ARQ (formerly DolarApp) Security & Privacy Scorecard

Android

52
Overall trust score
Use With Caution
40
Security
65
Privacy

User activity is shared with AppsFlyer and Facebook for marketing purposes. Financial identity verification relies on third-party services like Jumio and iProov, meaning ID documents and biometric data pass through external processors. Two critical findings in how user data is stored and handled internally add meaningful risk to financial information.

Best for

Cross-border transfers with standard analytics trade-offs

Avoid if

You keep sensitive financial documents in linked accounts

Findings

  • 2 critical
  • 3 high
  • 7 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Universal File Access Enabled in Card Activation WebView
  • Unencrypted SQLite Databases Storing Financial Data
  • Missing Root Detection

Top privacy issues

  • Extensive User Profiling Without Consent
  • Missing Screenshot Protection (FLAG_SECURE)
  • Facebook Debug Logging Enabled in Production

Full analysis

DolarApp

What This Means for You

User activity is shared with AppsFlyer and Facebook for marketing purposes. Financial identity verification relies on third-party services like Jumio and iProov, meaning ID documents and biometric data pass through external processors. Two critical findings in how user data is stored and handled internally add meaningful risk to financial information.

Recommendation: Use With Caution

Best For: Cross-border transfers with standard analytics trade-offs

Avoid If: You keep sensitive financial documents in linked accounts

Key Findings

Data Security - 3 findings (1 critical, 2 high)

Network Security - 4 findings (3 medium, 1 low)

Code Safety - 0 findings

Privacy - 2 findings (2 medium)

Privacy Concerns

What Data is Collected

DolarApp collects identity documents, biometric verification data, transaction history, and behavioral usage data. Location data is gathered through Google Maps and Places integrations. Analytics and crash data are collected through Firebase.

Third-Party Data Sharing

User data is shared with the following third-party services:

  • AppsFlyer - Marketing analytics and attribution tracking
  • Facebook SDK - Social advertising and behavioral profiling
  • Jumio - Identity document verification processing
  • iProov - Biometric facial recognition verification
  • Persona - Identity verification services
  • Intercom - Customer support communications
  • Firebase - App analytics and diagnostics
  • Google Maps / Google Places - Location and address services
  • Pomelo - Financial services infrastructure
  • Lokalise - In-app content localization

Understanding the Scores

Category Score
Security 40/100
Privacy 65/100
Data Security 30/100
Network Security 70/100
Code Safety 55/100
Data Collection 75/100
Data Sharing 80/100
User Control 70/100

Positive Security Features

  • Secure transport protocols are applied to data moving between the device and the app's servers.

Areas for Improvement

  • How sensitive financial data is stored and handled inside the app needs strengthening to better protect personal and account information.
  • The range of third-party services that receive identity and behavioral data increases the overall risk surface for financial privacy.
  • Internal data handling practices should be tightened to reduce the chance of financial details being exposed through the app's own processes.

About This Analysis

App Details

Field Value
App DolarApp
Package com.dolarapp
Version 6.51.8 (Build 10673)
Scan Date 2026-02-05

Versions & scan history

ScanDateOverall score
#1 (current) 52/100