Cooklist: Pantry & Cooking App Security & Privacy Scorecard
Android
Cooking habits, pantry contents, and in-app activity are shared with Facebook, Mixpanel, and Google Analytics for advertising and behavioral tracking. Purchase history is processed by multiple billing and attribution services. Users have limited control over what is collected or how long it is retained.
Best for
Home cooks comfortable with broad data sharing
Avoid if
You keep grocery and meal habits private
Findings
- 6 critical
- 5 high
- 3 medium
- 0 low
- 3 info
0 issues identified across security and privacy analysis.
Top security issues
- Unencrypted AsyncStorage Database
- Cleartext HTTP Traffic Allowed
- Facebook Client Token Exposed in Resources
Top privacy issues
- Pre-Consent Analytics Tracking (GDPR Violation)
- Personally Identifiable Information in Analytics Events
- Cross-App Tracking via GAID Without Opt-In
Full analysis
Cooklist: Pantry & Cooking App
Overall Score: 33/100 (F)
What This Means for You
Cooking habits, pantry contents, and in-app activity are shared with Facebook, Mixpanel, and Google Analytics for advertising and behavioral tracking. Purchase history is processed by multiple billing and attribution services. Users have limited control over what is collected or how long it is retained.
Recommendation: Use With Caution
Best For: Home cooks comfortable with broad data sharing
Avoid If: Keeping grocery and meal habits private is a priority
Key Findings
Data Security - 3 findings (2 critical, 1 high)
Network Security - 3 findings (1 critical, 1 high, 1 medium)
Code Safety - 0 findings
Privacy - 5 findings (2 critical, 2 high, 1 medium)
Privacy Concerns
What Data is Collected
Pantry inventory, meal plans, and shopping lists are stored remotely. In-app behavior, including which recipes are viewed, how frequently the app is opened, and how long is spent on each screen, is captured by multiple analytics services. Subscription and purchase history is processed by three separate billing services. Account identity is handled through Google Sign-In.
Third-Party Data Sharing
Activity and account data is shared with nine third-party services:
- Facebook SDK - behavioral data used for ad targeting across the Facebook network
- Mixpanel - detailed event-level behavioral analytics
- Google Analytics - usage and engagement tracking
- Firebase Analytics - session and event tracking
- Sentry - crash and error diagnostics
- RevenueCat - subscription lifecycle and purchase management
- Google Play Billing - payment processing
- Amazon IAP - payment processing
- Google Sign-In - account authentication
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 30/100 |
| Data Security | 25/100 |
| Network Security | 35/100 |
| Code Safety | 45/100 |
| Data Collection | 35/100 |
| Data Sharing | 40/100 |
| User Control | 25/100 |
Positive Security Features
No notable positive security practices were identified in this version of the app.
Areas for Improvement
- User data is shared with nine third parties, and the app provides no clear mechanism to limit, pause, or opt out of that sharing.
- Data sent between the device and the app's servers does not consistently apply strong protections, meaning user data travels with less protection than expected under certain network conditions.
- There is no visible way for users to request deletion of account data or review what has been collected.
About This Analysis
This scorecard reflects the security and privacy posture of the version analyzed. Scores may not reflect changes introduced in updates released after the scan date.
App Details
| Field | Value |
|---|---|
| App Name | Cooklist: Pantry & Cooking App |
| Package ID | com.cooklist.android |
| Version | 1.105.3 (Build 256) |
| Scan Date | 2026-01-21 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 32/100 |