Da Fit Security & Privacy Scorecard

Android

52
Overall trust score
Use With Caution
62
Security
48
Privacy

Health and fitness activity is shared with eight advertising networks, including companies linked to Facebook, ByteDance, and Yandex. Location is collected through mapping services built into the app. Ads are targeted using personal activity data across multiple platforms.

Best for

Users with a DaFit-compatible fitness tracker

Avoid if

Those who want health data kept off ad networks

Findings

  • 1 critical
  • 11 high
  • 8 medium
  • 6 low
  • 9 info

1 issue identified across security and privacy analysis.

Top security issues

  • Strava OAuth Refresh Token Silently Exfiltrated to Developer Server
  • SM2 Asymmetric Private Key Embedded in APK with Trivial XOR Obfuscation
  • WebView Remote Debugging Unconditionally Enabled in Production

Top privacy issues

  • Health Biometrics Sent to Firebase Analytics as Persistent User Properties
  • Analytics and Ad SDKs Initialize Before User Consent — Including on the Consent Screen Itself
  • AppMetrica (Yandex) SDK Sends Analytics Data to Russian Servers Without Consent

Full analysis

What This Means for You

Health and fitness activity is shared with eight advertising networks, including companies linked to Facebook, ByteDance, and Yandex. Location is collected through mapping services built into the app. Ads are targeted using personal activity data across multiple platforms.

Recommendation: Use With Caution

Best For: Users with a DaFit-compatible fitness tracker
Avoid If: Those who want health data kept off ad networks

Key Findings

Data Security - 7 findings (3 high, 2 medium, 1 low, 1 info)

Network Security - 6 findings (2 high, 2 medium, 1 low, 1 info)

Code Safety - 0 findings

Privacy - 6 findings (1 critical, 2 high, 2 medium, 1 info)

Privacy Concerns

What Data is Collected

The app collects health and fitness data from the user's connected tracker, including activity levels, sleep patterns, and heart rate. Precise location data is also gathered through multiple mapping services built into the app.

Third-Party Data Sharing

Activity and behavioral data is shared with eight advertising networks:

  • Google AdMob
  • Facebook Audience Network
  • ByteDance Pangle
  • IronSource
  • Unity Ads
  • InMobi
  • Vungle (Liftoff)
  • AppMetrica (Yandex)

Additional services include Firebase Analytics, Firebase Crashlytics, MBridge (Mobvista), Baidu mapping, AMap/AutoNavi, Google Maps, ByteDance performance monitoring, and Strava integration.

Understanding the Scores

  • Security: 62/100
  • Privacy: 48/100
  • Data Security: 50/100
  • Network Security: 60/100
  • Code Safety: 68/100
  • Data Collection: 48/100
  • Data Sharing: 63/100
  • User Control: 58/100

Positive Security Features

No notable positive security practices were identified in this version of the app.

Areas for Improvement

  • Health and activity data is shared with a large number of advertising partners. Reducing the number of ad networks involved would limit where personal fitness information travels.
  • Location data is collected by multiple mapping services simultaneously. Clearer in-app controls over location access would give users more say over how location data is used.
  • Some of the app's data transfers use configurations that could be made more robust to better protect user information as it moves between the device and remote servers.

About This Analysis

App Details

  • Package: com.crrepa.band.dafit
  • Version: V2.9.8-149-gbdcaba5120 (build 19625)
  • Scan Date: 2026-04-03
  • Total Findings: 35 (1 critical, 11 high, 8 medium, 6 low, 9 info)

Scores are based on static analysis of the app's code and configuration. No personal data is accessed or processed as part of this analysis.

Versions & scan history

ScanDateOverall score
#2 (current) 52/100