Bitwarden Authenticator Security & Privacy Scorecard
Android
Crash reports and basic app usage data are sent to Google. A concern was found with how authentication codes are protected on the device, which could leave them accessible in certain situations. Push notifications also route through Google's servers.
Best for
Anyone managing 2FA codes who accepts Google telemetry
Findings
- 1 critical
- 0 high
- 4 medium
- 2 low
- 0 info
1 issue identified across security and privacy analysis.
Top security issues
- Unencrypted TOTP Secrets in Database
- Screenshot Protection Not Enforced (FLAG_SECURE)
- No Root Detection
Top privacy issues
- Firebase Sessions Tracks Usage Without Explicit Consent
- Crashlytics Opt-In by Default
- Account IDs Stored in Plaintext SharedPreferences
Full analysis
Bitwarden Authenticator
Version: 2026.1.1 (Build 1243)
Analyzed: February 9, 2026
What This Means for You
Crash reports and basic app usage data are sent to Google. A concern was found with how authentication codes are protected on the device, which could leave them accessible in certain situations. Push notifications also route through Google's servers.
Recommendation: Use With Caution
Best For: Anyone managing 2FA codes who accepts Google telemetry
Key Findings
Data Security - 2 findings (1 critical, 1 medium)
Network Security - 0 findings
Code Safety - 0 findings
Privacy - 3 findings (2 medium, 1 low)
Privacy Concerns
What Data is Collected
The app collects crash reports and usage session data through Google's Firebase platform. This includes how the app performs on the device and basic usage patterns each time it is opened. The device is also registered with Google via Firebase Installations.
Third-Party Data Sharing
All third-party services in this app are operated by Google:
- Firebase Crashlytics - receives crash reports and device information when the app encounters an error
- Firebase Sessions - receives basic usage session data each time the app is opened
- Firebase Cloud Messaging - routes push notifications through Google's servers
- Firebase Installations - registers the device with Google's infrastructure
Data sharing is limited to Google's Firebase services, covering crash reporting, usage tracking, and push notifications.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 65/100 |
| Privacy | 85/100 |
| Data Security | 55/100 |
| Network Security | 100/100 |
| Code Safety | 100/100 |
| Data Collection | 85/100 |
| Data Sharing | 90/100 |
| User Control | 88/100 |
Positive Security Features
- All network communications use properly secured connections, with data protected in transit
- The app's code passes all safety checks with no risky system-level patterns present
- Data sharing is limited to a single provider family, with no advertising networks or data brokers receiving user information
Areas for Improvement
- The protection applied to stored authentication codes should be strengthened so they remain secure if someone gains physical access to the device
- Crash reporting and session data collection could offer an opt-out, giving users more control over what usage information is sent to Google
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration at the time of the scan. Findings reflect the state of the app as of the scan date.
App Details
| Field | Value |
|---|---|
| App Name | Bitwarden Authenticator |
| Package ID | com.bitwarden.authenticator |
| Version | 2026.1.1 (Build 1243) |
| Scan Date | February 9, 2026 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 75/100 |