Simplenote Security & Privacy Scorecard
Android
Notes are synced through Simperium, Automattic's own sync service. Usage patterns are collected via Automattic Tracks, their first-party analytics platform. Crash data is reported to Sentry, a third-party error monitoring service.
Best for
Note-takers comfortable with Automattic analytics
Findings
- 2 critical
- 1 high
- 1 medium
- 1 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Unencrypted Authentication Tokens in SharedPreferences
- Unencrypted SQLite Database Storage
- Hardcoded Encryption Key in PasscodeLock Library
Top privacy issues
- Analytics Enabled by Default Without Consent (GDPR Violation)
- Device Fingerprinting for User Tracking
- No Secure Wipe on Account Deletion (GDPR Right to Erasure)
Full analysis
Simplenote
Developer: Automattic
Version: 2.37 (Build 184)
Platform: Android
Scan Date: January 20, 2026
What This Means for Users
Notes are synced through Simperium, Automattic's own sync service. Usage patterns are collected via Automattic Tracks, their first-party analytics platform. Crash data is reported to Sentry, a third-party error monitoring service.
Recommendation: Trustworthy
Best For: Note-takers comfortable with Automattic analytics
Key Findings
Data Security - 4 findings (2 critical, 1 high, 1 medium)
Network Security - 0 findings
Code Safety - 0 findings
Privacy - 4 findings (1 high, 2 medium, 1 low)
Privacy Concerns
What Data is Collected
- Usage patterns and behavioral data are collected via Automattic Tracks, Automattic's first-party analytics platform.
- Crash reports and diagnostic information are sent to Sentry, a third-party error monitoring service.
- Account and note sync data is processed through Simperium, Automattic's own sync infrastructure.
Third-Party Data Sharing
- Sentry: Receives crash reports and error diagnostics generated during app use.
- Automattic Tracks: Collects usage pattern data through Automattic's first-party analytics service.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 80/100 |
| Privacy | 85/100 |
| Data Security | 75/100 |
| Network Security | 100/100 |
| Code Safety | 85/100 |
| Data Collection | 82/100 |
| Data Sharing | 90/100 |
| User Control | 80/100 |
Positive Security Features
- All network communications use modern, hardened protocols, resulting in a perfect Network Security score of 100/100.
- Data sharing is limited primarily to Automattic's own infrastructure and a small number of essential third-party services, reflected in a strong Data Sharing score of 90/100.
- Account and sync preferences give users meaningful control over their data, supporting the User Control score of 80/100.
Areas for Improvement
- Data storage practices on the device have issues that could put locally held notes at greater risk. Strengthening how note data is protected at rest would reduce exposure if the device is accessed by others.
- Crash reporting sends diagnostic information to an external service. Offering an opt-out for this data collection would give users more control over what leaves the device.
- Some usage data collection happens automatically without a clear in-app opt-out. Providing straightforward controls for analytics would better respect user preference for data minimization.
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration at the time of the scan. Scores reflect observed practices and may not capture all runtime behaviors.
App Details
- App Name: Simplenote
- Package ID: com.automattic.simplenote
- Version: 2.37 (Build 184)
- Scan Date: January 20, 2026
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 82/100 | |
| #2 | 42/100 | |
| #1 | 25/100 |