PostFinance App Security & Privacy Scorecard
Android
User devices are fingerprinted by ThreatMetrix for fraud detection. App performance and crash data are shared with Firebase Crashlytics and Splunk. User financial data may not be fully protected within the app, a consideration given the sensitivity of the banking information this app manages.
Best for
PostFinance customers comfortable with usage analytics
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
1 issue identified across security and privacy analysis.
Top security issues
- OAuth Token Storage Security Unknown
- JavaScript Bridge Exposes Cryptographic Operations
- Google API Key Exposed in Plaintext
Top privacy issues
- ThreatMetrix Installed Apps Collection Without Consent
- Automatic Device Fingerprinting Without Consent
- Splunk RUM Telemetry Without User Control
Full analysis
PostFinance App
What This Means for You
User devices are fingerprinted by ThreatMetrix for fraud detection. App performance and crash data are shared with Firebase Crashlytics and Splunk. User financial data may not be fully protected within the app, a consideration given the sensitivity of the banking information this app manages.
Recommendation: Use With Caution
Best For: PostFinance customers comfortable with usage analytics
Key Findings
Data Security - 13 findings (2 critical, 4 high, 5 medium, 2 low)
Network Security - 2 findings (2 low)
Code Safety - 0 findings
Privacy - 7 findings (1 critical, 2 high, 3 medium, 1 low)
Privacy Concerns
What Data is Collected
The app collects device identifiers, behavioral signals, and usage patterns. ThreatMetrix builds a detailed fingerprint of user devices to identify users across sessions for fraud detection purposes. Firebase Crashlytics gathers diagnostic information about how the app performs on user devices. Splunk RUM collects real-time interaction data to monitor app behaviour.
Third-Party Data Sharing
User data is shared with the following third-party services:
- ThreatMetrix - Device fingerprinting and fraud detection
- Splunk RUM - Real user monitoring and performance telemetry
- Firebase Crashlytics - Crash reporting and diagnostics
- Unblu - Customer engagement and co-browsing
- Swissquote - Financial services integration
- Google Play Services - Core Android platform services
- Google Maps - Location and mapping features
- Samsung Pay - Payment processing
- TWINT - Swiss mobile payment integration
- OkHttp / Retrofit - Network communication libraries
Understanding the Scores
- Security: 55/100
- Privacy: 50/100
- Data Security: 45/100
- Network Security: 92/100
- Code Safety: 60/100
- Data Collection: 55/100
- Data Sharing: 58/100
- User Control: 52/100
Positive Security Features
- No strong security controls were identified in this version of the app.
Areas for Improvement
- User financial data may not be fully protected within the app, particularly given the sensitivity of what this app manages.
- A high number of third-party services have access to user device data and usage patterns, with limited transparency about what each collects and why.
- The ability to control or limit data collection and analytics sharing is restricted, making it difficult to reduce exposure for users who wish to.
About This Analysis
App Details
- App: PostFinance App
- Package: ch.postfinance.android
- Version: 6.0.0 (1764922547)
- Scan Date: 2026-02-02
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 52/100 |