Scan results

    calimoto Motorcycle Navigation

    Android

    Scenic motorcycle navigation app with route planning, turn-by-turn GPS, offline maps, ride tracking, and community features for over 3 million riders.

    unTRUSTED

    This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.

    The five trust checks

    Truly LocalNot applicable
    CITT SCORE
    73
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Motorcycle riders wanting GPS routes off ad networks

    What It Means For You

    GPS location data is not passed to analytics or advertising services and remains within the app's own systems. Usage and device data flow to Firebase, AppsFlyer, CleverTap, Mixpanel, and Facebook for analytics and ad attribution. Mixpanel data is routed to EU-resident servers.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (12)

    Data Security

    3 total
    1 High
    2 Medium

    Code Security

    7 total
    2 High
    1 Medium
    4 Low

    Privacy

    1 total
    1 High

    Third-Party Risk

    1 total
    1 Medium

    Third-Party Services

    AppsFlyer, Firebase Analytics, Firebase Auth, Firebase Crashlytics, Firebase Cloud Messaging, Firebase Remote Config, Firebase Performance, CleverTap, Mixpanel, Facebook SDK, Parse Platform, Mapbox Maps, Google Play Billing, Google Play Services, WorkManager

    Security Strengths

    • Android backup is explicitly disabled, preventing ADB data extraction on non-rooted devices
    • GPS location data is not passed to any analytics or advertising SDK — location stays within the app's own infrastructure
    • No background location access declared; GPS is used only during active foreground navigation sessions
    • Mixpanel analytics data is routed to EU-resident servers, keeping it within EU jurisdiction
    • Core API traffic (routing, POIs, parse backend, maps) uses encrypted HTTPS connections
    • CleverTap SDK implements certificate pinning for its own traffic
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    location
    navigation
    ads
    third party risk

    Package

    com.calimoto.calimoto

    Version

    2026.08.1 (versionCode 624)

    Analysis Date

    Aug 12, 2026

    0

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Solid

    Build 2026.08.1 routes GPS data through calimoto's own backend rather than passing location to advertising or analytics services, which is a meaningful strength for a navigation app. The Play Store data safety label states no third-party sharing, while the binary links multiple services that initialize at startup, a gap riders should be aware of. For everyday navigation this is a capable and well-structured app; those who want full advance disclosure of data handling practices should review the privacy policy directly.

    Key Findings

    Data Security: 3 findings (1 high, 2 medium)

    Network Security: 0 findings

    Code Safety: 7 findings (2 high, 1 medium, 4 low)

    Privacy: 2 findings (1 high, 1 medium)

    Privacy Concerns

    What Leaves the Device

    • Device identifiers and app-open events: may reach AppsFlyer (attribution) and Meta Platforms (Facebook SDK) at startup; on-network transmission was not observed.
    • App engagement and behavioral data: linked to CleverTap (in-app messaging) and Mixpanel (behavioral analytics, configured to route to EU-resident servers); transmission was not observed.
    • Crash and stability data: linked to Firebase Crashlytics and Firebase Performance; transmission was not observed.
    • Push notification registration: linked to Firebase Cloud Messaging; transmission was not observed.
    • Map and routing requests: linked to Mapbox for map rendering and route calculation; transmission was not observed.

    What Stays on the Device

    • GPS location data: read for turn-by-turn navigation and ride tracking and kept within calimoto's own infrastructure. No advertising or analytics SDK initialization path for location data was found in the analyzed build.
    • Ride performance metrics (lean angle, acceleration): processed for post-trip analysis; no off-device flow to advertising or analytics services was identified.

    Third-Party Data Sharing

    Third parties that may receive data from the app:

    • AppsFlyer - install attribution and app usage analytics
    • Meta Platforms (Facebook SDK) - app engagement measurement
    • Firebase Analytics - app behavior analytics
    • Firebase Crashlytics - crash and stability reporting
    • Firebase Cloud Messaging - push notifications
    • Firebase Performance - app performance monitoring
    • CleverTap - in-app messaging and engagement
    • Mixpanel - behavioral analytics (EU-resident servers)
    • Mapbox - mapping and route rendering
    • Google Play Services - platform integration and billing
    • Parse Platform - app backend services

    Understanding the Scores

    Security: 72/100
    Privacy: 75/100

    Security Breakdown

    • Data Security: 80/100. Core API traffic for routing, maps, and the app backend uses encrypted HTTPS connections. The build embeds server authentication details as compile-time constants in the binary; the practical impact depends on server-side access controls that were not assessed.
    • Network Security: 76/100. Core API and routing traffic uses encrypted connections. The build's MQTT client configuration references port 1883, which corresponds to unencrypted MQTT transport; whether the server negotiates a TLS upgrade was not observed. The GPX file import path also registers HTTP alongside HTTPS for external route files.
    • Code Safety: 78/100. The app uses Rust for its offline map conversion library, providing a memory-safe core for that component. Two native libraries lack a stack overflow guard in their C-layer glue code, though both pass the remaining standard binary hardening checks.

