Cooklist: Pantry & Cooking App Security & Privacy Scorecard

Android

32
Overall trust score
Unsafe
35
Security
30
Privacy

Cooking habits, pantry contents, and in-app activity are shared with Facebook, Mixpanel, and Google Analytics for advertising and behavioral tracking. Purchase history is processed by multiple billing and attribution services. Users have limited control over what is collected or how long it is retained.

Best for

Home cooks comfortable with broad data sharing

Avoid if

You keep grocery and meal habits private

Findings

  • 6 critical
  • 5 high
  • 3 medium
  • 0 low
  • 3 info

0 issues identified across security and privacy analysis.

Top security issues

  • Unencrypted AsyncStorage Database
  • Cleartext HTTP Traffic Allowed
  • Facebook Client Token Exposed in Resources

Top privacy issues

  • Pre-Consent Analytics Tracking (GDPR Violation)
  • Personally Identifiable Information in Analytics Events
  • Cross-App Tracking via GAID Without Opt-In

Full analysis

Cooklist: Pantry & Cooking App

Overall Score: 33/100 (F)

What This Means for You

Cooking habits, pantry contents, and in-app activity are shared with Facebook, Mixpanel, and Google Analytics for advertising and behavioral tracking. Purchase history is processed by multiple billing and attribution services. Users have limited control over what is collected or how long it is retained.

Recommendation: Use With Caution

Best For: Home cooks comfortable with broad data sharing

Avoid If: Keeping grocery and meal habits private is a priority

Key Findings

Data Security - 3 findings (2 critical, 1 high)

Network Security - 3 findings (1 critical, 1 high, 1 medium)

Code Safety - 0 findings

Privacy - 5 findings (2 critical, 2 high, 1 medium)

Privacy Concerns

What Data is Collected

Pantry inventory, meal plans, and shopping lists are stored remotely. In-app behavior, including which recipes are viewed, how frequently the app is opened, and how long is spent on each screen, is captured by multiple analytics services. Subscription and purchase history is processed by three separate billing services. Account identity is handled through Google Sign-In.

Third-Party Data Sharing

Activity and account data is shared with nine third-party services:

  • Facebook SDK - behavioral data used for ad targeting across the Facebook network
  • Mixpanel - detailed event-level behavioral analytics
  • Google Analytics - usage and engagement tracking
  • Firebase Analytics - session and event tracking
  • Sentry - crash and error diagnostics
  • RevenueCat - subscription lifecycle and purchase management
  • Google Play Billing - payment processing
  • Amazon IAP - payment processing
  • Google Sign-In - account authentication

Understanding the Scores

Category Score
Security 35/100
Privacy 30/100
Data Security 25/100
Network Security 35/100
Code Safety 45/100
Data Collection 35/100
Data Sharing 40/100
User Control 25/100

Positive Security Features

No notable positive security practices were identified in this version of the app.

Areas for Improvement

  • User data is shared with nine third parties, and the app provides no clear mechanism to limit, pause, or opt out of that sharing.
  • Data sent between the device and the app's servers does not consistently apply strong protections, meaning user data travels with less protection than expected under certain network conditions.
  • There is no visible way for users to request deletion of account data or review what has been collected.

About This Analysis

This scorecard reflects the security and privacy posture of the version analyzed. Scores may not reflect changes introduced in updates released after the scan date.

App Details

Field Value
App Name Cooklist: Pantry & Cooking App
Package ID com.cooklist.android
Version 1.105.3 (Build 256)
Scan Date 2026-01-21

Versions & scan history

ScanDateOverall score
#2 (current) 32/100