Bitwarden Authenticator Security & Privacy Scorecard

Android

75
Overall trust score
Acceptable
65
Security
85
Privacy

Crash reports and basic app usage data are sent to Google. A concern was found with how authentication codes are protected on the device, which could leave them accessible in certain situations. Push notifications also route through Google's servers.

Best for

Anyone managing 2FA codes who accepts Google telemetry

Findings

  • 1 critical
  • 0 high
  • 4 medium
  • 2 low
  • 0 info

1 issue identified across security and privacy analysis.

Top security issues

  • Unencrypted TOTP Secrets in Database
  • Screenshot Protection Not Enforced (FLAG_SECURE)
  • No Root Detection

Top privacy issues

  • Firebase Sessions Tracks Usage Without Explicit Consent
  • Crashlytics Opt-In by Default
  • Account IDs Stored in Plaintext SharedPreferences

Full analysis

Bitwarden Authenticator

Version: 2026.1.1 (Build 1243)
Analyzed: February 9, 2026

What This Means for You

Crash reports and basic app usage data are sent to Google. A concern was found with how authentication codes are protected on the device, which could leave them accessible in certain situations. Push notifications also route through Google's servers.

Recommendation: Use With Caution

Best For: Anyone managing 2FA codes who accepts Google telemetry

Key Findings

Data Security - 2 findings (1 critical, 1 medium)

Network Security - 0 findings

Code Safety - 0 findings

Privacy - 3 findings (2 medium, 1 low)

Privacy Concerns

What Data is Collected

The app collects crash reports and usage session data through Google's Firebase platform. This includes how the app performs on the device and basic usage patterns each time it is opened. The device is also registered with Google via Firebase Installations.

Third-Party Data Sharing

All third-party services in this app are operated by Google:

  • Firebase Crashlytics - receives crash reports and device information when the app encounters an error
  • Firebase Sessions - receives basic usage session data each time the app is opened
  • Firebase Cloud Messaging - routes push notifications through Google's servers
  • Firebase Installations - registers the device with Google's infrastructure

Data sharing is limited to Google's Firebase services, covering crash reporting, usage tracking, and push notifications.

Understanding the Scores

Category Score
Security 65/100
Privacy 85/100
Data Security 55/100
Network Security 100/100
Code Safety 100/100
Data Collection 85/100
Data Sharing 90/100
User Control 88/100

Positive Security Features

  • All network communications use properly secured connections, with data protected in transit
  • The app's code passes all safety checks with no risky system-level patterns present
  • Data sharing is limited to a single provider family, with no advertising networks or data brokers receiving user information

Areas for Improvement

  • The protection applied to stored authentication codes should be strengthened so they remain secure if someone gains physical access to the device
  • Crash reporting and session data collection could offer an opt-out, giving users more control over what usage information is sent to Google

About This Analysis

This scorecard is based on automated static analysis of the app's code and configuration at the time of the scan. Findings reflect the state of the app as of the scan date.

App Details

Field Value
App Name Bitwarden Authenticator
Package ID com.bitwarden.authenticator
Version 2026.1.1 (Build 1243)
Scan Date February 9, 2026

Versions & scan history

ScanDateOverall score
#1 (current) 75/100