Fly Delta Security & Privacy Scorecard

Android

55
Overall trust score
Use With Caution
45
Security
65
Privacy

In-app behavior, session activity, and survey responses are collected by several analytics and experience-tracking services including QuantumMetric and Adobe. Purchase and booking activity flows through third-party fraud and identity verification systems. Sensitive transactions may travel with less protection than expected on public Wi-Fi.

Best for

Delta flyers who book trips on their phone

Findings

  • 0 critical
  • 5 high
  • 8 medium
  • 4 low
  • 0 info

1 issue identified across security and privacy analysis.

Top security issues

  • JavaScript Injection via Intent Extras
  • SSL Certificate Bypass in Development Environments
  • Unencrypted SQLite Database Storing User PII

Top privacy issues

  • QuantumMetric Feature-Toggle Gating (Not Consent-Gating)
  • Adobe Analytics Pre-Consent Initialization
  • Advertising ID Collection Without User Disclosure

Full analysis

Fly Delta

What This Means for You

In-app behavior, session activity, and survey responses are collected by several analytics and experience-tracking services including QuantumMetric and Adobe. Purchase and booking activity flows through third-party fraud and identity verification systems. Sensitive transactions may travel with less protection than expected on public Wi-Fi.

Recommendation: Use With Caution

Best For: Delta flyers who book trips on their phone

Key Findings

Data Security - 4 findings (3 medium, 1 low)

Network Security - 5 findings (3 high, 2 medium)

Code Safety - 0 findings

Privacy - 3 findings (2 medium, 1 low)

Privacy Concerns

What Data is Collected

The app collects behavioral data including user session activity, screen interactions, purchase history, and booking details. Qualtrics gathers survey responses and feedback, while Adobe Experience Cloud and QuantumMetric track in-app experience to analyze how users interact with features. Location and mapping data is processed for airport navigation through Google Maps and LocusLabs.

Third-Party Data Sharing

User data is distributed across a large number of third-party services. Session behavior and experience data flows to QuantumMetric, Adobe Experience Cloud, and Dynatrace. User payment and identity information passes through Cardinal Commerce and PingIdentity for transaction processing. Firebase services receive device telemetry, crash data, and remote configuration signals. Akamai Bot Manager and Cyberfend analyze user traffic patterns for fraud and bot detection.

Understanding the Scores

  • Security: 45/100
  • Privacy: 65/100
  • Data Security: 70/100
  • Network Security: 35/100
  • Code Safety: 50/100
  • Data Collection: 70/100
  • Data Sharing: 75/100
  • User Control: 60/100

Positive Security Features

  • No notable positive security practices were identified in this version of the app.

Areas for Improvement

  • Network communication protections could be significantly strengthened to better safeguard booking and payment data in transit.
  • The number of third-party services receiving user behavioral data and activity could be reduced to limit the scope of tracking across platforms.
  • Clearer in-app controls and transparency around data collection would give users more meaningful choices about what information is retained and shared.

About This Analysis

Static analysis of the app binary and code, performed on 2026-02-14. Results reflect the security and privacy posture of the version analyzed.

App Details

  • App: Fly Delta
  • Package: com.delta.mobile.android
  • Version: 7.7 (Build 24269)
  • Scan Date: 2026-02-14

Versions & scan history

ScanDateOverall score
#6 (current) 55/100