BM2 Security & Privacy Scorecard
Android
Usage data is collected by Umeng, a Chinese analytics platform, along with device identifiers from MIUI and Vivo. Network traffic is handled with weak protections, meaning data sent from the device may not be fully protected on public Wi-Fi. Customer service features connect to a third-party platform, meaning support conversations may leave the device.
Best for
Battery monitoring with tolerance for analytics sharing
Avoid if
You avoid apps with China-based analytics services
Findings
- 1 critical
- 5 high
- 7 medium
- 6 low
- 9 info
1 issue identified across security and privacy analysis.
Top security issues
- SSL/TLS Certificate Validation Completely Disabled — all 13 HTTPS endpoints interceptable by any network attacker
- Plaintext FTP Used for Diagnostic Log Upload With Server-Controlled Credentials — credentials and log content exposed on network
- Device Session Token Stored Unencrypted in SharedPreferences — API impersonation possible via ADB backup
Top privacy issues
- GPS Coordinates and Physical Address Uploaded Without User Disclosure — vehicle location history sent to Shenzhen, China servers
- Umeng Analytics and Qiyu SDK Initialize Before User Consent — device identifiers collected before opt-in
- No Post-Consent Opt-Out Mechanism for Analytics or Data Deletion — GDPR/CCPA withdrawal rights unsupported
Full analysis
BM2
What This Means for You
Usage data is collected by Umeng, a Chinese analytics platform, along with device identifiers from MIUI and Vivo. Network traffic is handled with weak protections, meaning data sent from the device may not be fully protected on public Wi-Fi. Customer service features connect to a third-party platform, meaning support conversations may leave the device.
Recommendation: Use With Caution
Best For: Battery monitoring with tolerance for analytics sharing
Avoid If: You avoid apps with China-based analytics services
Key Findings
Data Security - 7 findings (2 high, 2 medium, 1 low, 2 info)
Network Security - 5 findings (1 critical, 1 high, 2 low, 1 info)
Code Safety - 0 findings
Privacy - 5 findings (2 high, 2 medium, 1 info)
Privacy Concerns
What Data is Collected
This app collects device identifiers specific to MIUI and Vivo hardware, along with behavioral and usage data gathered through Umeng analytics services. These identifiers allow user activity to be linked across sessions and potentially connected to user identity across other apps using the same services.
Third-Party Data Sharing
User data is shared with Umeng Analytics and Umeng EFS Performance SDK, both operating under Chinese data jurisdiction. Customer service interactions are routed through Qiyu/NetEase Unicorn, a third-party support platform, meaning support conversations are stored on external servers outside the app. Behavioral profiling data may be processed in regions with different privacy protections than those in the user's region.
Understanding the Scores
- Overall Security: 28/100
- Overall Privacy: 32/100
- Data Security: 38/100
- Network Security: 18/100
- Code Safety: 52/100
- Data Collection: 40/100
- Data Sharing: 35/100
- User Control: 30/100
Positive Security Features
- No notable positive security practices were identified for this app.
Areas for Improvement
- Network communications should use stronger protections so that data sent from the device travels with full protection on public Wi-Fi.
- The scope of data sharing with third-party analytics services could be reduced, giving users more control over what information leaves the device.
- Collection of manufacturer-specific device identifiers from MIUI and Vivo goes beyond what a battery monitoring app requires and adds unnecessary tracking scope.
About This Analysis
App Details
- App Name: BM2
- Package ID: com.dc.battery.monitor2
- Version: 3.8.0 (build 111)
- Scan Date: February 17, 2026
- Platform: Android
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #4 (current) | 30/100 | |
| #2 | 40/100 | |
| #1 | 32/100 |