    Privacy Breakdown

    • Data Collection: 81/100. GPS location is kept within calimoto's own infrastructure and is not linked to advertising or analytics SDK initialization paths. Attribution and engagement SDKs initialize at startup and may collect device identifiers before a consent prompt is presented.
    • Data Sharing: 78/100. Data may reach multiple third-party analytics, attribution, and engagement services. GPS location is not among the data types linked to those services.
    • User Control: 81/100. The app provides a data deletion request option, and the privacy policy links to a deletion mechanism. Some analytics consent configuration flags appear set to a permissive state by default in the analyzed build.

    Positive Security Features

    • Android backup is explicitly disabled in the manifest, preventing backup-based data extraction on unmodified Android devices.
    • GPS location data is not linked to advertising or analytics SDK initialization paths; location stays within calimoto's own infrastructure in the analyzed build.
    • Background location access is not declared; GPS is available only during active foreground navigation sessions.
    • Mixpanel analytics data is configured to route to EU-resident servers, keeping it within EU jurisdiction.
    • Core API traffic for routing, points of interest, maps, and backend services uses encrypted HTTPS connections.
    • CleverTap implements its own network security protections for its own traffic.

    Areas for Improvement

    Disclosure observations

    Observations about disclosure, each stated against the published guidance so a reader can compare:

    1. Data Safety Label and Third-Party SDK Presence
      The Google Play Data Safety label for com.calimoto.calimoto (retrieved 2026-08-11) states: "No data shared with third parties." Google Play's published Data Safety guidance defines third parties as companies independent of the developer. Build 2026.08.1 links AppsFlyer (an independent attribution company headquartered separately from calimoto GmbH) and the Facebook SDK (Meta Platforms), both with startup initialization code present in the binary. Readers can compare the label statement against Google's published Data Safety guidance and the binary contents and reach their own conclusion.

    2. Advertising Permission Suite
      The build's manifest declares the full Android Privacy Sandbox advertising permission set, including permissions for OS-derived interest-category profiling (Topics API) and remarketing cohort targeting (Custom Audience API). These capabilities were not described in the Play Store data safety label as retrieved. Google's published Privacy Sandbox guidance recommends disclosing these capabilities to users.

    Security Enhancements

    1. MQTT Transport Configuration
      The build's MQTT client configuration references port 1883, which corresponds to unencrypted MQTT transport. Industry guidance recommends configuring MQTT over TLS (port 8883) to protect data in transit. If the server enforces a TLS upgrade on port 1883, adding explicit TLS configuration in the client would make that protection visible and verifiable.

    2. Compiled Server Access Keys in the Release Build
      Authentication details for both production and test backend environments are compiled into the release binary as string constants. Industry best practice is to provision short-lived, scope-limited access keys from a secure server-side endpoint at runtime rather than embedding long-lived values in the distributed package.

    3. Pre-Consent SDK Initialization
      AppsFlyer and Facebook attribution SDKs are initialized in the application startup sequence. Deferring initialization until after the user responds to a consent prompt aligns with published guidance from Google Play and major app store privacy frameworks.

    4. GPX File Import Over HTTP
      The build's manifest registers HTTP (unencrypted) alongside HTTPS for GPX file imports from external URLs. Restricting the GPX import path to HTTPS-only sources would reduce exposure to content substitution when riders import routes from external hosts.

    Technical Context

    App Type: Maps & Navigation, location-aware community platform
    Classes Analyzed: 0
    Third-Party Services: 15
    Context Tags: location, navigation, ads, third_party_risk


    About This Analysis

    This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of Android applications, intended to help people make informed decisions about app security and privacy.

    App Details

    Developer: calimoto GmbH
    Version: 2026.08.1 (Build 624)
    Analysis Date: 2026-08-12
    Package: com.calimoto.calimoto

    Analysis Limitations

    • Static analysis only (code review without running the app)
    • Based on APK version 2026.08.1 analyzed on 2026-08-12
    • May not reflect server-side security controls
    • Cannot detect all runtime behaviors

    Right of Reply

    Developer not yet contacted