Cryptographic Operations
  • Google API Key Exposed in Plaintext

Top privacy issues

  • ThreatMetrix Installed Apps Collection Without Consent
  • Automatic Device Fingerprinting Without Consent
  • Splunk RUM Telemetry Without User Control

Full analysis

PostFinance App

What This Means for You

User devices are fingerprinted by ThreatMetrix for fraud detection. App performance and crash data are shared with Firebase Crashlytics and Splunk. User financial data may not be fully protected within the app, a consideration given the sensitivity of the banking information this app manages.

Recommendation: Use With Caution

Best For: PostFinance customers comfortable with usage analytics

Key Findings

Data Security - 13 findings (2 critical, 4 high, 5 medium, 2 low)

Network Security - 2 findings (2 low)

Code Safety - 0 findings

Privacy - 7 findings (1 critical, 2 high, 3 medium, 1 low)

Privacy Concerns

What Data is Collected

The app collects device identifiers, behavioral signals, and usage patterns. ThreatMetrix builds a detailed fingerprint of user devices to identify users across sessions for fraud detection purposes. Firebase Crashlytics gathers diagnostic information about how the app performs on user devices. Splunk RUM collects real-time interaction data to monitor app behaviour.

Third-Party Data Sharing

User data is shared with the following third-party services:

  • ThreatMetrix - Device fingerprinting and fraud detection
  • Splunk RUM - Real user monitoring and performance telemetry
  • Firebase Crashlytics - Crash reporting and diagnostics
  • Unblu - Customer engagement and co-browsing
  • Swissquote - Financial services integration
  • Google Play Services - Core Android platform services
  • Google Maps - Location and mapping features
  • Samsung Pay - Payment processing
  • TWINT - Swiss mobile payment integration
  • OkHttp / Retrofit - Network communication libraries

Understanding the Scores

  • Security: 55/100
  • Privacy: 50/100
  • Data Security: 45/100
  • Network Security: 92/100
  • Code Safety: 60/100
  • Data Collection: 55/100
  • Data Sharing: 58/100
  • User Control: 52/100

Positive Security Features

  • No strong security controls were identified in this version of the app.

Areas for Improvement

  • User financial data may not be fully protected within the app, particularly given the sensitivity of what this app manages.
  • A high number of third-party services have access to user device data and usage patterns, with limited transparency about what each collects and why.
  • The ability to control or limit data collection and analytics sharing is restricted, making it difficult to reduce exposure for users who wish to.

About This Analysis

App Details

  • App: PostFinance App
  • Package: ch.postfinance.android
  • Version: 6.0.0 (1764922547)
  • Scan Date: 2026-02-02

Versions & scan history

ScanDateOverall score
#1 (current) 52/100