Scan results

    ARQ (formerly DolarApp)

    Android

    A digital dollar finance app that enables currency exchange, international payments, and a global Mastercard. Available in Mexico, Argentina, Colombia, and Brazil for remittances, travelers, and digital nomads with no hidden fees.

    CITT SCORE
    52
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Cross-border transfers with standard analytics trade-offs

    Not For: You keep sensitive financial documents in linked accounts

    What It Means For You

    User activity is shared with AppsFlyer and Facebook for marketing purposes. Financial identity verification relies on third-party services like Jumio and iProov, meaning ID documents and biometric data pass through external processors. Two critical findings in how user data is stored and handled internally add meaningful risk to financial information.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (14)

    Data Security

    3 total
    1 Critical
    2 High

    Network Security

    4 total
    3 Medium
    1 Low

    Code Security

    4 total
    1 Critical
    1 High
    2 Medium

    Privacy

    2 total
    2 Medium

    Permission Usage

    1 total
    1 Low

    Third-Party Services

    Pomelo, Intercom, iProov, Jumio, Persona, AppsFlyer, Facebook SDK, Firebase, Google Maps, Google Places, Lokalise

    Security Strengths

    • EncryptedSharedPreferences with AES-256-GCM properly implemented
    • HTTPS strictly enforced with cleartextTrafficPermitted=false
    • No JavaScript interfaces in app's own WebViews
    • Auto-backup disabled to prevent Google Drive uploads
    • No financial data in analytics events (PCI-DSS compliant)
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    banking
    cryptocurrency
    international payments
    identity verification
    biometric
    location
    camera
    ads

    Package

    com.dolarapp

    Version

    6.51.8 (Build 10673)

    Analysis Date

    Feb 5, 2026

    Classes Analyzed

    42,668

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 3 findings (1 critical, 2 high)

    Network Security - 4 findings (3 medium, 1 low)

    Code Safety - 0 findings

    Privacy - 2 findings (2 medium)

    Privacy Concerns

    What Data is Collected

    DolarApp collects identity documents, biometric verification data, transaction history, and behavioral usage data. Location data is gathered through Google Maps and Places integrations. Analytics and crash data are collected through Firebase.

    Third-Party Data Sharing

    User data is shared with the following third-party services:

    • AppsFlyer - Marketing analytics and attribution tracking
    • Facebook SDK - Social advertising and behavioral profiling
    • Jumio - Identity document verification processing
    • iProov - Biometric facial recognition verification
    • Persona - Identity verification services
    • Intercom - Customer support communications
    • Firebase - App analytics and diagnostics
    • Google Maps / Google Places - Location and address services
    • Pomelo - Financial services infrastructure
    • Lokalise - In-app content localization

    Understanding the Scores

    CategoryScore
    Security40/100
    Privacy65/100
    Data Security30/100
    Network Security70/100
    Code Safety55/100
    Data Collection75/100
    Data Sharing80/100
    User Control70/100

    Positive Security Features

    • Secure transport protocols are applied to data moving between the device and the app's servers.

    Areas for Improvement

    • How sensitive financial data is stored and handled inside the app needs strengthening to better protect personal and account information.
    • The range of third-party services that receive identity and behavioral data increases the overall risk surface for financial privacy.
    • Internal data handling practices should be tightened to reduce the chance of financial details being exposed through the app's own processes.

    About This Analysis

    App Details

    FieldValue
    AppDolarApp
    Packagecom.dolarapp
    Version6.51.8 (Build 10673)
    Scan Date2026-02-05

    Right of Reply

    Developer not yet contacted