Da Fit Security & Privacy Scorecard
Android
Health and fitness activity is shared with eight advertising networks, including companies linked to Facebook, ByteDance, and Yandex. Location is collected through mapping services built into the app. Ads are targeted using personal activity data across multiple platforms.
Best for
Users with a DaFit-compatible fitness tracker
Avoid if
Those who want health data kept off ad networks
Findings
- 1 critical
- 11 high
- 8 medium
- 6 low
- 9 info
1 issue identified across security and privacy analysis.
Top security issues
- Strava OAuth Refresh Token Silently Exfiltrated to Developer Server
- SM2 Asymmetric Private Key Embedded in APK with Trivial XOR Obfuscation
- WebView Remote Debugging Unconditionally Enabled in Production
Top privacy issues
- Health Biometrics Sent to Firebase Analytics as Persistent User Properties
- Analytics and Ad SDKs Initialize Before User Consent — Including on the Consent Screen Itself
- AppMetrica (Yandex) SDK Sends Analytics Data to Russian Servers Without Consent
Full analysis
What This Means for You
Health and fitness activity is shared with eight advertising networks, including companies linked to Facebook, ByteDance, and Yandex. Location is collected through mapping services built into the app. Ads are targeted using personal activity data across multiple platforms.
Recommendation: Use With Caution
Best For: Users with a DaFit-compatible fitness tracker
Avoid If: Those who want health data kept off ad networks
Key Findings
Data Security - 7 findings (3 high, 2 medium, 1 low, 1 info)
Network Security - 6 findings (2 high, 2 medium, 1 low, 1 info)
Code Safety - 0 findings
Privacy - 6 findings (1 critical, 2 high, 2 medium, 1 info)
Privacy Concerns
What Data is Collected
The app collects health and fitness data from the user's connected tracker, including activity levels, sleep patterns, and heart rate. Precise location data is also gathered through multiple mapping services built into the app.
Third-Party Data Sharing
Activity and behavioral data is shared with eight advertising networks:
- Google AdMob
- Facebook Audience Network
- ByteDance Pangle
- IronSource
- Unity Ads
- InMobi
- Vungle (Liftoff)
- AppMetrica (Yandex)
Additional services include Firebase Analytics, Firebase Crashlytics, MBridge (Mobvista), Baidu mapping, AMap/AutoNavi, Google Maps, ByteDance performance monitoring, and Strava integration.
Understanding the Scores
- Security: 62/100
- Privacy: 48/100
- Data Security: 50/100
- Network Security: 60/100
- Code Safety: 68/100
- Data Collection: 48/100
- Data Sharing: 63/100
- User Control: 58/100
Positive Security Features
No notable positive security practices were identified in this version of the app.
Areas for Improvement
- Health and activity data is shared with a large number of advertising partners. Reducing the number of ad networks involved would limit where personal fitness information travels.
- Location data is collected by multiple mapping services simultaneously. Clearer in-app controls over location access would give users more say over how location data is used.
- Some of the app's data transfers use configurations that could be made more robust to better protect user information as it moves between the device and remote servers.
About This Analysis
App Details
- Package: com.crrepa.band.dafit
- Version: V2.9.8-149-gbdcaba5120 (build 19625)
- Scan Date: 2026-04-03
- Total Findings: 35 (1 critical, 11 high, 8 medium, 6 low, 9 info)
Scores are based on static analysis of the app's code and configuration. No personal data is accessed or processed as part of this analysis.
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 52/100 |