ARQ (formerly DolarApp) Security & Privacy Scorecard
Android
User activity is shared with AppsFlyer and Facebook for marketing purposes. Financial identity verification relies on third-party services like Jumio and iProov, meaning ID documents and biometric data pass through external processors. Two critical findings in how user data is stored and handled internally add meaningful risk to financial information.
Best for
Cross-border transfers with standard analytics trade-offs
Avoid if
You keep sensitive financial documents in linked accounts
Findings
- 2 critical
- 3 high
- 7 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Universal File Access Enabled in Card Activation WebView
- Unencrypted SQLite Databases Storing Financial Data
- Missing Root Detection
Top privacy issues
- Extensive User Profiling Without Consent
- Missing Screenshot Protection (FLAG_SECURE)
- Facebook Debug Logging Enabled in Production
Full analysis
DolarApp
What This Means for You
User activity is shared with AppsFlyer and Facebook for marketing purposes. Financial identity verification relies on third-party services like Jumio and iProov, meaning ID documents and biometric data pass through external processors. Two critical findings in how user data is stored and handled internally add meaningful risk to financial information.
Recommendation: Use With Caution
Best For: Cross-border transfers with standard analytics trade-offs
Avoid If: You keep sensitive financial documents in linked accounts
Key Findings
Data Security - 3 findings (1 critical, 2 high)
Network Security - 4 findings (3 medium, 1 low)
Code Safety - 0 findings
Privacy - 2 findings (2 medium)
Privacy Concerns
What Data is Collected
DolarApp collects identity documents, biometric verification data, transaction history, and behavioral usage data. Location data is gathered through Google Maps and Places integrations. Analytics and crash data are collected through Firebase.
Third-Party Data Sharing
User data is shared with the following third-party services:
- AppsFlyer - Marketing analytics and attribution tracking
- Facebook SDK - Social advertising and behavioral profiling
- Jumio - Identity document verification processing
- iProov - Biometric facial recognition verification
- Persona - Identity verification services
- Intercom - Customer support communications
- Firebase - App analytics and diagnostics
- Google Maps / Google Places - Location and address services
- Pomelo - Financial services infrastructure
- Lokalise - In-app content localization
Understanding the Scores
| Category | Score |
|---|---|
| Security | 40/100 |
| Privacy | 65/100 |
| Data Security | 30/100 |
| Network Security | 70/100 |
| Code Safety | 55/100 |
| Data Collection | 75/100 |
| Data Sharing | 80/100 |
| User Control | 70/100 |
Positive Security Features
- Secure transport protocols are applied to data moving between the device and the app's servers.
Areas for Improvement
- How sensitive financial data is stored and handled inside the app needs strengthening to better protect personal and account information.
- The range of third-party services that receive identity and behavioral data increases the overall risk surface for financial privacy.
- Internal data handling practices should be tightened to reduce the chance of financial details being exposed through the app's own processes.
About This Analysis
App Details
| Field | Value |
|---|---|
| App | DolarApp |
| Package | com.dolarapp |
| Version | 6.51.8 (Build 10673) |
| Scan Date | 2026-02-05 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 52/100 |