# Can I trust Gummo?

Gummo for Android, version 1.2.0 (versionCode 22) (scanned 1 October 2026) is labelled unTRUSTED, with a score of 79 out of 100. This app did not meet two or more trust checks, has a critical issue in one, or has a red flag. The scan names 14 third-party services: Sentry, Firebase Cloud Messaging, Firebase Installations, PairIP, ObjectBox, sqflite, WorkManager, flutter_local_notifications, share_plus, url_launcher, flutter_map, play_install_referrer, geolocator and Mapbox. It recorded 7 findings rated low or higher across 3 categories, 4 of them rated medium or higher. A static scan shows what the app's code and manifest contain; the app's network traffic needs a capture of the running app.

- Package: `co.com.gummo.gummo`
- Platform: Android
- Version: 1.2.0 (versionCode 22)
- Scanned: 1 October 2026
- Label and score: unTRUSTED, 79 of 100 (criteria: https://canitrustthat.com/methodology)

## Trust checks

- Secure by Design: Items recorded, result pending review
  - Security gaps detected
  - This check looks for security issues at high severity or above in the code of this build, and at least one was recorded. Issues of this kind include a credential or token another app on the device can reach, sensitive data stored without protection, and network paths that expose information in transit.
- Data Minimization: One criterion not met
  - Tracking lacks clear disclosure
  - This build contains analytics or attribution code written to send data to companies other than the developer. No consent step was found before that code runs, and the app's disclosures do not describe the collection in full. Tracking by itself is ordinary; what this check reports is the combination of collection, recipient and absent disclosure.
- Manifest Mismatch: An item rated high or above is open
  - Disclosure incomplete or contradicted
  - The check compares the app's privacy disclosures against what the code does, and at least one claim did not match in this build. Mismatches of this kind include a data category collected but not disclosed, a recipient the disclosure omits, and an identifier attached to data the disclosure describes as anonymous.
- User Control: Strong
  - No lock-in
  - The check looks for a way to export the data an account has accumulated and a way to delete the account itself. In this build, either both were found, or the app has no account of its own and keeps its data on the device. For an app without an account, the developer has no server-side copy to export or delete, and deleting the app removes the data in its own storage.
  - No proprietary data formats, artificial cancellation barriers, or obstacles to switching services were identified. The app stores preferences, favorites, and order history locally on the device, and removing the app removes that local data. No server-side mechanisms that would trap user data or make it unreasonably difficult to leave the service were found.

## Red flags

- The app's privacy declarations do not match its code
  - The privacy declarations shipped in this build, or the ones on the store listing, state less than the code does. Declarations of this kind are what a store, a regulator and a person comparing two apps rely on.

## Summary

- What it means for you: Location data stays on the device and is not shared with Sentry, Firebase, or any analytics service. No advertising network SDKs are present. Firebase handles push notifications, and the Play Install Referrer library is linked for install attribution.
- Main concern: Bundled .env exposes staging HTTP API endpoint, Mapbox token, and Sentry DSN
- The developer's description: Discover everything San José del Guaviare has to offer with Gummo, the app that connects you with the best tourist spots, events, and local businesses in the region. Whether you're a tourist or a resident, explore unique experiences.

## Strengths

- Location data stays on the device with no observed transmission to Sentry, Firebase, or any third-party analytics service
- No advertising network SDKs are present — no AdMob, Meta Audience Network, AppLovin, or equivalent
- App integrity is enforced on every launch via PairIP license verification before the Flutter engine starts
- Production API traffic uses HTTPS throughout

## What the app contains

- Sentry
- Firebase Cloud Messaging
- Firebase Installations
- PairIP
- ObjectBox
- sqflite
- WorkManager
- flutter_local_notifications
- share_plus
- url_launcher
- flutter_map
- play_install_referrer
- geolocator
- Mapbox

## Libraries

- Room
- Datatransport
- Google Sign-In 12451000
- Google Play Services 12451000
- Google Play Services Location 12451000
- Firebase 12451000
- Sentry

## Corrections

No correction is published for this app.

## Method and limits

Static analysis: the decompiled code, manifest and resources of this build, read file by file. Network traffic at run time is established by a capture of the running app.

Build SHA-256: `a4161c872ed250a82d5c8c6cf4bdec4b582af0d3dc616f212136b960b694f7ac`
Rule pack: `citt-ruleset-2026-08-v1`

HTML page: https://canitrustthat.com/apps/co.com.gummo.gummo
